1. Cross-site scripting (reflected)
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.legacy.com | 
| Path: | /legacies/2011/obituary | 
| GET /legacies/2011/obituary Host: www.legacy.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=179553081 | 
| HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:21:47 GMT Server: Microsoft-IIS/6.0 X-UA-Compatible: IE=EmulateIE7 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 44800 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> Betty Garret ...[SNIP]... <link rel="canonical" href="http://www.legacy ...[SNIP]... |