Take a look at one of several good papers on the subject. This one was written by NGSSoftware, a company that has authored several auditing tools and research papers on the subject. http://www.nextgenss.com/papers/advanced_sql_injection.pdf Loki Fate Research Labs Internet Warfare and Intelligence http://www.fatelabs.com -----Original Message----- From: michael judge [mailto:mjudge3414at_private] Sent: Sunday, December 15, 2002 4:12 AM To: vuln-devat_private Subject: Cross site scripting explained Can anyone explain to me or point me to a paper that explains exactly what cross site scripting is, and how it could be useful/cause problems for someone? Thanks. Mike
This archive was generated by hypermail 2b30 : Wed Dec 18 2002 - 16:08:16 PST