1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
3. HTML does not specify charset
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://searchnet.chitika |
Path: | /audience |
GET /audience?cc=US&domain Host: searchnet.chitika.net Proxy-Connection: keep-alive Referer: http://whois.domaintools User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html Date: Fri, 11 Mar 2011 13:00:01 GMT Server: Apache Vary: Accept-Encoding Connection: keep-alive Content-Length: 350 <html><body><img src="http://ib.adnxs.com <img src="http://ad.yi ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://searchnet.chitika |
Path: | /audience |
GET /audience?cc=US&domain Host: searchnet.chitika.net Proxy-Connection: keep-alive Referer: http://whois.domaintools User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html Date: Fri, 11 Mar 2011 12:59:13 GMT Server: Apache Vary: Accept-Encoding Connection: keep-alive Content-Length: 307 <html><body><img src="http://ib.adnxs.com <img src="http://ad.yield <img src="http://ib.adnxs.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://searchnet.chitika |
Path: | /audience |
GET /audience?cc=US&domain Host: searchnet.chitika.net Proxy-Connection: keep-alive Referer: http://whois.domaintools User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html Date: Fri, 11 Mar 2011 12:59:13 GMT Server: Apache Vary: Accept-Encoding Connection: keep-alive Content-Length: 307 <html><body><img src="http://ib.adnxs.com <img src="http://ad.yield ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://searchnet.chitika |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: searchnet.chitika.net Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/plain Date: Fri, 11 Mar 2011 13:02:17 GMT ETag: "911a7-57e-444513d941fc0" Last-Modified: Tue, 22 Jan 2008 15:27:03 GMT Server: Apache Content-Length: 1406 Connection: keep-alive ..............h.......(.. ...........v.rrr......... ...[SNIP]... |