1. Cross-site scripting (reflected)
1.1. http://www.sqlmag.com/categories/category/t-sql-powershell-scripting [REST URL parameter 3]
2. Cross-domain Referer leakage
3. Cross-domain script include
4.1. http://www.sqlmag.com/DesktopModules/PentonMojo/Resources/Scripts/jquery.colorbox.js
4.2. http://www.sqlmag.com/Resources/Shared/scripts/DotNetNukeAjaxShared.js
4.3. http://www.sqlmag.com/Resources/Shared/scripts/widgets.js
Severity: | High |
Confidence: | Firm |
Host: | http://www.sqlmag.com |
Path: | /categories/category/t |
GET /categories/category/t Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Connection: keep-alive Set-Cookie: language=en-US; path=/; HttpOnly Set-Cookie: ContentURL=//categories/ Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET Content-Type: text/html; charset=utf-8 Date: Thu, 23 Jun 2011 14:52:43 GMT Content-Length: 57649 ETag: "pvf4624c5c987e6de4f Cache-Control: private X-PvInfo: [S10203.C70461.A45964.RA0 Vary: Accept-Encoding Accept-Ranges: none <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org <h ...[SNIP]... <script src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /categories/category/t |
GET /categories/category/t Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Connection: keep-alive Set-Cookie: language=en-US; path=/; HttpOnly Set-Cookie: ContentURL=//categories/ Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET Content-Type: text/html; charset=utf-8 Date: Thu, 23 Jun 2011 14:51:25 GMT Content-Length: 114296 ETag: "pv8f2d884894468243a Cache-Control: private X-PvInfo: [S10203.C70461.A45964.RA0 Vary: Accept-Encoding Accept-Ranges: none <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org <h ...[SNIP]... <script src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /categories/category/t |
GET /categories/category/t Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Connection: keep-alive Set-Cookie: language=en-US; path=/; HttpOnly Set-Cookie: ContentURL=//categories/ Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET Content-Type: text/html; charset=utf-8 Date: Thu, 23 Jun 2011 14:51:18 GMT Content-Length: 115054 ETag: "pvd8a581fda1d8f49a1 Cache-Control: private X-PvInfo: [S10203.C70461.A45964.RA0 Vary: Accept-Encoding Accept-Ranges: none <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org <h ...[SNIP]... <a href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /print/sql-server |
GET /print/sql-server Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Connection: keep-alive Set-Cookie: language=en-US; path=/; HttpOnly Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET Content-Type: text/html; charset=utf-8 Date: Thu, 23 Jun 2011 14:50:16 GMT Content-Length: 33000 ETag: "pv8a955dac828ac5ecd Cache-Control: private X-PvInfo: [S10203.C70461.A45964.RA0 Vary: Accept-Encoding Accept-Ranges: none <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org <h ...[SNIP]... <iframe src="http://www.facebook scrolling="no" frameborder="0" style="border:none; width:380px; height:40px; margin-top:20px;"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /404 |
GET /404?aspxerrorpath=/404 Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 404 Not Found Connection: keep-alive Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 Set-Cookie: language=en-US; path=/; HttpOnly Set-Cookie: ContentURL=//404 ; path=/; HttpOnly X-Powered-By: ASP.NET Date: Thu, 23 Jun 2011 13:43:50 GMT Content-Length: 39127 Cache-Control: private X-PvInfo: [S10203.C70461.A45964.RA0 Vary: Accept-Encoding Accept-Ranges: none <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org <h ...[SNIP]... <noscript><a href="http://www.omniture height="1" width="1" border="0" alt="" /> ...[SNIP]... <li class="first"><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li class="rmItem rmFirst"><a href="http://www ...[SNIP]... <li class="rmItem rmFirst"><a href="http://devconn ...[SNIP]... <li class="rmItem "><a href="http://elearning ...[SNIP]... <li class="rmItem rmLast"><a href="http://www ...[SNIP]... <li><a target="_blank" href="http://www ...[SNIP]... <li><a target="_blank" href="http://www.ittv.net ...[SNIP]... <li><a target="_blank" href="http://www.left ...[SNIP]... <li><a target="_blank" href="http://www ...[SNIP]... <li><a target="_blank" href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.penton ...[SNIP]... <li><a href="http://www.penton ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /categories/category/t |
