1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Firm |
Host: | http://www.aolnews.com |
Path: | /story/wikileaks-chief |
GET /story/wikileaks-chief Host: www.aolnews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 18 Dec 2010 01:07:27 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Keep-Alive: timeout=5, max=999989 Connection: Keep-Alive Content-Type: text/html X-Pad: avoid browser bug Content-Length: 64485 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... linkInternalFilters= s_265.mmxgo = true; s_265.prop1="story"; s_265.prop2="article"; s_265.prop12="http://www s_265.prop23="AP"; s_265.prop9="1462023"; var s_code=s_265.t();if(s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.aolnews.com |
Path: | /story/wikileaks-chief |
GET /story/wikileaks-chief Host: www.aolnews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 18 Dec 2010 01:07:26 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Keep-Alive: timeout=5, max=999966 Connection: Keep-Alive Content-Type: text/html X-Pad: avoid browser bug Content-Length: 64696 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |