1. Cross-site scripting (reflected)
2.1. http://www.savvis.com/assets/scripts/js/jquery.bgiframe.js
2.2. http://www.savvis.com/assets/scripts/js/jquery.dimensions.js
2.3. http://www.savvis.com/assets/scripts/js/jquery.hoverintent.js
2.4. http://www.savvis.com/assets/shadowbox/shadowbox.js
2.5. http://www.savvis.com/assets/shadowbox/skin/classic/skin.css
2.6. http://www.savvis.com/assets/shadowbox/skin/classic/skin.js
Severity: | High |
Confidence: | Certain |
Host: | http://www.savvis.com |
Path: | /_layouts/SavvisUtilities |
GET /_layouts/SavvisUtilities Host: www.savvis.com Proxy-Connection: keep-alive Referer: http://www.savvis.com/en X-Requested-With: XMLHttpRequest Accept: text/html, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISAWPLB{D019C4BA-90BB |
HTTP/1.1 200 OK Connection: Keep-Alive Expires: Fri, 04 Mar 2011 02:14:19 GMT Date: Fri, 04 Mar 2011 02:15:19 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 MicrosoftSharePointT X-Server: EW06 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Cache-Control: private Vary: Accept-Encoding Content-Length: 175 <p id="breadcrumb" |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.savvis.com |
Path: | /assets/scripts/js/jquery |
GET /assets/scripts/js/jquery Host: www.savvis.com Proxy-Connection: keep-alive Referer: http://www.savvis.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISAWPLB{D019C4BA-90BB |
HTTP/1.1 200 OK Connection: Keep-Alive Content-Length: 4825 Date: Fri, 04 Mar 2011 02:13:34 GMT Content-Type: application/x-javascript ETag: "{1AFB43C9-11D7-4D1C-AE61 Server: Microsoft-IIS/6.0 MicrosoftSharePointT X-Server: EW06 X-Powered-By: ASP.NET Last-Modified: Wed, 16 Feb 2011 05:01:32 GMT ResourceTag: rt:1AFB43C9-11D7-4D1C Exires: Thu, 17 Feb 2011 02:13:34 GMT Cache-Control: private,max-age=0 Public-Extension: http://schemas.microsoft /* Copyright (c) 2006 Brandon Aaron (http://brandonaaron.net) * Dual licensed under the MIT (http://www.opensource * and GPL (http://www.opensource ...[SNIP]... ided so that one could change * the src of the iframe to whatever they need. * Default: "javascript:false;" * * @name bgiframe * @type jQuery * @cat Plugins/bgiframe * @author Brandon Aaron (brandon.aaron@gmail.com || http://brandonaaron.net) */ $.fn.bgIframe = $.fn.bgiframe = function(s) { // This is only for IE6 if ( $.browser.msie && /6.0/.test(navigator s = $.extend({ top : 'auto', ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.savvis.com |
Path: | /assets/scripts/js/jquery |
GET /assets/scripts/js/jquery Host: www.savvis.com Proxy-Connection: keep-alive Referer: http://www.savvis.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISAWPLB{D019C4BA-90BB |
HTTP/1.1 200 OK Connection: Keep-Alive Content-Length: 3523 Date: Fri, 04 Mar 2011 02:13:34 GMT Content-Type: application/x-javascript ETag: "{9F9A09C1-C51B-4F8B-8799 Server: Microsoft-IIS/6.0 MicrosoftSharePointT X-Server: EW06 X-Powered-By: ASP.NET Last-Modified: Wed, 16 Feb 2011 05:01:32 GMT ResourceTag: rt:9F9A09C1-C51B-4F8B Exires: Thu, 17 Feb 2011 02:13:34 GMT Cache-Control: private,max-age=0 Public-Extension: http://schemas.microsoft /* Copyright (c) 2007 Paul Bakaus (paul.bakaus@googlemail * Dual licensed under the MIT (http://www.opensource * and GPL (http://www.opensource * * $LastCha ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.savvis.com |
Path: | /assets/scripts/js/jquery |
GET /assets/scripts/js/jquery Host: www.savvis.com Proxy-Connection: keep-alive Referer: http://www.savvis.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISAWPLB{D019C4BA-90BB |
