DataStructures / Cyber Security Interview Questions
What is Cross-Site Scripting (XSS)?
Cross-Site Scripting is a web vulnerability where an attacker injects malicious JavaScript into a page viewed by other users, letting the script run in their browser under the trust of the vulnerable site.
| Type | Description |
| Stored XSS | Malicious script is saved on the server, e.g. in a comment, and served to every visitor |
| Reflected XSS | Script is embedded in a request, e.g. a URL parameter, and reflected back in the response |
| DOM-based XSS | Script executes purely through client-side JavaScript manipulating the page's DOM |
Because the script runs as the victim in their own browser, it can steal session cookies, log keystrokes, or redirect the page. Escaping output and setting a strict Content Security Policy are the main defenses.
Invest now in Acorns!!! 🚀
Join Acorns and get your $5 bonus!
Acorns is a micro-investing app that automatically invests your "spare change" from daily purchases into diversified, expert-built portfolios of ETFs. It is designed for beginners, allowing you to start investing with as little as $5. The service automates saving and investing. Disclosure: I may receive a referral bonus.
Invest now!!! Get Free equity stock (US, UK only)!
Use Robinhood app to invest in stocks. It is safe and secure. Use the Referral link to claim your free stock when you sign up!.
The Robinhood app makes it easy to trade stocks, crypto and more.
Webull! Receive free stock by signing up using the link: Webull signup.
More Related questions...
