cross site scripting (XSS) attacks

  • Stored XSS
    .
  • Reflected XSS: escape all user output
    .
  • Protecting forms
    .
  • Don't forget HTML5 features!
    .
 


+ o -