1. Cross-site scripting (reflected)
1.1. http://bestbuy.shoplocal.com/bestbuy/new_user_entry.aspx [adref parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://bestbuy.shoplocal |
Path: | /bestbuy/new_user_entry |
GET /bestbuy/new_user_entry Host: bestbuy.shoplocal.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET P3P: CP="NON DSP TAIa PSAa PSDa OUR NOR IND ONL UNI COM NAV INT" Cache-Control: private, max-age=0 Expires: Tue, 03 Jan 2012 02:15:09 GMT Date: Tue, 03 Jan 2012 02:15:09 GMT Content-Length: 364 Connection: close <script language='javascript' type='text/javascript' |
Severity: | High |
Confidence: | Certain |
Host: | http://bestbuy.shoplocal |
Path: | /bestbuy/new_user_entry |
GET /bestbuy/new_user_entry Host: bestbuy.shoplocal.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET P3P: CP="NON DSP TAIa PSAa PSDa OUR NOR IND ONL UNI COM NAV INT" Cache-Control: private, max-age=0 Expires: Tue, 03 Jan 2012 02:15:09 GMT Date: Tue, 03 Jan 2012 02:15:09 GMT Content-Length: 344 Connection: close <script language='javascript' type='text/javascript' |