Cross-site scripting (XSS)


In WebGoat read the lessons under “Cross Site Scripting."



Work the exercises of "Cross Site Scripting.

The exercises to improve WebGoat are not mandatory (try them if you have experience with Java).  

To prevent this kind of attack in PHP as noted in

  • If you need to emit text in HTML that includes user input, use the function htmlentities or the function htmlspecialchars.
  • If you need to use an URL that can include user input, use the function urlencode



