Cross-Sight ScriptingVulnerabilities
Cross-sight scripting is a vulnerability that is a potential threat to most Web servers and browsers. It is not a product specific attack. Servers that embed browser input into dynamically generated HTML pages can be manipulated into becoming a launch pad for running an attacker's malicious code. Servers that use static pages are immune to this type of attack because they have full control over how their Web pages will be interpreted. The attacker does not modify the content of the Website. The attacker merely inserts new script that can be executed by a browser. As a result, it is possible for the malicious code to run without the server or the end user realizing that anything different has happened.
Read the Complete Paper
Current Tags:
None
Add Tags:
|
Current Rating:
(0 votes)
Add Rating:
|
Similar content:
Cross Site Scripting (XSS) FAQ, in
Cross Site Scripting
A Web Developer's Guide to Cross-SiteScripting, in
Cross Site Scripting
Detection of SQL Injection and Cross-site ScriptingAttacks, in
Web Security
Sarbanes-Oxley: A Cross-Industry Email Compliance Challenge, in
Sarbanes Oxley
Post Comment
Cite in Modern Language Association (MLA) Style
"Cross-Sight ScriptingVulnerabilities" SANS Institute, , UTC.
03 Jul 2008, 23:39
<http://www.sans.org/reading_room/whitepapers/threats/478.php>
Cite in Chicago Style
Mark Shiarla, "Cross-Sight ScriptingVulnerabilities," http://www.sans.org/reading_room/whitepapers/threats/478.php (accessed
Jul 03, 2008
).