1. Cross-site scripting (reflected)
2. Cross-domain script include
| Severity: | High |
| Confidence: | Certain |
| Host: | http://www.neoease.com |
| Path: | / |
| GET /?288dc</script><script Host: www.neoease.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Date: Mon, 02 Jan 2012 20:12:48 GMT Server: Apache X-Pingback: http://www.neoease.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 33859 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <meta charset="UTF-8" /> <title>NeoEase</title> ...[SNIP]... <a class=\"translate\" href=\"http://translate ...[SNIP]... |
| Severity: | Information |
| Confidence: | Certain |
| Host: | http://www.neoease.com |
| Path: | / |
| GET / HTTP/1.1 Host: www.neoease.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Date: Mon, 02 Jan 2012 20:12:37 GMT Server: Apache X-Pingback: http://www.neoease.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 33542 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <meta charset="UTF-8" /> <title>NeoEase</title> ...[SNIP]... </script> <script type="text/javascript" src="http://pagead2 ...[SNIP]... |