1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://api.nextag.com |
Path: | /goto.jsp |
GET /goto.jsp?p=56381&aff=y Host: api.nextag.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 09 Dec 2010 21:07:32 GMT Server: Apache-Coyote/1.1 Set-Cookie: nxtgPubId=30; Domain=.nextag.com; Path=/ Set-Cookie: lpage=http%3A%2F%2Fapi Set-Cookie: nxtgCmpKW=Apple+Laptops+a P3P: CP="IDC DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONo TELi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM CNT STA PRE" Set-Cookie: nxtgTestCookie=good; Domain=.nextag.com; Path=/ Set-Cookie: nxtgTestCookie=good; Domain=.nextag.com; Path=/ Set-Cookie: prf=WltbW1paWF9RXEQZ Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding,User Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <a href="/apple-laptop-a ...[SNIP]... |