1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
2.1. http://www.servicemagic.com/ext/706046
2.2. http://www.servicemagic.com/ext/793795
2.3. http://www.servicemagic.com/ext/795020
2.4. http://www.servicemagic.com/ext/795021
2.5. http://www.servicemagic.com/ext/795022
2.6. http://www.servicemagic.com/ext/795214
2.7. http://www.servicemagic.com/ext/795216
2.8. http://www.servicemagic.com/ext/795217
2.9. http://www.servicemagic.com/ext/795218
Severity: | Low |
Confidence: | Certain |
Host: | http://www.servicemagic |
Path: | /ext/706046 |
GET /ext/706046 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.0 200 OK Set-Cookie: ServerID=1231; path=/ Date: Fri, 03 Jun 2011 01:41:09 GMT Server: Apache/2 Set-Cookie: JSESSIONID=18F72EF85 Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:41:09 GMT; Path=/ Set-Cookie: csdcn=1307065269644; Expires=Mon, 02-Jun-2014 01:41:09 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:41:09 GMT; Path=/ Set-Cookie: csacn=746971; Expires=Mon, 02-Jun-2014 01:41:09 GMT; Path=/ P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=ISO <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- /rfs/home/guestHome.jsp --> <html xmlns="http://www.w3.org ...[SNIP]... <input type="hidden" name="referringUrl" value="/search?hl=en&q=823c1"><script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/706046 |
GET /ext/706046 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1230; path=/ Date: Fri, 03 Jun 2011 01:40:52 GMT Server: Apache/2 Set-Cookie: JSESSIONID=52C73CE3A Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csdcn=1307065252402; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csacn=3181196; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Location: / Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/793795 |
GET /ext/793795 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1210; path=/ Date: Fri, 03 Jun 2011 01:40:53 GMT Server: Apache/2 Set-Cookie: JSESSIONID=43AF1C280 Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csdcn=1307065253998; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Location: /sem/category.Siding Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/795020 |
GET /ext/795020 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1211; path=/ Date: Fri, 03 Jun 2011 01:40:52 GMT Server: Apache/2 Set-Cookie: JSESSIONID=719AD7007 Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csdcn=1307065252531; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Location: /sem/category.Landscape Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/795021 |
GET /ext/795021 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1227; path=/ Date: Fri, 03 Jun 2011 01:40:52 GMT Server: Apache/2 Set-Cookie: JSESSIONID=6EC4E034C Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csdcn=1307065252472; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Location: /sem/category.Landscape Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/795022 |
GET /ext/795022 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1212; path=/ Date: Fri, 03 Jun 2011 01:40:52 GMT Server: Apache/2 Set-Cookie: JSESSIONID=9E46A4A93 Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csdcn=1307065252815; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:52 GMT; Path=/ Location: /sem/category.Landscape Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/795214 |
GET /ext/795214 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1211; path=/ Date: Fri, 03 Jun 2011 01:40:53 GMT Server: Apache/2 Set-Cookie: JSESSIONID=BB1979C6D Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csdcn=1307065253250; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Location: /sem/task.Sunroom-or Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/795216 |
GET /ext/795216 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1210; path=/ Date: Fri, 03 Jun 2011 01:40:53 GMT Server: Apache/2 Set-Cookie: JSESSIONID=197C1203D Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csdcn=1307065253561; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Location: /sem/category.Additions Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/795217 |
GET /ext/795217 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1230; path=/ Date: Fri, 03 Jun 2011 01:40:53 GMT Server: Apache/2 Set-Cookie: JSESSIONID=1A4BC6D63 Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csdcn=1307065253659; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Location: /sem/category.Roofing Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.servicemagic |
Path: | /ext/795218 |
GET /ext/795218 HTTP/1.1 Host: www.servicemagic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Set-Cookie: ServerID=1212; path=/ Date: Fri, 03 Jun 2011 01:40:53 GMT Server: Apache/2 Set-Cookie: JSESSIONID=CA1CCF3AF Set-Cookie: psacn=; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csdcn=1307065253711; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: originatingSessionID Set-Cookie: psdcn=0; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Set-Cookie: csacn=8786438; Expires=Mon, 02-Jun-2014 01:40:53 GMT; Path=/ Location: /sem/category.Painting Content-Length: 0 P3P: CP='CAO DSP COR CUR ADMa DEVa PSDa CONi TELi OUR BUS PHY ONL UNI COM NAV INT STA GOV' Connection: close Content-Type: text/plain; charset=ISO-8859-1 |