XSS and XSRF

(OBJ 2.3 & 2.4)

Cross-Site Scripting (XSS)

https://www.maccgenics.com/index.html#default<script>alert(document.cookie)</script>

Session Management

Cross-Site Request Forgery (XSRF)