<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	  <title>Ask MetaFilter questions tagged with cross-site</title>
      <link>http://ask.metafilter.com/tags/cross-site</link>
      <description>Questions tagged with 'cross-site' at Ask MetaFilter.</description>
	  <pubDate>Tue, 22 May 2007 18:01:03 -0800</pubDate> <lastBuildDate>Tue, 22 May 2007 18:01:03 -0800</lastBuildDate>

      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>	  
	<item>
	<title>Kris-Kross Site Scripting</title>
	<link>http://ask.metafilter.com/63202/KrisKross%2DSite%2DScripting</link>	
	<description>Help explain how a hacker could perform a XSS exploit.  This &lt;a href=&apos;http://ez.no/community/articles/dangers_of_csrf_and_xss/xss_attacks&apos;&gt;article&lt;/a&gt; explains how a bad-guy could send a malicious query through an unvalidated  searchbox and essentially modify the html on the search results page.  What I don&apos;t understand is how the hacker could have this malicious code display on a page that I am browsing.  Except for unvalidated forum posts, how can a hacker inject malicious code into a webpage.  If I ensure that my forum posts don&apos;t allow HTML and I am not loading external js files, what do I have to worry about? </description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.63202</guid>
	<pubDate>Tue, 22 May 2007 18:01:03 -0800</pubDate>
	<category>cross-site</category>
	<category>csrf</category>
	<category>css</category>
	<category>scripting</category>
	<dc:creator>kaizen</dc:creator>
	</item>
	
	</channel>
</rss>

