1. Cross-site scripting (reflected)
2. Content type incorrectly stated
2.1. http://answers.microsoft.com/en-us/Site/SetTimeZoneOffset
2.2. http://answers.microsoft.com/en-us/site/resources
Severity: | High |
Confidence: | Certain |
Host: | http://answers.microsoft |
Path: | /en-us/Search/Search |
GET /en-us/Search/Search Host: answers.microsoft.com Proxy-Connection: keep-alive Referer: http://answers.microsoft User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.218 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=f4593467ede |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.5 X-AspNetMvc-Version: 2.0 X-AspNet-Version: 4.0.30319 Date: Sat, 03 Sep 2011 02:52:36 GMT Content-Length: 30465 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- CP01 --> <html xmlns="http://www.w3.org <head> < ...[SNIP]... <li class="forumSelect" data-forum="ie" data-filter="ie8-windows ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://answers.microsoft |
Path: | /en-us/Site/SetTimeZ |
POST /en-us/Site/SetTimeZ Host: answers.microsoft.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: application/json, text/javascript, */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Content-Type: application/x-www-form X-Requested-With: XMLHttpRequest Referer: http://answers.microsoft Content-Length: 12 Cookie: WT_FPC=id=20b4a619ec Pragma: no-cache Cache-Control: no-cache tzOffset=300 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: application/json; charset=utf-8 Server: Microsoft-IIS/7.5 X-AspNetMvc-Version: 2.0 X-AspNet-Version: 4.0.30319 Set-Cookie: tzo=300; domain=answers.microsoft Date: Sat, 03 Sep 2011 03:02:39 GMT Content-Length: 1 1 |
Severity: | Information |
Confidence: | Firm |
Host: | http://answers.microsoft |
Path: | /en-us/site/resources |
GET /en-us/site/resources HTTP/1.1 Host: answers.microsoft.com Proxy-Connection: keep-alive Referer: http://answers.microsoft User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.218 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=f4593467ede |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.5 X-AspNetMvc-Version: 2.0 X-AspNet-Version: 4.0.30319 Date: Sat, 03 Sep 2011 02:06:23 GMT Content-Length: 14849 if (typeof(Answers) == "undefined") Answers = {}; Answers.Res = { SiteReadOnlyMsg:'We ...[SNIP]... |