1. Cross-site scripting (reflected)
Severity: | Information |
Confidence: | Certain |
Host: | http://att.my.yahoo.com |
Path: | / |
GET / HTTP/1.1 Host: att.my.yahoo.com Proxy-Connection: keep-alive Referer: http://www.wireless.att Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: AO=o=1; B=4qhoo656b19gs&b=4&d |
HTTP/1.1 200 OK Date: Sun, 19 Dec 2010 16:26:14 GMT P3P: policyref="http://info Set-Cookie: U_mtupes=YToyOntzOjE Expires: Thu, 01 Jan 1995 22:00:00 GMT Last-Modified: Sun, 19 Dec 2010 16:26:14 GMT Cache-Control: private, no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: myc=d=99VsEJUq.loXk4 Set-Cookie: MYTMI=6; expires=Mon, 19-Dec-2011 16:26:14 GMT; path=/; domain=my.yahoo.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 247567 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html class="ua-wk ua-win"> <head> <script>var gTop = Number(new Date());</script> <script> if ( ...[SNIP]... <!-- PERF pid[15195]|user ...[SNIP]... |