1.1. http://adc2.adcentriconline.com/adcentric/click/1728/2/50458 [ADCUserID cookie]
1.2. http://adc2.adcentriconline.com/adcentric/data/1728/1/50458 [ADCUserID cookie]
1.3. http://adc2.adcentriconline.com/adcentric/event/1728/3/50458 [ADCUserID cookie]
1.4. http://adc2.adcentriconline.com/adcentric/form/1728/2/50458 [ADCUserID cookie]
1.5. http://adc2.adcentriconline.com/adcentric/tag/1728/1/50458 [ADCUserID cookie]
2. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://adc2.adcentri |
Path: | /adcentric/click/1728/2 |
GET /adcentric/click/1728/2 Host: adc2.adcentriconline.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ADCUserID=c222f%0d%0a5c335e93809; 1728-1-50458=12300; |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 08:11:26 GMT Server: Apache X-RealServer: h010 P3P: CP="NOI OTC OTP OUR NOR" Cache-Control: no-cache, no-store, must-revalidate, proxy-revalidate Pragma: no-cache Expires: Thu, 23 Sep 2004 17:42:04 GMT Set-cookie: ADCUserID=c222f 5c335e93809; expires=Monday, 28-Sep-2020 04:11:26 GMT; path=/; domain=.adcentriconline Set-cookie: 1728-2-50458=0; expires=Saturday, 20-Nov-2010 02:11:26 GMT; path=/; domain=.adcentriconline Refresh: 0; URL=http://best.bell.ca Connection: close Content-Type: text/html Content-Length: 165 <html><head><meta http-equiv="Refresh" content="0; URL=http://best.bell.ca |
Severity: | High |
Confidence: | Certain |
Host: | http://adc2.adcentri |
Path: | /adcentric/data/1728/1 |
GET /adcentric/data/1728/1 Host: adc2.adcentriconline.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ADCUserID=dddf0%0d%0ae1f4a682539; 1728-1-50458=12300; |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 08:11:35 GMT Server: Apache X-RealServer: h001 P3P: CP="NOI OTC OTP OUR NOR" Cache-Control: no-cache, no-store, must-revalidate, proxy-revalidate Pragma: no-cache Expires: Thu, 23 Sep 2004 17:42:04 GMT Set-cookie: ADCUserID=dddf0 e1f4a682539; expires=Monday, 28-Sep-2020 04:11:39 GMT; path=/; domain=.adcentriconline Refresh: 0; URL=http://adc2 Connection: close Content-Type: text/html Content-Length: 161 <html><head><meta http-equiv="Refresh" content="0; URL=http://adc2 |
Severity: | High |
Confidence: | Certain |
Host: | http://adc2.adcentri |
Path: | /adcentric/event/1728/3 |
GET /adcentric/event/1728/3 Host: adc2.adcentriconline.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ADCUserID=94add%0d%0a21c43d4d130; 1728-1-50458=12300; |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 08:11:34 GMT Server: Apache X-RealServer: h002 P3P: CP="NOI OTC OTP OUR NOR" Cache-Control: no-cache, no-store, must-revalidate, proxy-revalidate Pragma: no-cache Expires: Thu, 23 Sep 2004 17:42:04 GMT Set-cookie: ADCUserID=94add 21c43d4d130; expires=Monday, 28-Sep-2020 04:11:34 GMT; path=/; domain=.adcentriconline Refresh: 0; URL=http://adc2 Connection: close Content-Type: text/html Content-Length: 161 <html><head><meta http-equiv="Refresh" content="0; URL=http://adc2 |
Severity: | High |
Confidence: | Certain |
Host: | http://adc2.adcentri |
Path: | /adcentric/form/1728/2 |
GET /adcentric/form/1728/2 Host: adc2.adcentriconline.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ADCUserID=d9cae%0d%0ab69c9c46b1; 1728-1-50458=12300; |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 08:11:31 GMT Server: Apache X-RealServer: h009 P3P: CP="NOI OTC OTP OUR NOR" Cache-Control: no-cache, no-store, must-revalidate, proxy-revalidate Pragma: no-cache Expires: Thu, 23 Sep 2004 17:42:04 GMT Set-cookie: ADCUserID=d9cae b69c9c46b1; expires=Monday, 28-Sep-2020 04:11:31 GMT; path=/; domain=.adcentriconline Location: http://best.bell.ca/en Refresh: 0; URL=http://best.bell.ca Connection: close Content-Type: text/html Content-Length: 165 <html><head><meta http-equiv="Refresh" content="0; URL=http://best.bell.ca |
Severity: | High |
Confidence: | Certain |
Host: | http://adc2.adcentri |
Path: | /adcentric/tag/1728/1 |
GET /adcentric/tag/1728/1 Host: adc2.adcentriconline.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ADCUserID=82e3e%0d%0aaee656c8f57; 1728-1-50458=12300; |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 08:11:21 GMT Server: Apache X-RealServer: h010 P3P: CP="NOI OTC OTP OUR NOR" Cache-Control: no-cache, no-store, must-revalidate, proxy-revalidate Pragma: no-cache Expires: Thu, 23 Sep 2004 17:42:04 GMT Set-cookie: ADCUserID=82e3e aee656c8f57; expires=Monday, 28-Sep-2020 04:11:21 GMT; path=/; domain=.adcentriconline Set-cookie: 1728-1-50458=12300; path=/; domain=.adcentriconline Last-Modified: Sat, 20 Nov 2010 08:11:21 GMT Connection: close Content-Type: text/javascript Content-Length: 13979 // adc2 headers var adc_creative_12300_clicks = []; var adc_creative_12300_events = []; adc_creative_12300_clicks adc ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adc2.adcentri |
Path: | /adcentric/form/1728/2 |
GET /adcentric/form/1728/2 Host: adc2.adcentriconline.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ADCUserID=NkDrm5M4SVIi4zZ |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 08:05:56 GMT Server: Apache X-RealServer: h009 P3P: CP="NOI OTC OTP OUR NOR" Cache-Control: no-cache, no-store, must-revalidate, proxy-revalidate Pragma: no-cache Expires: Thu, 23 Sep 2004 17:42:04 GMT Set-cookie: ADCUserID=NkDrm5M4SVIi4zZ Location: http://best.bell.ca/en Refresh: 0; URL=http://best.bell.ca Connection: close Content-Type: text/html Content-Length: 211 <html><head><meta http-equiv="Refresh" content="0; URL=http://best.bell.ca ...[SNIP]... |