Site-specific Cross-site Scripting Vulnerabilities Time to Patch, in Days
Site-specific vulnerabilities are a growing concern. The number of cross-site scripting vulnerabilities that affected specific sites in 2007 exceeds the total number of traditional vulnerabilities tracked. Moreover, the numbers presented in this section are also only representative of site-specific vulnerabilities that are reported voluntarily by security researchers to the XSSed Project archive. Other types of Web-application vulnerabilities are not covered.

Symantec Internet Security Threat Report, Vol. XIII
|