September 24, 2002

Cross-site scripting danger

Kellie writes: "Cross-site scripting is a potentially dangerous security exposure that should be considered when designing a secure Web-based application. Users can unknowingly execute malicious scripts when viewing dynamically generated pages based on content provided by an attacker. An attacker can take over the user session before the user's session cookie expires. An attacker can connect users to a malicious server of the attacker's choice. This article describes the nature of the exposure, how it works, and has an overview of some recommended remediation strategies."



  • Security
