When an additional user clicks on this hyperlink, the browser executes the piece of code within the onclick attribute, hence replacing the string document.cookie with the list of cookies of the user that are active for the web page. As a outcome, this list of cookies is sent to the attacker.












