1. Cross-site scripting (reflected)
1.1. http://api.ak.facebook.com/restserver.php [method parameter]
1.2. http://api.ak.facebook.com/restserver.php [urls parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://api.ak.facebook |
Path: | /restserver.php |
GET /restserver.php?v=1.0 Host: api.ak.facebook.com Proxy-Connection: keep-alive Referer: http://www.nba.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: datr=1286843309 |
HTTP/1.1 200 OK Content-Type: text/javascript;charset Pragma: no-cache X-Cnection: close Content-Length: 385 Cache-Control: private, no-cache, no-store, must-revalidate Expires: Mon, 08 Nov 2010 00:30:39 GMT Date: Mon, 08 Nov 2010 00:30:39 GMT Connection: close fb_sharepro_render({ |
Severity: | High |
Confidence: | Certain |
Host: | http://api.ak.facebook |
Path: | /restserver.php |
GET /restserver.php?v=1.0 Host: api.ak.facebook.com Proxy-Connection: keep-alive Referer: http://www.nba.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: datr=1286843309 |
HTTP/1.1 200 OK Content-Type: text/javascript;charset Pragma: X-Cnection: close Content-Length: 401 Cache-Control: public, max-age=120 Expires: Mon, 08 Nov 2010 00:32:43 GMT Date: Mon, 08 Nov 2010 00:30:43 GMT Connection: close fb_sharepro_render({ |
Severity: | High |
Confidence: | Certain |
Host: | http://api.ak.facebook |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: api.ak.facebook.com |
HTTP/1.0 200 OK Content-Type: application/xml X-Cnection: close Cache-Control: max-age=86400 Expires: Tue, 09 Nov 2010 00:30:29 GMT Date: Mon, 08 Nov 2010 00:30:29 GMT Content-Length: 280 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" secure="false" /> <site- ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://api.ak.facebook |
Path: | /restserver.php |
GET /restserver.php?v=1.0 Host: api.ak.facebook.com Proxy-Connection: keep-alive Referer: http://www.nba.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: datr=1286843309 |
HTTP/1.1 200 OK Content-Type: text/javascript;charset Pragma: X-Cnection: close Content-Length: 731 Cache-Control: public, max-age=120 Expires: Mon, 08 Nov 2010 00:32:49 GMT Date: Mon, 08 Nov 2010 00:30:49 GMT Connection: close fb_sharepro_render('<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://api.ak.facebook |
Path: | /restserver.php |
GET /robots.txt HTTP/1.0 Host: api.ak.facebook.com |
HTTP/1.0 200 OK Accept-Ranges: bytes Content-Type: text/plain; charset=UTF-8 X-Cnection: close Content-Length: 24 Cache-Control: max-age=86400 Expires: Tue, 09 Nov 2010 00:30:29 GMT Date: Mon, 08 Nov 2010 00:30:29 GMT Connection: close User-agent: * Disallow: |