2. Cross-site scripting (reflected)
3. Cookie scoped to parent domain
3.2. http://www.groupon.com/contact-us
3.3. http://www.groupon.com/san-jose/
3.4. http://www.groupon.com/san-jose/deals/pure-barre-los-gatos-1
3.5. http://www.groupon.com/user_demographics/demographic_form_banner.html
3.6. http://www.groupon.com/user_demographics/dismiss
3.7. http://www.groupon.com/user_demographics/update_with_optional_subscription
4. Cross-domain Referer leakage
5. Cross-domain script include
5.1. http://www.groupon.com/contact-us
5.2. http://www.groupon.com/san-jose/
5.3. http://www.groupon.com/san-jose/deals/pure-barre-los-gatos-1
6. Cookie without HttpOnly flag set
6.2. http://www.groupon.com/contact-us
6.3. http://www.groupon.com/san-jose/
6.4. http://www.groupon.com/san-jose/deals/pure-barre-los-gatos-1
6.5. http://www.groupon.com/user_demographics/demographic_form_banner.html
6.6. http://www.groupon.com/user_demographics/dismiss
6.7. http://www.groupon.com/user_demographics/update_with_optional_subscription
8. Content type incorrectly stated
Severity: | High |
Confidence: | Tentative |
Host: | http://www.groupon.com |
Path: | /user_demographics |
GET /user_demographics Host: www.groupon.com Proxy-Connection: keep-alive Referer: http://www.groupon.com x-requested-with: XMLHttpRequest content-type: application/x-www-form accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 500 Internal Server Error Server: nginx/0.7.65 Content-Type: text/html Content-Length: 30917 Age: 4 Date: Tue, 01 Mar 2011 19:26:30 GMT Expires: Tue, 01 Mar 2011 19:26:36 GMT Connection: keep-alive <!DOCTYPE html> <!--[if lt IE 7 ]> <html class="ie6" lang="en" xmlns:fb="http://www <!--[if IE 7 ]> <html class="ie7" lang="en" xmlns:fb="http://www <!--[if IE 8 ]> <html class="ie8" lang="en" xmlns:fb="http://www <!--[if IE 9 ]> <html class="ie9" lang="en" xmlns:fb="http://www <!--[if (gt IE 9)|!(IE)]><!--> <html lang='en' xmlns:fb='http://www <!--<![endif]--> <head> <link href='http://assets1 <script type="text/javascript" <script type='text/javascript'> //<![CDATA[ Finch = { onReady : function(f) { this.onReadyFunctions = this.onReadyFunctions || []; this.onReadyFunctions }, execute : function() { if (!this.onReadyFunctions) return; for (i=0; i<this.onReadyFunctions this.onReadyFunctions[i] } } }; //]]> </script> <script type='text/javascript'> //<![CDATA[ var _groanalytics = _groanalytics || []; //]]> </script> <script type='text/javascript'> //<![CDATA[ //Chartbeat var _sf_startpt=(new Date()).getTime(); //]]> </script> <title>Something broke...</title> <meta content='text/html <link href="http://feeds <link href="http://assets1 <!--[if IE 6]> <link href="http://assets1 <![endif]--> <!--[if lte IE 7]> <![endif]--> <link href='http://assets1 </head> <body class=' '> <div class='clearfix default' id='global_container'> <script type='text/javascript'> //<![CDATA[ document.body.className += " js_enabled"; //]]> </script> <span class="js_attribute" data-value="production" id="env" style="display:none;">< <span class="js_attribute" data-value="false" id="mobile_device" style="display:none;">< <div id='fb-root'></div> <span class='js_attribute' data-value='7829106395' id='facebook_appid'>< <script type='text/javascript'> //<![CDATA[ (function() { var e = document.createElement( e.src = document.location document.getElementById( }()); //]]> </script> <div class='inserted_tracking </div> <div id='drawer'> <div id='drawer_inner'> <div id='follow_drawer' style='display: block;'> <a href="#" class="hide" id="hide_follow">hide</a> <div id='follow_drawer_inner'> <div class='follow_container clearfix'> <div class='follow_desc'> Get the Daily Deal for: </div> <form action="http://www <ul class='subscribe clearfix'> <li class='label'> <select id='subscription_division <option value='abbotsford' <option value='abilene'>Abilene, TX</option> <option value='akron-canton' <option value='albany-capital <option value='albany-ga'>Albany, GA</option> <option value='albuquerque' <option value='allentown <option value='amarillo'>Amarillo <option value='anchorage' <option value='ann-arbor'>Ann Arbor</option> <option value='appleton'>Appleton <option value='asheville' <option value='athens-ga'>Athens, GA</option> <option value='atlanta'>Atlanta< <option value='augusta'>Augusta< <option value='austin'>Austin< <option value='bakersfield' <option value='baltimore' <option value='barrie'>Barrie< <option value='baton-rouge'>Baton Rouge</option> <option value='beaumont'>Beaumont <option value='billings'>Billings <option value='birmingham' <option value='bloomington-in' <option