1. Cross-site scripting (reflected)
1.1. http://ads.adsonar.com/adserving/getAds.jsp [pid parameter]
1.2. http://ads.adsonar.com/adserving/getAds.jsp [placementId parameter]
1.3. http://ads.adsonar.com/adserving/getAds.jsp [ps parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://ads.adsonar.com |
Path: | /adserving/getAds.jsp |
GET /adserving/getAds.jsp Host: ads.adsonar.com Proxy-Connection: keep-alive Referer: http://www.bit-tech.net Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:43:57 GMT Cache-Control: no-cache Pragma: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: policyref="http://ads Content-Type: text/html;charset=utf-8 Vary: Accept-Encoding,User Content-Length: 1639 <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN"> <html> <head> <title>Ads by Quigo</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> ...[SNIP]... </style> java.lang.NumberForm </head> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.adsonar.com |
Path: | /adserving/getAds.jsp |
GET /adserving/getAds.jsp Host: ads.adsonar.com Proxy-Connection: keep-alive Referer: http://www.bit-tech.net Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:43:49 GMT Vary: Accept-Encoding,User Content-Type: text/plain Content-Length: 3340 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <body> <!-- java.lang.NumberForm ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.adsonar.com |
Path: | /adserving/getAds.jsp |
GET /adserving/getAds.jsp Host: ads.adsonar.com Proxy-Connection: keep-alive Referer: http://www.bit-tech.net Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:44:05 GMT Vary: Accept-Encoding,User Content-Type: text/plain Content-Length: 3779 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <body> <!-- java.lang.NumberForm ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://ads.adsonar.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ads.adsonar.com |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:43:13 GMT Server: Apache Last-Modified: Tue, 07 Apr 2009 17:58:21 GMT ETag: "a3d-466fac2afc940" Accept-Ranges: bytes Content-Length: 2621 Vary: Accept-Encoding,User Keep-Alive: timeout=300, max=994 Connection: Keep-Alive Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="assets.espn.go.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="static.espn.go.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="*.quigo.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="*.lonelyplanet.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="*.mochila.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="*.conxise.net" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="app.scanscout.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="media.scanscout.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="static.scanscout.com" to-ports="*" secure="false"/> ...[SNIP]... <allow-access-from domain="*.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.digitalcity.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.aolcdn.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="cdn-startpage.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="startpage.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.channels.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.channel.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.web.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.my.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.news.aol.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="iamalpha.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="imakealpha.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="aimcreate.mdat.aim.com ...[SNIP]... <allow-access-from domain="*.spinner.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.popeater.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.theboombox.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.opticalcortex.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.yourminis.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.facebook.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.liveminis.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.brightcove.com" to-ports="*" secure="false" /> ...[SNIP]... <allow-access-from domain="*.lightningcast.com" to-ports="*" secure="false" /> ...[SNIP]... |