Skip to main content

Cross-site scripting - Wikipedia, the free encyclopedia

Popularity Report

Total Popularity Score: 0

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...

Rank

Related Lists

Bookmark History

Saved by 10 people (4 private), first by anonymouse user on 2007-10-13


Public Comment

on 2008-09-02 by benkjljsd

Clients input strings which when served is read as code. Serving entity encoding responses prevents this.

Public Sticky notes

70% of websites are open to XSS attacks

Highlighted by benkjljsd

HTML or XHTML and a client-side scripting language

Highlighted by benkjljsd

Java, Microsoft's ActiveX and VBScript, Adobe's Flash and ActionScript, and RSS and Atom feeds

Highlighted by benkjljsd

accessing blacklisted web resources

Highlighted by benkjljsd

non-persistent, persistent and DOM-based

Highlighted by benkjljsd