0) A simple echo Hi there!! 1) The XMP tags in the script prevent the browser from interpreting this
Hi!!
2) See how we can send HTML and force the browser to interpret it
Hi!!
3) Can force the browser to load an image 4) Even load something from another website 5) Can cause the browser to execute javascript 6) More involved javascript or 7) After setting a cookie in browser 1, have browser 2 put this in the shared file. Have browser 1 view the strings in the shared file. OOPS! Browser 1 gets a popup displaying their secret. 8) After setting a cookie in browser 1, have browser 2 put this in the shared file. Have browser 1 view the strings in the shared file. OOPS! Browser 1 has now sent their secret cookie (for use in this domain) to a different domain!!