1. Cross-site scripting (reflected)
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://arstechnica.com | 
| Path: | /security/news/2010/06 | 
| GET /security/news/2010/06 Host: arstechnica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close  | 
| HTTP/1.1 200 OK X-ID: .22/vm4 Link: <http://arst.ch/l44>; rel=shorturl Ars-Exec-Time: 0.064 Content-type: text/html Content-Length: 28557 Server: Joost NRG/0.0.1 X-Powered-By: Rainbows and unicorns Date: Fri, 07 Jan 2011 21:56:57 GMT X-Varnish: 295022905 Via: 1.1 varnish Connection: close X-Cache: MISS <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <link rel="canonical" href="http://arstechnica ...[SNIP]...  |