1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://sitelife |
Path: | /ver1.0/daapi2.api |
GET /ver1.0/daapi2.api Accept: */* Referer: http://www.theglobea Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: sitelife.theglobeandmail Proxy-Connection: Keep-Alive Cookie: s_pers=%20_ga_tsm%3Dm |
HTTP/1.1 200 OK Cache-Control: private Content-Type: application/x-javascript; charset=utf-8 Vary: Content-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 x-SiteLife-host: l3vm163l3pluckcom Set-Cookie: SiteLifeHost=l3vm163 Date: Sat, 20 Nov 2010 02:08:18 GMT Content-Length: 96 PluckSDK.jsonpcb('request "Envelopes": [] }); |
Severity: | Information |
Confidence: | Certain |
Host: | http://sitelife |
Path: | /ver1.0/daapi2.api |
GET /ver1.0/daapi2.api?ctk=i Accept: */* Referer: http://www.theglobea Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: sitelife.theglobeandmail Proxy-Connection: Keep-Alive Cookie: s_pers=%20s_user_zip |
HTTP/1.1 200 OK Cache-Control: private Content-Type: application/x-javascript; charset=utf-8 Vary: Content-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 x-SiteLife-host: l3vm163l3pluckcom Set-Cookie: SiteLifeHost=l3vm163 Set-Cookie: anonId=a8359dd6-06b2-4e88 Date: Sat, 20 Nov 2010 02:06:03 GMT Content-Length: 117 PluckSDK.jsonpcb('request |
Severity: | Information |
Confidence: | Certain |
Host: | http://sitelife |
Path: | /ver1.0/daapi2.api |
GET /ver1.0/daapi2.api?ctk=i Accept: */* Referer: http://www.theglobea Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: sitelife.theglobeandmail Proxy-Connection: Keep-Alive Cookie: s_pers=%20s_user_zip |
HTTP/1.1 200 OK Cache-Control: private Content-Type: application/x-javascript; charset=utf-8 Vary: Content-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 x-SiteLife-host: l3vm163l3pluckcom Set-Cookie: SiteLifeHost=l3vm163 Set-Cookie: anonId=a8359dd6-06b2-4e88 Date: Sat, 20 Nov 2010 02:06:03 GMT Content-Length: 117 PluckSDK.jsonpcb('request |