Cross-Site Scripting (XSS)


Not to be confused with XML Stylesheets (same acronym), cross-site scripting, also known as XSS, is a web security vulnerability that allows an attacker to compromise the interactions that users have with a vulnerable application. It works by manipulating a vulnerable web site so that it returns malicious JavaScript to users. When the malicious code executes inside a victim's browser, the attacker can fully compromise their interaction with the application.

Cross-site scripting vulnerabilities normally allow an attacker to masquerade as a user, carry out any actions that the user can perform, and access any of the user's data. If the user has privileged access within the application, then the attacker might be able to gain full control of all the application's functionality and data.

Watch this Radware Minute episode with Radware’s Uri Dorot to learn what Cross-Site Scripting (XSS) is, what the common XSS-based cyber attacks are, and how they can damage your applications and put your database at risk.

There are three main types of XSS attacks. These are: Reflected XSS - where the malicious script comes from the current HTTP request. Stored XSS - where the malicious script comes from the website's database. DOM-based XSS - where the vulnerability exists in client-side code rather than server-side code.

与Radware销售部门接洽

我们的专家将回答您的问题、评估您的需求,并帮助您了解哪些产品最适合您的业务。

已经是客户?

无论您需要支持或更多服务,还是需要解答有关我们产品和解决方案的问题,我们都会随时提供帮助。

公司地点
马上从知识库获得答案
获得免费在线产品培训
联系Radware技术支持部
加入Radware客户计划

参与社交

联系专家并加入有关Radware技术的对话。

Blog
安全研究中心
CyberPedia