1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://ncaafootball |
Path: | /2010/11/06/joe-paterno |
GET /2010/11/06/joe-paterno Host: ncaafootball.fanhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 07 Nov 2010 08:55:09 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Set-Cookie: comment_by_existing Keep-Alive: timeout=5, max=999997 Connection: Keep-Alive Content-Type: text/html Content-Length: 86815 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... om,fleaflicker.com"; s_265.mmxgo = true; s_265.prop1="NCAAFB"; s_265.prop2="Article"; s_265.prop9="bsd:19706089 s_265.prop12="http:/ s_265.prop17="joe-paterno s_265.prop19="fanhouse s_265.prop22="StubHub"; s_265.prop21="commen var s_code=s_265.t();if(s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ncaafootball |
Path: | /2010/11/06/joe-paterno |
GET /2010/11/06/joe-paterno Host: ncaafootball.fanhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 07 Nov 2010 08:55:04 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Set-Cookie: comment_by_existing Keep-Alive: timeout=5, max=999972 Connection: Keep-Alive Content-Type: text/html Content-Length: 86889 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <link rel="canonical" href="http://ncaafootball ...[SNIP]... |