How is a cross-site scripting attack executed?
Force a currently authenticated end user to execute unwanted actions on a web app
Execute malicious client-side scripts injected to a client via a web app
Inject a database query via the input data from the client to a web app
Intercept communications between a client and a web server
Submit