Hacker News new | past | comments | ask | show | jobs | submit login

Depending on the application even if it's a multiple step operation, if the operation is purely based on session/cookies it's still possible to carry out a successful XSS attack.



Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: