• Embed Doc
  • Readcast
  • Collections
  • CommentGo Back
Download
 
 
Cross-Site Scripting-Cross-Site Scripting-(XSS/CSS)(XSS/CSS)
sriram5gokul@gmail.comsriram5gokul@gmail.com Technology team Technology team
 
 
What is Cross Site Scripting?What is Cross Site Scripting?
Cross-site scriptingCross-site scripting
((
XSSXSS
) is a type of ) is a type of computer security vulnerability typicallycomputer security vulnerability typicallyfound in web applications whichfound in web applications whichallow code injection by malicious weballow code injection by malicious webusers (attackers) into the webusers (attackers) into the webpages viewed by other userspages viewed by other users
 This involves an attacker attempting to This involves an attacker attempting tomanipulate a web application so that itmanipulate a web application so that itembeds malicious script code in the pageembeds malicious script code in the pagedisplayed to the user. The browser thendisplayed to the user. The browser thenprocesses the injected code as if it wereprocesses the injected code as if it werelegitimate content of the web page - withlegitimate content of the web page - withthe corresponding security permissions.the corresponding security permissions.
 
 
What is Cross Site Scripting?What is Cross Site Scripting?
 The heart of the issue is that if  The heart of the issue is that if untrusted content can be introduceduntrusted content can be introducedinto a dynamic page, neither theinto a dynamic page, neither theserver nor the client has enoughserver nor the client has enoughinformation to recognize that this hasinformation to recognize that this hashappened and take protectivehappened and take protectiveactions.actions.
Used by attackers to bypass theUsed by attackers to bypass thesame origin policysame origin policy
of 00

Leave a Comment

You must be to leave a comment.
Submit
Characters: ...
You must be to leave a comment.
Submit
Characters: ...