1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.iso.org |
Path: | /iso/catalogue_detail.htm |
GET /iso/catalogue_detail.htm Host: www.iso.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 02:16:11 GMT Server: Apache/2.2.11 (Unix) Last-Modified: Mon, 14 Feb 2011 03:00:00 GMT ETag: "11a2b073-01010000" Expires: Tue, 15 Feb 2011 03:00:00 GMT Content-Type: text/html;charset=utf-8 Content-Length: 10079 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <base href="http://www. ...[SNIP]... <a href="iso_catalogue ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.iso.org |
Path: | /iso/catalogue_detail.htm |
GET /iso/catalogue_detail.htm HTTP/1.1 Host: www.iso.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 02:16:05 GMT Server: Apache/2.2.11 (Unix) Last-Modified: Mon, 14 Feb 2011 03:00:00 GMT ETag: "11a2b073-01010000" Expires: Tue, 15 Feb 2011 03:00:00 GMT Content-Type: text/html;charset=utf-8 Content-Length: 10033 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <base href="http://www. ...[SNIP]... <!-- AddThis Button BEGIN --> <script type="text/javascript" src="http://s7.addthis ...[SNIP]... </div> <script src="http://www.google ...[SNIP]... |