2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://forums.ebay.com |
Path: | /db2/forum/Trust-Safety |
GET /db2/forum/Trust-Safety Host: forums.ebay.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 301 Moved Permanently Server: LiveWorldPlatform/1.3.21 P3P: CP="CAO PSA OUR" Location: http://forums.ebay.com d061dbc09a9 Content-Type: text/html; charset=UTF-8 Date: Tue, 27 Sep 2011 19:10:38 GMT Connection: close Cache-Control: private, must-revalidate, max-age=0, s-maxage=0 Vary: Accept-Encoding <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <!-- null --> <title>: eBay Discussion Boards</title> <meta http-equiv="content-type" content="text/html; charset ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://forums.ebay.com |
Path: | /db2/forum/Trust-Safety |
GET /db2/forum/Trust-Safety Host: forums.ebay.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Server: LiveWorldPlatform/1.3.21 P3P: CP="CAO PSA OUR" Content-Type: text/html; charset=UTF-8 Date: Tue, 27 Sep 2011 19:10:36 GMT Connection: close Cache-Control: private, must-revalidate, max-age=0, s-maxage=0 Vary: Accept-Encoding <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <!-- template = template-2col --> <head> ...[SNIP]... <link rel="stylesheet" type="text/css" href="http://ir ...[SNIP]... </div><script src="http://include ...[SNIP]... </script><script src="http://include ...[SNIP]... |