1. Cross-site scripting (reflected)
1.1. http://www.facebook.com/fetchdog [sk parameter]
1.2. http://www.facebook.com/fetchdog [sk parameter]
Severity: | High |
Confidence: | Firm |
Host: | http://www.facebook.com |
Path: | /fetchdog |
GET /fetchdog?sk=app Host: www.facebook.com Proxy-Connection: keep-alive Referer: http://www.fetchdog.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: campaign_click_url= |
HTTP/1.1 200 OK Cache-Control: private, no-cache, no-store, must-revalidate Expires: Sat, 01 Jan 2000 00:00:00 GMT P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p" Pragma: no-cache Set-Cookie: lsd=OwD2D; path=/; domain=.facebook.com Set-Cookie: noscript=1; path=/; domain=.facebook.com Set-Cookie: reg_ext_ref=http%3A%2F Set-Cookie: reg_fb_gate=http%3A%2F Set-Cookie: reg_fb_ref=http%3A%2F Content-Type: text/html; charset=utf-8 X-Powered-By: HPHP X-FB-Server: 10.52.229.75 X-Cnection: close Date: Wed, 02 Mar 2011 19:24:57 GMT Content-Length: 31164 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... ssage":false,"poke":false onloadRegister(function (){window.__UIContro ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.facebook.com |
Path: | /fetchdog |
GET /fetchdog?sk=app Host: www.facebook.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: campaign_click_url= |
HTTP/1.1 200 OK Cache-Control: private, no-cache, no-store, must-revalidate Expires: Sat, 01 Jan 2000 00:00:00 GMT P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p" Pragma: no-cache Set-Cookie: reg_fb_ref=http%3A%2F Content-Type: text/html; charset=utf-8 X-Powered-By: HPHP X-FB-Server: 10.43.108.45 X-Cnection: close Date: Thu, 03 Mar 2011 01:29:32 GMT Content-Length: 31158 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... sage":false,"poke":false, onloadRegister(function (){window.__UIContro ...[SNIP]... |