1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://nationaljobs |
Path: | /a/all-jobs/list/q |
GET /a/all-jobs/list/q Host: nationaljobs.washing Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx Date: Sun, 14 Nov 2010 01:02:53 GMT Content-Type: text/html; charset=UTF-8 Connection: close Set-Cookie: gc=1; expires=Mon, 15-Nov-2010 01:02:53 GMT; path=/ Set-Cookie: sess=ct%3D4cdf353d; path=/; domain=nationaljobs Set-Cookie: sh3=id%3D11765277444 Set-Cookie: sh2=cso%3D4cdf353d%3Bslu Set-Cookie: shabts=none; expires=Thu, 13-Jan-2011 01:02:53 GMT; path=/; domain=nationaljobs Set-Cookie: shut=deleted; expires=Sat, 14-Nov-2009 01:02:52 GMT; path=/ Set-Cookie: shmk=deleted; expires=Sat, 14-Nov-2009 01:02:52 GMT; path=/ Set-Cookie: shup=fvt%3D4cdf353d%26ncs Cache-Control: no-cache, must-revalidate P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Content-Length: 21473 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... <a class="bread_crumbs" href="/a/all-jobs/list/q ...[SNIP]... |