1. Cookie scoped to parent domain
2. Cookie without HttpOnly flag set
2.1. http://ww30.1800baskets.com/deliverycalendarnew.do
2.2. http://ww30.1800baskets.com/include/cookieCloner.asp
2.3. http://ww30.1800baskets.com/shoppingbasket.do
2.4. http://ww30.1800baskets.com/template.do
3. Password field with autocomplete enabled
4. Cross-site scripting (reflected)
4.1. http://ww30.1800baskets.com/product.do [ShopperManagerEnterprise cookie]
4.2. http://ww30.1800baskets.com/product.do [ShopperManagerEnterprise cookie]
4.3. http://ww30.1800baskets.com/shoppingbasket.do [ShopperManagerEnterprise cookie]
4.4. http://ww30.1800baskets.com/shoppingbasket.do [ShopperManagerEnterprise cookie]
4.5. http://ww30.1800baskets.com/template.do [ShopperManagerEnterprise cookie]
5. Cross-domain Referer leakage
5.1. http://ww30.1800baskets.com/deliverycalendarnew.do
5.2. http://ww30.1800baskets.com/product.do
5.3. http://ww30.1800baskets.com/template.do
6. Cross-domain script include
6.1. http://ww30.1800baskets.com/deliverycalendarnew.do
6.2. http://ww30.1800baskets.com/product.do
6.3. http://ww30.1800baskets.com/shoppingbasket.do
6.4. http://ww30.1800baskets.com/template.do
Severity: | Low |
Confidence: | Firm |
Host: | http://ww30.1800baskets |
Path: | /include/cookieCloner.asp |
GET /include/cookieCloner.asp Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800flowers User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Mon, 09 May 2011 01:15:57 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Location: http://ww30.1800baskets Content-Length: 0 Set-Cookie: JSESSIONID=0000s Set-Cookie: ShopperManagerEnterprise Set-Cookie: FSESSIONID=847b741e4 Set-Cookie: brandCode=1001; Path=/; Domain=1800baskets.com Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache="set-cookie, set-cookie2" X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/plain Content-Language: en-US |
Severity: | Low |
Confidence: | Firm |
Host: | http://ww30.1800baskets |
Path: | /deliverycalendarnew.do |
POST /deliverycalendarnew.do Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Origin: http://ww30.1800baskets X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd Content-Length: 0 |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:18:13 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=00001N288 Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 52934 <html> <head> <link rel="stylesheet" type="text/css" href="http://media1 <script type="text ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://ww30.1800baskets |
Path: | /include/cookieCloner.asp |
GET /include/cookieCloner.asp Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800flowers User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Mon, 09 May 2011 01:15:57 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Location: http://ww30.1800baskets Content-Length: 0 Set-Cookie: JSESSIONID=0000s Set-Cookie: ShopperManagerEnterprise Set-Cookie: FSESSIONID=847b741e4 Set-Cookie: brandCode=1001; Path=/; Domain=1800baskets.com Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache="set-cookie, set-cookie2" X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/plain Content-Language: en-US |
Severity: | Low |
Confidence: | Firm |
Host: | http://ww30.1800baskets |
Path: | /shoppingbasket.do |
GET /shoppingbasket.do HTTP/1.1 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ShopperManagerEnterprise |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:18:26 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0000elBrn Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 146143 <html> <head> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Cache-Control <meta http-equiv="Expir ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://ww30.1800baskets |
Path: | /template.do |
GET /template.do?id=template3 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800flowers User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:16:16 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Set-Cookie: JSESSIONID=0000dNGqKXu Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache="set-cookie, set-cookie2" Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 37878 <html> <head> <meta http-equiv="Content-Type" content="text/html <title></title> <meta name="description" content="ThePopco ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /product.do |
POST /product.do HTTP/1.1 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Cache-Control: max-age=0 Origin: http://ww30.1800baskets User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ShopperManagerEnterprise Content-Length: 660 delDateColl=&persona ...[SNIP]... |
