When i use method Get and intercept the request with any proxy tool. then Cross site scripting because of absence of server side validations. But in case of post method, as we know data flows in the body of the request and when i intercept any body parameter with the script, then again XSS executes.
I want to know do i need to do server side validations on each screen or is their any global thing which can save me from XSS. I am using Java J2