Talk With an Expert

Cross-Sight Scripting Vulnerabilities

Cross-Sight Scripting Vulnerabilities (PDF, 1.75MB)Published: 09 Jan, 2002
Created by:
Mark Shiarla

Cross-sight scripting is a vulnerability that is a potential threat to most Web servers and browsers. It is not a product specific attack. Servers that embed browser input into dynamically generated HTML pages can be manipulated into becoming a launch pad for running an attacker's malicious code. Servers that use static pages are immune to this type of attack because they have full control over how their Web pages will be interpreted. The attacker does not modify the content of the Website. The attacker merely inserts new script that can be executed by a browser. As a result, it is possible for the malicious code to run without the server or the end user realizing that anything different has happened.