HTTP/1.1 500 Internal Server Error Date: Mon, 09 May 2011 01:18:24 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 34787 <html> <head> <meta http-equiv="Content-Type" content="text/html <meta name="robots" content="noindex,nofollow <title>Error Occurr ...[SNIP]... </tr> <form action="https://ww30 <input type="hidden" name="welcomePage" value="error.do" /> ...[SNIP]... <br> <input type="password" style="width:100px" name="password" class="textfield" maxlength="64" onkeypress="if(event ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /product.do |
GET /product.do?baseCode Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:19:00 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 83754 <html xmlns="http://www.w3.org xmlns:og="http://ogp.me xmlns:fb="http://www.face ...[SNIP]... <!-- lpAddVars('visitor', lpAddVars('page','pageid' //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /product.do |
GET /product.do?delDateColl= Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Cache-Control: max-age=0 Origin: http://ww30.1800baskets User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ShopperManagerEnterprise |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:29:00 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0000XUNWu9J Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 31981 <html> <head> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Cache-Control <meta http-equiv="Expir ...[SNIP]... <!-- lpAddVars('visitor', lpAddVars('page','pageid' //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /shoppingbasket.do |
GET /shoppingbasket.do HTTP/1.1 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ShopperManagerEnterprise |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:20:34 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 31975 <html> <head> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Cache-Control <meta http-equiv="Expir ...[SNIP]... <!-- lpAddVars('visitor', lpAddVars('page','pageid' //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /shoppingbasket.do |
GET /shoppingbasket.do Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Cache-Control: max-age=0 Origin: http://ww30.1800baskets User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ShopperManagerEnterprise |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:50:48 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 31981 <html> <head> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Cache-Control <meta http-equiv="Expir ...[SNIP]... <!-- lpAddVars('visitor', lpAddVars('page','pageid' //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /template.do |
GET /template.do?id=template3 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800flowers User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:17:14 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 37911 <html> <head> <meta http-equiv="Content-Type" content="text/html <title></title> <meta name="description" content="ThePopco ...[SNIP]... <!-- lpAddVars('visitor', lpAddVars('page','pageid' //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /deliverycalendarnew.do |
POST /deliverycalendarnew.do Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Origin: http://ww30.1800baskets X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd Content-Length: 0 |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:18:13 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=00001N288 Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 52934 <html> <head> <link rel="stylesheet" type="text/css" href="http://media1 <script type="text/javascript" src="http://media1 ...[SNIP]... <span class="calNavText"><img alt="Previous" src="http://media3 ...[SNIP]... <span class="calNavText"><img alt="Next" src="http://media3 ...[SNIP]... <span id="shipMessageFed" class="shipMsg"><img src="http://media2 <span id="shipMessage" class="shipMsg"><img src="http://media2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /product.do |
GET /product.do?baseCode Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:17:19 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 83726 <html xmlns="http://www.w3.org xmlns:og="http://ogp.me xmlns:fb="http://www.face ...[SNIP]... <meta property="og:type" content="product_service" <link rel="image_src" href="http://media3 <!-- /*Defect Id:INC000000351640 User:201815 Date:Sep-29-2010 Reason:Meta Tag Change Start*/ --> ...[SNIP]... <link rel="canonical" href="http://www <link rel="shortcut icon" href="http://media6 <link rel="stylesheet" type="text/css" href="http://media1 <!-- global css zone --> ...[SNIP]... </style> <script src="http://w.sharethis ...[SNIP]... </script> <link rel="stylesheet" type="text/css" href="http://media6 </head> ...[SNIP]... </a><img src="http://media5 ...[SNIP]... </a><img src="http://media5 ...