1. Cross-site scripting (reflected)
1.1. https://sales.liveperson.net/hc/12703439/ [SESSIONVAR%21skill parameter]
1.2. https://sales.liveperson.net/hc/12703439/ [HumanClickKEY cookie]
Severity: | High |
Confidence: | Certain |
Host: | https://sales.liveperson |
Path: | /hc/12703439/ |
GET /hc/12703439/?cmd=file Host: sales.liveperson.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: HumanClickKEY=818382 |
HTTP/1.1 200 OK Connection: close Date: Mon, 15 Nov 2010 23:10:43 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM" X-Powered-By: ASP.NET Set-Cookie: HumanClickSiteContainerID Set-Cookie: LivePersonID=-438028 Set-Cookie: HumanClickCHATKEY Content-Type: text/html Last-Modified: Mon, 15 Nov 2010 23:10:43 GMT Cache-Control: no-store Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Length: 8318 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... r(true) pageTracker._setAllowHash setTimeout('sendGAData()' function sendGAData(){ try{ var path = 'LivePerson PreChat/Sales-SL-WWW pageTracker._trackPa }catch(e){ pageTracker._trackPa } </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://sales.liveperson |
Path: | /hc/12703439/ |
GET /hc/12703439/?cmd=file Host: sales.liveperson.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: HumanClickKEY=818382 |
HTTP/1.1 200 OK Connection: close Date: Mon, 15 Nov 2010 23:10:52 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM" X-Powered-By: ASP.NET Set-Cookie: HumanClickSiteContainerID Set-Cookie: LivePersonID=-438028 Content-Type: text/html Last-Modified: Mon, 15 Nov 2010 23:10:52 GMT Cache-Control: no-store Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Length: 35454 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <link href="/hc/12703439/?cmd ...[SNIP]... |