■ Attacking Other Users
70779c12.qxd:WileyRed 9/14/07 3:14 PM Page 411
Suppose that there are length restrictions on each of the fields, such that no
feasible attack string can be inserted into any of them. Nevertheless, you can
still deliver a working exploit, by using the following URL to span a script
across the three locations that you control:
https://myapp.com/account.php?page_id=”>
When the parameter values from this URL are embedded into the page, the
result is the following: