1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
2.1. http://www.jcpenney.com/jcp/emailupdates.aspx
2.2. http://www.jcpenney.com/jcp/jcpRoute.aspx
2.3. http://www.jcpenney.com/jcp/mobile1.aspx
2.4. http://www.jcpenney.com/giftcards
3. Cookie without HttpOnly flag set
3.1. http://www.jcpenney.com/jcp/emailupdates.aspx
3.2. http://www.jcpenney.com/jcp/jcpRoute.aspx
3.3. http://www.jcpenney.com/jcp/mobile1.aspx
3.4. http://www.jcpenney.com/giftcards
4. Cross-domain Referer leakage
4.1. http://www.jcpenney.com/jcp/X2.aspx
4.2. http://www.jcpenney.com/jcp/emailupdates.aspx
4.3. http://www.jcpenney.com/jcp/getjcpheaderc.aspx
5. Cross-domain script include
5.1. http://www.jcpenney.com/jcp/X2.aspx
5.2. http://www.jcpenney.com/jcp/default.aspx
5.3. http://www.jcpenney.com/jcp/emailupdates.aspx
5.4. http://www.jcpenney.com/jcp/jcpRoute.aspx
6. HTML does not specify charset
6.1. http://www.jcpenney.com/products/C00469.jsp
6.2. http://www.jcpenney.com/products/C00597.jsp
6.3. http://www.jcpenney.com/products/C11848.jsp
6.4. http://www.jcpenney.com/products/C25437.jsp
6.5. http://www.jcpenney.com/products/C25439.jsp
6.6. http://www.jcpenney.com/products/C40379.jsp
6.7. http://www.jcpenney.com/products/C40380.jsp
6.8. http://www.jcpenney.com/products/C40525.jsp
6.9. http://www.jcpenney.com/products/index.html
Severity: | High |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/getjcpheaderc.aspx |
GET /jcp/getjcpheaderc.aspx Host: www.jcpenney.com Proxy-Connection: keep-alive Referer: http://www.jcpenney.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: stop_mobi=yes; AKJCP=CT-1 |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Cache-Control: private Expires: Sun, 13 Feb 2011 04:15:48 GMT Content-Type: text/html; charset=utf-8 ntCoent-Length: 56 Date: Sat, 12 Feb 2011 16:15:48 GMT Connection: close Vary: Accept-Encoding Content-Length: 56 Error function : getmenuitemsa88b0;alert(1)/ |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.jcpenney.com |
Path: | /jcp/emailupdates.aspx |
GET /jcp/emailupdates.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 29186 Expires: Sat, 12 Feb 2011 16:51:06 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:06 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Content-Length: 29186 <html><head><title <script type='text/JavaScript' src='http://www5.jcpenney <script language=J ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.jcpenney.com |
Path: | /jcp/jcpRoute.aspx |
GET /jcp/jcpRoute.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 27437 Expires: Sat, 12 Feb 2011 16:51:34 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:34 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Set-Cookie: JCPCluster=www5.jcpenney Content-Length: 27437 <HTML> <HEAD> <TITLE>JCPenney - Partner Site Unavailable</TITLE> </HEAD> <BODY BGCOLOR=#FFFFFF LEFTMARGIN=4 MARGINWIDTH=4 MARGINHEIGHT=4 TOPMARGIN=4> <script type="text/javascript" src= ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.jcpenney.com |
Path: | /jcp/mobile1.aspx |
GET /jcp/mobile1.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 30199 Expires: Sat, 12 Feb 2011 16:50:56 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:50:56 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Content-Length: 30199 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"><HTML> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /giftcards |
GET /giftcards HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 302 Moved Temporarily Server: Microsoft-IIS/6.0 Content-Type: text/html Location: http://www.jcpenney.com X-Powered-By: ASP.NET Vary: Accept-Encoding RTSS: 1 Expires: Sat, 12 Feb 2011 16:51:57 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:57 GMT Connection: close Set-Cookie: SSLB=0; path=/; domain=.jcpenney.com Set-Cookie: SSID=AwBfwSkAAAAArLp Set-Cookie: SSSC=46.G55728468369 Set-Cookie: SSRT=rLpWTQA; path=/; domain=.jcpenney.com; expires=Sun, 12-Feb-2012 16:51:56 GMT Content-Length: 306 <head><title>Document Moved</title></head> <body><h1>Object Moved</h1>This document may be found <a HREF="http://www.jcpenney ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.jcpenney.com |
Path: | /jcp/emailupdates.aspx |
GET /jcp/emailupdates.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 29186 Expires: Sat, 12 Feb 2011 16:51:06 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:06 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Content-Length: 29186 <html><head><title <script type='text/JavaScript' src='http://www5.jcpenney <script language=J ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.jcpenney.com |
Path: | /jcp/jcpRoute.aspx |
GET /jcp/jcpRoute.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 27437 Expires: Sat, 12 Feb 2011 16:51:34 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:34 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Set-Cookie: JCPCluster=www5.jcpenney Content-Length: 27437 <HTML> <HEAD> <TITLE>JCPenney - Partner Site Unavailable</TITLE> </HEAD> <BODY BGCOLOR=#FFFFFF LEFTMARGIN=4 MARGINWIDTH=4 MARGINHEIGHT=4 TOPMARGIN=4> <script type="text/javascript" src= ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.jcpenney.com |
Path: | /jcp/mobile1.aspx |
GET /jcp/mobile1.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 30199 Expires: Sat, 12 Feb 2011 16:50:56 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:50:56 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Content-Length: 30199 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"><HTML> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /giftcards |
GET /giftcards HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 302 Moved Temporarily Server: Microsoft-IIS/6.0 Content-Type: text/html Location: http://www.jcpenney.com X-Powered-By: ASP.NET Vary: Accept-Encoding RTSS: 1 Expires: Sat, 12 Feb 2011 16:51:57 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:57 GMT Connection: close Set-Cookie: SSLB=0; path=/; domain=.jcpenney.com Set-Cookie: SSID=AwBfwSkAAAAArLp Set-Cookie: SSSC=46.G55728468369 Set-Cookie: SSRT=rLpWTQA; path=/; domain=.jcpenney.com; expires=Sun, 12-Feb-2012 16:51:56 GMT Content-Length: 306 <head><title>Document Moved</title></head> <body><h1>Object Moved</h1>This document may be found <a HREF="http://www.jcpenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/X2.aspx |
GET /jcp/X2.aspx?DeptID=70660 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Pragma: no-cache Content-Type: text/html; charset=utf-8 ntCoent-Length: 38111 Cache-Control: no-cache Expires: Sat, 12 Feb 2011 16:51:25 GMT Date: Sat, 12 Feb 2011 16:51:25 GMT Connection: close Connection: Transfer-Encoding Content-Length: 38111 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML> <HEAD> <title id="PageTitle">JCPenney : american living</title> <meta name="vs_defaultClie ...[SNIP]... <BODY style="MARGIN: 4px" BGCOLOR="#ffffff" > <script type="text/javascript" src="http://media ...[SNIP]... <div id="pbRepeater_ctl01 ...[SNIP]... <noscript><iframe src="http://switch.atdmt ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/emailupdates.aspx |
GET /jcp/emailupdates.aspx Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 29186 Expires: Sat, 12 Feb 2011 16:51:10 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Content-Length: 29186 <html><head><title <script type='text/JavaScript' src='http://www5.jcpenney <script language=J ...[SNIP]... <div id="pbRepeater_ctl01 ...[SNIP]... cpenney.com/jcp <script type="text/javascript" src="http://media ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/getjcpheaderc.aspx |
GET /jcp/getjcpheaderc.aspx Host: www.jcpenney.com Proxy-Connection: keep-alive Referer: http://www.jcpenney.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: stop_mobi=yes; AKJCP=CT-1 |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Cache-Control: private Expires: Sat, 12 Feb 2011 23:20:32 GMT Content-Type: text/html; charset=utf-8 Date: Sat, 12 Feb 2011 16:15:45 GMT Connection: close Vary: Accept-Encoding Content-Length: 92387 <div id="rptTabItem_ctl00_tab <div id="rptTabItem_ctl00_Div1 <div id="rptTabItem_ctl00 ...[SNIP]... <li id="rptTabItem_ctl08 <a id="rptTabItem_ctl08 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/X2.aspx |
GET /jcp/X2.aspx?DeptID=70660 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Pragma: no-cache Content-Type: text/html; charset=utf-8 ntCoent-Length: 38111 Cache-Control: no-cache Expires: Sat, 12 Feb 2011 16:51:25 GMT Date: Sat, 12 Feb 2011 16:51:25 GMT Connection: close Connection: Transfer-Encoding Content-Length: 38111 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML> <HEAD> <title id="PageTitle">JCPenney : american living</title> <meta name="vs_defaultClie ...[SNIP]... <BODY style="MARGIN: 4px" BGCOLOR="#ffffff" > <script type="text/javascript" src="http://media ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/default.aspx |
GET /jcp/default.aspx HTTP/1.1 Host: www.jcpenney.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: stop_mobi=yes |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Pragma: no-cache Content-Type: text/html; charset=utf-8 ntCoent-Length: 37591 Cache-Control: no-cache Expires: Sat, 12 Feb 2011 16:15:42 GMT Date: Sat, 12 Feb 2011 16:15:42 GMT Connection: close Vary: Accept-Encoding Content-Length: 37591 <SCRIPT LANGUAGE=Javascript> <!-- function PopupWindow(pagename) { var popWind; //Close the popup window if it's currently open if (popWind && (navigator.appName == "Microsoft Interne ...[SNIP]... </script> <script type="text/javascript" src="http://media ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/emailupdates.aspx |
GET /jcp/emailupdates.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 29186 Expires: Sat, 12 Feb 2011 16:51:06 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:06 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Content-Length: 29186 <html><head><title <script type='text/JavaScript' src='http://www5.jcpenney <script language=J ...[SNIP]... cpenney.com/jcp <script type="text/javascript" src="http://media ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /jcp/jcpRoute.aspx |
GET /jcp/jcpRoute.aspx HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: CP="CAO DSP COR CURa DEVa PSAa IVAa OURa IND UNI NAV STA OTC" Content-Type: text/html; charset=utf-8 ntCoent-Length: 27437 Expires: Sat, 12 Feb 2011 16:51:34 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:51:34 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: JCPSession=ShopperID Set-Cookie: IsFirstTime=Y; domain=.jcpenney.com; path=/jcp Set-Cookie: JCPCluster=www5.jcpenney Content-Length: 27437 <HTML> <HEAD> <TITLE>JCPenney - Partner Site Unavailable</TITLE> </HEAD> <BODY BGCOLOR=#FFFFFF LEFTMARGIN=4 MARGINWIDTH=4 MARGINHEIGHT=4 TOPMARGIN=4> <script type="text/javascript" src="http://media ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C00469.jsp |
GET /products/C00469.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "97941fae230542852a4 Last-Modified: Fri, 11 Feb 2011 15:31:25 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:21 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:21 GMT Connection: close Connection: Transfer-Encoding Content-Length: 104564 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 00469 (2011-02-11 09:31:18 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C00597.jsp |
GET /products/C00597.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "13eec31429734da9dac Last-Modified: Fri, 11 Feb 2011 15:31:07 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:07 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:07 GMT Connection: close Connection: Transfer-Encoding Content-Length: 101152 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 00597 (2011-02-11 09:30:59 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C11848.jsp |
GET /products/C11848.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "d529ec4eb4eb25cedd1 Last-Modified: Fri, 11 Feb 2011 15:30:44 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:19 GMT Connection: close Connection: Transfer-Encoding Content-Length: 99347 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 11848 (2011-02-11 09:30:32 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C25437.jsp |
GET /products/C25437.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "d3219b1432dc07013d7 Last-Modified: Fri, 11 Feb 2011 15:31:10 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:27 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:27 GMT Connection: close Connection: Transfer-Encoding Content-Length: 81784 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 25437 (2011-02-11 09:31:07 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C25439.jsp |
GET /products/C25439.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "d54587e31f41ff02974 Last-Modified: Fri, 11 Feb 2011 15:31:18 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:30 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:30 GMT Connection: close Connection: Transfer-Encoding Content-Length: 84825 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 25439 (2011-02-11 09:31:12 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C40379.jsp |
GET /products/C40379.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "b53093db60be8c689e2 Last-Modified: Fri, 11 Feb 2011 15:30:55 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:10 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:10 GMT Connection: close Connection: Transfer-Encoding Content-Length: 88724 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 40379 (2011-02-11 09:30:50 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C40380.jsp |
GET /products/C40380.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "a75eeb7697ca0900d4b Last-Modified: Fri, 11 Feb 2011 15:29:02 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:16 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:16 GMT Connection: close Connection: Transfer-Encoding Content-Length: 95730 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 40380 (2011-02-11 09:28:51 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/C40525.jsp |
GET /products/C40525.jsp HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "393068199654dff7899 Last-Modified: Fri, 11 Feb 2011 15:30:06 GMT Content-Type: text/html Expires: Sat, 12 Feb 2011 16:52:28 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 12 Feb 2011 16:52:28 GMT Connection: close Connection: Transfer-Encoding Content-Length: 87001 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html xmlns="http://www.w3.org <head id="Head1"> <!-- CATEGORY 40525 (2011-02-11 09:30:00 CST) --> <title>JCPenney ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.jcpenney.com |
Path: | /products/index.html |
GET /products/index.html HTTP/1.1 Host: www.jcpenney.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: AKJCP=3WeCbFQDPaRDTU9MM4J |
HTTP/1.1 200 OK Server: Apache ETag: "5525ce7238e98bdb5ff Last-Modified: Fri, 11 Feb 2011 15:32:44 GMT Content-Type: text/html Date: Sat, 12 Feb 2011 16:51:59 GMT Connection: close Connection: Transfer-Encoding Content-Length: 398452 <html> <head> <!-- JCPenney Index Page (2011-02-11 09:31:36 CST) --> <title>JCPenney: Women's Clothing, Men's Clothing, Furniture, Women's & Men's Jewelry, Home Decor, Furniture</title> ...[SNIP]... |