1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://js.revsci.net |
Path: | /gateway/gw.js |
GET /gateway/gw.js?csid Accept: */* Referer: http://news.cnet.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: js.revsci.net Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Last-Modified: Sun, 07 Nov 2010 22:29:58 GMT Cache-Control: max-age=86400, private Expires: Mon, 08 Nov 2010 22:29:58 GMT Content-Type: application/javascript Date: Sun, 07 Nov 2010 22:29:58 GMT Content-Length: 128 /* * JavaScript include error: * The customer code "K055408F32C<SCRIPT>ALERT(1)< */ |