★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/security_sources_article-4548.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Security Sources 3/5/2002 11:28

Cross-Site Scripting Vulnerabilities

CERT
Posted By: Jen Olson
3/5/2002

This PDF published by CERT gives a brief overview of cross-site scripting vulnerabilities and suggests solutions to the problem. "A CSS vulnerability is caused by the failure of a site to validate user input before returning it to the clients web-browser. > The essence of cross-site scripting is that an intruder causes a legitimate web server to send a page to a victim's browser that contains malicious script or HTML of the intruder's choosing. The malicious script runs with the privileges of a legitimate script originating from the legitimate web server.


Click here to go to this article.
Barbarians at the Gate
Aug 26

SatireWire: Hackers Beg Boring People to Stop Encrypting Email
Aug 26

Linux Security Week - August 26th 2002
Aug 26

Safety: Assessing The Infrastructure Risk
Aug 26

Decision Support: You Can't Outsource Liability For Security
Aug 26

Security At Your Service
Aug 26

Former Motorola Engineers Develop Secure, Reliable Web Server
Aug 26

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000