Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Scope of XSS vulnerabilities 1

Status
Not open for further replies.

adam0101

Programmer
Jun 25, 2002
1,952
US
Are cross-site scripting attacks only a threat against visitors to your site, or could a crafty script kiddie actually cause a problem on the server (like deleting or reading files)?

Adam
 
Everything I read about CSS shows that in the worst case scenario, data from the culprit could get stored within a table on the server. Besides that, unless it leads to an SQL injection attack, nothing on the server would be in harm's way.

A definition of a CSS attack says this:

Cross-site scripting attacks exploit vulnerabilities in Web page validation by injecting client-side script code

Since it injects client-side script, there's really no way of getting to the server.

[monkey][snake] <.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top