2. Cross-site scripting (reflected)
2.1. http://www.accuweather.com/index-radar.asp [Referer HTTP header]
2.2. http://www.accuweather.com/maps-satellite.asp [Referer HTTP header]
3. Cross-domain Referer leakage
4. Cross-domain script include
4.1. http://www.accuweather.com/us/NY/HONEOYE%20FALLS/14472/city-weather-forecast.asp
4.2. http://www.accuweather.com/us/satellite/ei/us_/satellite.asp
5. Cookie without HttpOnly flag set
5.1. http://www.accuweather.com/index-radar.asp
5.2. http://www.accuweather.com/maps-satellite.asp
5.3. http://www.accuweather.com/us/NY/HONEOYE%20FALLS/14472/city-weather-forecast.asp
5.4. http://www.accuweather.com/us/satellite/ei/us_/satellite.asp
Severity: | High |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.accuweather.com |
HTTP/1.0 200 OK Content-Length: 1403 Content-Type: text/xml Last-Modified: Tue, 09 Feb 2010 20:00:39 GMT Accept-Ranges: bytes ETag: "c28f298dc2a9ca1:a74" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Thu, 03 Feb 2011 16:34:40 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> <allow-access-from domain="*.accuweather.com" /> <allow-access-from domain="*.accuweatherchannel.com" /> <allow-access-from domain="*.discovery.com" /> <allow-access-from domain="*.oddcast.com" /> <allow-access-from domain="*.ucview.com" /> <allow-access-from domain="*.2mdn.net" secure="true" /> ...[SNIP]... <allow-access-from domain="*.doubleclick.net" secure="true" /> ...[SNIP]... <allow-access-from domain="*.doubleclick.com" secure="true" /> ...[SNIP]... <allow-access-from domain="*.adcdn.com" secure="true" /> ...[SNIP]... <allow-access-from domain="*.dartmotif.com" secure="true" /> ...[SNIP]... <allow-access-from domain="*.aolcdn.com" secure="true" /> ...[SNIP]... <allow-access-from domain="maps.google.com" /> <allow-access-from domain="maps.yahooapis.com"/> <allow-access-from domain="spm161.brinkster.net" /> <allow-access-from domain="www.dotglu.com" /> <allow-access-from domain="www.johnfrieda.com" /> <allow-access-from domain="www.travelboards.com" /> <allow-access-from domain="www.topix.com"/> <allow-access-from domain="66.42.146.50" /> <allow-access-from domain="66.42.146.66" /> <allow-access-from domain="68.167.121.226" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /index-radar.asp |
GET /index-radar.asp HTTP/1.1 Host: www.accuweather.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Content-Length: 64616 Content-Type: text/html Cache-Control: public Date: Thu, 03 Feb 2011 16:35:04 GMT Connection: close Set-Cookie: acm=ct1=Los+Angeles&uf0 Set-Cookie: aco=dbg=0; path=/ <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <hea ...[SNIP]... <script>var apgUserInfoObj={country: ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /maps-satellite.asp |
GET /maps-satellite.asp HTTP/1.1 Host: www.accuweather.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Content-Length: 64040 Content-Type: text/html Cache-Control: public Date: Thu, 03 Feb 2011 16:35:14 GMT Connection: close Set-Cookie: acm=ct1=Los+Angeles&uf0 Set-Cookie: aco=dbg=0; path=/ <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <script>var apgUserInfoObj={country: ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /us/NY/HONEOYE%20FALLS |
GET /us/NY/HONEOYE%20FALLS Host: www.accuweather.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Content-Length: 80324 Content-Type: text/html Cache-Control: public Date: Thu, 03 Feb 2011 16:34:42 GMT Connection: close Set-Cookie: aco=hi2=36&lo1=16&dn0=day Set-Cookie: acm=nm0=ROC&vi0=ROC&ob0 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <hea ...[SNIP]... <noscript><a href="http://www.omniture src="http://accuweather height="1" width="1" border="0" alt="" /> ...[SNIP]... </h4> <a href="http://www.adci.com ...[SNIP]... <a href="http://www <img src="http://brightcove.vo ...[SNIP]... <a href="http://www <img src="http://brightcove.vo ...[SNIP]... <a href="http://www <img src="http://brightcove.vo ...[SNIP]... <a href="http://www <img src="http://brightcove.vo ...