1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://blogs.forbes.com |
Path: | /firewall/2010/09/29/did |
GET /firewall/2010/09/29/did Host: blogs.forbes.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 24 Nov 2010 23:11:05 GMT Server: Apache/2.2.3 (Unix) PHP/5.2.6 X-Powered-By: PHP/5.2.6 Vary: Cookie,Accept-Encoding Set-Cookie: PHPSESSID=39d87f134d Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: max-age=1, private, must-revalidate Pragma: no-cache X-Pingback: http://blogs.forbes.com Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 134108 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <![CDATA[ */ var ppi_help_referer = '/firewall/2010/09/29/did var ppi_help_ismember = false; var ppi_abuse_popup = '<div class="help-popup-content ...[SNIP]... |