The web application does not filter user-controlled input for executable script disguised using doubling of the involved characters.
Impact: Read Application DataExecute Unauthorized Code or Commands
Strategy: Output Encoding
Strategy: Attack Surface Reduction
Effectiveness: Defense in Depth