1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.nbclosangeles |
Path: | /results/ |
GET /results/?keywords=%2729cfb</script><script Host: www.nbclosangeles.com Proxy-Connection: keep-alive Referer: http://www.nbclosangeles Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ak-mobile-detected=no; snas_noinfo=1; cc=t; __qca=P0-408697682 |
HTTP/1.1 200 OK Server: Apache X-Server-Name: dv-c1-r2-u7-b6 Content-Type: text/html;charset=utf-8 Date: Sun, 12 Dec 2010 19:13:44 GMT Connection: close Vary: Accept-Encoding Content-Length: 116600 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... rr[1] + " typeArr[1]: " + typeArr[1]); var sortByStr = "&sort=date"; if (sortBy != undefined && sortBy != "") { sortByStr = "&sort=" + sortBy; } var keywordStr = "keywords=\'29cfb</script><script if (keyword != undefined) { keywordStr = "keywords=" + keyword; } var url = "/results/?" + keywordStr + typeStr + wssStr + sortByStr + timelineStr + "&adv=y"; windo ...[SNIP]... |