Are cross-site scripting attacks only a threat against visitors to your site, or could a crafty script kiddie actually cause a problem on the server (like deleting or reading files)?
Everything I read about CSS shows that in the worst case scenario, data from the culprit could get stored within a table on the server. Besides that, unless it leads to an SQL injection attack, nothing on the server would be in harm's way.
A definition of a CSS attack says this:
Cross-site scripting attacks exploit vulnerabilities in Web page validation by injecting client-side script code
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.