1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Firm |
Host: | http://blog.moviefone.com |
Path: | /2010/11/18/what-to-see |
GET /2010/11/18a264c"><a>858b47aab9a/what-to-see-this-weekend Host: blog.moviefone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:12:22 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Set-Cookie: GEO-174_121_222_18=usa%3A Set-Cookie: comment_by_existing Keep-Alive: timeout=5, max=999952 Connection: Keep-Alive Content-Type: text/html Content-Length: 72781 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <link rel="canonical" href="http://blog ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://blog.moviefone.com |
Path: | /2010/11/18/what-to-see |
GET /2010/11/18/what-to-see Host: blog.moviefone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:12:03 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Set-Cookie: GEO-174_121_222_18=usa%3A Set-Cookie: comment_by_existing Keep-Alive: timeout=5, max=999959 Connection: Keep-Alive Content-Type: text/html Content-Length: 73252 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <link rel="canonical" href="http://blog ...[SNIP]... |