cross site scripting to steal cookies