The Network Security. Org

RSS Feed

XSS (Cross Site Scripting) Cheat Sheet

July 1st, 2006 · No Comments


XSS is Cross Site Scripting. If you don’t know how XSS (Cross Site Scripting) works, this page virus.jpgprobably won’t help you. This page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion. This page will also not show you how to mitigate XSS vectors or how to write the actual cookie/credential stealing/replay/session riding portion of the attack. It will simply show the underlying methodology and you can infer the rest. Also, please note my XSS page has been replicated by the OWASP 2.0 Guide in the Appendix section with my permission. However, because this is a living document I suggest you continue to use this site to stay up to date.

Also, please note that most of these cross site scripting vectors have been tested in the browsers listed at the bottom of the page, however, if you have specific concerns about outdated or obscure versions please download them from Evolt. Please see the XML format of the XSS Cheat Sheet if you intend to use CAL9000 or other automated tools. XSS (Cross Site Scripting) Cheat Sheet

From around the Web

  • Advertisments