value='boise'>Boise< <option value='boston'>Boston< <option value='buffalo'>Buffalo< <option value='calgary'>Calgary< <option value='cape-breton'>Cape Breton</option> <option value='cedar-rapids-iowa <option value='central-jersey' <option value='charleston' <option value='charleston-wv' <option value='charlotte' <option value='chattanooga' <option selected='selected' value='chicago'>Chicago< <option value='cincinnati' <option value='cleveland' <option value='colorado-springs' <option value='columbia'>Columbia <option value='columbia-mo' <option value='columbus'>Columbus <option value='columbus-ga' <option value='corpus-christi' <option value='dallas'>Dallas< <option value='dayton'>Dayton< <option value='daytona-beach' <option value='denver'>Denver< <option value='des-moines'>Des Moines</option> <option value='detroit'>Detroit< <option value='edmonton'>Edmonton <option value='el-paso'>El Paso</option> <option value='erie'>Erie</option <option value='eugene'>Eugene< <option value='evansville' <option value='fairfield-county' <option value='fayetteville' <option value='fort-lauderdale' <option value='fort-myers-cape <option value='fort-wayne'>Fort Wayne</option> <option value='fort-worth'>Fort Worth</option> <option value='fresno'>Fresno< <option value='gainesville' <option value='grand-rapids' <option value='greater-toronto <option value='green-bay'>Green Bay</option> <option value='greenville' <option value='halifax'>Halifax< <option value='hampton-roads' <option value='harrisburg' <option value='hartford'>Hartford <option value='honolulu'>Honolulu <option value='houston'>Houston< <option value='huntsville' <option value='indianapolis' <option value='inland-empire' <option value='jackson'>Jackson< <option value='jacksonville' <option value='kalamazoo' <option value='kansas-city' <option value='kelowna'>Kelowna< <option value='kingston'>Kingston <option value='kitchener-waterloo <option value='knoxville' <option value='lakeland'>Lakeland <option value='lancaster-pa' <option value='lansing'>Lansing< <option value='las-vegas'>Las Vegas</option> <option value='lexington' <option value='lincoln'>Lincoln< <option value='little-rock' <option value='london'>London, ON</option> <option value='long-island'>Long Island</option> <optgroup label='Los Angeles'> <option value='los-angeles:los <option value='los-angeles:san <option value='los-angeles:san </optgroup> <option value='louisville' <option value='lubbock'>Lubbock< <option value='macon'>Macon< <option value='madison'>Madison< <option value='memphis'>Memphis< <option value='miami'>Miami< <option value='midland-odessa' <option value='milwaukee' <option value='minneapolis-stpaul <option value='mobile-baldwin <option value='modesto'>Modesto< <option value='montgomery' <option value='napa-sonoma'>Napa / Sonoma</option> <option value='naples'>Naples< <option value='nashville' <option value='new-orleans'>New Orleans</option> <option value='new-york'>New York City</option> <option value='north-jersey' <option value='ocala'>Ocala< <option value='ogden'>Ogden< <option value='oklahoma-city' <option value='omaha'>Omaha< <option value='orange-county' <option value='orlando'>Orlando< <option value='ottawa'>Ottawa< <option value='palm-beach'>Palm Beach</option> <option value='pensacola' <option value='philadelphia' <option value='phoenix'>Phoenix< <option value='piedmont-triad' <option value='pittsburgh' <option value='portland'>Portland <option value='portland-me' <option value='providence' <option value='raleigh-durham' <option value='reading'>Reading< <option value='regina'>Regina< <option value='reno'>Reno</option <option value='richmond'>Richmond <option value='rio-grande-valley' <option value='roanoke'>Roanoke< <option value='rochester' <option value='rockford'>Rockford <option value='sacramento' <option value='salem-or'>Salem OR</option> <option value='salt-lake-city' <option value='san-angelo'>San Angelo</option> <option value='san-antonio'>San Antonio</option> <option value='san-diego'>San Diego</option> <optgroup label='San Francisco'> <option value='san-francisco:san <option value='san-francisco:east </optgroup> <option value='san-jose'>San Jose</option> <option value='santa-barbara' <option value='santa-clarita' <option value='santa-cruz'>Santa Cruz</option> <option value='santa-fe'>Santa Fe</option> <option value='saskatoon' <option value='savannah-hilton <optgroup label='Seattle'> <option value='seattle:tacoma' <option value='seattle:seattle' </optgroup> <option value='shreveport-bossier <option value='sioux-falls'>Sioux Falls</option> <option