Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
We have discovered 366,888 live websites that are affected by CVE-2011-4969.
| Product | |
| Category | JavaScript Frameworks |
| Vulnerable Domains | 366,888 live websites (2.28% of jQuery install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 120 versions ( 34% of all versions) |
| 105,243 websites | |
| 35,158 websites | |
| 21,836 websites | |
| 20,290 websites | |
| 17,786 websites | |
| 14,759 websites | |
| 13,446 websites | |
| 12,587 websites | |
| 10,278 websites | |
| 9,165 websites |
| .com | 163,434 websites |
| .de | 22,438 websites |
| .ru | 17,530 websites |
| .net | 14,401 websites |
| .org | 13,955 websites |
| .co.uk | 8,470 websites |
| .it | 7,161 websites |
| .cz | 7,106 websites |
| .pl | 7,097 websites |
| .jp | 6,719 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **.******.com | *** | ||
| *********.com | *** | ||
| ****.org | *,*** | ||
| ***********.net | *,*** | ||
| ***.***.cn | *,*** | ||
| ****.******.**.com | *,*** | ||
| ****.ru | *,*** | ||
| *********.de | *,*** | ||
| **.****.com | *,*** | ||
| ***.****.org | *,*** |