XSS Targeting Error Pages
CAPEC-198 · Detailed · Draft
An adversary distributes a link (or possibly some other query structure) with a request to a third party web server that is malformed and also contains a block of exploit code in order to have the exploit become live code in the resulting error page.
severity: Medium