1. Cross-site scripting (reflected)
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://sales.liveperson |
Path: | /hc/47760958/ |
GET /hc/47760958/?&visitor Host: sales.liveperson.net Proxy-Connection: keep-alive Referer: http://www.patagonia.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: HumanClickKEY=958751 |
HTTP/1.1 200 OK Date: Sun, 27 Mar 2011 17:34:48 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM" X-Powered-By: ASP.NET Set-Cookie: HumanClickKEY=958751 Set-Cookie: HumanClickKEY=958751 Content-Type: application/x-javascript Accept-Ranges: bytes Last-Modified: Sun, 27 Mar 2011 17:34:48 GMT Set-Cookie: HumanClickSiteContainerID Cache-Control: no-store Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Length: 29170 lpConnLib.Process({ ...[SNIP]... "code_id": "FPCookie", "js_code": "lpMTagConfig.FPC_VID ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://sales.liveperson |
Path: | /hc/47760958/ |
GET /hc/47760958/?&visitor Host: sales.liveperson.net Proxy-Connection: keep-alive Referer: http://www.patagonia.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: HumanClickKEY=958751 |
HTTP/1.1 200 OK Date: Sun, 27 Mar 2011 17:33:49 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM" X-Powered-By: ASP.NET Content-Type: application/x-javascript Accept-Ranges: bytes Last-Modified: Sun, 27 Mar 2011 17:33:49 GMT Set-Cookie: HumanClickSiteContainerID Cache-Control: no-store Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Length: 94 lpConnLib.Process({ |
Severity: | Information |
Confidence: | Certain |
Host: | http://sales.liveperson |
Path: | /hc/47760958/ |
GET /hc/47760958/?&visitor Host: sales.liveperson.net Proxy-Connection: keep-alive Referer: http://www.patagonia.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: HumanClickKEY=958751 |
HTTP/1.1 200 OK Date: Sun, 27 Mar 2011 17:33:49 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM" X-Powered-By: ASP.NET Content-Type: application/x-javascript Accept-Ranges: bytes Last-Modified: Sun, 27 Mar 2011 17:33:49 GMT Set-Cookie: HumanClickSiteContainerID Cache-Control: no-store Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Length: 94 lpConnLib.Process({ |