Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. Java
  3. Question
Java

Is the javascript in url executable?

Asked by Gillian Hamer Oct 11, 2022 1.0K views 1 answer
Share

About this question

 I am learning about "Session fixation" and have read the corresponding OWASP page.


In their Example 2 in the above page, they describe an attack via JavaScript, that is embedded in the URL like:


http://website.kom/[removed][removed]=”sessionid=abcd”;[removed]

I tried this with an embedded [removed]alert("XSS!!");[removed], but as expected, it did not work.


Is there ANY way an URL can run embedded JavaScript?


Note: This question is somewhat similar to Execute reflected XSS in URL, but I am talking about scripts in the URL, not from a HTTP header.

Your answer

1 Answer

More Java discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest Java Blogs

Guides, tips and career advice on Java from JanBask experts.