> For the complete documentation index, see [llms.txt](https://infosecgirls.gitbook.io/infosecgirls-training/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://infosecgirls.gitbook.io/infosecgirls-training/appsec/web-application-pentesting/a7-cross-site-scripting/reflected-xss.md).

# Reflected XSS

## Parameter Based XSS - DVNA

**Step 1:** Login to the application and navigate to `http://192.168.31.112:9090/app/products`

**Step 2:** Click "Search Product". Enter some string and click "submit". Intercept the request using Burp.

**Step 3:** Modify the "name" parameter in the POST request body to `<script>alert(document.domain)</script>`. Forward the request

![](https://990422818-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LWGXF4oLcghA1GLq0CM%2F-LWqCcmo_1VLxmvtkl-R%2F-LWqCwQWRIhTqCg0Ql0m%2Fimage.png?alt=media\&token=ef66df01-3c70-4d75-ad59-29d17c6f7b1c)

**Step 4:** In the response, notice that `<script>alert(document.domain)</script>` is part of the HTML in the products page.&#x20;

![](https://990422818-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LWGXF4oLcghA1GLq0CM%2F-LWqCcmo_1VLxmvtkl-R%2F-LWqD9afRTWzJl-nbemf%2Fimage.png?alt=media\&token=84f6af90-6d4f-453c-b77a-7269eafc7dd4)

## You can try iframe's as well

`<iframe onload=alert('XSS');></iframe>`
