2. Cross-site scripting (reflected)
2.1. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [adSize parameter]
2.2. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [glam_sid cookie]
2.3. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [qcsegs cookie]
4. Cookie scoped to parent domain
5. Cross-domain Referer leakage
5.1. http://www2.glam.com/app/site/affiliate/viewChannelModule.act
5.2. http://www2.glam.com/app/site/affiliate/viewChannelModule.act
6. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Firm |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.glam.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=3600 Date: Mon, 04 Apr 2011 13:42:47 GMT Connection: close Content-Length: 2011 root:x:0:0:root:/root:/bin bin:x:1:1:bin:/bin:/sbin daemon:x:2:2:daemon:/sbin adm:x:3:4:adm:/var/adm: lp:x:4:7:lp:/var/spool sync:x:5:0:sync:/sbin: shutdown:x:6:0:shutdow ...[SNIP]... ucp:/sbin/nologin operator:x:11:0:operator: games:x:12:100:games:/usr gopher:x:13:30:gopher: ftp:x:14:50:FTP User:/var/ftp:/sbin nobody:x:99:99:Nobody:/:/sbin nscd:x:28:28:NSCD Daemon:/:/sbin/nologin distcache:x:94:94 vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin pcap:x:77:77::/var/arpwa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.glam.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: glam_cookie_sid X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 04 Apr 2011 13:42:58 GMT Connection: close Content-Length: 59412 // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Apr 4 2011 6:42:58 PDT] --> window.glam_session = new Object(); window.glam_session.c ...[SNIP]... sion.region_code='DC'; window.glam_session.user function GlamProcessScriptParams() { } window.glam_affiliate_id = '0'; window.glam_zone = ''; window.glam_ad_size = '300x8556523';alert(1)/ window.glam_status = ''; window.glam_status = (window.glam_status=='' /* */ function GlamShowCustomDefaultAd window.glam_affiliate ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.glam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: bkpix2=1; expires=Mon, 04 Apr 2011 19:18:42 GMT; path=/; domain=.glam.com; X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 04 Apr 2011 13:45:22 GMT Connection: close Content-Length: 60240 // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Apr 4 2011 6:44:28 PDT] --> window.glam_session = new Object(); window.glam_session /* */ window.glam_session.edge = true; window.glam_session.glam window.glam_session window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user docu ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://family.glam.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 04 Apr 2011 13:47:36 GMT Connection: close Content-Length: 53689 // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Apr 4 2011 6:46:01 PDT] --> window.glam_session = new Object(); window.glam_session /* */ window.glam_session.edge = true; window.glam_session.glam window.glam_session window.glam_session window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user fu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www2.glam.com |
HTTP/1.0 200 OK Server: Apache/2.2.3 (CentOS) Last-Modified: Thu, 16 Sep 2010 21:08:11 GMT ETag: "6b8007-cc-49066d7f404c0" Accept-Ranges: bytes Content-Length: 204 Content-Type: text/xml Date: Mon, 04 Apr 2011 13:42:20 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.glam.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: glam_cookie_sid X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 04 Apr 2011 13:42:19 GMT Connection: close Content-Length: 59384 // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Apr 4 2011 6:42:18 PDT] --> window.glam_session = new Object(); window.glam_session.c ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.glam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: bkpix2=1; expires=Mon, 04 Apr 2011 19:17:49 GMT; path=/; domain=.glam.com; X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 04 Apr 2011 13:44:29 GMT Connection: close Content-Length: 60210 // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Apr 4 2011 6:44:28 PDT] --> window.glam_session = new Object(); window.glam_session ...[SNIP]... lam_session.country_code= window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user document.write('<img style="display:none;" src="http://pixel var bkimg = new Image(); bkimg.src='http://tags document.write('<iframe height="0" width="0" frameborder="0" style="position:absolute document.write('<img style="display:none;" src="http://tags.bluekai function GlamProcessScriptParams() { } window.glam_affiliate_id = '0'; window.glam_zone = ''; window.glam_ad_size = '300x250'; window.glam_status = ''; window.glam_status = (window ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.glam.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: bkpix2=1; expires=Mon, 04 Apr 2011 19:16:34 GMT; path=/; domain=.glam.com; X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 04 Apr 2011 13:43:14 GMT Connection: close Content-Length: 60118 // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Apr 4 2011 6:43:14 PDT] --> window.glam_session = new Object(); window.glam_session ...[SNIP]... lam_session.country_code= window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user document.write('<img style="display:none;" src="http://pixel var bkimg = new Image(); bkimg.src='http://tags document.write('<iframe height="0" width="0" frameborder="0" style="position:absolute document.write('<img style="display:none;" src="http://tags.bluekai function GlamProcessScriptParams() { } window.glam_affiliate_id = '0'; window.glam_zone = ''; window.glam_ad_size = '300x250'; window.glam_status = ''; window.glam_status = (window ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://www.glam.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=234602824 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript Set-Cookie: glam_cookie_sid X-Powered-By: PHP/5.1.6 P3P: policyref="http://www Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 04 Apr 2011 13:42:19 GMT Connection: close Content-Length: 59384 // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Apr 4 2011 6:42:18 PDT] --> window.glam_session = new Object(); window.glam_session.c ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /robots.txt HTTP/1.0 Host: www2.glam.com |
HTTP/1.0 200 OK Server: Apache/2.2.3 (CentOS) Last-Modified: Mon, 22 Jun 2009 18:04:04 GMT ETag: "250088-1a-46cf3b3120d00" Accept-Ranges: bytes Content-Length: 26 Content-Type: text/plain; charset=UTF-8 Date: Mon, 04 Apr 2011 13:42:21 GMT Connection: close User-agent: * Disallow: / |