How Prevalent Are XSS Vulnerabilities?
There's an excellent post over on Michael Sutton's blog on the prevalence of XSS Vulnerabilities (Hat Tip: ha.ckers.org blog). The looks first to Mitre's numbers on XSS and then moves on to searching Google to find XSS, potential search strings, how to automate the process, the actual detection and then provides results.
The raw results are below:
Unique sites identified by Google 288 Unique sites accessible at time of testing 272 Sites with confirmed XSS vulnerabilities 47 Percentage vulnerable 17.3%
From start to finish... it was a great read.
