1. Cross-site scripting (reflected)
1.1. http://extras.expedia.com/Package/Delivery/PkgSearchDirect.aspx [dtla parameter]
1.2. http://extras.expedia.com/Package/Delivery/PkgSearchDirect.aspx [otla parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://extras.expedia.com |
Path: | /Package/Delivery |
GET /Package/Delivery Host: extras.expedia.com Proxy-Connection: keep-alive Referer: http://www.expedia.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=236C6364572 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: application/x-javascript; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: expEAPID=0; expires=Sun, 14-Nov-2010 21:52:14 GMT; path=/ Set-Cookie: hl_upm=Nn2Ysa9T4CoOd2Jy Set-Cookie: hl_ubm=nHnTf7LftB6hx X-Powered-By: ASP.NET p3p: CP="ALL DSP COR CUR ADMo DEVo PSAo PSDo IVDi OUR STP PRE" Date: Sat, 13 Nov 2010 21:52:13 GMT Connection: close var THSearch = 1408536938;if(typeof th_domain=="undefined") ...[SNIP]... thru=www.expedia.com ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://extras.expedia.com |
Path: | /Package/Delivery |
GET /Package/Delivery Host: extras.expedia.com Proxy-Connection: keep-alive Referer: http://www.expedia.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=236C6364572 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: application/x-javascript; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: expEAPID=0; expires=Sun, 14-Nov-2010 21:52:14 GMT; path=/ Set-Cookie: hl_upm=Nn2Ysa9T4CoOd2Jy Set-Cookie: hl_ubm=vs5tTNZUIDiE2 X-Powered-By: ASP.NET p3p: CP="ALL DSP COR CUR ADMo DEVo PSAo PSDo IVDi OUR STP PRE" Date: Sat, 13 Nov 2010 21:52:13 GMT Connection: close var THSearch = 1408536929;if(typeof th_domain=="undefined") ...[SNIP]... E|0', 'THclckthru=www.expedia ...[SNIP]... |