1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.ecommerce |
Path: | /news/24293_phishing-does |
GET /news/24293_phishing-does Host: www.ecommerce-journal.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx Date: Sat, 11 Dec 2010 06:24:28 GMT Content-Type: text/html; charset=utf-8 Connection: close Set-Cookie: SESS318efe45f0731a63 Set-Cookie: mt_redirect=true; expires=Mon, 10-Jan-2011 02:17:12 GMT; path=/ Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 11 Dec 2010 02:17:12 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Length: 106783 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <title>Phishing does not fade, with financial brands as most exploited in junk mails | Ecommerce Journa ...[SNIP]... <a style="color: #ffffff;text-decoration: underline;" href="http://m.ecommerce ...[SNIP]... |