1. Cross-site scripting (reflected)
3. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://inyourface |
Path: | /2011/02/03/tv-bride-won |
GET /2011/02/03/tv-bride-won Host: inyourface.ocregister.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Thu, 03 Feb 2011 19:06:29 GMT Server: Apache X-Powered-By: PHP/5.2.5 Vary: Cookie X-Pingback: http://inyourface Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Thu, 03 Feb 2011 19:06:29 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 70357 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... k rel="alternate" type="application/rss+xml ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://inyourface |
Path: | /2011/02/03/tv-bride-won |
GET /2011/02/03/tv-bride-won Host: inyourface.ocregister.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 03 Feb 2011 19:06:12 GMT Server: Apache X-Powered-By: PHP/5.2.5 Vary: Cookie X-Pingback: http://inyourface Link: <http://inyourface Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 84939 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... lication/rss+xml" title=" TV bride won more surgery than she knew - In Your Face - www.ocregister.com" href="http://inyourface ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://inyourface |
Path: | /2011/02/03/tv-bride-won |
GET /2011/02/03/tv-bride-won Host: inyourface.ocregister.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 03 Feb 2011 19:05:49 GMT Server: Apache X-Powered-By: PHP/5.2.5 Vary: Cookie Last-Modified: Thu, 03 Feb 2011 19:04:54 +0000 Cache-Control: max-age=245, must-revalidate X-Pingback: http://inyourface Link: <http://inyourface Connection: close Content-Type: text/html Content-Length: 84762 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... </div> <img src="http://bh.contextweb <script language="JavaScript"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://inyourface |
Path: | /2011/02/03/tv-bride-won |
GET /2011/02/03/tv-bride-won Host: inyourface.ocregister.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 03 Feb 2011 19:05:49 GMT Server: Apache X-Powered-By: PHP/5.2.5 Vary: Cookie Last-Modified: Thu, 03 Feb 2011 19:04:54 +0000 Cache-Control: max-age=245, must-revalidate X-Pingback: http://inyourface Link: <http://inyourface Connection: close Content-Type: text/html Content-Length: 84762 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... </title> <script type="text/javascript" src="http://admin ...[SNIP]... <link rel="shortcut icon" type="image/x-icon" href="http://www <script type="text/javascript" src="http://common.onset ...[SNIP]... <div id="stats"><script language="javascript" src="http://common.onset <div id="PageWrap"> <script type="text/javascript" src="http://static ...[SNIP]... </a><script type="text/javascript" src="http://platform ...[SNIP]... </a><script src="http://static.ak ...[SNIP]... <li class="rssfeedme_li" id="" style="list-style:none ...[SNIP]... <li class="rssfeedme_li" id="" style="list-style:none ...[SNIP]... <li class="rssfeedme_li" id="" style="list-style:none ...[SNIP]... <li class="rssfeedme_li" id="" style="list-style:none ...[SNIP]... <div id="afcblog" align="center"><script type="text/javascript" src="http://common.onset ...[SNIP]... </script> <script src="http://an.tacoda.net ...[SNIP]... |