1. Cross-site scripting (reflected)
2. Content type is not specified
Severity: | High |
Confidence: | Certain |
Host: | http://init.zopim.com |
Path: | /register |
GET /register?tabId=%5Fflash Host: init.zopim.com Proxy-Connection: keep-alive Referer: http://cdn.zopim.com/swf Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmx=258922369 |
HTTP/1.1 200 OK Server: nginx Date: Thu, 28 Apr 2011 13:37:50 GMT Connection: keep-alive Content-Length: 1461 {"status": "online", "__status": "ok", "name": "Visitor 274294888", "settings": {"chat_request_form": {"show_form": true, "standard_fields": {"question": {"required": false, "id": "question", "label": ...[SNIP]... Leave a message"}, "online": {"window": "Leave a question or comment and our agents will try to attend to you shortly =)", "bar": "Click here to chat"}}}, "machineID": "1NXvtXqNxnjKLyTqQSN ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://init.zopim.com |
Path: | /register |
POST /register HTTP/1.1 Host: init.zopim.com Proxy-Connection: keep-alive Referer: http://cdn.zopim.com/swf Content-Length: 586 content-type: application/x-www-form Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmx=258922369 tabId=%5Fflash%5F09a ...[SNIP]... |
HTTP/1.1 200 OK Server: nginx Date: Thu, 28 Apr 2011 13:35:53 GMT Connection: keep-alive Content-Length: 1414 {"status": "online", "__status": "ok", "name": "Visitor 274292619", "settings": {"chat_request_form": {"show_form": true, "standard_fields": {"question": {"required": false, "id": "question", "label": ...[SNIP]... |