HTTP/1.1 200 OK Connection: Keep-Alive Content-Length: 1606 Date: Fri, 04 Mar 2011 02:13:33 GMT Content-Type: application/x-javascript ETag: "{7C340466-C5A0-4EC3-A102 Server: Microsoft-IIS/6.0 MicrosoftSharePointT X-Server: EW06 X-Powered-By: ASP.NET Last-Modified: Fri, 31 Dec 2010 01:38:05 GMT ResourceTag: rt:7C340466-C5A0-4EC3 Exires: Thu, 17 Feb 2011 02:13:33 GMT Cache-Control: private,max-age=0 Public-Extension: http://schemas.microsoft /** * hoverIntent r5 // 2007.03.27 // jQuery 1.1.2+ * <http://cherne.net/brian * * @param f onMouseOver function || An object with configuration options * @param ...[SNIP]... <brian@cherne.net> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.savvis.com |
Path: | /assets/shadowbox |
GET /assets/shadowbox Host: www.savvis.com Proxy-Connection: keep-alive Referer: http://www.savvis.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISAWPLB{D019C4BA-90BB |
HTTP/1.1 200 OK Connection: Keep-Alive Content-Length: 71504 Date: Fri, 04 Mar 2011 02:13:35 GMT Content-Type: application/x-javascript ETag: "{1B575407-C135-4468-8137 Server: Microsoft-IIS/6.0 MicrosoftSharePointT X-Server: EW06 X-Powered-By: ASP.NET Last-Modified: Wed, 16 Feb 2011 05:01:32 GMT ResourceTag: rt:1B575407-C135-4468 Exires: Thu, 17 Feb 2011 02:13:35 GMT Cache-Control: private,max-age=0 Public-Extension: http://schemas.microsoft /** * The Shadowbox class. * * This file is part of Shadowbox. * * Shadowbox is an online media viewer application that supports all of the * web's most popular media publishing formats. Shadowb ...[SNIP]... <mjijackson@gmail.com> ...[SNIP]... <mjijackson@gmail.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.savvis.com |
Path: | /assets/shadowbox/skin |
GET /assets/shadowbox/skin Host: www.savvis.com Proxy-Connection: keep-alive Referer: http://www.savvis.com/en Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISAWPLB{D019C4BA-90BB |
HTTP/1.1 200 OK Connection: Keep-Alive Date: Fri, 04 Mar 2011 02:13:37 GMT Content-Type: text/css ETag: "{3B660B76-75F6-4AE6-8CB3 Server: Microsoft-IIS/6.0 MicrosoftSharePointT X-Server: EW06 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: public, max-age=86400 Vary: Accept-Encoding Content-Length: 5304 /** * The "classic" theme CSS for Shadowbox. * * This file is part of Shadowbox. * * Shadowbox is an online media viewer application that supports all of the * web's most popular media publishin ...[SNIP]... <mjijackson@gmail.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.savvis.com |
Path: | /assets/shadowbox/skin |
GET /assets/shadowbox/skin Host: www.savvis.com Proxy-Connection: keep-alive Referer: http://www.savvis.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISAWPLB{D019C4BA-90BB |
HTTP/1.1 200 OK Connection: Keep-Alive Content-Length: 3495 Date: Fri, 04 Mar 2011 02:13:37 GMT Content-Type: application/x-javascript ETag: "{CA7A4A56-1FE0-4AA6-A1DD Server: Microsoft-IIS/6.0 MicrosoftSharePointT X-Server: EW06 X-Powered-By: ASP.NET Last-Modified: Fri, 31 Dec 2010 01:38:07 GMT ResourceTag: rt:CA7A4A56-1FE0-4AA6 Exires: Thu, 17 Feb 2011 02:13:37 GMT Cache-Control: private,max-age=0 Public-Extension: http://schemas.microsoft /** * The "classic" theme markup for Shadowbox. * * This file is part of Shadowbox. * * Shadowbox is an online media viewer application that supports all of the * web's most popular media publis ...[SNIP]... <mjijackson@gmail.com> ...[SNIP]... |