1.4. http://x17online.com/css/main.css [REST URL parameter 1]
1.5. http://x17online.com/css/main.css [REST URL parameter 2]
1.6. http://x17online.com/favicon.ico [REST URL parameter 1]
1.7. http://x17online.com/js/common.js [REST URL parameter 1]
1.8. http://x17online.com/js/common.js [REST URL parameter 2]
1.9. http://x17online.com/js/main.js [REST URL parameter 1]
1.10. http://x17online.com/js/main.js [REST URL parameter 2]
2. Cross-domain script include
3.2. http://x17online.com/thematics/126hoodlum_added_value/126hoodlum_added_value.css
Severity: | High |
Confidence: | Certain |
Host: | http://x17online.com |
Path: | /celebrities/sean_penn |
GET /celebrities'/sean_penn/sean_penn Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:05:06 GMT Server: Apache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 1859 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' or fileinfo_url = '/celebrities'/sean_penn ...[SNIP]... |
GET /celebrities''/sean_penn/sean_penn Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:05:07 GMT Server: Apache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 1516 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://x17online.com |
Path: | /celebrities/sean_penn |
GET /celebrities/sean_penn'/sean_penn_throws_a_hissy Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:05:08 GMT Server: Apache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 1859 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' or fileinfo_url = '/celebrities/sean_penn' ...[SNIP]... |
GET /celebrities/sean_penn''/sean_penn_throws_a_hissy Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:05:08 GMT Server: Apache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 1516 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://x17online.com |
Path: | /celebrities/sean_penn |
GET /celebrities/sean_penn Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:05:09 GMT Server: Apache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 1859 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''/') or (fileinfo_url like '/celebrities/sean_penn ...[SNIP]... |
GET /celebrities/sean_penn Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:05:09 GMT Server: Apache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 1516 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://x17online.com |
Path: | /css/main.css |
GET /css'/main.css?8313 HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: x17online.com |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:11:06 GMT Server: Apache Content-Type: text/html; charset=utf-8 Content-Length: 1786 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' or fileinfo_url = '/css'/main.css/') or (fileinfo_url like '/css'/main.css/ind' at line 5</font> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://x17online.com |
Path: | /css/main.css |
GET /css/main.css'?8313 HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: x17online.com |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:11:08 GMT Server: Apache Content-Type: text/html; charset=utf-8 Content-Length: 1786 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''/') or (fileinfo_url like '/css/main.css'/index%')) and blo' at line 5</font> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://x17online.com |
Path: | /favicon.ico |
GET /favicon.ico' HTTP/1.1 Host: x17online.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:08:48 GMT Server: Apache Content-Type: text/html; charset=utf-8 Content-Length: 1785 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''/') or (fileinfo_url like '/favicon.ico'/index%')) and blog' at line 5</font> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://x17online.com |
Path: | /js/common.js |
GET /js'/common.js?3121 HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: x17online.com |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:13:13 GMT Server: Apache Content-Type: text/html; charset=utf-8 Content-Length: 1786 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' or fileinfo_url = '/js'/common.js/') or (fileinfo_url like '/js'/common.js/ind' at line 5</font> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://x17online.com |
Path: | /js/common.js |
GET /js/common.js'?4068 HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: x17online.com |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:13:15 GMT Server: Apache Content-Type: text/html; charset=utf-8 Content-Length: 1786 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''/') or (fileinfo_url like '/js/common.js'/index%')) and blo' at line 5</font> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://x17online.com |
Path: | /js/main.js |
GET /js'/main.js?9728 HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: x17online.com |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:14:21 GMT Server: Apache Content-Type: text/html; charset=utf-8 Content-Length: 1784 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' or fileinfo_url = '/js'/main.js/') or (fileinfo_url like '/js'/main.js/index%'' at line 5</font> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://x17online.com |
Path: | /js/main.js |
GET /js/main.js'?9728 HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: x17online.com |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 20:14:22 GMT Server: Apache Content-Type: text/html; charset=utf-8 Content-Length: 1784 <blockquote><font face=arial size=2 color=ff0000><b>SQL/DB Error --</b> [<font color=000077>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''/') or (fileinfo_url like '/js/main.js'/index%')) and blog_' at line 5</font> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://x17online.com |
Path: | /celebrities/sean_penn |
GET /celebrities/sean_penn Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 20:04:47 GMT Server: Apache Content-Length: 182937 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </script> <script type="text/javascript" src="http://w.sharethis ...[SNIP]... </script> <script language="JavaScript" src="http://d3.zedo.com ...[SNIP]... <div class="contain"> <script src="http://widgets.twimg ...[SNIP]... <div class="contain"> <script src="http://widgets.twimg ...[SNIP]... </script><script language="JavaScript" src="http://js.adsonar ...[SNIP]... <img id="bottomCap" src="/graphics/page <script src="http://www.google ...[SNIP]... </script> <script type="text/javascript" src="http://resources ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://x17online.com |
Path: | /celebrities/sean_penn |
GET /celebrities/sean_penn Host: x17online.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 20:04:47 GMT Server: Apache Content-Length: 182937 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <link rev="made" href="mailto:x17@x17online.com" /> <meta http-equiv="reply-to" content="x17@x17online.com" /> ...[SNIP]... <!-- //Disable right mouse click Script //By Maximus (maximus@nsimail.com) w/ mods by DynamicDrive //For full source code, visit http://www.dynamicdrive var message="X17's photos are available for license ... please contact x17@x17agency.com for purchase info."; //var message="X17online.com has disabled right clicks and drags and drops. If you'd like to share our images with others, please simply send them to this page. Thank you!"; //// ...[SNIP]... <a href="mailto:x17@x17agency.com"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://x17online.com |
Path: | /thematics/126hoodlum |
GET /thematics/126hoodlum Host: x17online.com Proxy-Connection: keep-alive Referer: http://x17online.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 20:08:18 GMT Server: Apache Last-Modified: Tue, 07 Dec 2010 20:24:31 GMT ETag: "91d05af-6012-496d7c Accept-Ranges: bytes Content-Length: 24594 Content-Type: text/css /* name: Hoodlum Added Value designer: Matt Lum, Hoodlum Productions designer_url: http://www.hoodlumpr description: Three column media blog with photographic focus and video exhibition ...[SNIP]... color: #000; font-size: 11px; padding: 3px; margin: 15px; text-align: center; } .comments-open-footer { margin: 6px 0; } /*DROP SHADDOWED */ /* yDSF (ydnar Drop-Shadow-Fu) ydnar@sixapart.com - http://www.sixapart.com */ .ydsf { display: block; position: relative; margin: 4px -4px -4px 4px; background: url(shadow-grid.gif) repeat; } /* ie6 ignores this selector */ html> ...[SNIP]... |