Cross-Site Scripting in a Nutshell Consider a web site that gathers user input User input is displayed back to user Validate address, search results, etc. Attacker crafts URL with a script in it and sends to victim Victim clicks on link Script in the URL is sent to server as user input User input displayed; script "reflected" back to client Script runs on client Which state do I live in? I am a resident of: alert ("You are vulnerable to cross-site scripting!");
Your consent to our cookies if you continue to use this website.