Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 5965389
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 22, 20262026-05-22T19:37:22+00:00 2026-05-22T19:37:22+00:00

What exactly can a malicious user gain if the XSS input he enters will

  • 0

What exactly can a malicious user gain if the XSS input he enters will be viewed only by him? Is there anything he can gain?

I understand how XSS is a problem when the malicious user input will be viewed by all site users. But if each user view only his own input, his malicious input will be viewed only by him, so my questions:

  • can this affect other users indirectly in some way?
  • what can he gain from this?
  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-22T19:37:22+00:00Added an answer on May 22, 2026 at 7:37 pm

    What an attacker can gain with viewing that the xss attack vector he found works, is just that 🙂 But! Then he can use that attack vector, and there are several ways to do that.

    If it’s a non-persistent XSS vulnerability (aka reflected), then probably by sending a link (most probably obfuscated via a urlshortener) to potential victims.
    If it’s a persistent XSS vulnerability (i.e. stored as a comment like the one I’m writing now), then he would just make his post and wait.

    Now, what he can gain is a big talk. Just think what you could do if you could inject a script tag into a web page. You could then load a whole javascript file from your server.

    The malicious code would then steal some cookies perhaps (if those are not set httponly) and immediately post them via ajax to a backend application..which would probably notify the attacker and who knows..those cookies might be enough to login into that website as the victim.

    Well..there are many things an attacker can do..so please eliminate all XSS vulnerabilities you might have.

    XSS vulnerabilities mainly take advantage of the trust people have in other websites.
    Don’t underestimate the XSRF vulnerabilities which depend on the trust a website has on your browser (another big talk), and Sql Injection attacks.

    A few tips (I’m sure you know all about it but for the sake of completeness:

    • set httponly in cookies you use to authenticate users
    • use htmlentities when printing user input back to your output
    • use mysql_real_escape_string before storing user input into your db
    • do not perform critical actions (i.e. save/delete/modify articles) using GET requests..use POST for those (xsrf).

    Good luck!

    UPDATE:

    A few tools that can help:

    • Chrome plugin : Websecurify
    • Firefox Plugin: xss-me
    • Windows App: NetSparker Community Edition (free)
    • X-platrofm: SkipFish , wapiti
    • Nessus

    (I recommend SkipFish)

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

How exactly can I create a new directory using Emacs? What commands do I
How exactly can one implement a Log off function when using ASP.NET Forms Authentication
I know why I want to use private virtual functions, but how exactly can
how exactly I can use public methods (non-virtual) with NHibernate? I have this code:
How exactly using VB6 can I can call any Windows shell command as you
How can I highlight exactly one item (particularly a line on the x axis)
I can't remember exactly where I've seen this strange `1 (single-tick and the number
How can you detect exactly when the scroll bar appears in a UserControl? Is
Can someone explain what exactly the string 0 but true means in Perl? As
Can someone define what exactly 'POCO' means? I am encountering the term more and

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.