An attack technique where a programming flaw allows an attacker to execute script in the victims's browser which can hijack user sessions, deface websites, possibly introduce worms, etc
Broken authentication and Sesion Management
Cross Site Request Forgery (CSRF)
SQL Injection
Cross Site Scripting (XSS)