Description
|
|
The presence of tags allowing the execution of active code should not be authorised in the URL. Cross Site scripting attacks (XSS) may allow a user's browser to execute codes. These codes, which are included in the targeted web page and executed on the user's computer, can be used for stealing session cookies and can also authenticate a malicious user passing off as a legitimate user on a vulnerable site.
|