5 ms·
Yes. They are referred to as "reflective" or "non-persistent" XSS vulnerabilities. The attacker might exploit these using for example an "invisible" iframe on a
by a1a 13y ago
Yes. They are referred to as "reflective" or "non-persistent" XSS vulnerabilities. The attacker might exploit these using for example an "invisible" iframe on a different website, and thus loading the vulnerable website, in the background, with the desired parameters.
This will result in the malicious javascript being executed "on the vuln. website", in the victims browser.
This (http://web.math.jjay.cuny.edu/fcm791/web2.0_Vulnerabilities.pdf http://web.math.jjay.cuny.edu/fcm791/web2.0_Vulnerabilities....) is a pretty good paper (jump to page 7) if you are interested.