1. Cross-site scripting (reflected)
1.1. http://adserver.teracent.net/tase/ad [name of an arbitrarily supplied request parameter]
1.2. http://adserver.teracent.net/tase/ad [rcu parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.teracent |
Path: | /tase/ad |
GET /tase/ad?AdBoxType=49 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://finance.yahoo.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: adserver.teracent.net Proxy-Connection: Keep-Alive Cookie: uid=MhkKf1z.4ChimO; imp=a$le#1289789126719 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Expires: Sat, 6 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: imp=a$le#1289925791467 Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Tue, 16 Nov 2010 16:43:10 GMT Content-Length: 1893 <!-- image_dynamic.jsp --> <!DOCTYPE html> <head> <meta charset="utf-8"> <title>1289925791467 </head> <body> <div id="1289925791467_754 ...[SNIP]... em9/M=757214.13840878 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.teracent |
Path: | /tase/ad |
GET /tase/ad?AdBoxType=49 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://finance.yahoo.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: adserver.teracent.net Proxy-Connection: Keep-Alive Cookie: uid=MhkKf1z.4ChimO; imp=a$le#1289789126719 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Expires: Sat, 6 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: imp=a$le#1289925791268 Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Tue, 16 Nov 2010 16:43:10 GMT Content-Length: 1906 <!-- image_dynamic.jsp --> <!DOCTYPE html> <head> <meta charset="utf-8"> <title>1289925791268 </head> <body> <div id="1289925791268_773 ...[SNIP]... 6em9/M=757214.13840878 ...[SNIP]... |