1. Cross-site scripting (reflected)
1.1. http://www.huffingtonpost.com/ [icid parameter]
1.2. http://www.huffingtonpost.com/ [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.huffingtonpost |
Path: | / |
GET /?icid=navbar_rootnews Host: www.huffingtonpost.com Proxy-Connection: keep-alive Referer: http://www.aol.com/video User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.8 (Unix) Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Cache-Control: max-age=30 Date: Thu, 18 Aug 2011 22:17:12 GMT Connection: close Connection: Transfer-Encoding Content-Length: 295445 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- --> <html xmlns="http://www.w3.org ...[SNIP]... PConfig.current_vertical HPConfig.current_vertical HPConfig.current_web HPConfig.current_uri = "/?icid=navbar_rootnews HPConfig.inst_type = "prod"; HPConfig.timestamp_for HPConfig.bit_ly_key = {"user_name":"huffpost", HPConfig.display_d ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.huffingtonpost |
Path: | / |
GET /?icid=navbar_rootnews Host: www.huffingtonpost.com Proxy-Connection: keep-alive Referer: http://www.aol.com/video User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.8 (Unix) Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Cache-Control: max-age=29 Date: Thu, 18 Aug 2011 22:17:32 GMT Connection: close Connection: Transfer-Encoding Content-Length: 295495 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- --> <html xmlns="http://www.w3.org ...[SNIP]... Config.current_vertical HPConfig.current_vertical HPConfig.current_web HPConfig.current_uri = "/?icid=navbar_rootnews HPConfig.inst_type = "prod"; HPConfig.timestamp_for HPConfig.bit_ly_key = {"user_name":"huffpost", HPConfig.display ...[SNIP]... |