This material was presented on CorunhaJS by Murillo Henrique Pedroso Ferreira. Most of the content present here was based on the links in the end of this document.
Type of attack where it is possible to inject malicious code in de DOM by abusing the HTML/JS parsers. Typically done when the user input is not properly handled by the server or the client.