hi have jsp page in following lines

if(exception err) {   out.println (err.getmessage() + "<br/><br/>"); } 

may xss attacks want display above things without xss attacks thought ?

use c:out tag.

also see


