1. Cross-site scripting (reflected)
1.1. http://snas.nbcuni.com/snas/api/getRemoteDomainCookies [callback parameter]
1.2. http://snas.nbcuni.com/snas/api/getRemoteDomainCookies [JSESSIONID cookie]
1.3. http://snas.nbcuni.com/snas/api/getRemoteDomainCookies [s_vi cookie]
2. Cookie without HttpOnly flag set
3. HTML does not specify charset
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://snas.nbcuni.com |
Path: | /snas/api/getRemoteD |
GET /snas/api/getRemoteD Host: snas.nbcuni.com Proxy-Connection: keep-alive Referer: http://www.nbc.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|26985E91 |
HTTP/1.1 200 OK Date: Fri, 11 Feb 2011 15:34:29 GMT Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8b DAV/2 mod_jk/1.2.30 X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=8AC6D7558 Cache-Control: max-age=10 Expires: Fri, 11 Feb 2011 15:34:39 GMT Content-Length: 137 Content-Type: text/html __nbcsnasadops.doSCa |
Severity: | Information |
Confidence: | Certain |
Host: | http://snas.nbcuni.com |
Path: | /snas/api/getRemoteD |
GET /snas/api/getRemoteD Host: snas.nbcuni.com Proxy-Connection: keep-alive Referer: http://my.nbc.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|26985E91 |
HTTP/1.1 200 OK Date: Fri, 11 Feb 2011 15:36:35 GMT Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8b DAV/2 mod_jk/1.2.30 X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=A298FC997 Cache-Control: max-age=10 Expires: Fri, 11 Feb 2011 15:36:45 GMT Content-Length: 185 Content-Type: text/html __nbcsnasadops.doSCa |
Severity: | Information |
Confidence: | Certain |
Host: | http://snas.nbcuni.com |
Path: | /snas/api/getRemoteD |
GET /snas/api/getRemoteD Host: snas.nbcuni.com Proxy-Connection: keep-alive Referer: http://www.nbc.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|26985E91 |
HTTP/1.1 200 OK Date: Fri, 11 Feb 2011 15:34:31 GMT Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8b DAV/2 mod_jk/1.2.30 X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=87B115732 Cache-Control: max-age=10 Expires: Fri, 11 Feb 2011 15:34:41 GMT Content-Length: 137 Content-Type: text/html __nbcsnasadops.doSCa |
Severity: | Low |
Confidence: | Firm |
Host: | http://snas.nbcuni.com |
Path: | /snas/api/getRemoteD |
GET /snas/api/getRemoteD Host: snas.nbcuni.com Proxy-Connection: keep-alive Referer: http://www.nbc.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|26985E91 |
HTTP/1.1 200 OK Date: Fri, 11 Feb 2011 15:34:14 GMT Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8b DAV/2 mod_jk/1.2.30 X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=634024310 Cache-Control: max-age=10 Expires: Fri, 11 Feb 2011 15:34:24 GMT Content-Length: 96 Content-Type: text/html __nbcsnasadops.doSCa |
Severity: | Information |
Confidence: | Certain |
Host: | http://snas.nbcuni.com |
Path: | /snas/api/getRemoteD |
GET /snas/api/getRemoteD Host: snas.nbcuni.com Proxy-Connection: keep-alive Referer: http://www.nbc.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|26985E91 |
HTTP/1.1 200 OK Date: Fri, 11 Feb 2011 15:34:14 GMT Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8b DAV/2 mod_jk/1.2.30 X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=634024310 Cache-Control: max-age=10 Expires: Fri, 11 Feb 2011 15:34:24 GMT Content-Length: 96 Content-Type: text/html __nbcsnasadops.doSCa |
Severity: | Information |
Confidence: | Firm |
Host: | http://snas.nbcuni.com |
Path: | /snas/api/getRemoteD |
GET /snas/api/getRemoteD Host: snas.nbcuni.com Proxy-Connection: keep-alive Referer: http://www.nbc.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|26985E91 |
HTTP/1.1 200 OK Date: Fri, 11 Feb 2011 15:34:14 GMT Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8b DAV/2 mod_jk/1.2.30 X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=634024310 Cache-Control: max-age=10 Expires: Fri, 11 Feb 2011 15:34:24 GMT Content-Length: 96 Content-Type: text/html __nbcsnasadops.doSCa |