1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.wltx.com |
Path: | /news/story.aspx |
GET /news/story.aspx?storyid Host: www.wltx.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-Type: text/html; charset=iso-8859-1 Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 P3P: CP="CAO CUR ADM DEVa TAIi PSAa PSDa CONi OUR OTRi IND PHY ONL UNI COM NAV DEM" Cache-Control: private, max-age=480 Date: Fri, 19 Nov 2010 23:52:49 GMT Connection: close Connection: Transfer-Encoding Content-Length: 74700 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equ ...[SNIP]... <a href="mailto:klrice@wltx ...[SNIP]... |