What is Cross-Site Scripting
Cross-site
scripting (XSS) is a type of computer security vulnerability typically
found in web applications that enables malicious attackers to inject
client-side script into web pages viewed by other users. An exploited
cross-site scripting vulnerability can be used by attackers to bypass
access controls such as the same origin policy. Cross-site scripting
carried out on websites were roughly 80% of all security
vulnerabilities documented by Symantec as of 2007. Their impact may
range from a petty nuisance to a significant security risk, depending on
the sensitivity of the data handled by the vulnerable site, and the
nature of any security mitigation implemented by the site's owner.
Post a Comment