1. Cross-site scripting (reflected)
1.1. http://syndicate.verizon.net/ads/js.ashx [page parameter]
1.2. http://syndicate.verizon.net/ads/js.ashx [pos parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://syndicate.verizon |
Path: | /ads/js.ashx |
GET /ads/js.ashx?page Accept: */* Referer: http://www.verizon.net Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: syndicate.verizon.net Proxy-Connection: Keep-Alive Pragma: no-cache |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/plain; charset=utf-8 Content-Length: 2442 Date: Sat, 20 Nov 2010 01:34:44 GMT Connection: close //Copyright (c) 2000-2003 by 24/7 Real Media, Inc. ALL RIGHTS RESERVED. 3/13/2008 //New changes made on 06/25 and pushed to fuat on 06/25 //configuration OAS_url = 'http://oascentral OAS_sitepage = 'vznewsroom.net/homepage OAS_listpos = 'Top1,x20,x21,x37,x38,x48 OAS_query = 'search='; OAS_target = '_blank'; OAS_RegLocurl = 'http://syndicate.verizon OAS_SynHandlerurl = ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://syndicate.verizon |
Path: | /ads/js.ashx |
GET /ads/js.ashx?page Accept: */* Referer: http://www.verizon.net Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: syndicate.verizon.net Proxy-Connection: Keep-Alive Pragma: no-cache |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/plain; charset=utf-8 Content-Length: 2442 Date: Sat, 20 Nov 2010 01:34:49 GMT Connection: close //Copyright (c) 2000-2003 by 24/7 Real Media, Inc. ALL RIGHTS RESERVED. 3/13/2008 //New changes made on 06/25 and pushed to fuat on 06/25 //configuration OAS_url = 'http://oascentral OAS_sitepage = 'vznewsroom.net/homepage OAS_listpos = 'Top1,x20,x21,x37,x38,x48 OAS_query = 'search='; OAS_target = '_blank'; OAS_RegLocurl = 'http://syndicate.verizon OAS_SynHandlerurl = 'http://syndicate.verizon ...[SNIP]... |