1. Cross-site scripting (reflected)
3. Cookie scoped to parent domain
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://picasaweb.google | 
| Path: | /data/feed/api/user | 
| GET /data/feed/api/user Host: picasaweb.google.com Proxy-Connection: keep-alive Referer: http://picasaweb.google Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=sorry=6N0zPerLQtZIDQDH- | 
| HTTP/1.1 400 Bad Request Expires: Sat, 05 Mar 2011 14:40:02 GMT Date: Sat, 05 Mar 2011 14:40:02 GMT Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _rtok=kBbE7Kz1nOis; Path=/; HttpOnly Set-Cookie: S=sorry=6N0zPerLQtZIDQDH- Content-Type: text/html; charset=UTF-8 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 66 Invalid value for kind parameter: photo54546;alert(1)/ | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://picasaweb.google | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: picasaweb.google.com | 
| HTTP/1.0 200 OK Expires: Sun, 06 Mar 2011 14:35:50 GMT Date: Sat, 05 Mar 2011 14:35:50 GMT Cache-Control: public, max-age=86400 Content-Type: text/x-cross-domain X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.google.com" /> <allow-access-from domain="*.google.de" /> <allow-access-from domain="*.google.ch" /> <allow-access-from domain="*.google.at" /> <allow-access-from domain="*.google.it" /> <allow-access-from domain="*.google.co.jp" /> <allow-access-from domain="*.google.co.kr" /> <allow-access-from domain="*.google.pl" /> <allow-access-from domain="*.google.com.br" /> <allow-access-from domain="*.google.ru" /> <allow-access-from domain="*.google.es" /> <allow-access-from domain="*.google.com.tw" /> <allow-access-from domain="*.google.com.hk" /> <allow-access-from domain="*.google.com.tr" /> <allow-access-from domain="*.google.co.th" /> <allow-access-from domain="*.google.dk" /> <allow-access-from domain="*.google.fi" /> <allow-access-from domain="*.google.no" /> <allow-access-from domain="*.google.se" /> <allow-access-from domain="*.google.bg" /> <allow-access-from domain="*.google.hr" /> <allow-access-from domain="*.google.cz" /> <allow-access-from domain="*.google.gr" /> <allow-access-from domain="*.google.co.in" /> <allow-access-from domain="*.google.hu" /> <allow-access-from domain="*.google.co.id" /> <allow-access-from domain="*.google.lv" /> <allow-access-from domain="*.google.lt" /> <allow-access-from domain="*.google.pt" /> <allow-access-from domain="*.google.ro" /> <allow-access-from domain="*.google.sk" /> <allow-access-from domain="*.google.si" /> <allow-access-from domain="*.google.com.ph" /> <allow-access-from domain="*.google.com.ua" /> <allow-access-from domain="*.google.com.vn" /> <allow-access-from domain="*.google.co.uk" /> <allow-access-from domain="*.google.com.au" /> <allow-access-from domain="*.google.ca" /> <allow-access-from domain="*.google.nl" /> <allow-access-from domain="*.google.be" /> <allow-access-from domain="*.google.fr" /> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://picasaweb.google | 
| Path: | /data/feed/api/user | 
| GET /data/feed/api/user Host: picasaweb.google.com Proxy-Connection: keep-alive Referer: http://picasaweb.google Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=sorry=6N0zPerLQtZIDQDH- | 
| HTTP/1.1 200 OK Expires: Sat, 05 Mar 2011 14:39:52 GMT Date: Sat, 05 Mar 2011 14:39:52 GMT Cache-Control: private, max-age=0, must-revalidate, no-transform Set-Cookie: _rtok=KfyGPGMy2O9Q; Path=/; HttpOnly Set-Cookie: S=sorry=6N0zPerLQtZIDQDH- Content-Type: application/rss+xml; charset=UTF-8 Vary: Accept, X-GData-Authorization, GData-Version, Cookie GData-Version: 1.0 Last-Modified: Wed, 24 Jun 2009 20:06:29 GMT X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 73985 <?xml version='1.0' encoding='UTF-8'?><rss xmlns:exif='http:/ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://picasaweb.google | 
| Path: | / | 
| TRACE / HTTP/1.0 Host: picasaweb.google.com Cookie: 49a1fceff44b1a19 | 
| HTTP/1.0 200 OK Expires: Sat, 05 Mar 2011 14:35:50 GMT Date: Sat, 05 Mar 2011 14:35:50 GMT Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _rtok=ehpYxI-cF8Rb; Path=/; HttpOnly Set-Cookie: S=photos_html=jmm24VE6By Content-Type: message/http; charset=UTF-8 Content-Length: 468 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE TRACE /errors/405 HTTP/1.1 Host: picasaweb.google.com Cookie: 49a1fceff44b1a19 X-Google-GFE-Frontline X-Google-GFE-Can-Retry: yes X-User-IP: 1 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://picasaweb.google | 
| Path: | /s/c/bin/slideshow.swf | 
| GET /robots.txt HTTP/1.0 Host: picasaweb.google.com | 
| HTTP/1.0 200 OK Content-Type: text/plain Date: Sat, 05 Mar 2011 14:35:50 GMT Expires: Sat, 05 Mar 2011 14:35:50 GMT Cache-Control: private, max-age=0 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE User-agent: * Allow: /lh/albumList Allow: /lh/album Allow: /lh/favorites Allow: /lh/idredir Allow: /lh/photo Allow: /lh/sredir Disallow: /lh/ |