cross-site scripting (xss) attacks exploit vulnerabilities in web page validation by injecting client-side script code. common vulnerabilities that make your web applications susceptible to cross-site scripting attacks include failing to properly validate input, failing to encode output, and trusting the data retrieved from a shared database. to protect your application against cross-site scripting attacks, assume that all input is malicious. constrain and validate all input. encode all output that could, potentially, include html characters. this includes data read from files and databases.

Author: CodeCall Programming Forum

  • July 22, 2009 5:45 pm
