Imagine you are the owner of breddit.com, the number one social media site for the baking industry. You have an avid community of commenters who love sharing their bread knowledge.
Because the main use of your website is to facilitate discussion, users can add comments, which are saved to the database and displayed to other users.
Unfortunately the popularity of your site has also attracted the attention of hackers, who want to access your site for nefarious purposes.
A real attack might use cross-site scripting to steal another user's cookie, which can permit session hijacking.
Now you try. Inject a script tag to call the
upvote()function whenever the page is viewed.