Cross-Site Scripting: Running Your Code in Someone Else's Browser
The same bug as SQL injection, moved to the browser. How attacker text becomes attacker script in your users' sessions, the three flavours, and the layered fix.
Security From the Ground Up03