1. Cross-site scripting (reflected)
1.1. http://bs.serving-sys.com/BurstingPipe/adServer.bs [h parameter]
1.2. http://bs.serving-sys.com/BurstingPipe/adServer.bs [w parameter]
1.3. http://bs.serving-sys.com/BurstingPipe/adServer.bs [eyeblaster cookie]
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://bs.serving-sys.com | 
| Path: | /BurstingPipe/adServer.bs | 
| GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://dm.travelocity.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.41 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Cache-Control: no-cache, no-store Connection: close Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT P3P: CP="NOI DEVa OUR BUS UNI" Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A2=eEn39Ir+07ft0000820wrA Set-Cookie: B2=76Kr0820wrA; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: C3=0uyK820wrA0000001_; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: D3=0uyK005D820wrA; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: E2=07ft820wrA; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: u2=0367e1d9-da22-4de9 Set-Cookie: u3=1; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: U=0367e1d9-da22-4de9-8eb2 Vary: Accept-Encoding Content-Length: 2430 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... ig,ebRand).replace(/\ ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://bs.serving-sys.com | 
| Path: | /BurstingPipe/adServer.bs | 
| GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://dm.travelocity.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.41 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Cache-Control: no-cache, no-store Connection: close Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT P3P: CP="NOI DEVa OUR BUS UNI" Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A2=eEn29IrZ07ft0000820wrA Set-Cookie: B2=76Kr0820wrA; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: C3=0uyK820wrA0000001_; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: D3=0uyK005D820wrA; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: E2=07ft820wrA; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: u2=cde36ee6-38f7-46c7 Set-Cookie: u3=1; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: U=cde36ee6-38f7-46c7-bc2f Vary: Accept-Encoding Content-Length: 2430 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... Random\]/ig,ebRand) ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://bs.serving-sys.com | 
| Path: | /BurstingPipe/adServer.bs | 
| GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://dm.travelocity.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.41 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: eyeblaster=BWVal=&BWDate= | 
| HTTP/1.1 200 OK Cache-Control: no-cache, no-store Connection: close Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT P3P: CP="NOI DEVa OUR BUS UNI" Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A2=eEn29IrS07ft00008 Set-Cookie: B2=76Kr0820wrA6Dcf0820wrA Set-Cookie: C3=0t8k820wrA0000200 Set-Cookie: D3=0t8k005D820wrA0uy Set-Cookie: E2=07ftg410rA; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: u2=a471c162-f9b4-4640 Set-Cookie: u3=1; expires=Thu, 31-Dec-2037 22:00:00 GMT; domain=.serving-sys.com; path=/ Set-Cookie: U=a471c162-f9b4-4640-82eb Vary: Accept-Encoding Content-Length: 2565 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... \]/ig,ebRand).replace(/\[ ...[SNIP]... |