1. Cross-site scripting (reflected)
| Severity: | High |
| Confidence: | Certain |
| Host: | http://rosetta.scree |
| Path: | /bestbuy/lookup_multiple |
| GET /bestbuy/lookup_multiple Host: rosetta.screenplayinc.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Content-Type: application/x-javascript Server: Google Frontend Cache-Control: no-cache Expires: Tue, 03 Jan 2012 01:52:27 GMT Date: Tue, 03 Jan 2012 01:52:27 GMT Content-Length: 84 Connection: close busopsLow.ExternalContent |