Skip to content

What it blocks

Script injection

Someone tries to plant a script in one of your pages.

What it is

Script code sent as if it were ordinary text, hoping your site shows it back to other visitors, whose browsers would then run it.

  • <script> in a comment
  • An image tag with an onerror handler
  • A link that starts javascript:

Why it matters

A planted script acts as the visitor: it can take over their session, change what the page says, or send them somewhere else.

When it stops a real visitor

Editors that save HTML, such as a page builder or a blog's writing screen, send real markup that looks like this. Mark the request as real and that one field is let through.

What you will see most

The request contained a script.
The input was recognised as script code meant to run in a visitor's browser.
The request contained a script tag.
The input included a <script> tag.
The request contained HTML that runs script.
The input included a tag or attribute that makes a browser run code.
All 26 rules in this kind, as the rule set names them

For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.

  • 941100XSS Attack Detected via libinjection
  • 941110XSS Filter - Category 1: Script Tag Vector
  • 941120XSS Filter - Category 2: Event Handler Vector
  • 941130XSS Filter - Category 3: Attribute Vector
  • 941140XSS Filter - Category 4: Javascript URI Vector
  • 941160NoScript XSS InjectionChecker: HTML Injection
  • 941170NoScript XSS InjectionChecker: Attribute Injection
  • 941180Node-Validator Deny List Keywords
  • 941190IE XSS Filters - Attack Detected
  • 941200IE XSS Filters - Attack Detected
  • 941210Javascript Word Detected
  • 941220IE XSS Filters - Attack Detected
  • 941230IE XSS Filters - Attack Detected
  • 941240IE XSS Filters - Attack Detected
  • 941250IE XSS Filters - Attack Detected
  • 941260IE XSS Filters - Attack Detected
  • 941270IE XSS Filters - Attack Detected
  • 941280IE XSS Filters - Attack Detected
  • 941290IE XSS Filters - Attack Detected
  • 941300IE XSS Filters - Attack Detected
  • 941310US-ASCII Malformed Encoding XSS Filter - Attack Detected
  • 941350UTF-7 Encoding IE XSS - Attack Detected
  • 941360JSFuck / Hieroglyphy obfuscation detected
  • 941370JavaScript global variable found
  • 941390Javascript method detected
  • 941400XSS JavaScript function without parentheses