1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://about.bankofa |
Path: | /partnering-locally |
GET /partnering-locally Host: about.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Last-Modified: Mon, 06 Aug 2012 01:06:57 GMT Expires: Mon, 06 Aug 2012 01:06:58 GMT Date: Mon, 06 Aug 2012 01:06:57 GMT Content-Type: text/html;charset=utf-8 Cache-Control: max-age=2419200 Vary: Accept-Encoding,User Set-Cookie: JSESSIONID=967F62F1A Set-Cookie: NSC_bcpvu.cbolpgbnfsjdb X-Cache: MISS from 12.120.79.28 Via: 1.1 12.120.79.28:80 (cache/2.6.2.3.14.ATT) Connection: close <!DOCTYPE html> <!--[if lt IE 7]> <html xmlns="http://www.w3.org <!--[if IE 7]> <html xmlns="http: ...[SNIP]... <div id="social-widget" class="social-widget" title="/en-us/enterprise ...[SNIP]... |