1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.ervik.as |
Path: | /index.php/citrix |
GET /index.php/citrix Host: www.ervik.as Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 01 Dec 2010 06:38:05 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-Powered-By: PHP/5.2.6 Set-Cookie: 28e923606f6b0f5de46e P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Content-Type: text/html; charset=utf-8 Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Wed, 01 Dec 2010 06:38:05 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <link rel="stylesheet" h ...[SNIP]... <a href="/index.php?option ...[SNIP]... |