Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

POSTs can be forged too, if another vulnerable site permits Javascript on their domain accidentally (among other ways, but that's the big one).


Isn't that CSRF, though?


CSRF is what allows you to post. XSS is what happens after it is posted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: