Study. uk . com
  1. Home
  2. All questions
  3. Question 464

CompTIA Security+ study material · question 464 of 611

What does cross-site scripting give the attacker access to?

  1. Whatever the site's origin can reach in the victim's browser
  2. The database directly
  3. The web server's file system
  4. The victim's operating system credentials
Show the answer

Answer: A. Whatever the site's origin can reach in the victim's browser

The script runs under the site's origin, so it inherits that origin's access to cookies, storage and the DOM.

Source: OWASP Cross Site Scripting Prevention Cheat Sheet (OWASP) — OWASP Cross Site Scripting Prevention Cheat Sheet › Introduction

Challenge yourself on this topic → Study as cards