1. Cross-site scripting (reflected)
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.opselect.com | 
| Path: | /ad_feedback/survey.adp | 
| GET /ad_feedback/survey.adp Host: www.opselect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close  | 
| HTTP/1.0 200 OK MIME-Version: 1.0 Date: Wed, 17 Nov 2010 18:03:37 GMT Server: AOLserver/4.0.10 Content-Type: text/html; charset=iso-8859-1 Content-Length: 7418 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>AOL Ad Feedback</title> <link rel="stylesheet" href="css/default.css" type="text/css"> <meta http-equiv="content ...[SNIP]... <input type='hidden' name='source' value=10198723><script>alert(1)< ...[SNIP]...  |