1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://claimid.com |
Path: | /username |
GET /username15cd9"><img%20src%3da Host: claimid.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 04:16:57 GMT Server: Mongrel 1.1.4 Served-By: Joyent Status: 200 OK Cache-Control: no-cache Content-Type: text/html; charset=utf-8 Content-Length: 2950 Set-Cookie: _ruby_claimid=654940 Via: 1.1 claimid.com Vary: Accept-Encoding Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <meta http-equiv="x-xrds ...[SNIP]... |