1. Cross-site scripting (reflected)
1.1. http://mads.cnet.com/mac-ad [adfile parameter]
1.2. http://mads.cnet.com/mac-ad [celt parameter]
1.3. http://mads.cnet.com/mac-ad [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Firm |
Host: | http://mads.cnet.com |
Path: | /mac-ad |
GET /mac-ad?SP=16&_RGROUP Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://news.cnet.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: mads.cnet.com Proxy-Connection: Keep-Alive Cookie: tempSessionId=Cg5goU |
HTTP/1.1 200 OK Date: Sun, 07 Nov 2010 22:48:39 GMT Server: Apache/2.2 Pragma: no-cache Cache-Control: no-cache, must-revalidate Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-15 Expires: Sun, 07 Nov 2010 22:48:39 GMT Content-Length: 735 <!-- MAC ad --><!-- NO AD TEXT: _QUERY_STRING="SP=16& ...[SNIP]... -ID=3&POS=100&ENG ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://mads.cnet.com |
Path: | /mac-ad |
GET /mac-ad?celt=ifcf1522<a>842fa7c3927&SITE=3&BRAND=5&NCAT=1&SP Host: mads.cnet.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: arrowLat=1289161488474; arrowSpc=1; tempSessionId=Cg5goU |
HTTP/1.1 200 OK Date: Sun, 07 Nov 2010 22:45:39 GMT Server: Apache/2.2 Content-Length: 518 Pragma: no-cache Cache-Control: no-cache, must-revalidate Vary: Accept-Encoding Keep-Alive: timeout=15, max=515 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-15 Expires: Sun, 07 Nov 2010 22:45:39 GMT <!-- MAC ad --><!-- NO AD TEXT: _QUERY_STRING="celt=ifcf1522<a>842fa7c3927&SITE=3&BRAND=5&NCAT=1&SP ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://mads.cnet.com |
Path: | /mac-ad |
GET /mac-ad?debfc<a>667496e829b=1 HTTP/1.1 Host: mads.cnet.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: arrowLat=1289161488474; arrowSpc=1; tempSessionId=Cg5goU |
HTTP/1.1 200 OK Date: Sun, 07 Nov 2010 20:44:10 GMT Server: Apache/2.2 Content-Length: 364 Pragma: no-cache Cache-Control: no-cache, must-revalidate Vary: Accept-Encoding Keep-Alive: timeout=15, max=865 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-15 Expires: Sun, 07 Nov 2010 20:44:10 GMT <!-- MAC ad --><!-- NO AD TEXT: _QUERY_STRING="debfc<a>667496e829b=1" _REQ_NUM="0" --><!-- MAC-AD STATUS: COULD NOT MAP BRAND="" SITE="" NCAT="" PTNR="2" TO MA ...[SNIP]... |