[SNIP]... </a><img src="http://media5 ...[SNIP]... <a href="http://ww30 <img src="http://media1 </a> ...[SNIP]... <a href="http://ww30 ...[SNIP]... </div> <script type="text/javascript" src="http://media3 ...[SNIP]... <div id="enlargeImgHide" onMouseOut="hideObject( <img name="bigimage" src="http://media3 border="0" alt="Popcorn Snack Tin - 1800baskets.com" /> </div> ...[SNIP]... <td valign="top" id="trsHeader"> <img border="0" src="http://media5 </td> ...[SNIP]... <td valign="top" id="trsHeader"> <img border="0" src="http://media5 </td> ...[SNIP]... <div class="trsProductImage"> <img id="prodimg" name="prodimg" src="http://media3 alt="Popcorn Snack Tin - 1800baskets.com" /> ...[SNIP]... ');" id="calendarLink" class="calendarImage"> <img src="http://media2 alt="Calendar" width="16" height="16" border="0" /> ...[SNIP]... <td align="left" style="padding-top: 10px; padding-right:8px;"> <img src="http://media5 height="10" /> ...[SNIP]... <br /> <img src="http://media5 </td> ...[SNIP]... <a id="verify" name="verify" href="javascript src="http://media6 border="0" id="btnAddToBasket" /> ...[SNIP]... <a id="verifyd" name="verifyd"><img src="http://media6 border="0" id="btnAddToBasket" /> ...[SNIP]... <input value="0" name="Tab_1_state" type="hidden"> <link rel="stylesheet" type="text/css" href="http://media4 <table id="Tab_1_table" border="0" cellSpacing="0" cellPadding="0" class="gui-tab" width="100%"> ...[SNIP]... <div id = "prodMOP7" class = "prodMOP7"> <img src="http://a764.g.akamai </div> ...[SNIP]... <a href="http://ww30 <img src="http://media6 ...[SNIP]... <div class="trsFooterLinks"> <a class="footerlink" href="http://help ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... </a> - Send us <a class="copylink" href="http://vovici.com ...[SNIP]... </div> <script type="text/javascript" src="http://media1 <script type="text/javascript" src="http://media3 <script type="text/javascript" src="http://media6 <script type="text/javascript" src="http://media3 ...[SNIP]... </script> <script type="text/javascript" src="http://media5 ...[SNIP]... </script> <script src="http://connect ...[SNIP]... <div id="rr_allpages"><script type="text/javascript" src="http://media ...[SNIP]... <!-- Mercent Tag Start --> <script src="https://cdn.mercent type="text/javascript"> ...[SNIP]... <noscript><img src="https://link.mercent style="display: none"> ...[SNIP]... </div><script type="text/javascript" src="//libs.coremetrics <script type="text/javascript" src="http://media1 ...[SNIP]... </script> <script language="javascript1.1" src="http://media2 ...[SNIP]... <!-- End LP Custom Variables--> <iframe frameborder="0" width="0" height="0" src="http://adsfac.us/pct <img src="http://xcdn.xgraph </body> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /template.do |
GET /template.do?id=template3 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800flowers User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:16:16 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Set-Cookie: JSESSIONID=0000dNGqKXu Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache="set-cookie, set-cookie2" Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 37878 <html> <head> <meta http-equiv="Content-Type" content="text/html <title></title> <meta name="description" content="ThePopco ...[SNIP]... <link rel="canonical" href="http://www <link rel="shortcut icon" href="http://media6 <link rel="stylesheet" type="text/css" href="http://media1 <!-- global css zone --> ...[SNIP]... </a><img src="http://media5 ...[SNIP]... </a><img src="http://media5 ...[SNIP]... </a><img src="http://media5 ...[SNIP]... <a href="http://ww30 <img src="http://media1 </a> ...[SNIP]... <a href="http://ww30 ...[SNIP]... </div> <script type="text/javascript" src="http://media3 ...[SNIP]... </div><script type="text/javascript" src="//libs.coremetrics <script type="text/javascript" src="http://media1 ...[SNIP]... <td colspan="2" valign="top" align="center" zone="2"> <link rel="stylesheet" type="text/css" href="http://media1 ...[SNIP]... <a href="../collection.do ...[SNIP]... <a href="../product.do ...[SNIP]... <a href="../product.do ...[SNIP]... <a href="../product.do ...[SNIP]... <a href="../collection.do ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... <a href="../collection.do ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... <a href="../collection.do ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... <a href="../collection.do ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... <div class="trsFooterLinks"> <a class="footerlink" href="http://help ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... </a> <img src="http://media5 ...[SNIP]... </a> - Send us <a class="copylink" href="http://vovici.com ...[SNIP]... <div id="rr_allpages"><script type="text/javascript" src="http://media ...[SNIP]... <!-- pageid END --> <script language="javascript1.1" src="http://media2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /deliverycalendarnew.do |
