1. Cross-site scripting (reflected)
2. Content type incorrectly stated
2.1. http://social.zune.net/frag/FriendsBlock/
2.2. http://social.zune.net/xweb/lx/pic/TwitterFeed.gif
Severity: | High |
Confidence: | Certain |
Host: | http://social.zune.net |
Path: | /frag/LiveSearchBlock/ |
GET /frag/LiveSearchBlock/ Host: social.zune.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html, */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive X-Requested-With: XMLHttpRequest lx-ajax-source: http://social.zune.net Referer: http://social.zune.net Cookie: lastCulture=en-US; defCulture=en-US; WT_FPC=id=50.23.123.106 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 eid: b42bd67c-be02-4dfb-a878 X-AspNet-Version: 2.0.50727 lx-svr: S504 X-Powered-By: ASP.NET Content-Length: 542 Expires: Sun, 06 Nov 2011 19:51:20 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 06 Nov 2011 19:51:20 GMT Connection: close Vary: Accept-Encoding Set-Cookie: EXPCONTEXTHASZUNEPASS <div id="ajaxErr" style="display:none">< <div class="SearchHeader" isDark="false" bname="LiveSearchBlock" count=0 fragPageUrl="" qs="true"> <span class="SeeAll"><a style="cursor:pointer; display:none; " href='http://www.zune.net ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://social.zune.net |
Path: | /frag/FriendsBlock/ |
GET /frag/FriendsBlock/ Host: social.zune.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html, */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive X-Requested-With: XMLHttpRequest lx-ajax-source: http://social.zune.net Referer: http://social.zune.net Cookie: lastCulture=en-US; defCulture=en-US; WT_FPC=id=50.23.123.106 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 eid: c68185b7-2648-42b9-ad95 X-AspNet-Version: 2.0.50727 lx-svr: S801 X-Powered-By: ASP.NET Content-Length: 92 Expires: Sun, 06 Nov 2011 19:49:26 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 06 Nov 2011 19:49:26 GMT Connection: close Vary: Accept-Encoding Set-Cookie: EXPCONTEXTHASZUNEPASS <h2>friends plays</h2> <div class="EmptyState">No friends? Don't be anti-social :) </div> |
Severity: | Information |
Confidence: | Firm |
Host: | http://social.zune.net |
Path: | /xweb/lx/pic/TwitterFeed |
GET /xweb/lx/pic/TwitterFeed Host: social.zune.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://social.zune.net Cookie: lastCulture=en-US; defCulture=en-US; WT_FPC=id=50.23.123.106 |
HTTP/1.1 200 OK Content-Type: image/gif Last-Modified: Fri, 08 Jul 2011 05:01:22 GMT Accept-Ranges: bytes ETag: "0fd93142c3dcc1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Content-Length: 1040 Cache-Control: max-age=23228467 Date: Sun, 06 Nov 2011 20:28:35 GMT Connection: close ......JFIF.....d.d..... ...................... .. . .......................... ...[SNIP]... |