1. Cross-site scripting (reflected)
3. HTML does not specify charset
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://wd.sharethis.com |
Path: | /api/getApi.php |
GET /api/getApi.php?return Accept: */* Referer: http://edge.sharethis.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: wd.sharethis.com Proxy-Connection: Keep-Alive Cookie: __stid=CspST0zY2orBc |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 23:27:20 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 173 initWidgetOnSuccess86a5d<script>alert(1)< |
Severity: | Medium |
Confidence: | Firm |
Host: | http://wd.sharethis.com |
Path: | /api/sharer.php |
GET /api/sharer.php Accept: */* Referer: http://edge.sharethis.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: wd.sharethis.com Proxy-Connection: Keep-Alive Cookie: __stid=CspST0zY2orBc |
HTTP/1.1 302 Found Date: Tue, 16 Nov 2010 23:27:20 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Location: http://digg.com/submit Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://wd.sharethis.com |
Path: | /api/getApi.php |
GET /api/getApi.php?return Accept: */* Referer: http://edge.sharethis.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: wd.sharethis.com Proxy-Connection: Keep-Alive Cookie: __stid=CspST0zY2orBc |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 23:27:14 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 112 initWidgetOnSuccess({ |
Severity: | Information |
Confidence: | Firm |
Host: | http://wd.sharethis.com |
Path: | /api/getApi.php |
GET /api/getApi.php?return Accept: */* Referer: http://edge.sharethis.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: wd.sharethis.com Proxy-Connection: Keep-Alive Cookie: __stid=CspST0zY2orBc |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 23:27:14 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 112 initWidgetOnSuccess({ |