While there are a ton of great free options that provide us with a CMS to power a website (Word Press, Drupal, etc.), it doesn't hurt to peek under the hood and get a feel for how these systems work.These scripts can even rewrite the content of the HTML page.For more details on the different types of XSS flaws, see: Types of Cross-Site Scripting.Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it.An attacker can use XSS to send a malicious script to an unsuspecting user.