1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
Severity: | High |
Confidence: | Certain |
Host: | http://www.simplyhired |
Path: | /a/job-widget/list/q-onet |
GET /a/job-widget/list/q-onet Host: www.simplyhired.com Proxy-Connection: keep-alive Referer: http://www.computerworld User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: nginx Date: Thu, 17 Mar 2011 01:33:24 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive Keep-Alive: timeout=20 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Content-Length: 9223 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html id="html" dir="ltr" xml:lang="en" lang="en" xmlns="http://www.w3.org <h ...[SNIP]... <body id="sh_job_widget" class="computerworld22e70"style="x:expression ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.simplyhired |
Path: | /a/job-widget/list/q-onet |
GET /a/job-widget/list/q-onet Host: www.simplyhired.com Proxy-Connection: keep-alive Referer: http://www.computerworld User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: nginx Date: Thu, 17 Mar 2011 01:33:28 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive Keep-Alive: timeout=20 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Content-Length: 8452 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html id="html" dir="ltr" xml:lang="en" lang="en" xmlns="http://www.w3.org <h ...[SNIP]... <link rel="stylesheet" type="text/css" href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.simplyhired |
Path: | /a/job-widget/list/q-onet |
GET /a/job-widget/list/q-onet Host: www.simplyhired.com Proxy-Connection: keep-alive Referer: http://www.computerworld User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: nginx Date: Thu, 17 Mar 2011 01:32:57 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive Keep-Alive: timeout=20 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Via: Simply Cache Content-Length: 8375 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html id="html" dir="ltr" xml:lang="en" lang="en" xmlns="http://www.w3.org <h ...[SNIP]... </style> <link rel="stylesheet" type="text/css" href="http://www </head> ...[SNIP]... <!-- Start Quantcast tag --> <img src="http://pixel <!-- End Quantcast tag --> ...[SNIP]... <!-- Begin comScore Tag --> <img src="http://b.scorec <!-- End comScore Tag --> ...[SNIP]... |