首页
提交漏洞
排行榜
市场
兑换
最新 PoC
搜索
社区
Pocsuite
Ceye.io
Paper
KCon
ZoomEye
关于
数据统计
漏洞市场
开发文档
相关说明
意见反馈
帮助
登录
注册
Toggle navigation
登录
首页
悬赏与排名
详情悬赏列表
PoC 悬赏列表
兑换
排行榜
提交新漏洞
漏洞库
漏洞列表
组件分类
漏洞分类
搜索
数据统计
Paper
漏洞分类
— 通用跨站脚本
英文名字
UXSS
漏洞详情:
UXSS(Universal Cross-Site Scripting通用跨站脚本)是一种利用浏览器或者浏览器扩展漏洞来制造产生XSS的条件并执行代码的一种攻击类型。常见的XSS攻击的是因为客户端或服务端的代码开发不严谨等问题而存在漏洞的目标网站或者应用程序。这些攻击的先决条件是页面存在漏洞,而它们的影响往往也围绕着漏洞页面本身的用户会话。换句话说,因为浏览器的安全功能的影响,XSS攻击只能读取受感染的会话,而无法读取其他的会话信息,也就是同源策略的影响。 UXSS保留了基本XSS的特点,利用漏洞,执行恶意代码,但是有一个重要的区别: UXSS可以在漏洞触发时访问浏览器打开或缓存的页面的所有会话(即使不同域的情况),不管会话对应的网站或应用程序有无xss漏洞。
相关漏洞
SSV ID
提交时间
漏洞等级
漏洞名称
漏洞状态
人气 | 评论
SSV-99044
2020-11-17
Evernote uxss漏洞
9927 | 0
SSV-97154
2018-02-27
mavo中noscript xss的安全绕过
2220 | 1
SSV-97113
2018-01-29
chrome: UXSS in DocumentLoader::createWriterFor
1789 | 0
SSV-97111
2018-01-29
chrome:Persistent UXSS via SchemaRegistry(CVE-2016-1676)
1653 | 0
SSV-97110
2018-01-29
chrome:UXSS via window.open() via file:// pages
1424 | 0
SSV-97107
2018-01-29
WebKit: UXSS via ContainerNode::parserInsertBefore(CVE-2017-2508)
1683 | 0
SSV-97057
2018-01-02
Samsung Internet Browser 6.2.01.12 SOP Bypass / UXSS
1251 | 0
SSV-96867
2017-11-16
Chrome < 62 UXSS(CVE-2017-5124)
2222 | 0
SSV-96616
2017-10-09
Apple Safari uxss(CVE-2017-7089)
1503 | 0
SSV-96298
2017-07-27
WebKit: JSC: UXSS via JSObject::putInlineSlow and JSValue::putToPrimitive(CVE-2017-7037)
1093 | 0
SSV-93184
2017-06-06
WebKit: UXSS via Document::prepareForDestruction and CachedFrame
1597 | 0
SSV-93183
2017-06-06
WebKit: UXSS via CachedFrameBase::restore
1501 | 0
SSV-93182
2017-06-06
WebKit: UXSS: CachedFrame doesn't detach openers(CVE-2017-2528)
1692 | 0
SSV-93150
2017-05-26
WebKit: UXSS through HTMLObjectElement::updateWidget(CVE-2017-2493)
1519 | 1
SSV-93148
2017-05-26
WebKit enqueuePageshowEvent / enqueuePopstateEvent Universal XSS(CVE-2017-2510)
1429 | 0
SSV-93147
2017-05-26
WebKit: UXSS via Editor::Command::execute(CVE-2017-2504)
1345 | 0
SSV-93146
2017-05-26
WebKit: UXSS via ContainerNode::parserRemoveChild
1314 | 0
SSV-93036
2017-04-24
Chrome Universal XSS using IDBKeyRange static methods(CVE-2015-1268)
1552 | 0
SSV-93035
2017-04-24
Chrome Universal XSS via ContainerNode::parserInsertBefore (CVE-2015-6755)
1049 | 0
SSV-93034
2017-04-24
Chrome Universal XSS using navigator.serviceWorker.ready (CVE-2015-1292)
1245 | 0
SSV-93033
2017-04-24
Chrome Universal XSS by loading a javascript: URI from an unloaded window (CVE-2015-1293)
1278 | 0
SSV-93032
2017-04-24
Chrome Universal XSS using stack overflow exceptions (CVE-2015-1303)
1177 | 0
SSV-93031
2017-04-24
Chrome Universal XSS using exceptions thrown from Object.observe (CVE-2015-1304)
1339 | 0
SSV-93030
2017-04-24
Chrome Universal XSS via the unload_event module (CVE-2015-6769)
1438 | 0
SSV-93029
2017-04-24
Chrome Universal XSS using document.adoptNode (CVE-2015-6770)
1009 | 0
SSV-93028
2017-04-24
Chrome Universal XSS using plugin objects (CVE-2015-6772)
955 | 0
SSV-93027
2017-04-24
Chrome Universal XSS via persistence of subframes (CVE-2015-6768)
982 | 0
SSV-93026
2017-04-24
Chrome Universal XSS using widget updates in ContainerNode::parserRemoveChild (CVE-2016-1630)
950 | 0
SSV-93025
2017-04-24
