1. Cross-site scripting (reflected)
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.veracode.com | 
| Path: | /index.php | 
| GET /index.php?option=com Host: www.veracode.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close  | 
| HTTP/1.1 200 OK Date: Thu, 08 Dec 2011 00:25:00 GMT Server: Apache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Thu, 08 Dec 2011 00:25:00 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=ISO-8859-1 Content-Length: 44776 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Search</title> <m ...[SNIP]... <a href="http://www.veracode ...[SNIP]...  |