
262 Chapter 6 9 XSS Exploited
Figure 6.21 Type2 Injection Along With a Top
Score
The point is, you can never trust the user. This not only includes data coming from Web
sites and forms, but also data being passed in via Flash or Java files, or executables. If the data
resides on the user's system, it should be considered insecure.
XSS Old School- Windows Mobile PIE 4.2
While the majority of Internet users view surf from their PC's, there is a small but growing
number of mobile users that access Web pages via their mobile devices. One of the more
popular browsers for the mobile world