1. Cross-site scripting (reflected)
1.1. http://ads.tw.adsonar.com/adserving/getAds.jsp [pid parameter]
1.2. http://ads.tw.adsonar.com/adserving/getAds.jsp [placementId parameter]
1.3. http://ads.tw.adsonar.com/adserving/getAds.jsp [ps parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://ads.tw.adsonar.com |
Path: | /adserving/getAds.jsp |
GET /adserving/getAds.jsp Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.politicsdaily Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: ads.tw.adsonar.com Proxy-Connection: Keep-Alive Cookie: TID=16e8oqe01cg8de; TData=99999%7C50085 |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:43:28 GMT Cache-Control: no-cache Pragma: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: policyref="http://ads Content-Type: text/html;charset=utf-8 Vary: Accept-Encoding,User Content-Length: 2512 <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN"> <html> <head> <title>Ads by Quigo</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> ...[SNIP]... </script> java.lang.NumberForm </head> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.tw.adsonar.com |
Path: | /adserving/getAds.jsp |
GET /adserving/getAds.jsp Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.aolnews.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: ads.tw.adsonar.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: TID=16e8oqe01cg8de; TData=99999%7C50085 |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:42:42 GMT Vary: Accept-Encoding,User Content-Type: text/plain Content-Length: 3236 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <body> <!-- java.lang.NumberForm ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.tw.adsonar.com |
Path: | /adserving/getAds.jsp |
GET /adserving/getAds.jsp Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.politicsdaily Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: ads.tw.adsonar.com Proxy-Connection: Keep-Alive Cookie: TID=16e8oqe01cg8de; TData=99999%7C50085 |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:43:32 GMT Vary: Accept-Encoding,User Content-Type: text/plain Content-Length: 3724 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <body> <!-- java.lang.NumberForm ...[SNIP]... |