Chrome Universal XSS using Flash message loop (CVE-2016-1631)
950 | 0
SSV-93024
2017-04-24
Chrome Universal XSS by circumventing the unload event ( CVE-2016-1623)
952 | 0
SSV-93023
2017-04-24
Chrome Universal XSS using an intercepted native function (CVE-2016-1672)
952 | 0
SSV-93022
2017-04-24
Chrome Universal XSS using a FrameNavigationDisabler bypass (CVE-2016-1673)
946 | 0
SSV-93021
2017-04-24
Chrome Universal XSS via the interception of |Binding| with Object.prototype.create (CVE-2016-1674)
981 | 0
SSV-93020
2017-04-24
Chrome Universal XSS using deferred history loads (CVE-2016-1675)
1138 | 0
SSV-93019
2017-04-24
Chrome Universal XSS using a flaw in the load deferral logic
948 | 0
SSV-93007
2017-04-22
Chrome Universal XSS through adopting image elements (CVE-2016-1667)
1070 | 0
SSV-93004
2017-04-21
Chrome Universal XSS using iterables (CVE-2016-1668)
1081 | 0
SSV-93003
2017-04-21
Chrome Universal XSS via reentrancy in FrameLoader::startLoad (CVE-2016-1697)
1339 | 0
SSV-93002
2017-04-21
Chrome Universal XSS via same document navigations (CVE-2016-1711)
1303 | 0
SSV-93001
2017-04-21
Chrome Universal XSS by intercepting a UA shadow tree(CVE-2016-5204)
1037 | 0
SSV-93000
2017-04-21
Chrome Universal XSS via fullscreen element updates (CVE-2016-5207)
940 | 0
SSV-92999
2017-04-21
Chrome Universal XSS using an <input type="color"> element (CVE-2016-5208)
944 | 0
SSV-92998
2017-04-21
Chrome Security: Universal XSS through removing link elements (CVE-2017-5010)
913 | 0
SSV-92997
2017-04-21
Chrome Universal XSS by polluting private scripts with named properties (CVE-2017-5008)
1009 | 1
SSV-92996
2017-04-21
Chrome Universal XSS through bypassing ScopedPageSuspender with closing windows (CVE-2017-5007)
964 | 0
SSV-92994
2017-04-21
Chrome Universal XSS using late widget updates (CVE-2017-5006)
985 | 0
SSV-92974
2017-04-19
WebKit: UXSS via operationSpreadGeneric
1181 | 0
SSV-92969
2017-04-19
Apple WebKit: UXSS via PrototypeMap::createEmptyStructure
1179 | 1
SSV-92923
2017-04-07
WebKit: UXSS via a synchronous page load(CVE-2017-2480)
1636 | 0
SSV-92922
2017-04-07
WebKit: UXSS via a focus event and a link element (CVE-2017-2479)
1433 | 0
SSV-92883
2017-04-04
Apple WebKit: UXSS via Frame::setDocument (1)(CVE-2017-2364)
1695 | 0
SSV-92882
2017-04-04
Apple Webkit: UXSS with JSCallbackData(CVE-2017-2442)
1046 | 0
SSV-92881
2017-04-04
Apple Webkit: UXSS by accessing a named property from an unloaded window (CVE-2017-2367)
995 | 0
SSV-92880
2017-04-04
Apple WebKit: UXSS via disconnectSubframes (CVE-2017-2445)
1025 | 0
SSV-92824
2017-03-23
LastPass: FireFox error pages still load Content Scripts, allowing access to ExtensionProxyService
2280 | 0
SSV-92802
2017-03-20
Microsoft Internet Explorer Elevation of Privilege Vulnerability (CVE-2017-0154)
1386 | 0
SSV-92801
2017-03-20
Microsoft Edge allows remote attackers to bypass the Same Origin Policy(CVE-2017-0002)
1126 | 0
SSV-92706
2017-02-23
Apple WebKit: UXSS via Frame::setDocument (CVE-2017-2365)
1764 | 0
SSV-92704
2017-02-23
Apple WebKit: UXSS via FrameLoader::clear (CVE-2017-2363)
1437 | 0
SSV-90964
2016-03-10
Android Open Source Platform (AOSP) Browser UXSS
3286 | 0
×
您好,
续费请拨打客服热线,感谢您一直支持 Seebug!
010-57076191