1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://bats.blogs.nytimes |
Path: | /2010/11/19/yankees-pick |
GET /2010/11/19/yankees-pick Host: bats.blogs.nytimes.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 03:49:46 GMT Server: Apache X-Powered-By: PHP/5.1.6 Vary: Cookie X-Pingback: http://bats.blogs.nytimes Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 58480 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://gm ...[SNIP]... kees+spring+training ...[SNIP]... |