1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://sitelife.boston |
Path: | /ver1.0/Direct/Jsonp |
GET /ver1.0/Direct/Jsonp?r= Host: sitelife.boston.com Proxy-Connection: keep-alive Referer: http://www.boston.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=rcHW801iXt4ADx8I; RMFL=011PrVAnU105z0Y; s_vi=[CS]v1|26B12F72 |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 17276 Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 x-SiteLife-host: l3vm208l3pluckcom Set-Cookie: SiteLifeHost=l3vm208 Date: Mon, 28 Mar 2011 19:42:26 GMT RequestBatch.callbacks ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://sitelife.boston |
Path: | /ver1.0/Direct/Jsonp |
GET /ver1.0/Direct/Jsonp?r= Host: sitelife.boston.com Proxy-Connection: keep-alive Referer: http://www.boston.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=rcHW801iXt4ADx8I; RMFL=011PrVAnU105z0Y; s_vi=[CS]v1|26B12F72 |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 17235 Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 x-SiteLife-host: l3vm208l3pluckcom Set-Cookie: SiteLifeHost=l3vm208 Date: Mon, 28 Mar 2011 19:41:25 GMT RequestBatch.callbacks ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://sitelife.boston |
Path: | /ver1.0/Direct/Jsonp |
GET /ver1.0/Direct/Jsonp?r= Host: sitelife.boston.com Proxy-Connection: keep-alive Referer: http://www.boston.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=rcHW801iXt4ADx8I; RMFL=011PrVAnU105z0Y; s_vi=[CS]v1|26B12F72 |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 17235 Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 x-SiteLife-host: l3vm208l3pluckcom Set-Cookie: SiteLifeHost=l3vm208 Date: Mon, 28 Mar 2011 19:41:25 GMT RequestBatch.callbacks ...[SNIP]... |