At any case, while in some vehicles, the server does receive the payload, it is important to note that the server does not necessarily embed the payload into the response page - the essence of DOM based XSS is that the client-side code does the embedding.

The DOM-based XSS attack concept is extended into the realm of non-JS client side code, such as Flash.

A registered user is commonly tracked using a session ID cookie authorizing them to post.URL Encoded example of Cookie Stealing URL: DOM-based Attack Example Unlike the previous two flavors, DOM based XSS does not require the web server to receive the malicious XSS payload.Instead, in a DOM-based XSS, the attacker abuses runtime embedding of attacker data in the client side, from within a page served from the web server. For example, an HTML page can have Java Script code that embeds the location/URL of the page into the page. In such case, an attacker can force the client (browser) to render the page with parts of the DOM (the location and/or the referrer) controlled by the attacker.The unsuspecting user is not required to interact with any additional site/link ( attacker site or a malicious link sent via email), just simply view the web page containing the code.