GET /categories/category/t Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Connection: keep-alive Set-Cookie: language=en-US; path=/; HttpOnly Set-Cookie: ContentURL=//categories/ Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET Content-Type: text/html; charset=utf-8 Date: Thu, 23 Jun 2011 14:45:32 GMT Content-Length: 112765 ETag: "pv17c53290aa23a71b3 Cache-Control: private X-PvInfo: [S10203.C70461.A45964.RA0 Vary: Accept-Encoding Accept-Ranges: none <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xml:lang="en-US" lang="en-US" xmlns="http://www.w3.org <h ...[SNIP]... </script> <script language="javascript" src="http://pagead2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /DesktopModules |
GET /DesktopModules Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Type: application/x-javascript Last-Modified: Wed, 15 Jun 2011 15:35:12 GMT ETag: "pv2fe1ca7eb19362939 X-PvInfo: [S11101.C70461.A45914.RA0 Vary: Accept-Encoding Accept-Ranges: bytes Connection: Keep-Alive Date: Thu, 23 Jun 2011 14:11:53 GMT Age: 1533 Content-Length: 23666 // ColorBox v1.3.15 - a full featured, light-weight, customizable lightbox based on jQuery 1.3+ // Copyright (c) 2010 Jack Moore - jack@colorpowered.com // Licensed under the MIT license: http://www.opensource.org (function ($, window) { // ColorBox Default Settings. // See http://colorpowered.com va ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /Resources/Shared/scripts |
GET /Resources/Shared/scripts Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/javascript, application/javascript, */*; q=0.01 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Type: application/x-javascript Last-Modified: Mon, 21 Mar 2011 16:15:34 GMT ETag: "pv4a3eb4c5e9334813b X-PvInfo: [S11101.C70461.A45914.RA0 Vary: Accept-Encoding Accept-Ranges: bytes Connection: Keep-Alive Date: Thu, 23 Jun 2011 14:12:53 GMT Age: 2153 Content-Length: 10101 /* DotNetNuke. - http://www.dotnetnuke.com Copyright (c) 2002-2010 by DotNetNuke Corporation Permission is hereby granted, free of charge, to any person obtaining a copy of this softwar ...[SNIP]... <history> ''' Version 1.0.0: Feb. 28, 2007, Nik Kalyani, nik.kalyani@dotnetnuke ''' Version 1.0.1: Oct. 28, 2007, Nik Kalyani, nik.kalyani@dotnetnuke ''' </history> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.sqlmag.com |
Path: | /Resources/Shared/scripts |
GET /Resources/Shared/scripts Host: www.sqlmag.com Proxy-Connection: keep-alive Referer: http://www.sqlmag.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/javascript, application/javascript, */*; q=0.01 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: .ASPXANONYMOUS=hLbIa |
HTTP/1.1 200 OK Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Type: application/x-javascript Last-Modified: Mon, 21 Mar 2011 16:15:34 GMT ETag: "pv64f306009d1f30152 X-PvInfo: [S11101.C70461.A45914.RA0 Vary: Accept-Encoding Accept-Ranges: bytes Connection: Keep-Alive Date: Thu, 23 Jun 2011 14:12:54 GMT Age: 2153 Content-Length: 11495 /* DotNetNuke. - http://www.dotnetnuke.com Copyright (c) 2002-2010 by DotNetNuke Corporation Permission is hereby granted, free of charge, to any person obtaining a copy of this software and as ...[SNIP]... <history> ''' Version 1.0.0: Oct. 16, 2007, Nik Kalyani, nik.kalyani@dotnetnuke ''' </history> ...[SNIP]... |