1. Cross-site scripting (reflected)
1.1. http://autotrader.autos.msn.com/fyc/index.jsp [make parameter]
1.2. http://autotrader.autos.msn.com/fyc/index.jsp [Referer HTTP header]
3. Cookie without HttpOnly flag set
3.1. http://autotrader.autos.msn.com/fyc/index.jsp
3.2. http://autotrader.autos.msn.com/fyc/index.jsp
4. Cookie scoped to parent domain
4.1. http://autotrader.autos.msn.com/fyc/index.jsp
4.2. http://autotrader.autos.msn.com/fyc/index.jsp
Severity: | High |
Confidence: | Certain |
Host: | http://autotrader.autos |
Path: | /fyc/index.jsp |
GET /fyc/index.jsp?hide_nav Host: autotrader.autos.msn.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 20 Apr 2012 03:41:12 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: v1st=5F1BA0DFC5544E11; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Set-Cookie: ATC_USER_ZIP=02130; Domain=.msn.com; Expires=Sun, 20-Apr-2014 03:41:12 GMT; Path=/ Set-Cookie: ATC_USER_ZIP=02130; Domain=.msn.com; Expires=Sun, 20-Apr-2014 03:41:12 GMT; Path=/ Set-Cookie: oam.Flash.RENDERMAP.TOKEN Set-Cookie: JSESSIONID=2207D3D9F P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Vary: Accept-Encoding Connection: close Set-Cookie: BIGipServerwww=294248458 Set-Cookie: DCNAME=www-7001 Content-Length: 67308 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <script type="text/javascript"> $("#cache-make1").val('25407';alert(1)/ </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://autotrader.autos |
Path: | /fyc/index.jsp |
GET /fyc/index.jsp HTTP/1.1 Host: autotrader.autos.msn.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Fri, 20 Apr 2012 03:40:41 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: v1st=BCB9E0DDC90631A8; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Set-Cookie: oam.Flash.RENDERMAP.TOKEN Set-Cookie: JSESSIONID=D45244973 P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Vary: Accept-Encoding Connection: close Set-Cookie: BIGipServerwww=260694026 Set-Cookie: DCNAME=www-7001 Content-Length: 64509 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... rm","detailedPageName": ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://autotrader.autos |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: autotrader.autos.msn.com |
HTTP/1.1 200 OK Date: Fri, 20 Apr 2012 03:40:20 GMT Server: Apache Set-Cookie: v1st=8C6860CA5D517E06; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Last-Modified: Mon, 09 Apr 2012 04:09:31 GMT Accept-Ranges: bytes Content-Length: 271 Vary: Accept-Encoding P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Keep-Alive: timeout=10, max=100 Connection: close Content-Type: text/xml Set-Cookie: BIGipServerwww=579461130 Set-Cookie: DCNAME=www-7001 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.autotrader.com" /> <allow-access-from domain="ads.autotrader.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://autotrader.autos |
Path: | /fyc/index.jsp |
GET /fyc/index.jsp?hide_nav Host: autotrader.autos.msn.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Date: Fri, 20 Apr 2012 03:40:22 GMT Location: /cars-for-sale/index Set-Cookie: v1st=D66444D4C1DA7303; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Set-Cookie: JSESSIONID=50A978187 Set-Cookie: CBRND="LNX=MSNATMSNS P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Content-Type: text/plain Connection: close Set-Cookie: BIGipServerwww=478797834 Set-Cookie: DCNAME=www-7001 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://autotrader.autos |
Path: | /fyc/index.jsp |
GET /fyc/index.jsp?hide_nav Host: autotrader.autos.msn.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Date: Fri, 20 Apr 2012 03:40:23 GMT Location: /cars-for-sale/index Set-Cookie: v1st=C60F0CDF54D3C8A; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Set-Cookie: ATC_USER_ZIP=02130; Domain=.msn.com; Expires=Sun, 20-Apr-2014 03:40:23 GMT; Path=/ P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Content-Type: text/plain Connection: close Set-Cookie: BIGipServerwww=25813002 Set-Cookie: DCNAME=www-7001 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://autotrader.autos |
Path: | /fyc/index.jsp |
GET /fyc/index.jsp?hide_nav Host: autotrader.autos.msn.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Date: Fri, 20 Apr 2012 03:40:22 GMT Location: /cars-for-sale/index Set-Cookie: v1st=D66444D4C1DA7303; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Set-Cookie: JSESSIONID=50A978187 Set-Cookie: CBRND="LNX=MSNATMSNS P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Content-Type: text/plain Connection: close Set-Cookie: BIGipServerwww=478797834 Set-Cookie: DCNAME=www-7001 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://autotrader.autos |
Path: | /fyc/index.jsp |
GET /fyc/index.jsp?hide_nav Host: autotrader.autos.msn.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Date: Fri, 20 Apr 2012 03:40:23 GMT Location: /cars-for-sale/index Set-Cookie: v1st=C60F0CDF54D3C8A; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Set-Cookie: ATC_USER_ZIP=02130; Domain=.msn.com; Expires=Sun, 20-Apr-2014 03:40:23 GMT; Path=/ P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Content-Type: text/plain Connection: close Set-Cookie: BIGipServerwww=25813002 Set-Cookie: DCNAME=www-7001 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://autotrader.autos |
Path: | /fyc/index.jsp |
GET /robots.txt HTTP/1.0 Host: autotrader.autos.msn.com |
HTTP/1.1 200 OK Date: Fri, 20 Apr 2012 03:40:20 GMT Server: Apache Set-Cookie: v1st=AED09B56025BE1DD; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.msn.com Set-Cookie: ATC_ID=63.209.227.200 Last-Modified: Mon, 09 Apr 2012 04:09:31 GMT Accept-Ranges: bytes Content-Length: 439 Vary: Accept-Encoding P3P: CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Keep-Alive: timeout=10, max=100 Connection: close Content-Type: text/plain Set-Cookie: BIGipServerwww=42590218 Set-Cookie: DCNAME=www-7001 User-agent: * Disallow: /fyc # This is an infinite virtual URL space Disallow: /inventory # This is an infinite virtual URL space # Start Home Page Test Disallow: /index_hpra0.jsp Disallow: /index_h ...[SNIP]... |