1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://slashdot.org |
Path: | /my/login |
POST /my/login HTTP/1.1 Referer: http://slashdot.org/my User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations) Cache-Control: no-cache Content-Type: application/x-www-form Host: slashdot.org Expect: 100-continue Accept-Encoding: gzip, deflate Content-Length: 74 returnto=&op=userlogin |
HTTP/1.1 200 OK Server: Apache/1.3.42 (Unix) mod_perl/1.31 X-Powered-By: Slash 2.005001 X-Fry: I have more important things to do today than laugh and clap my hands. X-XRDS-Location: http://slashdot.org Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Content-Length: 15013 Date: Tue, 08 Mar 2011 16:02:14 GMT X-Varnish: 1629930435 Age: 0 Connection: keep-alive <!DOCTYPE html> <html lang="en"> <head> <meta name="viewport" content="width=device <meta name="apple-mobile-web ...[SNIP]... <input type="text" name="unickname" value="6bcdc"style="x:expression ...[SNIP]... |