1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.couponmountain |
Path: | /coupon-codes--se-bobs |
GET /coupon-codes--se-bobs Host: www.couponmountain.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:48:07 GMT Server: Apache P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: S_T_USER_ID=d94db7b4 Set-Cookie: S_T_SEM_TPLID=75; path=/; domain=.couponmountain Set-Cookie: S_T_SCORE=deleted; expires=Sat, 02-Jan-2010 13:48:06 GMT; path=/; domain=.couponmountain Set-Cookie: S_T_REFERER=AwA%3D; path=/; domain=.couponmountain Set-Cookie: S_T_USER_SESSION Set-Cookie: S_T_TRAFFIC_TYPE=0; path=/; domain=.couponmountain Set-Cookie: S_T_SOURCE=deleted; expires=Sat, 02-Jan-2010 13:48:06 GMT; path=/; domain=.couponmountain Set-Cookie: S_T_PRE_RANDSTR Set-Cookie: S_T_SEM_LANDING=0; path=/; domain=.couponmountain Set-Cookie: PHPSESSID=4l0ddj5jev Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: qrylnk=deleted; expires=Sat, 02-Jan-2010 13:48:08 GMT; path=/; domain=.couponmountain Vary: Accept-Encoding,User Keep-Alive: timeout=5, max=87 Connection: Keep-Alive Content-Type: text/html Content-Length: 58696 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Bobs Store Coupons P ...[SNIP]... <link rel="canonical" href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couponmountain |
Path: | /coupon-codes--se-bobs |
GET /coupon-codes--se-bobs Host: www.couponmountain.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=256737945 |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 15:41:16 GMT Server: Apache P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: S_T_USER_ID=acfc492a Set-Cookie: S_T_SEM_TPLID=46; path=/; domain=.couponmountain Set-Cookie: S_T_SCORE=deleted; expires=Sat, 02-Jan-2010 15:41:15 GMT; path=/; domain=.couponmountain Set-Cookie: S_T_REFERER=AwA%3D; path=/; domain=.couponmountain Set-Cookie: S_T_USER_SESSION Set-Cookie: S_T_TRAFFIC_TYPE=0; path=/; domain=.couponmountain Set-Cookie: S_T_SOURCE=deleted; expires=Sat, 02-Jan-2010 15:41:15 GMT; path=/; domain=.couponmountain Set-Cookie: S_T_PRE_RANDSTR Set-Cookie: S_T_SEM_LANDING=0; path=/; domain=.couponmountain Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: qrylnk=deleted; expires=Sat, 02-Jan-2010 15:41:15 GMT; path=/; domain=.couponmountain Vary: Accept-Encoding,User Keep-Alive: timeout=5, max=90 Connection: Keep-Alive Content-Type: text/html Content-Length: 58515 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Bobs Store Coupons P ...[SNIP]... <script type="text/javascript" src="/async_ads_panda.php ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.couponmountain |
Path: | /coupon-codes--se-bobs |
GET /coupon-codes--se-bobs Host: www.couponmountain.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Date: Sun, 02 Jan 2011 13:47:44 GMT Server: Apache P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: S_T_USER_ID=1f430c19 Set-Cookie: S_T_SEM_TPLID=98; path=/; domain=.couponmountain Set-Cookie: S_T_SCORE=deleted; expires=Sat, 02-Jan-2010 13:47:43 GMT; path=/; domain=.couponmountain Set-Cookie: S_T_REFERER=AwA%3D; path=/; domain=.couponmountain Set-Cookie: S_T_USER_SESSION Set-Cookie: S_T_TRAFFIC_TYPE=0; path=/; domain=.couponmountain Set-Cookie: S_T_SOURCE=google_000+CMa Set-Cookie: S_T_PRE_RANDSTR Set-Cookie: S_T_LANDING_SEARCH Set-Cookie: S_T_SEM_LANDING=1; path=/; domain=.couponmountain location: /coupon-codes--se-bobs Vary: Accept-Encoding,User Content-Length: 0 Keep-Alive: timeout=5, max=99 Connection: Keep-Alive Content-Type: text/html |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.couponmountain |
Path: | /coupon-codes--se-bobs |
GET /coupon-codes--se-bobs Host: www.couponmountain.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Date: Sun, 02 Jan 2011 13:47:44 GMT Server: Apache P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" Set-Cookie: S_T_USER_ID=1f430c19 Set-Cookie: S_T_SEM_TPLID=98; path=/; domain=.couponmountain Set-Cookie: S_T_SCORE=deleted; expires=Sat, 02-Jan-2010 13:47:43 GMT; path=/; domain=.couponmountain Set-Cookie: S_T_REFERER=AwA%3D; path=/; domain=.couponmountain Set-Cookie: S_T_USER_SESSION Set-Cookie: S_T_TRAFFIC_TYPE=0; path=/; domain=.couponmountain Set-Cookie: S_T_SOURCE=google_000+CMa Set-Cookie: S_T_PRE_RANDSTR Set-Cookie: S_T_LANDING_SEARCH Set-Cookie: S_T_SEM_LANDING=1; path=/; domain=.couponmountain location: /coupon-codes--se-bobs Vary: Accept-Encoding,User Content-Length: 0 Keep-Alive: timeout=5, max=99 Connection: Keep-Alive Content-Type: text/html |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.couponmountain |
Path: | /async_ads_panda.php |
GET /async_ads_panda.php?ct=2 Host: www.couponmountain.com Proxy-Connection: keep-alive Referer: http://www.couponmountain Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S_T_PRE_RANDSTR |
HTTP/1.1 200 OK Date: Sun, 02 Jan 2011 13:49:16 GMT Server: Apache Vary: Accept-Encoding,User Content-Type: text/html; charset=iso-8859-1 Content-Length: 77 document.write('<!-- advertisement begin --> <!-- advertisement end -->'); |