1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.merriam |
Path: | /dictionary/epizootic |
GET /dictionary/epizooticcf53f</title><script Host: www.merriam-webster.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache/2.0.52 (Red Hat) X-Powered-By: PHP/4.3.9 Set-Cookie: pview=2; expires=Sat, 13-Nov-2010 10:15:18 GMT; path=/ Set-Cookie: ptime=1289643318; expires=Sat, 13-Nov-2010 10:15:18 GMT; path=/ Vary: Accept-Encoding Content-Type: text/html Content-Length: 29017 Date: Sat, 13 Nov 2010 10:05:18 GMT X-Varnish: 898451490 Age: 0 Via: 1.1 varnish Connection: close X-Cache: MISS <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta name="Description" content="De ...[SNIP]... <title>Epizooticcf53f</title><script ...[SNIP]... |