1. Cross-site scripting (reflected)
1.1. http://www.spambully.com/ [Referer HTTP header]
1.2. http://www.spambully.com/contact.php [Referer HTTP header]
1.3. http://www.spambully.com/register.php [Referer HTTP header]
Severity: | Low |
Confidence: | Certain |
Host: | http://www.spambully.com |
Path: | / |
GET / HTTP/1.1 Host: www.spambully.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Referer: http://www.google.com |
HTTP/1.1 200 OK Content-Type: text/html Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.3.5 X-Powered-By: ASP.NET Date: Tue, 26 Apr 2011 14:20:38 GMT Content-Length: 11901 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <img alt="" src="/tracker.php?domain ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.spambully.com |
Path: | /contact.php |
GET /contact.php HTTP/1.1 Host: www.spambully.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tracker=3067624; __utma=249553477 |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.3.5 X-Powered-By: ASP.NET Date: Tue, 26 Apr 2011 14:22:12 GMT Content-Length: 19976 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <img alt="" src="/tracker.php?domain ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.spambully.com |
Path: | /register.php |
GET /register.php HTTP/1.1 Host: www.spambully.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tracker=3067624; __utma=249553477 |
HTTP/1.1 200 OK Content-Type: text/html Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.3.5 X-Powered-By: ASP.NET Date: Tue, 26 Apr 2011 14:22:13 GMT Content-Length: 7806 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <img alt="" src="/tracker.php?domain ...[SNIP]... |