OWASP/wstg

Inappropriate content (Testing for Cross Site Script Inclusion)

Open

#954 opened on Jul 18, 2022

View on GitHub
 (8 comments) (0 reactions) (0 assignees) (1,624 forks)github user discovery
help wantedrevise

Repository metrics

Stars
 (9,439 stars)
PR merge metrics
 (PR metrics pending)

Description

4.11.13 Testing for Cross Site Script Inclusion is not a WEB vulnerability, is a Web Browser application vulnrability. The WSTG is a framework for WEB aplications testing and 4.11 is for client side applications but no client applications. This vulnerability only can affect to specific browsers like as ie6, in this case you need include all other cve vulnerabilities or all other browsers like as how to broken the origin policy from ie8.

This document shouldn't be.

Contributor guide