1. Cross-site scripting (reflected)
1.1. http://www.mapquest.com/maps/map.adp [address parameter]
1.2. http://www.mapquest.com/maps/map.adp [cat parameter]
1.3. http://www.mapquest.com/maps/map.adp [country parameter]
1.4. http://www.mapquest.com/maps/map.adp [name parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.mapquest.com |
Path: | /maps/map.adp |
GET /maps/map.adp?searchtype Host: www.mapquest.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: t_Id=ZGVmYXVsdDpudWxs; Path=/ Set-Cookie: tsession="JSKdyzmqkE Set-Cookie: tsexpiry=1; Domain=mapquest.com; Expires=Mon, 05-Mar-2012 02:02:19 GMT; Path=/ Set-Cookie: psession="RXe2ZPgRaP Set-Cookie: c_Id=MjY2OjQyOA%3D%3D; Expires=Mon, 05-Mar-2012 02:17:19 GMT; Path=/ Expires: -1 Cache-Control: private, max-age=0 Content-Type: text/html;charset=UTF-8 Content-Language: en-US Date: Mon, 05 Mar 2012 01:47:19 GMT Content-Length: 46606 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... alse,"latchQuery":null, ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.mapquest.com |
Path: | /maps/map.adp |
GET /maps/map.adp?searchtype Host: www.mapquest.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: t_Id=ZGVmYXVsdDpudWxs; Path=/ Set-Cookie: tsession="leVmDx Set-Cookie: tsexpiry=1; Domain=mapquest.com; Expires=Mon, 05-Mar-2012 02:01:57 GMT; Path=/ Set-Cookie: psession="Yb0G5 Set-Cookie: c_Id=MjY2OjQyOA%3D%3D; Expires=Mon, 05-Mar-2012 02:16:57 GMT; Path=/ Expires: -1 Cache-Control: private, max-age=0 Content-Type: text/html;charset=UTF-8 Content-Language: en-US Date: Mon, 05 Mar 2012 01:46:58 GMT Content-Length: 62423 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... tBizCategory":null, ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.mapquest.com |
Path: | /maps/map.adp |
GET /maps/map.adp?searchtype Host: www.mapquest.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: t_Id=ZGVmYXVsdDpudWxs; Path=/ Set-Cookie: tsession="9BFQWEy+6 Set-Cookie: tsexpiry=1; Domain=mapquest.com; Expires=Mon, 05-Mar-2012 02:00:12 GMT; Path=/ Set-Cookie: psession="j9Qv4T04G9 Set-Cookie: c_Id=MjY2OjQyOA%3D%3D; Expires=Mon, 05-Mar-2012 02:15:12 GMT; Path=/ Expires: -1 Cache-Control: private, max-age=0 Content-Type: text/html;charset=UTF-8 Content-Language: en-US Date: Mon, 05 Mar 2012 01:45:12 GMT Content-Length: 46547 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... chQuery":null,"locale": ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.mapquest.com |
Path: | /maps/map.adp |
GET /maps/map.adp?searchtype Host: www.mapquest.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: t_Id=ZGVmYXVsdDpudWxs; Path=/ Set-Cookie: tsession="8VV9xJfi1X Set-Cookie: tsexpiry=1; Domain=mapquest.com; Expires=Mon, 05-Mar-2012 02:01:39 GMT; Path=/ Set-Cookie: psession="6XBGlNdSDu Set-Cookie: c_Id=MjY2OjQyOA%3D%3D; Expires=Mon, 05-Mar-2012 02:16:39 GMT; Path=/ Expires: -1 Cache-Control: private, max-age=0 Content-Type: text/html;charset=UTF-8 Content-Language: en-US Date: Mon, 05 Mar 2012 01:46:39 GMT Content-Length: 46785 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... tBizCategory":null, ...[SNIP]... |