1. Cross-site scripting (reflected)
1.3. http://news.bbc.co.uk/2/hi/in_depth/sci_tech/green_room/default.stm [Referer HTTP header]
1.4. http://news.bbc.co.uk/2/hi/programmes/newsnight/ethical_man/default.stm [Referer HTTP header]
Severity: | High |
Confidence: | Certain |
Host: | http://news.bbc.co.uk |
Path: | /2/hi/in_depth/sci_tech |
GET /2/hi/in_depth/sci_tech Host: news.bbc.co.uk Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Cache-Control: max-age=0 Content-Type: text/html Date: Sat, 13 Nov 2010 08:32:07 GMT Keep-Alive: timeout=10, max=553 Expires: Sat, 13 Nov 2010 08:32:07 GMT Connection: close Set-Cookie: BBC-UID=64cced0e24dd Set-Cookie: BBC-UID=64cced0e24dd Content-Length: 99324 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-GB" xmlns="http://www.w3.org <hea ...[SNIP]... <!-- bbc.fmtj.page = { serverTime: 1289637127000, editionToServe: 'international', queryString: '9360e'-alert(1)- referrer: null, section: null, sectionPath: '/in_depth/sci_tech/green siteName: null, siteToServe: 'news', siteVersion: '4', storyId: '-', assetType: null, uri: ' ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://news.bbc.co.uk |
Path: | /2/hi/programmes |
GET /2/hi/programmes Host: news.bbc.co.uk Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Cache-Control: max-age=0 Content-Type: text/html Date: Sat, 13 Nov 2010 08:32:01 GMT Keep-Alive: timeout=10, max=725 Expires: Sat, 13 Nov 2010 08:32:01 GMT Connection: close Set-Cookie: BBC-UID=642c8d7e44fd Set-Cookie: BBC-UID=642c8d7e44fd Content-Length: 65639 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-GB" xmlns="http://www.w3.org <hea ...[SNIP]... <!-- bbc.fmtj.page = { serverTime: 1289637121000, editionToServe: 'international', queryString: '9a6f4'-alert(1)- referrer: null, section: null, sectionPath: '/programmes/newsnight siteName: null, siteToServe: 'newsnight', siteVersion: '4', storyId: '-', assetType: null, ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://news.bbc.co.uk |
Path: | /2/hi/in_depth/sci_tech |
GET /2/hi/in_depth/sci_tech Host: news.bbc.co.uk Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Apache Cache-Control: max-age=0 Content-Type: text/html Date: Sat, 13 Nov 2010 08:33:13 GMT Keep-Alive: timeout=10, max=782 Expires: Sat, 13 Nov 2010 08:33:13 GMT Connection: close Set-Cookie: BBC-UID=64cc8dae745d Set-Cookie: BBC-UID=64cc8dae745d Content-Length: 99396 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-GB" xmlns="http://www.w3.org <hea ...[SNIP]... <!-- bbc.fmtj.page = { serverTime: 1289637193000, editionToServe: 'international', queryString: null, referrer: 'http://www.google.com section: null, sectionPath: '/in_depth/sci_tech/green siteName: null, siteToServe: 'news', siteVersion: '4', storyId: '-', assetType: null, uri: '/2/hi/in_depth/sci_te ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://news.bbc.co.uk |
Path: | /2/hi/programmes |
GET /2/hi/programmes Host: news.bbc.co.uk Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Apache Cache-Control: max-age=0 Content-Type: text/html Date: Sat, 13 Nov 2010 08:32:42 GMT Keep-Alive: timeout=10, max=637 Expires: Sat, 13 Nov 2010 08:32:42 GMT Connection: close Set-Cookie: BBC-UID=44acdd4e547d Set-Cookie: BBC-UID=44acdd4e547d Content-Length: 65711 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-GB" xmlns="http://www.w3.org <hea ...[SNIP]... <!-- bbc.fmtj.page = { serverTime: 1289637162000, editionToServe: 'international', queryString: null, referrer: 'http://www.google.com section: null, sectionPath: '/programmes/newsnight siteName: null, siteToServe: 'newsnight', siteVersion: '4', storyId: '-', assetType: null, uri: '/2/hi/progra ...[SNIP]... |