Slide 41
Slide 41 text
XSS Attacks
• Stored: injected code permanently stored in
database, message forum, comment, etc.
• Reflected: injected code in live request to
server, reflected back in error message or
search result
• DOM: injected code in browser DOM
environment that causes scripts to run in
unexpected ways (eg, reading from URL)