1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cross-domain Referer leakage
4. Cross-domain script include
5. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit?title=Curbing Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: PHPSESSID=thdr0hluc1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cmf_i=3676180644d247 Set-Cookie: cmf_spr=A%2FN; expires=Fri, 04-Feb-2011 14:10:49 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=b4ba2ac9c71548e Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 48016 Date: Wed, 05 Jan 2011 14:10:49 GMT X-Varnish: 1100795404 Age: 0 Via: 1.1 varnish Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <input type="hidden" name="url" value="http://blog ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit HTTP/1.1 Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: PHPSESSID=q0relcshp1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cmf_i=8436994294d247 Set-Cookie: cmf_spr=A%2FN; expires=Fri, 04-Feb-2011 14:06:17 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=c50259cbd2e8838 Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 6645 Date: Wed, 05 Jan 2011 14:06:17 GMT X-Varnish: 1603492222 Age: 0 Via: 1.1 varnish Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit?title=Aujas Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: PHPSESSID=ufo7dq43g2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cmf_i=5893461054d247 Set-Cookie: cmf_spr=A%2FN; expires=Fri, 04-Feb-2011 14:06:23 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=0c21d24db07e9f5 Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 6645 Date: Wed, 05 Jan 2011 14:06:23 GMT X-Varnish: 1603495947 Age: 0 Via: 1.1 varnish Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta name="description" content="Submit a site to StumbleUpon" /> <link rel="stylesheet" href="http://cdn.stumble <!--[if lte IE 6]> ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://ajax ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://cdn.stumble <link rel="shortcut icon" href="http://cdn.stumble <title> ...[SNIP]... <div id="ff-install-helper" style="display: none;"> <img id="close-button" src="http://cdn.stumble <h2>Installing is Easy!<img src="http://cdn.stumble ...[SNIP]... <div style="padding: 35px 0 200px 320px;" class="clearfix"> <img src="http://cdn.stumble <h2 style="padding-top: 15px; margin-bottom: 25px; font-size: 20px;"> ...[SNIP]... <!-- end wrapper --> <script type="text/javascript" charset="utf-8" src="http://cdn.stumble ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit HTTP/1.1 Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: PHPSESSID=q0relcshp1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cmf_i=8436994294d247 Set-Cookie: cmf_spr=A%2FN; expires=Fri, 04-Feb-2011 14:06:17 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=c50259cbd2e8838 Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 6645 Date: Wed, 05 Jan 2011 14:06:17 GMT X-Varnish: 1603492222 Age: 0 Via: 1.1 varnish Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://ajax ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://cdn.stumble ...[SNIP]... <!-- end wrapper --> <script type="text/javascript" charset="utf-8" src="http://cdn.stumble ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stumbleupon |
Path: | /submit |
GET /submit HTTP/1.1 Host: www.stumbleupon.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache Set-Cookie: PHPSESSID=q0relcshp1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cmf_i=8436994294d247 Set-Cookie: cmf_spr=A%2FN; expires=Fri, 04-Feb-2011 14:06:17 GMT; path=/; domain=.stumbleupon.com Set-Cookie: cmf_sp=http%3A%2F%2Fwww Set-Cookie: su_c=c50259cbd2e8838 Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 6645 Date: Wed, 05 Jan 2011 14:06:17 GMT X-Varnish: 1603492222 Age: 0 Via: 1.1 varnish Connection: keep-alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |