1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.manta.com |
Path: | /c/mmc8r0d/united-parcel |
GET /c/mmc8r0d/united-parcel Host: www.manta.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 01 Dec 2010 06:32:12 GMT Content-Type: text/html; charset=UTF-8 Connection: close X-UA-Compatible: IE=EmulateIE8 Vary: Accept-Encoding Set-Cookie: tcc=one; path=/ Set-Cookie: member_session=UmFuZ Set-Cookie: refer_id=0000; domain=.manta.com; path=/ Set-Cookie: refer_id_persistent=0000; domain=.manta.com; path=/; expires=Fri, 30-Nov-2012 06:32:12 GMT Set-Cookie: cust_id=1291185132.857398 Via: 1.0 www.manta.com Content-Length: 53078 X-Varnish: 1243433237 Via: 1.1 varnish X-Served-By: ecnext42 X-Cache: MISS <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>United Parcel Serv ...[SNIP]... <input type="hidden" name="rld" value="http://www.manta ...[SNIP]... |