1. Cross-site scripting (reflected)
1.1. http://b.scorecardresearch.com/beacon.js [c1 parameter]
1.2. http://b.scorecardresearch.com/beacon.js [c2 parameter]
1.3. http://b.scorecardresearch.com/beacon.js [c3 parameter]
1.4. http://b.scorecardresearch.com/beacon.js [c4 parameter]
1.5. http://b.scorecardresearch.com/beacon.js [c5 parameter]
1.6. http://b.scorecardresearch.com/beacon.js [c6 parameter]
3. Silverlight cross-domain policy
4. Cookie scoped to parent domain
4.1. http://b.scorecardresearch.com/b
4.2. http://b.scorecardresearch.com/p
5. Cookie without HttpOnly flag set
5.1. http://b.scorecardresearch.com/b
5.2. http://b.scorecardresearch.com/p
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3adf3e<script>alert(1)< Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://ad.doubleclick.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Wed, 04 May 2011 23:15:26 GMT Date: Wed, 27 Apr 2011 23:15:26 GMT Connection: close Content-Length: 1257 if(typeof COMSCORE=="undefined") ...[SNIP]... E.purge=function(a){try COMSCORE.beacon({c1:"3adf3e<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://ad.doubleclick.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Wed, 04 May 2011 23:15:26 GMT Date: Wed, 27 Apr 2011 23:15:26 GMT Connection: close Content-Length: 1257 if(typeof COMSCORE=="undefined") ...[SNIP]... on(a){try{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"3", c2:"60357018a1e8<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://ad.doubleclick.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Wed, 04 May 2011 23:15:26 GMT Date: Wed, 27 Apr 2011 23:15:26 GMT Connection: close Content-Length: 1257 if(typeof COMSCORE=="undefined") ...[SNIP]... c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"3", c2:"6035701", c3:"537427631c1f<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://ad.doubleclick.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Wed, 04 May 2011 23:15:26 GMT Date: Wed, 27 Apr 2011 23:15:26 GMT Connection: close Content-Length: 1257 if(typeof COMSCORE=="undefined") ...[SNIP]... comscore;for(b=a.length-1 COMSCORE.beacon({c1:"3", c2:"6035701", c3:"5374276", c4:"41748593de99a<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://ad.doubleclick.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Wed, 04 May 2011 23:15:26 GMT Date: Wed, 27 Apr 2011 23:15:26 GMT Connection: close Content-Length: 1257 if(typeof COMSCORE=="undefined") ...[SNIP]... a.length-1;b>=0;b--){f COMSCORE.beacon({c1:"3", c2:"6035701", c3:"5374276", c4:"41748593", c5:"61926988335dc<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://ad.doubleclick.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Wed, 04 May 2011 23:15:26 GMT Date: Wed, 27 Apr 2011 23:15:26 GMT Connection: close Content-Length: 1257 if(typeof COMSCORE=="undefined") ...[SNIP]... h-1;b>=0;b--){f=COMSCORE COMSCORE.beacon({c1:"3", c2:"6035701", c3:"5374276", c4:"41748593", c5:"61926988", c6:"aeeef<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: b.scorecardresearch.com |
HTTP/1.0 200 OK Last-Modified: Wed, 10 Jun 2009 18:02:58 GMT Content-Type: application/xml Expires: Thu, 28 Apr 2011 21:27:25 GMT Date: Wed, 27 Apr 2011 21:27:25 GMT Content-Length: 201 Connection: close Cache-Control: private, no-transform, max-age=86400 Server: CS <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*"/> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: b.scorecardresearch.com |
HTTP/1.0 200 OK Last-Modified: Thu, 15 Oct 2009 22:41:14 GMT Content-Type: application/xml Expires: Thu, 28 Apr 2011 21:27:25 GMT Date: Wed, 27 Apr 2011 21:27:25 GMT Content-Length: 320 Connection: close Cache-Control: private, no-transform, max-age=86400 Server: CS <?xml version="1.0" encoding="utf-8" ?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*" /> </allow-from> <grant-to> <resou ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /b |
GET /b?c1=2&c2=3000023&rn=0 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://domainhelp.search User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: image/gif Content-Length: 43 Pragma: no-cache Date: Wed, 27 Apr 2011 21:27:25 GMT Connection: close Set-Cookie: UID=25894b9d-24.143.206 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC" Expires: Mon, 01 Jan 1990 00:00:00 GMT Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate Server: CS GIF89a.............!..... |
Severity: | Information |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /p |
GET /p?c1=3&c2=6035701&c3 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://news.cnet.com/8301 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Location: http://ad.doubleclick.net Date: Wed, 27 Apr 2011 23:14:58 GMT Connection: close Set-Cookie: UID=25894b9d-24.143.206 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC" Expires: Mon, 01 Jan 1990 00:00:00 GMT Pragma: no-cache Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate Server: CS |
Severity: | Information |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /b |
GET /b?c1=2&c2=3000023&rn=0 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://domainhelp.search User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 200 OK Content-Type: image/gif Content-Length: 43 Pragma: no-cache Date: Wed, 27 Apr 2011 21:27:25 GMT Connection: close Set-Cookie: UID=25894b9d-24.143.206 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC" Expires: Mon, 01 Jan 1990 00:00:00 GMT Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate Server: CS GIF89a.............!..... |
Severity: | Information |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /p |
GET /p?c1=3&c2=6035701&c3 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://news.cnet.com/8301 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=25894b9d-24.143.206 |
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Location: http://ad.doubleclick.net Date: Wed, 27 Apr 2011 23:14:58 GMT Connection: close Set-Cookie: UID=25894b9d-24.143.206 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC" Expires: Mon, 01 Jan 1990 00:00:00 GMT Pragma: no-cache Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate Server: CS |
Severity: | Information |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /b |
GET /robots.txt HTTP/1.0 Host: b.scorecardresearch.com |
HTTP/1.0 200 OK Last-Modified: Wed, 06 Jan 2010 17:35:59 GMT Content-Length: 28 Content-Type: text/plain Expires: Thu, 28 Apr 2011 21:27:25 GMT Date: Wed, 27 Apr 2011 21:27:25 GMT Connection: close Cache-Control: private, no-transform, max-age=86400 Server: CS User-agent: * Disallow: / |