1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cross-domain Referer leakage
3.1. http://www.stumbleupon.com/badge/embed/2/
3.2. http://www.stumbleupon.com/submit
4. Cross-domain script include
4.1. http://www.stumbleupon.com/badge/embed/2/
4.2. http://www.stumbleupon.com/badge/embed/2/
4.3. http://www.stumbleupon.com/submit
5. Cookie without HttpOnly flag set
6. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit?url=http:/ Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: su_sid=SmtOmG6tQUA2o- Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: su_sid=XtmT8yUp Set-Cookie: cmf_i=10678763484de8 Set-Cookie: cmf_spr=A%2FN; expires=Sun, 03-Jul-2011 01:41:48 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=13ff247be765bfd Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 49181 Date: Fri, 03 Jun 2011 01:41:48 GMT Age: 0 Via: 1.1 varnish Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <input type="hidden" name="url" value="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit HTTP/1.1 Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: su_sid=KUkshvxFTHqW Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: su_sid=y4yUONPr1WUfq Set-Cookie: cmf_i=19696947264de8 Set-Cookie: cmf_spr=A%2FN; expires=Sun, 03-Jul-2011 01:41:35 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=222d65df2202cad Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 7343 Date: Fri, 03 Jun 2011 01:41:35 GMT Age: 0 Via: 1.1 varnish Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /badge/embed/2/ |
GET /badge/embed/2/?url=http Host: www.stumbleupon.com Proxy-Connection: keep-alive Referer: http://www.pcmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 Content-Length: 1261 Date: Fri, 03 Jun 2011 17:54:42 GMT Age: 0 Via: 1.1 varnish Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link rel="stylesheet" href="http://cdn.stumble <script type="text/javascript" src="http://cdn.stumble ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit?url=http:/ Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: su_sid=bAvtii1HipTph Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: su_sid=MtF3Qnfw5tTQz Set-Cookie: cmf_i=4686958474de83 Set-Cookie: cmf_spr=A%2FN; expires=Sun, 03-Jul-2011 01:41:36 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=3e46984e9bbcb81 Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 49087 Date: Fri, 03 Jun 2011 01:41:36 GMT Age: 0 Via: 1.1 varnish Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta name="description" content="Submit a site to StumbleUpon" /> <link rel="stylesheet" href="http://cdn.stumble <!--[if lte IE 6]> ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://ajax ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://cdn.stumble <link rel="shortcut icon" href="http://cdn.stumble <title> ...[SNIP]... <noscript> <img src="http://b.scorec </noscript> ...[SNIP]... <div id="ff-install-helper" style="display: none;"> <img id="close-button" src="http://cdn.stumble <h2>Installing is Easy!<img src="http://cdn.stumble ...[SNIP]... <div style="padding: 35px 0 200px 320px;" class="clearfix"> <img src="http://cdn.stumble <h2 style="padding-top: 15px; margin-bottom: 25px; font-size: 20px;"> ...[SNIP]... <!-- end wrapper --> <script type="text/javascript" charset="utf-8" src="http://cdn.stumble ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /badge/embed/2/ |
GET /badge/embed/2/ HTTP/1.1 Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 Content-Length: 1023 Date: Fri, 03 Jun 2011 20:41:44 GMT Age: 0 Via: 1.1 varnish Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <link rel="stylesheet" href="http://cdn.stumble <script type="text/javascript" src="http://cdn.stumble ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /badge/embed/2/ |
GET /badge/embed/2/?url=http Host: www.stumbleupon.com Proxy-Connection: keep-alive Referer: http://www.pcmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 Content-Length: 1261 Date: Fri, 03 Jun 2011 17:54:42 GMT Age: 0 Via: 1.1 varnish Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <link rel="stylesheet" href="http://cdn.stumble <script type="text/javascript" src="http://cdn.stumble ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit HTTP/1.1 Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: su_sid=KUkshvxFTHqW Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: su_sid=y4yUONPr1WUfq Set-Cookie: cmf_i=19696947264de8 Set-Cookie: cmf_spr=A%2FN; expires=Sun, 03-Jul-2011 01:41:35 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=222d65df2202cad Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 7343 Date: Fri, 03 Jun 2011 01:41:35 GMT Age: 0 Via: 1.1 varnish Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://ajax ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://cdn.stumble ...[SNIP]... <!-- end wrapper --> <script type="text/javascript" charset="utf-8" src="http://cdn.stumble ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit HTTP/1.1 Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: su_sid=KUkshvxFTHqW Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: su_sid=y4yUONPr1WUfq Set-Cookie: cmf_i=19696947264de8 Set-Cookie: cmf_spr=A%2FN; expires=Sun, 03-Jul-2011 01:41:35 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=222d65df2202cad Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 7343 Date: Fri, 03 Jun 2011 01:41:35 GMT Age: 0 Via: 1.1 varnish Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.stumbleupon |
Path: | /hostedbadge.php |
GET /hostedbadge.php?s=2 HTTP/1.1 Host: www.stumbleupon.com Proxy-Connection: keep-alive Referer: http://www.pcmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Keep-Alive: timeout=30, max=100 Content-Type: text/html; charset=iso-8859-1 Content-Length: 413 Date: Fri, 03 Jun 2011 17:54:39 GMT Age: 0 Via: 1.1 varnish Connection: keep-alive function writeSuBadge () { var bdg = "<iframe src=\"http:\/\/www ...[SNIP]... |