value='south-bend'>South Bend</option> <option value='spokane-coeur <option value='springfield-mo' <option value='springfield-ma' <option value='stcatharines <option value='st-johns'>St John's</option> <option value='stlouis'>St Louis</option> <option value='stockton'>Stockton <option value='sudbury'>Sudbury< <option value='syracuse'>Syracuse <option value='tallahassee' <option value='tampa-bay-area' <option value='toledo'>Toledo< <option value='topeka-lawrence' <option value='tucson'>Tucson< <option value='tulsa'>Tulsa< <option value='vancouver' <option value='ventura-county' <option value='victoria'>Victoria <optgroup label='Washington DC'> <option value='washington-dc:dc <option value='washington-dc <option value='washington-dc </optgroup> <option value='westchester-county <option value='wichita'>Wichita< <option value='wilmington-newark' <option value='windsor'>Windsor< <option value='winnipeg'>Winnipeg <option value='worcester' <option value='york-pa'>York, PA</option> <option value='youngstown' </select> <div class="field subscription_email </li> <li> <input class='button cta_btn small G_event E-Subscribe_Email_Header disabled_on_submit' type='submit' value='Subscribe' /> </li> </ul> </form> </div> </div> </div> </div> </div> <div id='header_container'> <div id='header'> <div id='header_inner'> <h1 id='logo'> <a href="/" class="G_event E-LogoNH_click_group </h1> <div class='layer2 clearfix'> <ul id='header_nav'> <li class=''> <a href="/" class="G_event E-GobalTopNavNH <li> <a href="/chicago/all">All Deals</a> <!-- - if feature_enabled?( <!-- %ul.subnav --> <!-- %li= link_to "Local Deals", local_deals_path( <!-- - Channel.active.each do |channel| --> <!-- %li= link_to channel.name, channel_path(channel, :division => division), :class => ('current' if current_page?(channel </li> </li> <li><a href="/learn" class="G_event E-GobalTopNavNH_HowWorks </ul> <ul class='account_links'> <li class='sign_in'><a href="https://www.groupon <li><a href="https://www.groupon </ul> </div> </div> </div> </div> <div id='alerts_content'> </div> <div class='clearfix' id='main'> <div id='content'> <div class='doc'> <div class="box"><div class="box_top"></div> <h2>Something broke...</h2> </div> <div class='page_content'> <p>It appears that we are currently experiencing technical difficulties. We are working to correct the issue right now and should be back up soon. We apologize for the inconvenience.</p> </div> </div><div class="box_bottom"></div> </div> </div> <div id='footer'> <div class='footer_wrapper_top <div class='footer'> <div class='top clearfix'> <ul class='clearfix'> <li> <dl> <dt class='bucket mobile'> <a href="/mobile"><span>< </dt> <dd> The Groupon Mobile family is like having a digital wallet for your Groupons. <a href="/mobile" title="Groupon Mobile">Go mobile</a> </dd> </dl> </li> <li> <dl> <dt class='bucket log'> <a href="/pages/affiliates"> </dt> <dd> Get paid by spreading the Groupon word with the <a href="/pages/affiliates" title="Groupon Affiliates">Groupon Affiliate Program</a> </dd> </dl> </li> <li> <dl> <dt class='bucket works'> <a href="http://www </dt> <dd> Learn how to get your business featured on Groupon and enjoy the benefits. <a href="http://www </dd> </dl> </li> <li> <dl> <dt class='bucket gift'> <a href="https://my.groupon </dt> <dd> Show your love by giving Today's Deal or a Groupon Gift Card. <a href="https://my.groupon </dd> </dl> </li> <li> <div class='follow_us clearfix'> <dl> <dt>Follow Us:</dt> <dd><a href="http://www.twitter <dd><a href="http://www.facebook <dd><a href="http://feeds <dd><a href="/subscribe" class="sprite email">Sign Up for Groupon</a></dd> </dl> </div> <div class="tot_board"><p </li> </ul> </div> </div> </div> <div class='footer_wrapper <div class='footer'> <div class='bottom clearfix'> <ul> <li> <dl> <dt>Company</dt> <dd><a href="/">Home</a></dd> <dd><a href="/contact-us" <dd><a href="/about">About Groupon</a></dd> <dd><a href="/jobs">Jobs at Groupon</a></dd> <dd><a href="/press">Press</a>< <dd><a href="/legal">Legal</a>< <dd><a href="/privacy">Privacy Policy</a></dd> </dl> </li> <li> <dl> <dt>Learn More</dt> <dd><a href="/faq">FAQ</a></dd> <dd><a href="/pages/api" <dd><a href="/pages/affiliates" <dd><a href="/affiliate_widget" <dd><a href="/pages/suggestions" <dd><a href="/merchants/welcome" <dd><a href="/pages/corporate </dl> </li> <li> <dl> <dt>Extra</dt> <dd><a href="http://www.groupon <dd><a href="http://www <dd><a href="/mobile">Groupon Mobile</a></dd> <dd><a href="/widget">Groupon Referral Widget</a></dd> <dd><a href="/referral-ads" |