1. Cross-site scripting (reflected)
2.1. http://api.mywot.com/widgets/ratings.js
2.2. http://api.mywot.com/widgets/ratingwidget.js
Severity: | High |
Confidence: | Certain |
Host: | http://api.mywot.com |
Path: | /0.4/public_link_json |
GET /0.4/public_link_json Host: api.mywot.com Proxy-Connection: keep-alive Referer: http://www.mywot.com/en User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSf6ce7e3db2357230 |
HTTP/1.1 200 OK Date: Thu, 15 Sep 2011 19:28:31 GMT Server: Apache Cache-Control: no-store, max-age=0 Expires: Thu, 15 Sep 2011 19:28:31 GMT Vary: Accept-Encoding Content-Length: 565 Connection: close Content-Type: application/x-javascript jQuery15202863159140 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://api.mywot.com |
Path: | /widgets/ratings.js |
GET /widgets/ratings.js HTTP/1.1 Host: api.mywot.com Proxy-Connection: keep-alive Referer: http://www.mywot.com/en User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSf6ce7e3db2357230 |
HTTP/1.1 200 OK Date: Thu, 15 Sep 2011 19:26:46 GMT Server: Apache Last-Modified: Mon, 17 Jan 2011 10:04:03 GMT Accept-Ranges: bytes Cache-Control: max-age=259200 Expires: Sun, 18 Sep 2011 19:26:46 GMT Vary: Accept-Encoding Content-Length: 449 Connection: close Content-Type: application/javascript /* Copyright .. 2008 WOT Services Oy <info@mywot.com> */ var wotprotocol = (document.location var wotbase = wotprotocol + "api.mywot.com/widgets"; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://api.mywot.com |
Path: | /widgets/ratingwidget.js |
GET /widgets/ratingwidget.js HTTP/1.1 Host: api.mywot.com Proxy-Connection: keep-alive Referer: http://www.mywot.com/en User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSf6ce7e3db2357230 |
HTTP/1.1 200 OK Date: Thu, 15 Sep 2011 19:26:47 GMT Server: Apache Last-Modified: Mon, 17 Jan 2011 10:04:03 GMT Accept-Ranges: bytes Cache-Control: max-age=259200 Expires: Sun, 18 Sep 2011 19:26:47 GMT Vary: Accept-Encoding Content-Length: 4474 Connection: close Content-Type: application/javascript /* Copyright .. 2011 WOT Services Oy <info@mywot.com> */ eval(function(p,a,c,k,e,r ...[SNIP]... |