[SNIP]... <li class="last"> <a href="http://www ...[SNIP]... <h4><a href="http://www ...[SNIP]... <h4> <a href="http://www <br /><a href="http://www ...[SNIP]... </p> <a href="http://www ...[SNIP]... <li><a href="http://www.accumall ...[SNIP]... <p> This page may contain Mapping and <a href="http://www ...[SNIP]... </script> <script type="text/javascript" src="http://edge <noscript> <a href="http://www ...[SNIP]... <noscript> <img src="http://b.scorec </noscript> ...[SNIP]... <noscript> <img style="display:none;" src="//secure-us </noscript> <img style="display:none;" height="1" width="1" src="http://tags.bluekai </body> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /us/NY/HONEOYE%20FALLS |
GET /us/NY/HONEOYE%20FALLS Host: www.accuweather.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Content-Length: 79770 Content-Type: text/html Cache-Control: public Date: Thu, 03 Feb 2011 16:34:38 GMT Connection: close Set-Cookie: acm=nm0=ROC&vi0=ROC&ob0 Set-Cookie: aco=hi2=36&lo2=25&wx0=03 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <hea ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /us/satellite/ei/us_ |
GET /us/satellite/ei/us_ Host: www.accuweather.com Proxy-Connection: keep-alive Referer: http://burp/show/65 Cache-Control: max-age=0 Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=256067995 |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Content-Type: text/html Cache-Control: public Vary: Accept-Encoding Date: Thu, 03 Feb 2011 17:39:07 GMT Connection: close Set-Cookie: aco=dbg=0; path=/ Set-Cookie: acm=ptu=&mt=0&ct0=New Content-Length: 64023 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /index-radar.asp |
GET /index-radar.asp HTTP/1.1 Host: www.accuweather.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Location: http://www.accuweather Content-Length: 0 Content-Type: text/html Cache-Control: public Vary: Accept-Encoding Date: Thu, 03 Feb 2011 16:34:42 GMT Connection: close Set-Cookie: acm=ct1=Los+Angeles&uf0 Set-Cookie: aco=dbg=0; path=/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /maps-satellite.asp |
GET /maps-satellite.asp HTTP/1.1 Host: www.accuweather.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Location: http://www.accuweather Content-Length: 0 Content-Type: text/html Cache-Control: public Vary: Accept-Encoding Date: Thu, 03 Feb 2011 16:34:42 GMT Connection: close Set-Cookie: acm=ct1=Los+Angeles&uf0 Set-Cookie: aco=dbg=0; path=/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /us/NY/HONEOYE%20FALLS |
GET /us/NY/HONEOYE%20FALLS Host: www.accuweather.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Content-Length: 79770 Content-Type: text/html Cache-Control: public Date: Thu, 03 Feb 2011 16:34:38 GMT Connection: close Set-Cookie: acm=nm0=ROC&vi0=ROC&ob0 Set-Cookie: aco=hi2=36&lo2=25&wx0=03 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <hea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /us/satellite/ei/us_ |
GET /us/satellite/ei/us_ Host: www.accuweather.com Proxy-Connection: keep-alive Referer: http://burp/show/65 Cache-Control: max-age=0 Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=256067995 |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET p3p: CP="NOI DSP COR ADMa DEVa TAIa PSAa PSDa IVAa IVDa CONi HISa OUR IND CNT" Content-Type: text/html Cache-Control: public Vary: Accept-Encoding Date: Thu, 03 Feb 2011 17:39:07 GMT Connection: close Set-Cookie: aco=dbg=0; path=/ Set-Cookie: acm=ptu=&mt=0&ct0=New Content-Length: 64023 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.accuweather |
Path: | /us/NY/HONEOYE%20FALLS |
GET /robots.txt HTTP/1.0 Host: www.accuweather.com |
HTTP/1.0 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 1819 Content-Type: text/html Cache-Control: private Date: Thu, 03 Feb 2011 16:34:40 GMT Connection: close User-agent: * Disallow: /_mm/ Disallow: /_notes/ Disallow: /_baks/ Disallow: /adc2004/ Disallow: /MMWIP/ Disallow: /m/storm.aspx Disallow: /m/US/weather.aspx Disallow: /m/US/radar.aspx Disall ...[SNIP]... |