POST /deliverycalendarnew.do Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Origin: http://ww30.1800baskets X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd Content-Length: 0 |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:18:13 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=00001N288 Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 52934 <html> <head> <link rel="stylesheet" type="text/css" href="http://media1 <script type="text/javascript" src="http://media1 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /product.do |
GET /product.do?baseCode Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:17:19 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 83726 <html xmlns="http://www.w3.org xmlns:og="http://ogp.me xmlns:fb="http://www.face ...[SNIP]... </style> <script src="http://w.sharethis ...[SNIP]... </div> <script type="text/javascript" src="http://media3 ...[SNIP]... </div> <script type="text/javascript" src="http://media1 <script type="text/javascript" src="http://media3 <script type="text/javascript" src="http://media6 <script type="text/javascript" src="http://media3 ...[SNIP]... </script> <script type="text/javascript" src="http://media5 ...[SNIP]... </script> <script src="http://connect ...[SNIP]... <div id="rr_allpages"><script type="text/javascript" src="http://media ...[SNIP]... <!-- Mercent Tag Start --> <script src="https://cdn.mercent type="text/javascript"> ...[SNIP]... </div><script type="text/javascript" src="//libs.coremetrics <script type="text/javascript" src="http://media1 ...[SNIP]... </script> <script language="javascript1.1" src="http://media2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /shoppingbasket.do |
GET /shoppingbasket.do HTTP/1.1 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800baskets Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ShopperManagerEnterprise |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:18:26 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Pragma: no-cache Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0000elBrn Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 146143 <html> <head> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Cache-Control <meta http-equiv="Expir ...[SNIP]... <body onload='setDeliveryDates( <script type="text/javascript" src="http://media1 <script type="text/javascript" src="http://media3 ...[SNIP]... </div> <script type="text/javascript" src="http://media3 ...[SNIP]... <div id="rr_allpages"><script type="text/javascript" src="http://media ...[SNIP]... </div><script type="text/javascript" src="//libs.coremetrics <script type="text/javascript" src="http://media1 ...[SNIP]... </script> <script language="javascript1.1" src="http://media2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /template.do |
GET /template.do?id=template3 Host: ww30.1800baskets.com Proxy-Connection: keep-alive Referer: http://ww30.1800flowers User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000MKdbd |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:16:16 GMT Server: IBM_HTTP_Server P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAa IVDa CONo HISa TELo OUR DELa SAMo UNRo OTRo IND UNI NAV" Set-Cookie: JSESSIONID=0000dNGqKXu Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache="set-cookie, set-cookie2" Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/html; charset=UTF-8 Content-Language: en-US Content-Length: 37878 <html> <head> <meta http-equiv="Content-Type" content="text/html <title></title> <meta name="description" content="ThePopco ...[SNIP]... </div> <script type="text/javascript" src="http://media3 ...[SNIP]... </div><script type="text/javascript" src="//libs.coremetrics <script type="text/javascript" src="http://media1 ...[SNIP]... <div id="rr_allpages"><script type="text/javascript" src="http://media ...[SNIP]... <!-- pageid END --> <script language="javascript1.1" src="http://media2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ww30.1800baskets |
Path: | /include/cookieCloner.asp |
GET /robots.txt HTTP/1.0 Host: ww30.1800baskets.com |
HTTP/1.1 200 OK Date: Mon, 09 May 2011 01:15:59 GMT Server: IBM_HTTP_Server Last-Modified: Thu, 21 Apr 2011 18:22:34 GMT Content-Length: 127 Vary: Accept-Encoding X-Powered-By: 1800Flowers web server X-AspNet-Version: 1.21.366 Connection: close Content-Type: text/plain Content-Language: en-US # robots.txt for http://www.1800flowers User-agent: * Disallow: SITEMAP: http://www.1800flowers |