1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://static.wix.com |
Path: | /client/getComponent |
GET /client/getComponent Accept: */* Accept-Language: en-US Referer: http://static.wix.com x-flash-version: 10,1,102,64 Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Host: static.wix.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK X-Powered-By: PHP/5.2.6-1+lenny9 Last-Modified: Mon, 15 Nov 2010 08:23:15 GMT Etag: 785b80e09d49a8c8f04c Content-Type: text/xml Date: Sat, 20 Nov 2010 16:52:51 GMT Server: sputnik4 Accept-Ranges: bytes Cache-Control: private, max-age=10800 Age: 0 Expires: Sat, 20 Nov 2010 19:52:51 GMT x-cdn: Served by Cotendo Connection: Keep-Alive Content-Length: 45234 <?xml version="1.0" encoding="UTF-8" ?> <component-type-list <!-- filename = 5minMediaControl --> <component-type component_type="5minMedi ...[SNIP]... <!-- filename = wizard18780<a xmlns:a='http://www.w3 ...[SNIP]... |