1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://rover.ebay.com |
Path: | /idmap/0 |
GET /idmap/0?footer&cb=vjo Host: rover.ebay.com Proxy-Connection: keep-alive Referer: http://www.ebay.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: npii=btrm/svid%3D728 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 RlogId: p4n%60rujfudlwc%3D9vt Cache-Control: private, no-cache Pragma: no-cache Content-Type: text/json Date: Fri, 10 Dec 2010 18:39:40 GMT Connection: close try{vjo.dsf.assembly |