National Institute of Standards and Technology
Package illustrating a test case

Test case 1769

Description

Basic [b]Cross-Site Scripting[/b] (XSS) in PHP.[br]
The attacker will write a JavaScript (hop.js) which reads the cookie and send it to: http://www.bad.com/getCookie.php which store it in a file.[br]

Flaws

Have any comments on this test case? Please, send us an email.