2.1. http://udmserve.net/udm/img.fetch [REST URL parameter 1]
2.2. http://udmserve.net/udm/img.fetch [REST URL parameter 2]
3. Cookie without HttpOnly flag set
3.1. http://udmserve.net/udm/img.fetch
3.2. http://udmserve.net/udm/img.fetch
Severity: | High |
Confidence: | Certain |
Host: | http://udmserve.net |
Path: | /udm/img.fetch |
GET /udm/img.fetch?sid=3454 Host: udmserve.net Proxy-Connection: keep-alive Referer: http://www.merriam Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: udm1=6369:1:63424487863:1 |
HTTP/1.1 200 OK P3P: CP='NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT' P3P: policyref="/w3c/p3p.xml", CP="NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT" Set-Cookie: udm2=8320:1:63424489625:1 Set-Cookie: dt=b5076 866a77c7dd9; domain=udmserve.net; path=/; expires=Tue, 06-Mar-2012 01: 47:05 GMT Expires: Sun, 06 Mar 2011 01:47:05 GMT Date: Mon, 07 Mar 2011 01:47:05 GMT Content-Type: application/x-javascript Server: lighttpd/1.4.28 Set-Cookie: NSC_mc-nfejb=81e1a7ed3660 Content-Length: 1390 {document.writeln(" document.writeln("var udmsid = 3454;"); document.writeln("<\ document.writeln(""); document.writeln("<script type=\"text/javascript\" ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://udmserve.net |
Path: | /udm/img.fetch |
GET /udm]]>>/img.fetch?sid=3454;tid=1 Host: udmserve.net Proxy-Connection: keep-alive Referer: http://www.merriam Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found P3P: CP='NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT' Content-Type: text/html Content-Length: 345 Date: Mon, 07 Mar 2011 01:36:08 GMT Server: lighttpd/1.4.28 Set-Cookie: NSC_mc-nfejb=81e1a7db3660 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://udmserve.net |
Path: | /udm/img.fetch |
GET /udm/img.fetch]]>>?sid=3454;tid=1;ev=1;dt=2 Host: udmserve.net Proxy-Connection: keep-alive Referer: http://www.merriam Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found P3P: CP='NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT' Content-Type: text/html Content-Length: 345 Date: Mon, 07 Mar 2011 01:36:13 GMT Server: lighttpd/1.4.28 Set-Cookie: NSC_mc-nfejb=81e1a7ef3660 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://udmserve.net |
Path: | /udm/img.fetch |
GET /udm/img.fetch?sid=3454 Host: udmserve.net Proxy-Connection: keep-alive Referer: http://www.merriam Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: udm1=6369:1:63424487863:1 |
HTTP/1.1 200 OK P3P: CP='NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT' P3P: policyref="/w3c/p3p.xml", CP="NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT" Set-Cookie: udm2=8320:1:63424489614:1 Set-Cookie: dt=4ad7a249-13ba-40a0 Expires: Sun, 06 Mar 2011 01:46:54 GMT Date: Mon, 07 Mar 2011 01:46:54 GMT Content-Type: application/x-javascript Server: lighttpd/1.4.28 Set-Cookie: NSC_mc-nfejb=81e1a7ed3660 Content-Length: 1390 {document.writeln(" document.writeln("var udmsid = 3454;"); document.writeln("<\ document.writeln(""); document.writeln("<script type=\"text/javascript\" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://udmserve.net |
Path: | /udm/img.fetch |
GET /udm/img.fetch?sid=3454 Host: udmserve.net Proxy-Connection: keep-alive Referer: http://www.merriam Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK P3P: CP='NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT' P3P: policyref="/w3c/p3p.xml", CP="NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT" Set-Cookie: udm1=9513:1:63424488947:1 Set-Cookie: dt=8abd48e2-71f1-48b2 Expires: Sun, 06 Mar 2011 01:35:47 GMT Date: Mon, 07 Mar 2011 01:35:47 GMT Content-Type: application/x-javascript Server: lighttpd/1.4.28 Set-Cookie: NSC_mc-nfejb=81e1a7ef3660 Content-Length: 1583 {document.writeln(" document.writeln("var img_name = \"GalagaFBC728x90_1010 document.writeln("var clk_url = \"http://udmserve.net/udm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://udmserve.net |
Path: | /udm/img.fetch |
GET /robots.txt HTTP/1.0 Host: udmserve.net |
HTTP/1.0 200 OK P3P: CP='NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND UNI COM NAV INT' Content-Type: text/plain Accept-Ranges: bytes ETag: "1357487836" Last-Modified: Wed, 19 Jan 2011 00:32:49 GMT Content-Length: 26 Connection: keep-alive Date: Mon, 07 Mar 2011 01:35:48 GMT Server: lighttpd/1.4.28 Set-Cookie: NSC_mc-nfejb=81e1a7ef3660 User-Agent: * Disallow: / |