What is a cross-site scripting attack? @internet-class
What is a cross-site scripting attack?  @internet-class
Uploaded October 2016 | Updated September 2026, 1 hour ago
The explosion of JavaScript has created many security problems. One of the more important are so-called cross-site scripting attacks. These attacks attempt to violate the same origin policy normally used to protect content on web pages that may come from multiple sources. For example, JavaScript that is loaded by an HTML iFrame cannot normally access page contents outside of the iFrame, which could include sensitive information. However, in some cases badly designed web applications will allow users to accidentally run JavaScript in the context of the page—​frequently as the result of clicking on a link provided by the attacker. In other cases, social engineering is used to convince users to cut and paste a dangerous piece of JavaScript into their browser—​for example, to view the fictional Osama bin Laden death video.

Credits: Talking: Geoffrey Challen (Assistant Professor, Computer Science and Engineering, University at Buffalo). Producing: Greg Bunyea (Undergraduate, Computer Science and Engineering, University at Buffalo).

Part of the internet-class.org online internet course. A blue Systems Research Group (https://blue.cse.buffalo.edu) production.
What is a cross-site scripting attack?What is a URL similarity phishing attack?What are common HTTP protocol responses?What is metadata?What does JavaScript have to do with Java?What are some limitations of HTML hyperlinks?What is search engine optimization (SEO)?What do web crawlers miss?What are capacity achieving codes?What is a distributed denial of service (DDoS) attack?What is a zero-day exploit?What is a denial of service (DoS) attack?
internet-class |

What is a cross-site scripting attack?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER