
The Cross-Site Scripting Framework (XSSF) is a  security tool designed to turn the XSS vulnerability exploitation task  into a much easier work. The XSSF project aims to demonstrate the real  dangers of XSS vulnerabilities, vulgarizing their exploitation. This  project is created solely for education, penetration testing and lawful  research purposes. 
XSSF allows creating a communication channel  with the targeted browser (from a XSS vulnerability) in order to  perform further attacks. Users are free to select existing modules (a  module = an attack) in order to target specific browsers. 
XSSF  provides a powerfull documented API, which facilitates development of  modules and attacks. In addition, its integration into the Metasploit Framework allows users to launch MSF browser based exploit easilly from an XSS vulnerability. 
