# Cross-site scripting

**URL:** <https://boards.straightdope.com/t/cross-site-scripting/594989>\
**Category:** About This Message Board\
**Created:** [September 2, 2011, 7:16pm UTC](https://boards.straightdope.com/t/cross-site-scripting/594989 "2011-09-02T19:16:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dallas\_Jones](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dallas_jones/32/3277_2.png) [@Dallas\_Jones](https://boards.straightdope.com/u/Dallas_Jones)\
**Post date:** [September 2, 2011, 7:16pm UTC](https://boards.straightdope.com/t/cross-site-scripting/594989/1 "2011-09-02T19:16:18Z")

</div>

I recently upgraded from an XP computer to a new Windows 7 machine and the latest Norton Anti-Virus and Utilities.

I am getting a message when I visit this board that ‘Windows has modified this page to prevent Cross-site scripting.’ I have had the machine up and running for 2 weeks and so far this is the only web site where I encounter this message.

Is this a possible source of the frequent complaints here about virus hi-jacks or some other issue or setting on my machine that should be changed.

Go ahead and move this to General Questions if you see fit, but I put it in ATMB beacuse this is the only place I have so far encountered the message.

> **[Cross-site scripting](https://en.wikipedia.org/wiki/Cross-site_scripting)**
>
> Cross-site scripting (XSS) is a type of security vulnerability that can be found in some web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. Cross-site scripting carried out on websites accounted for roughly 84% of all security vulnerabilities documented by Symantec up until 2007. XSS effects vary in 
> range from p

No lectures about using either Windows or Norton please.

---

<div class="post-metadata">

**Author:** ![kayT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kayt/32/3633_2.png) [@kayT](https://boards.straightdope.com/u/kayT)\
**Post date:** [September 2, 2011, 7:19pm UTC](https://boards.straightdope.com/t/cross-site-scripting/594989/2 "2011-09-02T19:19:32Z")

</div>

I get that error message at another site but never here.
