1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
Severity: | High |
Confidence: | Certain |
Host: | http://www.conduit |
Path: | /drawtoolbar/ |
GET /drawtoolbar/?ct Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.conduit-banners.com |
HTTP/1.1 200 OK Cache-Control: private Date: Wed, 23 Feb 2011 22:39:59 GMT Content-Type: text/javascript; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Vary: Accept-Encoding Content-Length: 14150 document.write('<img style="visibility:hidden; ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.conduit |
Path: | /drawtoolbar/ |
GET /drawtoolbar/?ct Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.conduit-banners.com |
HTTP/1.1 200 OK Cache-Control: private Date: Wed, 23 Feb 2011 22:39:55 GMT Content-Type: text/javascript; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Vary: Accept-Encoding Content-Length: 14093 document.write('<img style="visibility:hidden; ...[SNIP]... <td style="white-space:nowrap ...[SNIP]... <td style="padding-left:2 ...[SNIP]... <td><img src="http://storage ...[SNIP]... <td><img src="http://storage ...[SNIP]... <td style="white-space:nowrap ...[SNIP]... <td style="white-space:nowrap ...[SNIP]... <td valign="middle" style="padding-left:3px ...[SNIP]... <td><img src="http://storage ...[SNIP]... <td><img src="http://storage ...[SNIP]... <td style="white-space:nowrap ...[SNIP]... <td style="white-space:nowrap ...[SNIP]... <td><img src="http://storage ...[SNIP]... |