Skip to contentExploitQuest
LearnWeb Application SecurityCross-Site Scripting

Chapter 05 of 05 · Web Application Security

Cross-Site Scripting

The other four bugs let you break the server. This one lets you run code in somebody else's browser, with their session, from a value the page rendered without escaping it. A comment field becomes a way to become the moderator.

FreeMedium
3 lessons8 quiz questionsabout 9 minup to 60 XP
Start this chapterWhose Code Runs
  1. Whose Code Runs3 min
  2. Steal The Session3 min
  3. Escape On The Way Out3 min
  4. Practice quiz8 questions