1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.azbiz.com |
Path: | /articles/2010/12/17 |
GET /articles/2010/12/17 Host: www.azbiz.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: WWW Vary: Accept-Encoding Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Content-Type: text/html Date: Sat, 18 Dec 2010 03:41:46 GMT X-Loop: 1 Keep-Alive: timeout=300, max=4999 Expires: Thu, 19 Nov 1981 08:52:00 GMT Pragma: no-cache X-PHP-Engine: enabled Connection: close Set-Cookie: has_cookies=1 Set-Cookie: PHPSESSID=6b30bd632e Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC X-Cache-Info: not cacheable; response specified "Cache-Control: no-store" Real-Hostname: azbiz.com Content-Length: 44080 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Me ...[SNIP]... <iframe src="http://www.facebook ...[SNIP]... |