1. Cross-site scripting (reflected)
1.1. http://pluckit.demandmedia.com/requests [apiKey parameter]
1.2. http://pluckit.demandmedia.com/requests [jsonpCallback parameter]
1.3. http://pluckit.demandmedia.com/requests [jsonpContext parameter]
2. Cross-domain Referer leakage
2.1. http://pluckit.demandmedia.com/Widgets/v1/PluckItMonetizationWidget/generated.js
2.2. http://pluckit.demandmedia.com/Widgets/v1/PluckItRelatedAdLinksWidget/generated.js
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://pluckit.deman |
Path: | /requests |
GET /requests?apiKey=c1e69f40 Host: pluckit.demandmedia.com Proxy-Connection: keep-alive Referer: http://mortgage Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: anonId=cff8d33d-b33f-4e84 |
HTTP/1.1 200 OK Cache-Control: public, must-revalidate Pragma: PluckOnDemandApiRev=7315 Content-Length: 920 Content-Type: application/json; charset=utf-8 Expires: Thu, 03 Feb 2011 19:03:22 GMT Server: Microsoft-IIS/6.0 P3P: policyref="/w3c/p3p.xml X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Thu, 03 Feb 2011 19:03:22 GMT dmpod.RequestService ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pluckit.deman |
Path: | /requests |
GET /requests?apiKey=c1e69f40 Host: pluckit.demandmedia.com Proxy-Connection: keep-alive Referer: http://mortgage Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: anonId=cff8d33d-b33f-4e84 |
HTTP/1.1 200 OK Cache-Control: public, must-revalidate Pragma: PluckOnDemandApiRev=7315 Content-Length: 4368 Content-Type: application/json; charset=utf-8 Expires: Thu, 03 Feb 2011 19:03:26 GMT Server: Microsoft-IIS/6.0 P3P: policyref="/w3c/p3p.xml X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Thu, 03 Feb 2011 19:03:25 GMT dmpod.RequestService ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pluckit.deman |
Path: | /requests |
GET /requests?apiKey=c1e69f40 Host: pluckit.demandmedia.com Proxy-Connection: keep-alive Referer: http://mortgage Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: anonId=cff8d33d-b33f-4e84 |
HTTP/1.1 200 OK Cache-Control: public, must-revalidate Pragma: PluckOnDemandApiRev=7315 Content-Length: 4388 Content-Type: application/json; charset=utf-8 Expires: Thu, 03 Feb 2011 19:03:29 GMT Server: Microsoft-IIS/6.0 P3P: policyref="/w3c/p3p.xml X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Thu, 03 Feb 2011 19:03:28 GMT dmpod.RequestService ...[SNIP]... 11a033338c2&t=' + trEscae8b1b2cb1(document |
Severity: | Information |
Confidence: | Certain |
Host: | http://pluckit.deman |
Path: | /Widgets/v1/PluckItM |
GET /Widgets/v1/PluckItM Host: pluckit.demandmedia.com Proxy-Connection: keep-alive Referer: http://mortgage Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: anonId=cff8d33d-b33f-4e84 |
HTTP/1.1 200 OK Cache-Control: max-age=28800 Content-Type: application/x-javascript Last-Modified: Wed, 08 Sep 2010 17:57:20 GMT Accept-Ranges: bytes ETag: "0c024487f4fcb1:23ca" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 P3P: policyref="/w3c/p3p.xml X-Powered-By: ASP.NET Date: Thu, 03 Feb 2011 16:31:57 GMT Set-Cookie: BIGipServerPluckit2 Content-Length: 100670 var PodTrimPath;(function() ...[SNIP]... <p>The Adobe Flash Player installed in this browser is out of date. <a href="http://www.adobe ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pluckit.deman |
Path: | /Widgets/v1/PluckItR |
GET /Widgets/v1/PluckItR Host: pluckit.demandmedia.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: anonId=cff8d33d-b33f-4e84 |
HTTP/1.1 200 OK Cache-Control: max-age=28800 Content-Length: 93601 Content-Type: application/x-javascript Last-Modified: Wed, 08 Sep 2010 17:57:24 GMT Accept-Ranges: bytes ETag: "01a874a7f4fcb1:23ca" Server: Microsoft-IIS/6.0 P3P: policyref="/w3c/p3p.xml X-Powered-By: ASP.NET Date: Thu, 03 Feb 2011 19:14:53 GMT Connection: close var PodTrimPath;(function() ...[SNIP]... <p>The Adobe Flash Player installed in this browser is out of date. <a href="http://www.adobe ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pluckit.deman |
Path: | /Widgets/v1/PluckItM |
GET /Widgets/v1/PluckItM Host: pluckit.demandmedia.com Proxy-Connection: keep-alive Referer: http://mortgage Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: anonId=cff8d33d-b33f-4e84 |
HTTP/1.1 200 OK Cache-Control: max-age=28800 Content-Type: application/x-javascript Last-Modified: Wed, 08 Sep 2010 17:57:20 GMT Accept-Ranges: bytes ETag: "0c024487f4fcb1:23ca" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 P3P: policyref="/w3c/p3p.xml X-Powered-By: ASP.NET Date: Thu, 03 Feb 2011 16:31:57 GMT Set-Cookie: BIGipServerPluckit2 Content-Length: 100670 var PodTrimPath;(function() ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pluckit.deman |
Path: | /requests |
GET /requests?apiKey=c1e69f40 Host: pluckit.demandmedia.com Proxy-Connection: keep-alive Referer: http://mortgage Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: anonId=cff8d33d-b33f-4e84 |
HTTP/1.1 200 OK Cache-Control: public, must-revalidate Pragma: PluckOnDemandApiRev=7315 Content-Length: 4367 Content-Type: application/json; charset=utf-8 Expires: Thu, 03 Feb 2011 16:31:59 GMT Server: Microsoft-IIS/6.0 P3P: policyref="/w3c/p3p.xml X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Thu, 03 Feb 2011 16:31:58 GMT dmpod.RequestService ...[SNIP]... |